![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
ive been hacked need help asap
I come home find all my index.html files were changed to this
<html> <head> <title>Hacked By USG!</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> </head> <body bgcolor="#000000" text="#999999" link="#6666FF"> <center><h3>USG (UNIX Security Guards)</h3></center> <hr> <p> There is no such thing as Jerusalem the capital of Israel</p> <p> There is only one arabic Jerusalem</p> <p> USA I think that you are all about to be some war criminals</p> <p> UK you are a slave to USA</p> <hr> <p align="center"><b>FREE PALESTINE!</b></p> <p align="center"><b>STOP THE PAIN!</b></p> <p> </p> <p>Greetz: AIC (Anti India Crew), WFD (World Fabulous Defacers),DkD, BreaKIce, Rivver, TheBugz, raiden4 and everyone else who fights for the same case.</p> <p> </p> <p align="center"><code> WE Are: Egyptian|Fighter, ShellCode, LinuxLover and rD.</code></p> <p align="center"> </p> <p align="center"><code>rD of USG</code></p> <p align="center"><b> <strong><a href="mailto:[email protected]">[email protected] m</a></strong></b></p> </body> </html> WTF how can this happen anyone know how or what they did to get in?
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
There can be only one
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
|
sorry man... I thought you'd like it.
__________________
SIG TOO BIG |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
salad tossing sig guy
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
|
And did the new front-end convert..?!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
There can be only one
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
|
Quote:
__________________
SIG TOO BIG |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Mar 2001
Location: Florida
Posts: 6,138
|
you're fucked... but seriously you need someone (who know's what they are doing) to take a look at your server.,, hit me up on icq if you need some help finding someone to do so.. 91573698
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
lol
Industry Role:
Join Date: Jan 2002
Posts: 15,969
|
that fucking sucks ass.....
![]() May the force be with you. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
FREAKING terriost or how ever you spell it lmao man that really sucks donkey balls
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Nice Kitty
Industry Role:
Join Date: Sep 2002
Location: The good old USA!!!
Posts: 21,053
|
Va2K I am sorry this happened to you. You seem to be a decent sort and hard working. I hope you can fix the problem ASAP.
![]()
__________________
When you're running down my country hoss...you're walking on the fighting side of me! FOR THE LYING LOWLIFE POSTING AS PATHFINDER...https://gfy.com/fucking-around-and-pr...athfinder.html |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
www.fuckingmature.com this is one out of about 150 sites on my box ARGH@#$@#$@#$@#$#@$$#@#$@#@$$#@
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
|
weird!
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a> Tons of Hosted Galleries. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Jun 2002
Location: Back in the USSA
Posts: 8,849
|
[/COLOR]
__________________
![]() Photos by Ian X.: Distinctive photos of goth babes. Blood Money:Your traffic, my sites, our money. MojoHost: Still the best. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Apr 2002
Location: Virgin - nee
Posts: 3,162
|
Are you prepared to wipe that box and re-load it?
Most likely they left themselves a backdoor. Hunting down that backdoor could take days, while simply reloading could take a few hours. When your sysadmin reappears, tell him you want IPChains set up on the box immediately with Logcheck emailing you every 15 minutes (at least) and all non-essential ports closed down. If you've got telnet on the box, install SSH2 and disable telnet. If you've got anonymous FTP turned on, turn it off. Change all of your passwords - and then do it again at *least* once a month from here on out. If you still can't get a hold of your sysadmin, install this until you can: http://www.pointman.org/PMFirewall/ It's got easy instructions and is just as easy to open up a port if you close it by mistake. Best of luck - and check your logs to find out who these fuckers are so you can fry 'em. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
lol
Industry Role:
Join Date: Jan 2002
Posts: 15,969
|
hey maybe you need to report that somewhere? to some authority?
