GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   I have a website that keeps on getting hacked... (https://gfy.com/showthread.php?t=1199018)

FreeHugeMovies 05-25-2016 01:58 PM

I have a website that keeps on getting hacked...
 
Custom made script, PHP. Host doesn't want to help.

Suggestions?

BigFurry 05-25-2016 02:06 PM

Step 1. Get a good PHP coder to look at the script.

Step 2. Get an actual expert to do a security audit.

If you have no money to spend, there are some tips here:
appsec - How to perform a security audit for a PHP application? - Information Security Stack Exchange

FreeHugeMovies 05-25-2016 02:07 PM

Host is telling me to go here.

https://sucuri.net

I don't want to pay a monthly fee for their firewall.

roxpoxy 05-25-2016 02:12 PM

sucuri.net is a good start.

does your script use a database? have an admin area with elevated privledges?
allow uploads of images or posting of text?

if you can, scan all files for "base64_decode(" & other common tale tale signs of compromise. "can't remember off the top of my head but a quick google search should point you in the right direction".

FreeHugeMovies 05-25-2016 02:13 PM

Quote:

Originally Posted by roxpoxy (Post 20919461)
sucuri.net is a good start.

does your script use a database? have an admin area with elevated privledges?
allow uploads of images or posting of text?

if you can, scan all files for "base64_decode(" & other common tale tale signs of compromise. "can't remember off the top of my head but a quick google search should point you in the right direction".

Yes, it does, but I don't update the website anymore.

I am afraid I am not that technical to do the simplest of programming.

Sly 05-25-2016 02:15 PM

Custom scripts often have security issues. Sometimes from laziness, sometimes because the coder simply didn't know better. Odds are your script is also on the older side, meaning no updates in years, making matters even worse.

If you care about your site, spend the money to get it patched up. Otherwise there is not much that can be done.

FreeHugeMovies 05-25-2016 02:17 PM

Quote:

Originally Posted by Sly (Post 20919470)
Custom scripts often have security issues. Sometimes from laziness, sometimes because the coder simply didn't know better. Odds are your script is also on the older side, meaning no updates in years, making matters even worse.

If you care about your site, spend the money to get it patched up. Otherwise there is not much that can be done.

Yes, that's what I am looking to do. The site doesn't bring in a whole lot of money, but it's getting hacked WEEKLY. LOL

BigFurry 05-25-2016 02:25 PM

Yeah I guess if it's possible to disable all user input (forms, uploads), and make the site "read only", that can be a solution. :p

Unless you have some bad file in your system already. :p

FreeHugeMovies 05-25-2016 02:34 PM

Quote:

Originally Posted by BigFurry (Post 20919479)
Yeah I guess if it's possible to disable all user input (forms, uploads), and make the site "read only", that can be a solution. :p

Unless you have some bad file in your system already. :p

So, if I remove all the malware, can I then make it read only and the website will be safe?

Klen 05-25-2016 02:45 PM

Quote:

Originally Posted by FreeHugeMovies (Post 20919497)
So, if I remove all the malware, can I then make it read only and the website will be safe?

If you dont plan to update site anymore, you could simply convert all content to HTML format and delete anything in PHP.

BigFurry 05-25-2016 02:58 PM

Quote:

Originally Posted by FreeHugeMovies (Post 20919455)
Host is telling me to go here.

https://sucuri.net

I don't want to pay a monthly fee for their firewall.

They could have meant this tool:
https://sitecheck.sucuri.net/

Quote:

Originally Posted by FreeHugeMovies (Post 20919497)
So, if I remove all the malware, can I then make it read only and the website will be safe?

Well your chances would definitely improve. As roxpoxy said, many breaches are done through Forms and Uploads.

But I guess it's also not impossible that some PHP scripts get hacked just by using simple URL parameters, if they're done really badly. It's not my expertise, just guessing really.

Quote:

Originally Posted by KlenTelaris (Post 20919512)
If you dont plan to update site anymore, you could simply convert all content to HTML format and delete anything in PHP.

That would work :-)

FreeHugeMovies 05-26-2016 07:14 AM

Any of you fuckers want to help and get paid for your time? =]

LMK

sandman! 05-26-2016 12:18 PM

Ask your host to change all the permissions they can to read only any decent managed host should have at least 1 tech with coding skills that can do this for you.

Colmike9 05-26-2016 12:32 PM

Quote:

Originally Posted by sandman! (Post 20921333)
Ask your host to change all the permissions they can to read only any decent managed host should have at least 1 tech with coding skills that can do this for you.

I use Filezilla to do that, is that as good as any other way to change permissions or is there another way that I should do it to be safer?

NatalieK 05-26-2016 12:39 PM

Quote:

Originally Posted by Colmike7 (Post 20921357)
I use Filezilla to do that, is that as good as any other way to change permissions or is there another way that I should do it to be safer?

this :2 cents:

FreeHugeMovies 05-26-2016 12:53 PM

Everything changed to read only. Let's see if I get fucked in a week or two!

TrafficRush 05-26-2016 01:16 PM

contact WOJ he can help! or quantox

celandina 05-27-2016 06:57 AM

About to launch a new site, just marking this thread in case I run into the same issues.:2 cents:

MrBeavis 05-27-2016 08:44 AM

Wordpress website?

freecartoonporn 05-27-2016 08:51 AM

contact woj, and get your php code updated and look for user input sanitization.

NatalieK 05-27-2016 09:10 AM

Quote:

Originally Posted by freecartoonporn (Post 20922764)
contact woj, and get your php code updated and look for user input sanitization.

woj is fantastic for "getting the job done" and "great service" :thumbsup


All times are GMT -7. The time now is 05:48 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123