Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-07-2002, 06:12 PM   #1
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
ive been hacked need help asap

I come home find all my index.html files were changed to this
<html>
<head>
<title>Hacked By USG!</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>

<body bgcolor="#000000" text="#999999" link="#6666FF">
<center><h3>USG (UNIX Security Guards)</h3></center>
<hr>
<p> There is no such thing as Jerusalem the capital of Israel</p>
<p> There is only one arabic Jerusalem</p>
<p> USA I think that you are all about to be some war criminals</p>

<p> UK you are a slave to USA</p>
<hr>
<p align="center"><b>FREE PALESTINE!</b></p>
<p align="center"><b>STOP THE PAIN!</b></p>
<p>&nbsp;</p>
<p>Greetz: AIC (Anti India Crew), WFD (World Fabulous Defacers),DkD,
BreaKIce, Rivver, TheBugz, raiden4 and everyone else who fights for the same case.</p>
<p>&nbsp;</p>
<p align="center"><code> WE Are: Egyptian|Fighter, ShellCode, LinuxLover
and rD.</code></p>
<p align="center">&nbsp;</p>
<p align="center"><code>rD of USG</code></p>
<p align="center"><b> <strong><a
href="mailto:[email protected]">[email protected] m</a></strong></b></p>
</body>
</html>


WTF how can this happen anyone know how or what they did to get in?
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:14 PM   #2
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
sorry man... I thought you'd like it.
__________________
SIG TOO BIG
Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:14 PM   #3
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
And did the new front-end convert..?!
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:15 PM   #4
Amputate Your Head
There can be only one
 
Amputate Your Head's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Somewhere else
Posts: 39,075
Quote:
Originally posted by mrthumbs
And did the new front-end convert..?!
I can't see how it wouldn't....
__________________
SIG TOO BIG
Amputate Your Head is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:16 PM   #5
pornJester
Confirmed User
 
Join Date: Mar 2001
Location: Florida
Posts: 6,138
you're fucked... but seriously you need someone (who know's what they are doing) to take a look at your server.,, hit me up on icq if you need some help finding someone to do so.. 91573698
__________________


FreshBucks | Webmaster Vault | GayAW
Trusted Names in Adult.
ICQ 9157.3698
pornJester is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:21 PM   #6
cherrylula
lol
 
cherrylula's Avatar
 
Industry Role:
Join Date: Jan 2002
Posts: 15,969
that fucking sucks ass.....

May the force be with you.
cherrylula is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:24 PM   #7
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
FREAKING terriost or how ever you spell it lmao man that really sucks donkey balls
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:25 PM   #8
theking
Nice Kitty
 
theking's Avatar
 
Industry Role:
Join Date: Sep 2002
Location: The good old USA!!!
Posts: 21,053
Va2K I am sorry this happened to you. You seem to be a decent sort and hard working. I hope you can fix the problem ASAP.
__________________
When you're running down my country hoss...you're walking on the fighting side of me!

FOR THE LYING LOWLIFE POSTING AS PATHFINDER...https://gfy.com/fucking-around-and-pr...athfinder.html

Last edited by theking; 10-07-2002 at 06:26 PM..
theking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:26 PM   #9
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
www.fuckingmature.com this is one out of about 150 sites on my box ARGH@#$@#$@#$@#$#@$$#@#$@#@$$#@
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:28 PM   #10
.:Frog:.
Confirmed User
 
Join Date: Jul 2002
Location: ~ C A N A D A ~
Posts: 2,123
weird!
__________________
<a href="http://www.pornopayouts.com/?rid=pp3076">PornoPayouts</a>
Tons of Hosted Galleries.

Last edited by .:Frog:.; 10-07-2002 at 06:30 PM..
.:Frog:. is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:30 PM   #11
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by theking
Va2K I am sorry this happened to you. You seem to be a decent sort and hard working. I hope you can fix the problem ASAP.
you know thank you I could understand if i fucked others or was a cheat but GOD DAMN what did i do to deserve this shit. FIRST god damn VISA then money and NOW MY SITES am I pissed hell yea cause I dont knwo what to do and my admin is been so busy I cant get a hold of him if there is anyone I MEAN anyone that knows me and I know them I will pay you what I can if you help me fig out how the FUCK they did this
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:39 PM   #12
gothweb
Confirmed User
 
Join Date: Jun 2002
Location: Back in the USSA
Posts: 8,849
[/COLOR]
__________________

Photos by Ian X.: Distinctive photos of goth babes.
Blood Money:Your traffic, my sites, our money.
MojoHost: Still the best.
gothweb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:40 PM   #13
Carrie
Confirmed User
 
Join Date: Apr 2002
Location: Virgin - nee
Posts: 3,162
Are you prepared to wipe that box and re-load it?
Most likely they left themselves a backdoor. Hunting down that backdoor could take days, while simply reloading could take a few hours.
When your sysadmin reappears, tell him you want IPChains set up on the box immediately with Logcheck emailing you every 15 minutes (at least) and all non-essential ports closed down.
If you've got telnet on the box, install SSH2 and disable telnet. If you've got anonymous FTP turned on, turn it off.
Change all of your passwords - and then do it again at *least* once a month from here on out.
If you still can't get a hold of your sysadmin, install this until you can: http://www.pointman.org/PMFirewall/
It's got easy instructions and is just as easy to open up a port if you close it by mistake.

