Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-04-2006, 01:27 PM   #1
LavenderLounge
Confirmed User
 
LavenderLounge's Avatar
 
Join Date: Apr 2006
Location: San Francisco
Posts: 110
My domain got hacked!

A friend called this morning to tell me my domain, Lavender Lounge dot com got hacked. When I checked, sure enough, there was an image of a gnarling dog and this text:

.:[ LegijaOne Ownz you! ]:.
.:[ by FDCR3W ]:.
.:[ H3LLdOgz on the NET! ]:.

I opened my ftp program and found that my "index.html" file had been renamed "xxxindex.html" and there was a new file named "index.php" with that image imbedded.

All I needed to do was delete those weird files and re-load the right file, and it seems to be alright for now.

I called my host, Webair, and they are checking for security leaks.

I am curious to find out the how's and why's. Has this happended to any of you before?
__________________
LavenderLounge.com - a FUN gay site!
LAVENDER LOUNGE AFFILIATE PROGRAM: http://nats.mygaycash.com/track/1271...6.47.0.0.0.0.0
VintageBareback.com - gay porn 1950s-1970s
MuscleBearCub.com - Unique niche
AFFILIATE PROGRAM FOR VINTAGE BAREBACK AND MUSCLE BEAR CUB: http://www.lavenderlounge.biz
LavenderLounge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 01:36 PM   #2
minusonebit
So Fucking Banned
 
Join Date: Feb 2006
Posts: 7,391
Defacement. Hackers do it for kicks.

At least your hacker was nice enough to leave your files intact and not do rm -rf on your root directory.

Change all of your passwords. Make sure you are using something secure for a password (Firefox's secure password generator plugin with an 18 char password is a good start) and then jump all over your host. Also, if you run a forum, be sure you have updated to the most recent version. Forums (esp. phpBB) are great entry points for hackers.
minusonebit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 01:53 PM   #3
pornguy
Too lazy to set a custom title
 
pornguy's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,911
Webair??? Dman I would expect more from thier stuff.
__________________
PornGuy skype me pornguy_epic

AmateurDough The Hottes Shemales online!
TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME!
pornguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 01:55 PM   #4
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
doesnt look like the domain got hacked, but the hosting got hacked

they have clans doing that for fun ... see who can do the most defacements...
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 01:55 PM   #5
juve20
Confirmed User
 
Join Date: Feb 2005
Location: uk
Posts: 2,542
shit happens!

cheers
tony
juve20 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 02:06 PM   #6
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
maybe your blog software .. what do you use for your blog ? version ?
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 02:09 PM   #7
HairToStay
Confirmed User
 
HairToStay's Avatar
 
Join Date: Oct 2002
Location: Southcoast, Mass.
Posts: 1,521
What programs do you run on the site? What scripts?

There is supposedly a new exploit in Apache but so far I haven't been able to track down specifically what it is, what versions it affects, or how it is executed.
__________________
Make bank by giving your surfers free pics every day and it costs you NOTHING! Use POTD Sponsors to find adult sponsors in more than 75 niches who offer a POTD feature!
HairToStay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 02:16 PM   #8
thricer
Confirmed User
 
Join Date: Dec 2005
Posts: 5,324
you got to hire some security guy to watch out for you server...
__________________
None So
thricer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 02:30 PM   #9
LavenderLounge
Confirmed User
 
LavenderLounge's Avatar
 
Join Date: Apr 2006
Location: San Francisco
Posts: 110
The blog is done with Moveable Type 3.01. Otherwise, the rest of the site is all done in very simple html. I wouldn't know php from pcp, except they both give me a headache.

I had a little javascript on the page from SexMoney that redirected foreign language users. Could that be the problem?
__________________
LavenderLounge.com - a FUN gay site!
LAVENDER LOUNGE AFFILIATE PROGRAM: http://nats.mygaycash.com/track/1271...6.47.0.0.0.0.0
VintageBareback.com - gay porn 1950s-1970s
MuscleBearCub.com - Unique niche
AFFILIATE PROGRAM FOR VINTAGE BAREBACK AND MUSCLE BEAR CUB: http://www.lavenderlounge.biz
LavenderLounge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 03:10 PM   #10
Vox
Confirmed User
 
Vox's Avatar
 
Industry Role:
Join Date: Mar 2002
Location: Montreal
Posts: 2,710
Quote:
Originally Posted by LavenderLounge
The blog is done with Moveable Type 3.01. Otherwise, the rest of the site is all done in very simple html. I wouldn't know php from pcp, except they both give me a headache.

I had a little javascript on the page from SexMoney that redirected foreign language users. Could that be the problem?

There's the culprit: MT 3.01
You need to upgrade to 3.2 ASAP, I've had the same thing happen to me back in November using an older version of MT
__________________
Social profile assassination for hire
Vox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2006, 03:17 PM   #11
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by Vox
There's the culprit: MT 3.01
You need to upgrade to 3.2 ASAP, I've had the same thing happen to me back in November using an older version of MT
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.