GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   My server was breached by a fuckin Russian (https://gfy.com/showthread.php?t=699041)

pradaboy 01-24-2007 02:17 PM

My server was breached by a fuckin Russian
 
So I noticed one of my pages was down, turns out some dirtbag hacked my account somehow and inserted iframe redirects into some of my pages.

Checked the whois for the domain he was redirecting to:

Registrant Name: Boriskin Gleb
Registrant Organization: Boriskin Gleb
Registrant Address1: vesekaya 4-155
Registrant City: Novosibirsk
Registrant State/Province: Novosibirsk
Registrant Postal Code: 109880
Registrant Country: Russian Federation
Registrant Country Code: RU
Registrant Phone Number: +7.3098098911
Registrant Facsimile Number: +7.3098098911

Hope he freezes his bitch ass off.

fris 01-24-2007 02:18 PM

should limit the connections per ip, i block off everyone except my ip to ssh/ftp in.

pradaboy 01-24-2007 02:21 PM

Quote:

Originally Posted by Fris (Post 11784361)
should limit the connections per ip, i block off everyone except my ip to ssh/ftp in.

Excellent idea, thanks

Phoenix 01-24-2007 02:24 PM

Privet.all your domains are belonging to Us
Spassibo

thunder99 01-24-2007 02:35 PM

Russians go crazy for Prada, change your nick to discountboy and they'll leave you alone.

bizarredollars 01-24-2007 02:53 PM

What kind of server is it (without giving too much away)... A lot of security packs are available that could save you a shit load of work.

pradaboy 01-24-2007 03:05 PM

Quote:

Originally Posted by bizarredollars (Post 11784522)
What kind of server is it (without giving too much away)... A lot of security packs are available that could save you a shit load of work.

what specs do you need?

Star 69 01-24-2007 04:50 PM

Quote:

Originally Posted by Fris (Post 11784361)
should limit the connections per ip, i block off everyone except my ip to ssh/ftp in.

That's sounds smart

directfiesta 01-24-2007 04:56 PM

install their free firewall :

http://www.configserver.com/

you can then config all your accesses ...

It is pretty good, I myself got blocked by it for entering wrtong password ...

And also make sure to :

- delete all php install folders
- chmod your files to a security safe level, mainly the phpconfig files. :2 cents

thonglife 01-24-2007 05:29 PM

deny from .ru
deny from .cn

MicDoohan 01-24-2007 05:38 PM

Quote:

Originally Posted by thunder99 (Post 11784449)
Russians go crazy for Prada, change your nick to discountboy and they'll leave you alone.

haha that made me laugh :thumbsup

_Rush_ 01-24-2007 05:52 PM

Quote:

Originally Posted by thonglife (Post 11785435)
deny from .ru
deny from .cn

Rather than a blacklist, I'd use a whitelist, especially for stuff like SSH and FTP.

Also, you can set your server to email you immediately when any user logs in via SSH or FTP, that way you're alerted instantly that something is going on.

Quote:

At command prompt type:
pico .bash_profile

Scroll down to the end of the file and add the following line:

echo 'ALERT - Root Shell Access on:' `date` `who` | mail -s "Alert: Root Access from `who | awk '{print $6}'`" [email protected]

Save and exit.
Make sure to disable Telnet as well.

Also, turn off Apache ID by editing httpd.conf and change ServerSignature to OFF.

Thats pretty much the main stuff I do on a new box. There are several others too, but this should do unless you're specifically targeted.

thonglife 01-24-2007 06:02 PM

PHP Code:

At command prompt type:
pico .bash_profile

Scroll down to the end of the file 
and add the following line:

echo 
'ALERT - Root Shell Access on:' `date` `who` | mail -"Alert: Root Access from `who | awk '{print $6}'`" your@email.com

Save 
and exit. 

That is good stuff man.. Thanks!!! :thumbsup

Scott McD 01-24-2007 06:13 PM

Damn Russians... :angrysoap

_Rush_ 01-24-2007 06:17 PM

Quote:

Originally Posted by thonglife (Post 11785609)
PHP Code:

At command prompt type:
pico .bash_profile

Scroll down to the end of the file 
and add the following line:

echo 
'ALERT - Root Shell Access on:' `date` `who` | mail -"Alert: Root Access from `who | awk '{print $6}'`" your@email.com

Save 
and exit. 

That is good stuff man.. Thanks!!! :thumbsup

np...

Please note that that's only for root.


All times are GMT -7. The time now is 03:30 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123