Best of luck - and check your logs to find out who these fuckers are so you can fry 'em.
Carrie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:41 PM   #14
cherrylula
lol
 
cherrylula's Avatar
 
Industry Role:
Join Date: Jan 2002
Posts: 15,969
hey maybe you need to report that somewhere? to some authority?

maybe you can get some free publicity = traffic
cherrylula is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:43 PM   #15
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by Carrie
Are you prepared to wipe that box and re-load it?
Most likely they left themselves a backdoor. Hunting down that backdoor could take days, while simply reloading could take a few hours.
When your sysadmin reappears, tell him you want IPChains set up on the box immediately with Logcheck emailing you every 15 minutes (at least) and all non-essential ports closed down.
If you've got telnet on the box, install SSH2 and disable telnet. If you've got anonymous FTP turned on, turn it off.
Change all of your passwords - and then do it again at *least* once a month from here on out.
If you still can't get a hold of your sysadmin, install this until you can: http://www.pointman.org/PMFirewall/
It's got easy instructions and is just as easy to open up a port if you close it by mistake.

Best of luck - and check your logs to find out who these fuckers are so you can fry 'em.
I allready have the firewall ill go do the ipchan prolly blow up my damn server now
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:54 PM   #16
trailboss
Registered User
 
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
Va2k,

There are some security holes in Cobalt. I'm not familiar with them. We run FreeBSD. Sure hope you got backups.

I wear belt and suspenders. Have a complete backup of everything on all three of our PC's.

The site www.fuckingmature.com is running
Apache/1.3.12 Cobalt (Unix) mod_ssl/2.6.4 OpenSSL/0.9.5a PHP/4.1.2 mod_auth_pam/1.0a FrontPage/4.0.4.3 mod_perl/1.24

We had an NT box get hacked last summer. After we moved all the sitesof it we got a box of shells took it out in the desert and had some fun target practice.

Blew the living shit out of it.
BTW you can have Full Auto in Nevada. Rock n' Roll.
trailboss is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 06:56 PM   #17
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by trailboss
Va2k,

There are some security holes in Cobalt. I'm not familiar with them. We run FreeBSD. Sure hope you got backups.

I wear belt and suspenders. Have a complete backup of everything on all three of our PC's.

The site www.fuckingmature.com is running
Apache/1.3.12 Cobalt (Unix) mod_ssl/2.6.4 OpenSSL/0.9.5a PHP/4.1.2 mod_auth_pam/1.0a FrontPage/4.0.4.3 mod_perl/1.24

We had an NT box get hacked last summer. After we moved all the sitesof it we got a box of shells took it out in the desert and had some fun target practice.

Blew the living shit out of it.
BTW you can have Full Auto in Nevada. Rock n' Roll.
HOW the hell did you get that info?????? CAN you help me fix these holes???? Pwease pretty pwease with a cherry on top or a tittie
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 07:10 PM   #18
trailboss
Registered User
 
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
Va2k,

my icq is 64074953.

I can try to help.
trailboss is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 07:11 PM   #19
AcidMax
Confirmed User
 
Join Date: May 2002
Location: MI
Posts: 1,827
That information is easy to get...just peep this URL:

Check out www.netcraft.com for more information (Click on "Whats that site running")

It will show you information about your webserver and even start keeping tabs about your uptime .

Let me just add that the URL above shows nothing that anyone can use OTHER than the information. Hackers are smart, upgrade your packages on your cobalt and get everything up to date.

Otherwise upgrade your sites to a newer box, Cobalt RaQ's are notorious for intrusions. Also, the newer version of the cobalt software has ways to notify you of port scans and hack attempts.


AJ
__________________
Latest MMA news. http://www.mmawrapup.com

Last edited by AcidMax; 10-07-2002 at 07:14 PM..
AcidMax is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 07:12 PM   #20
Cogitator
Confirmed User
 
Join Date: Feb 2002
Location: Florida
Posts: 672
Encrypt your damn password file!
__________________
- this space intentionally left blank -
Cogitator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 07:25 PM   #21
foe
Confirmed User
 
Join Date: May 2002
Location: CT
Posts: 5,246
That sucks man, seriously get some one who knows what hes doing to take a look at your servers and make sure to stay current with patches
foe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 07:42 PM   #22
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Ok I need an admin anyone want some $$$ hit me up asap
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 08:07 PM   #23
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Quote:
Originally posted by va2k
WTF how can this happen anyone know how or what they did to get in?
Many ways!!! Let's start with making sure all your passwords are not the same!
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 08:14 PM   #24
faytl
Confirmed User
 