maybe you can get some free publicity = traffic ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Registered User
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
|
Va2k,
There are some security holes in Cobalt. I'm not familiar with them. We run FreeBSD. Sure hope you got backups. I wear belt and suspenders. Have a complete backup of everything on all three of our PC's. The site www.fuckingmature.com is running Apache/1.3.12 Cobalt (Unix) mod_ssl/2.6.4 OpenSSL/0.9.5a PHP/4.1.2 mod_auth_pam/1.0a FrontPage/4.0.4.3 mod_perl/1.24 We had an NT box get hacked last summer. After we moved all the sitesof it we got a box of shells took it out in the desert and had some fun target practice. Blew the living shit out of it. BTW you can have Full Auto in Nevada. Rock n' Roll. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Registered User
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
|
Va2k,
my icq is 64074953. I can try to help. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: May 2002
Location: MI
Posts: 1,827
|
That information is easy to get...just peep this URL:
Check out www.netcraft.com for more information (Click on "Whats that site running") It will show you information about your webserver and even start keeping tabs about your uptime . Let me just add that the URL above shows nothing that anyone can use OTHER than the information. Hackers are smart, upgrade your packages on your cobalt and get everything up to date. Otherwise upgrade your sites to a newer box, Cobalt RaQ's are notorious for intrusions. Also, the newer version of the cobalt software has ways to notify you of port scans and hack attempts. AJ
__________________
Latest MMA news. http://www.mmawrapup.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Feb 2002
Location: Florida
Posts: 672
|
Encrypt your damn password file!
__________________
- this space intentionally left blank - |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: May 2002
Location: CT
Posts: 5,246
|
That sucks man, seriously get some one who knows what hes doing to take a look at your servers and make sure to stay current with patches
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Ok I need an admin anyone want some $$$ hit me up asap
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Confirmed User
Join Date: Jan 2001
Posts: 3,539
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Jul 2002
Location: Australia
Posts: 121
|
24449990, might be able to help...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Beach
Posts: 5,281
|
if your server is new make sure the root password is changed from the default
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
rockin tha trailerpark
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
|
man thats some terrorism right there
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Registered User
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
|
HiYa AcidMax,
I thought everbody and their dog knew about www.netcraft.com Here are a couple other usefull tools: Dns Traversal http://www.squish.net/dnscheck/ ARIN http://www.arin.net/whois/index.html CyTech http://www.cytechconsult.com/ So Tell your dogs. Trailboss |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
I found who was behind this attack
http://news.bbc.co.uk/1/hi/sci/tech/2052320.stm wtf woudl they pick on someone as little as me ![]()
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
here they are on tech tv http://www.techtv.com/news/security/...392443,00.html http://www.spitcum.com i still havevt gotten all my sites fixed
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
rockin tha trailerpark
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
|
Quote:
![]() Didn't they leave a mail box addy? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
I知 still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Join Date: Jan 2002
Location: anus fuckin' yo mama
Posts: 1,044
|
here's some hints:
turn off all services that are not needed update - update - update - update do not use telnet - use ssh just for example if you need any help icq me at 576 1 0 2 1 I've been running several linux servers for 5 years now have never been hacked (KNOCK ON WOOD HAHA) now that I have said this I will wake up in the morning with every damn one em hacked |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Oct 2001
Location: Somewhere in time
Posts: 143
|
Wow your server is full of security holes:
Server: Apache/1.3.12 Cobalt (Unix) mod_ssl/2.6.4 OpenSSL/0.9.5a PHP/4.1.2 mod_auth_pam/1.0a FrontPage/4.0.4.3 mod_perl/1.24 Apache: versions < 1.3.27 are unsafe PHP: you need to upgrade to 4.2.3 OpenSSL: you need to upgrade (the library) to 0.9.6e And it's only what can be seen really fast. Your sshd is probably vulnerable too, judging by the date of the software you run... From what I know they could very well change the pages through the PHP hole, without having shell access to your server.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Industry Role:
Join Date: Aug 2002
Posts: 9,752
|
Most hackers use port scanning make sure you get a good firewall and block every port you can, this might scare them off. They roll out onto thousands of servers and wait for a reply from there scans.
It's kinda like how a thief passes a car when they see the blinking alarm on the dash. If they see your firewall it will lead them to the next box that's showing a up front weakness. Basically any intense hacker can break a box you just to try and detour them before they get to interested. I would do a format they could of left another route anywhere on your box. Good luck, Charles |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Confirmed User
Join Date: May 2002
Location: Dayton, OH, USA
Posts: 1,863
|
Usama hitting at the heart of America; porn.
__________________
JamPlay.com - Online, video-based guitar lessons |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Registered User
Join Date: Oct 2002
Location: Tucson, AZ
Posts: 22
|
Quote:
__________________
... just a thought ... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |