|   |   |   | ||||
| Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. | 
|    | 
| 
 | |||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
|  | Thread Tools | 
|  08-30-2007, 10:39 AM | #1 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | 
				
				Fucking Hacker Cunts
			 Some fucker hacked my website and deleted the whole fucking website, fucking hacker scumbags, This is total bullshit, so anybody who has links to my site, it will be back up within 24 hours | 
|   |           | 
|  08-30-2007, 11:12 AM | #2 | 
| Confirmed User Join Date: Jun 2005 Location: ▓NY▓ 
					Posts: 2,080
				 | ouch.... nice directory :X 
				__________________ Each persons' level of stupidity makes us different. | 
|   |           | 
|  08-30-2007, 11:13 AM | #3 | 
| ♥♥♥ Likes Hugs ♥♥♥ Industry Role:  Join Date: Nov 2001 Location: /home 
					Posts: 15,841
				 | If people would secure their shit... Lets start by setting Options -Indexes 
				__________________ I like pie. | 
|   |           | 
|  08-30-2007, 11:28 AM | #4 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Ok so please help me out here with security issues as i am a noob at this game and any security help would really be apreciated | 
|   |           | 
|  08-30-2007, 11:30 AM | #5 | 
| Confirmed User Join Date: May 2007 Location: Sunny Florida 
					Posts: 3,884
				 | that sucks, hope you get it fixed! | 
|   |           | 
|  08-30-2007, 11:31 AM | #6 | 
| ICQ:649699063 Industry Role:  Join Date: Mar 2003 
					Posts: 27,763
				 | yea how do you secure shit? 
				__________________ Send me an email: [email protected] | 
|   |           | 
|  08-30-2007, 11:39 AM | #7 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Thanks, I do regular backups and so does the server, its just so bloody annoying , and inconvenient | 
|   |           | 
|  08-30-2007, 11:42 AM | #8 | 
| Confirmed User Join Date: Aug 2007 
					Posts: 128
				 | black hackers? 
				__________________ 230-699 | 
|   |           | 
|  08-30-2007, 11:43 AM | #9 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | |
|   |           | 
|  08-30-2007, 11:44 AM | #10 | 
| Confirmed User Industry Role:  Join Date: Aug 2005 Location: Austin, TX 
					Posts: 4,258
				 | hackers suck. if you're a hacker reading this, I didn't mean that. please leave my shit alone. 
				__________________   | 
|   |           | 
|  08-30-2007, 11:45 AM | #11 | 
| Too lazy to set a custom title Join Date: Jun 2004 Location: Brasil 
					Posts: 15,778
				 | 1st thing upload and INDEX page to your site! 
				__________________ Do you need cheap, fast and reliable porn website hosting? Host Head is the way to go!! Asian Gay Special | Live on MSN - Live Webcam Chat | Live Adult Webcam Performances | MY SWEET BLACKS LIVE ON CAM Pukka Tranny | Tattooed Shemales | She's A He | Menu Porno | Porn Performances | All Chubby MY ICQ# 169833797 | 
|   |           | 
|  08-30-2007, 11:46 AM | #12 | |
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Quote: 
   | |
|   |           | 
|  08-30-2007, 11:47 AM | #13 | 
| Confirmed User Join Date: Apr 2002 Location: Fl 
					Posts: 1,475
				 | that sucks man hopefully youll get everything up quick. | 
|   |           | 
|  08-30-2007, 11:48 AM | #14 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Thanks im doing that now | 
|   |           | 
|  08-30-2007, 11:51 AM | #15 | 
| Confirmed User Join Date: Oct 2005 Location: Houston 
					Posts: 1,529
				 | Ditch the virtual server and get a decent managed dedicated. 
				__________________ 264-543-302 | 
|   |           | 
|  08-30-2007, 12:02 PM | #16 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | wish i could but i cant afford that I have only had the website on the net for just over 4 months and I have only just started making a few pennies out of it, then all this shit happens | 
|   |           | 
|  08-30-2007, 12:19 PM | #17 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Thanks, should all be up and running again within 24 hours , I have found all sorts of strange files in my public_hml directory, lol and they changed all the directory and file permissions | 
|   |           | 
|  08-30-2007, 12:35 PM | #18 | 
| Good Old Fat Webmaster Industry Role:  Join Date: Jul 2002 Location: Boquete, Panamá 
					Posts: 970
				 | where are you hosting that site? 
				__________________ Whoever dies with most toys wins. | 
|   |           | 
|  08-30-2007, 12:53 PM | #19 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | |
|   |           | 
|  08-30-2007, 01:37 PM | #20 | 
| Confirmed User Join Date: Oct 2002 Location: Southcoast, Mass. 
					Posts: 1,521
				 | What was exploited in this "hack"? | 
|   |           | 
|  08-30-2007, 01:41 PM | #21 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | They deleted the whole website, I have only uploaded the index at the moment, The server host is doing the reinstall as they have the most recent backup of the website | 
|   |           | 
|  08-30-2007, 01:50 PM | #22 | 
| Confirmed User Join Date: Jul 2007 
					Posts: 313
				 | Bad times man... 
				__________________ Vibrators, dildos, cock rings and all other sex toys? We've got them ALL for you. http://venustoys.com | 
|   |           | 
|  08-30-2007, 02:41 PM | #23 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Found some pretty weird files in my public html folder these are some of the names .zshrc .canna | 