Join Date: Jul 2002
Location: Australia
Posts: 121
24449990, might be able to help...
faytl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 08:16 PM   #25
cosis
Confirmed User
 
Industry Role:
Join Date: Aug 2001
Location: Beach
Posts: 5,281
if your server is new make sure the root password is changed from the default
cosis is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 08:18 PM   #26
pr0
rockin tha trailerpark
 
pr0's Avatar
 
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
man thats some terrorism right there
pr0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 08:45 PM   #27
trailboss
Registered User
 
Join Date: Oct 2002
Location: 60 miles from nowhere and 6 feet from HELL!
Posts: 54
HiYa AcidMax,

I thought everbody and their dog knew about www.netcraft.com


Here are a couple other usefull tools:

Dns Traversal http://www.squish.net/dnscheck/

ARIN http://www.arin.net/whois/index.html

CyTech http://www.cytechconsult.com/

So Tell your dogs.

Trailboss
trailboss is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 09:44 PM   #28
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
I found who was behind this attack
http://news.bbc.co.uk/1/hi/sci/tech/2052320.stm wtf woudl they pick on someone as little as me
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 09:46 PM   #29
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
here they are on tech tv http://www.techtv.com/news/security/...392443,00.html http://www.spitcum.com i still havevt gotten all my sites fixed
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 09:46 PM   #30
pr0
rockin tha trailerpark
 
pr0's Avatar
 
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
Quote:
Originally posted by va2k
I found who was behind this attack
http://news.bbc.co.uk/1/hi/sci/tech/2052320.stm wtf woudl they pick on someone as little as me
Mail bomb em

Didn't they leave a mail box addy?
pr0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 09:51 PM   #31
Va2k
I知 still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by pr0


Mail bomb em

Didn't they leave a mail box addy?
yea hackermail.com FUCK THAT I aint pissing no one off..... Maybe they will never return to my little site lmao good nite this was a bitch of a night
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 10:03 PM   #32
redshift
Confirmed User
 
Join Date: Jan 2002
Location: anus fuckin' yo mama
Posts: 1,044
here's some hints:
turn off all services that are not needed
update - update - update - update
do not use telnet - use ssh

just for example

if you need any help
icq me at 576 1 0 2 1

I've been running several linux servers for 5 years now
have never been hacked (KNOCK ON WOOD HAHA)

now that I have said this I will wake up in the morning with every damn one em hacked

Last edited by redshift; 10-07-2002 at 10:10 PM..
redshift is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 10:32 PM   #33
[Dan]
Confirmed User
 
Join Date: Oct 2001
Location: Somewhere in time
Posts: 143
Wow your server is full of security holes:

Server: Apache/1.3.12 Cobalt (Unix) mod_ssl/2.6.4 OpenSSL/0.9.5a PHP/4.1.2 mod_auth_pam/1.0a FrontPage/4.0.4.3 mod_perl/1.24


Apache: versions < 1.3.27 are unsafe
PHP: you need to upgrade to 4.2.3
OpenSSL: you need to upgrade (the library) to 0.9.6e


And it's only what can be seen really fast. Your sshd is probably vulnerable too, judging by the date of the software you run... From what I know they could very well change the pages through the PHP hole, without having shell access to your server..

Last edited by [Dan]; 10-07-2002 at 10:44 PM..
[Dan] is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 11:57 PM   #34
chaze
Confirmed User
 
Industry Role:
Join Date: Aug 2002
Posts: 9,752
Most hackers use port scanning make sure you get a good firewall and block every port you can, this might scare them off. They roll out onto thousands of servers and wait for a reply from there scans.

It's kinda like how a thief passes a car when they see the blinking alarm on the dash. If they see your firewall it will lead them to the next box that's showing a up front weakness.

Basically any intense hacker can break a box you just to try and detour them before they get to interested.

I would do a format they could of left another route anywhere on your box.

Good luck,

Charles
chaze is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2002, 11:59 PM   #35
Ace-Ace
Confirmed User
 
Join Date: May 2002
Location: Dayton, OH, USA
Posts: 1,863
Usama hitting at the heart of America; porn.
Ace-Ace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-08-2002, 10:20 AM   #36
Acolyte
Registered User
 
Join Date: Oct 2002
Location: Tucson, AZ
Posts: 22
Quote:
I would do a format they could of left another route anywhere on your box.
You might consider using tripwire on your new install, or one of the opensource lookalikes. It makes it a little bit easier to spot new or changed files.
__________________
... just a thought ...

Last edited by Acolyte; 10-08-2002 at 10:24 AM..
Acolyte is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright ゥ 2000- Jelsoft Enterprises Limited.