|
Most 'hackers' use stolen creditcards # and sign up via an AOL account using an address of the CC's country of origin. If they had enough of it, they post the username/pw on a password site.
People then think their site is hacked while it's not.
If you use Apache 1.23.26 (or higher) and your Linix box doesn't contain all kind of shit that have open ports (webmin etc.) and the box is normally closed with IPChains, you're pretty much done.
Pennywize should then take care of brute force password tries and multiple users logging in from different IP's with the same username and password.
|