|   |           | 
|  08-30-2007, 02:59 PM | #24 | 
| Too lazy to set a koala Industry Role:  Join Date: Jan 2007 Location: CZ/EU forever! 
					Posts: 16,139
				 | funny   
				__________________ | 
|   |           | 
|  08-30-2007, 03:03 PM | #25 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | one of them had all this funny chinese writing in them lol | 
|   |           | 
|  08-30-2007, 03:11 PM | #26 | 
| Confirmed User Join Date: Apr 2003 Location: th3 1nt3Rwebz 
					Posts: 3,153
				 | You's g0t di h4x0r3d 
				__________________ "Unhappy with the riches 'cause you're piss poor morally." Trade traffic? - Highdef Blog | 
|   |           | 
|  08-30-2007, 03:19 PM | #27 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | [QUOTE=Spotter_03;13011354]You's g0t di h4x0r3d   I cannot fault hostgator they have reinstalled evrey thing and done it real quick, really great support from them  | 
|   |           | 
|  08-30-2007, 04:31 PM | #28 | |
| Too lazy to set a custom title Industry Role:  Join Date: Dec 2004 Location: Happy in the dark. 
					Posts: 93,664
				 | Quote: 
  ! 
				__________________ Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Windows VPS now available Great for TSS, Nifty Stats, remote work, virtual assistants, etc. | |
|   |           | 
|  08-30-2007, 04:57 PM | #29 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Thought i would just say a thankyou to hostgator for their great support and change my sig..and maybe get other peeps to sign up   | 
|   |           | 
|  08-30-2007, 05:04 PM | #30 | |
| Confirmed User Industry Role:  Join Date: Mar 2007 
					Posts: 7,771
				 | Quote: 
 Your host should detect the attempts at your password and shut login down and they should have the lastest SSH installed. 
				__________________     | |
|   |           | 
|  08-30-2007, 05:10 PM | #31 | |
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Quote: 
  and i had changed some of the directory and file perrmissions, so I guess this made it much more easyier to hack the site (not your scripts fault btw its was my stupidity i guess) | |
|   |           | 
|  08-30-2007, 07:23 PM | #32 | |
| Confirmed User Industry Role:  Join Date: Mar 2007 
					Posts: 7,771
				 | Quote: 
  Hackers can't do anything with bad file permissions unless they are actually on your server already. File permissions stop other accounts on your server from writing to your files. And if your server is partioned to private virtual account that shit don't even matter because nobody can even get a path to your account to even attempt to write. FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!! But hey, you will not listen...so good luck. 
				__________________     | |
|   |           | 
|  08-30-2007, 07:36 PM | #33 | |
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Quote: 
 Ok i also recieved this from the tech guys "but keep in mind if your scripts have SQL injection or other vulnerabilities this isn't something we can really actively scan for. You'll need to keep any scripts and/or CMS systems you have installed updated to the latest versions" also I was playing with another script which i did install and ran what I said was it had nothing to do with your script..unless you cant read, I also said that it was most probally my stupidy for leaving the directories/files vunrable | |
|   |           | 
|  08-30-2007, 07:44 PM | #34 | |
| Too lazy to set a custom title Industry Role:  Join Date: Oct 2002 Location: Montreal, Quebec 
					Posts: 29,754
				 | Quote: 
 A lot of open source scripts ( Wordpress,joomla,etc...) have holes that hackers use to either change your front page or delete your site. Keep your scipts up-to-date and lower as much as possible the permission of your folders. 
				__________________ I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... | |
|   |           | 
|  08-30-2007, 07:48 PM | #35 | 
| lurker Industry Role:  Join Date: Aug 2002 Location: atlanta 
					Posts: 57,021
				 | man that sucks. | 
|   |           | 
|  08-30-2007, 07:49 PM | #36 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Thank you. The script which i installed was nothing to do with the cgi tube, it was a topsite script, and as sortie stated i could not install his script as it gave me an internal server error and because i was mesing about with scripts I was changing directory perrmissions and did not put them back so this just makes it all the more easeir for some one to do what they did | 
|   |           | 
|  08-30-2007, 10:37 PM | #37 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Haha do you want to know what is funny about this, because pornpf69 sugested i upload my index page before the website was reinstalled I got a signup from my index page,   nothing big, but it was a signup, suppose it was because the users had nowhere else to go on the website but the index page, so after all this crap it actually turned out not so bad, maybe this is the way to go a one page website.....  Thanks guys for your help | 
|   |           | 
|  08-31-2007, 12:14 AM | #38 | 
| Too lazy to set a koala Industry Role:  Join Date: Jan 2007 Location: CZ/EU forever! 
					Posts: 16,139
				 | hey man what about to leave internet and bake some cookies? ;) 
				__________________ | 
|   |           | 
|  08-31-2007, 07:00 AM | #39 | |
| Confirmed User Join Date: Nov 2005 
					Posts: 2,167
				 | Quote: 
 
