Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Community Forums
 Community Discussions (All other subjects)
 Site Hacked
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

redbrad0
Advanced Member

USA
3725 Posts

Posted - 03 October 2003 :  15:18:14  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
One of my customers sites just got hacked and they changed the default.asp page so the only thing that is displayed is...

quote:
Fatal Error ownz you BY: Elemento_pcx - #Ferror irc.objetivonet.com.br Fatal Error we are Elemento_PCX :: the_danz :: MAXMEX :: Ka0t1c -Sl4cK_r0oT- Elemento_pcx@yahoo.com.br não sabe como funciona entao aprende :P Cgi-bin%$ of iis5-webdav nc.exe ON :D


What does this message say at the bottom? Has anyone else had this problem? I am guessing they got on the FTP and changed the file, but I would think they would of deleted files also.

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets

Roland
Advanced Member

Netherlands
9335 Posts

Posted - 03 October 2003 :  15:23:13  Show Profile
According to intertran "não sabe como funciona entao aprende" means "into the knows how does it work entao she learns", assuming they wrote that in brazilian portuguese
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 03 October 2003 :  16:37:37  Show Profile  Send ruirib a Yahoo! Message
Sorry Roland, that is ... ahem... a translation that can be improved...

I would translate it as: "if you don't know how it works, you'd better learn it".


Snitz 3.4 Readme | Like the support? Support Snitz too

Edited by - ruirib on 03 October 2003 16:38:17
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20595 Posts

Posted - 03 October 2003 :  17:11:40  Show Profile  Visit HuwR's Homepage
how were they able to get in via ftp ? do you have anonymous ftp enabled ?
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 03 October 2003 :  17:31:47  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
Its not a hosting customer of mine, I told her to make sure to change the password on her FTP but wasnt really sure what to tell her on anything else.

Oh when I looked into it a little more they inserted 4 files.
index.html
index.htm
default.htm
default.asp

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets

Edited by - redbrad0 on 03 October 2003 17:32:32
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20595 Posts

Posted - 03 October 2003 :  17:50:44  Show Profile  Visit HuwR's Homepage
may be worth checking if they have ftp logs, or in the iis logs incae they were uploaded via http
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 03 October 2003 :  18:02:06  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
Yea thats one thing I told her to check since we knew the exact time the files were uploaded since the files had the date and time in FTP. Thanks

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

bethabernathy
Starting Member

10 Posts

Posted - 03 October 2003 :  20:20:14  Show Profile
Hi - I think what happened is that I had read, write, execute and delete set on the snitz folder. Do you think that was it? -Beth
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 04 October 2003 :  10:30:18  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
it easily could of been, its hard to tell unless you look at the log files.

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

bethabernathy
Starting Member

10 Posts

Posted - 04 October 2003 :  13:41:33  Show Profile
Hi - I ran an analysis on the log files and they also hit the cgi-bin folder and the frontpage extension folders. So, it must be some sort of program where they can publish.

very strange? -Beth
Go to Top of Page

bethabernathy
Starting Member

10 Posts

Posted - 04 October 2003 :  14:15:58  Show Profile
More info:

link removed by admin. sorry but we don't really want links to sites telling people how to hack into other peoples machines.

-Beth
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20595 Posts

Posted - 04 October 2003 :  14:53:06  Show Profile  Visit HuwR's Homepage
if someone was able to upload files to your server then it has a serious security problem, you should ensure all current patches are installed, and tye down the security on the server, if this is with a host, then move imediately.
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.26 seconds. Powered By: Snitz Forums 2000 Version 3.4.07