Rather than posting this in everyone of the countless threads about the problem, I figured it was best to start a new thread with the solution.
It took me forever, but I "think" I?ve figured this out, they'd been hacking a couple of my sites roughly every other day with that same uniqcount.net code and also with megacount.net as well. (And a few other webmasters I am associated with).
I say "think" because I know how they are doing it (FTP) but I am not certain how they gained the password, so for now it's a partial solution.
Anywhoo, I enabled all of my logs and was checking them each time my site was hacked, but there was absolutely nothing to indicate how they were inserting the code into my index page.. I had removed all unnecessary scripts, updated scripts, you name it, but they were still changing the file. I had cross checked the webmasters sites on this forum plus others that I knew were having this issue, but there were no real similarities other than cPanel.
Then today after it was hacked I looked at my FTP log and BAM, they downloaded the index page and then quickly re-uploaded it. And the phucknut used his own IP address LOL, so after I sent the log to his ISP, he's probably gonna be looking for a new service provider LMAO!
For now I?ve changed my cpanel pass and my ftp pass, and I also went to:
FTP Manager -----> Anonymous FTP Controls (or Setup Anonymous FTP Access) and unchecked "Allow anonymous access to <yoursite.com>"
But what bothers me is that my cpanel/ftp pass was strong to begin with (random upper/lower case plus numbers).
There MUST be some security hole somewhere that allowed them to get that pass, because it would have been nearly impossible to Brute Force. If anyone has any ideas how they could get this pass, let us know.
FYI:
I wanted to join in on the conversation here when I was trying to figure out how they were doing it, but a few users seemed to be a little too ignorant for my tastes. i.e.:
(not meant as a flame, ignorant means uneducated on a subject, if I had wanted to flame I'd have said stupid LOL)
I mean here:
w ww.gofuckyourself.com/showthread.php?t=658360
this dude think that a webmaster would intentionally infect his own site LMFAO!! ya, great way to do business!!
and here:
w ww.gofuckyourself.com/showthread.php?p=10946872#post10946872
w ww.gofuckyourself.com/showthread.php?p=10949238#post10949238
(A guy's asking for help, but apparently this dude doesn't understand that, comments like his make it kind of difficult to engage in productive conversation)
(it also makes it more difficult to figure out the situation when the code is censored out of a post...)
and there are a dozen other threads out there about this, but for some reason there's always someone who thinks these webmasters are putting this code on their site themselves... LOL
It took me forever, but I "think" I?ve figured this out, they'd been hacking a couple of my sites roughly every other day with that same uniqcount.net code and also with megacount.net as well. (And a few other webmasters I am associated with).
I say "think" because I know how they are doing it (FTP) but I am not certain how they gained the password, so for now it's a partial solution.
Anywhoo, I enabled all of my logs and was checking them each time my site was hacked, but there was absolutely nothing to indicate how they were inserting the code into my index page.. I had removed all unnecessary scripts, updated scripts, you name it, but they were still changing the file. I had cross checked the webmasters sites on this forum plus others that I knew were having this issue, but there were no real similarities other than cPanel.
Then today after it was hacked I looked at my FTP log and BAM, they downloaded the index page and then quickly re-uploaded it. And the phucknut used his own IP address LOL, so after I sent the log to his ISP, he's probably gonna be looking for a new service provider LMAO!
For now I?ve changed my cpanel pass and my ftp pass, and I also went to:
FTP Manager -----> Anonymous FTP Controls (or Setup Anonymous FTP Access) and unchecked "Allow anonymous access to <yoursite.com>"
But what bothers me is that my cpanel/ftp pass was strong to begin with (random upper/lower case plus numbers).
There MUST be some security hole somewhere that allowed them to get that pass, because it would have been nearly impossible to Brute Force. If anyone has any ideas how they could get this pass, let us know.
FYI:
I wanted to join in on the conversation here when I was trying to figure out how they were doing it, but a few users seemed to be a little too ignorant for my tastes. i.e.:
(not meant as a flame, ignorant means uneducated on a subject, if I had wanted to flame I'd have said stupid LOL)
I mean here:
w ww.gofuckyourself.com/showthread.php?t=658360
this dude think that a webmaster would intentionally infect his own site LMFAO!! ya, great way to do business!!
and here:
w ww.gofuckyourself.com/showthread.php?p=10946872#post10946872
w ww.gofuckyourself.com/showthread.php?p=10949238#post10949238
(A guy's asking for help, but apparently this dude doesn't understand that, comments like his make it kind of difficult to engage in productive conversation)
(it also makes it more difficult to figure out the situation when the code is censored out of a post...)
and there are a dozen other threads out there about this, but for some reason there's always someone who thinks these webmasters are putting this code on their site themselves... LOL


Comment