				__________________ agentGFY *at* gmail.com | |
|   |           | 
|  08-31-2007, 07:10 AM | #40 | |
| Confirmed User Join Date: Oct 2005 Location: Charlotte, NC 
					Posts: 908
				 | Quote: 
 
				__________________ ICQ: 284903372 | |
|   |           | 
|  08-31-2007, 07:12 AM | #41 | |
| sex dwarf Join Date: May 2002 
					Posts: 17,860
				 | Quote: 
 
				__________________ /(bb|[^b]{2})/ | |
|   |           | 
|  08-31-2007, 08:19 AM | #42 | |
| Confirmed User Industry Role:  Join Date: Mar 2007 
					Posts: 7,771
				 | Quote: 
 I would like to know this. Didn't the wordpress hacks etc... all involve the script accepting data from an html page and then executing it, which is a no-no. They fixed that issue as soon as they realized the mistake. I'm serious, please explain. I'm not being sarcastic. If you have this information then please share it so people can protect themselves. 
				__________________     | |
|   |           | 
|  08-31-2007, 08:26 AM | #43 | |
| Confirmed User Industry Role:  Join Date: Mar 2007 
					Posts: 7,771
				 | Quote: 
 They could flood the old version of SSH and cause integer overflow which allowed them server access without a password. What have you seen that was different then that? I mean, if you know then don't keep it a secret and let us all get hacked. 
				__________________     | |
|   |           | 
|  08-31-2007, 09:07 AM | #44 | |
| Confirmed User Industry Role:  Join Date: Mar 2007 
					Posts: 7,771
				 | Quote: 
 http://resources.bravenet.com/articl...php_script s/ Have a good day. 
				__________________     | |
|   |           | 
|  08-31-2007, 10:04 AM | #45 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Hi just an update on what has happened The tech guys sent me this  This appears to be telnet script which allows the user to remove files. I have disabled these scripts from the cgi-bin and blocked the connecting IP. I am also showing that this user connected to the toplist scripts, If this script is not being used, I would recommend removing the toplist scripts from your account. I had an idea it was this stupid topsite script that caused it, the name of the toplist is "Best Top List" so stay away from it it is bad news | 
|   |           | 
|  08-31-2007, 10:13 AM | #46 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | BTW The IP address is showing up from Mauritius Africa but whois is to know that this is their real IP but glad they sorted it  | 
|   |           | 
|  08-31-2007, 11:05 AM | #47 | 
| Confirmed User Join Date: May 2007 
					Posts: 3,119
				 | that shit hurts! sucks 
				__________________ OnProbation Links Directory | OnProbation Design Services | OnProbation Cash | 
|   |           | 
|  08-31-2007, 11:27 AM | #48 | |
| sex dwarf Join Date: May 2002 
					Posts: 17,860
				 | Quote: 
 The reason you always set permissions as low as possible is so that, for example, you have some added security against badly written scripts. Every programmer knows, or should know, that mistakes can and will slip through. By using security at every level, you can prevent those mistakes from becoming disasters. You use low permissions for the same reason you don't keep unencrypted user passwords in your database: to make sure that if someone manages to slip through, he can do as little as possible. 
				__________________ /(bb|[^b]{2})/ | |
|   |           | 
|  08-31-2007, 11:33 AM | #49 | ||
| sex dwarf Join Date: May 2002 
					Posts: 17,860
				 | Quote: Quote: 
 
				__________________ /(bb|[^b]{2})/ | ||
|   |           | 
|  08-31-2007, 11:40 AM | #50 | 
| GFY's Halfpint Industry Role:  Join Date: Jun 2007 Location: UK 
					Posts: 15,223
				 | Yeah its a pain in the arse but most of it was my own fault for installing a crappy script in the first place, it has taught me not to use free scripts and from what i saw of the script that was deleteing my pages it was actually looking for files, it had commands like this 'find suid files' 'find config* files' 'find all writable files' 'find all writable directories' 'find all service.pwd files' 'show opened ports' and a load more, Im not gonna post them all here Pretty mad but I have learned a good lesson from this, like i would never get hacked, its always somebody else, and anyway why would someone hack a small site like mine so just watch what scripts you install | 
|   |           |