UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Shared Hosting

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-07-2007, 14:11
new member
 
Join Date: Apr 2007
Posts: 4
Default Hacked! turkprotest.com

Just had our website hosting hacked by some turkish hackers who seem to have uploaded index.whatever files of every type to our 'www' folder (i.e. index.php, index.cfm, index.htm etc.)

It looks like this may have been spotted by support staff already (site went down for a couple of minutes, and files have been renamed to index.php-hacked), but I need to know if this is a vulnerability of my website hosting or the hosts?

Has anyone else had this problem?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 02-07-2007, 14:25
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Your website hosting is resolving from server of some other company. I don't see your domain name in our billing system as well.

You will need to contact your web hosting company to get this sorted. currently none of our customers have any sort of such issues.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #3 (permalink)  
Old 02-07-2007, 14:42
new member
 
Join Date: Apr 2007
Posts: 4
Default

sorry - should have made that clearer: turkprotest.com is the website hosting that hacked mine (google it, they've been busy!)

our URL is sitel-cardiff.com

Ignore the bit about support working on it - this was another colleague of mine, who was working from home...

I'd appreciate it if you could investigate the vulnerability - from what I can find on other support forums, it seems to point to a need to patch the hosting server.
Reply With Quote
  #4 (permalink)  
Old 02-07-2007, 14:55
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Some of our customers hosted on one of our web hostingcontroller windows server have reported this matter. we are replacing their index pages right now and our windows system admins will take a look in getting this security vulnerability sorted ASAP.

We have made such exploits impossible on Linux Servers but they have now focussed on windows servers so we will implement some security rules on windows ( hostingcontroller ) as well.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #5 (permalink)  
Old 02-07-2007, 15:23
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

I had this happen a while ago - and yes it was by a Turkish hacking group doing exactly the same thing to my website hosting. This has no happened in nearly a year now to me but I am on Linux and like Mark says, the security rules have been updated on Linux.

I am sorry to here about your troubles - it only happened to me once so hopefully it is over for you now too!
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #6 (permalink)  
Old 02-07-2007, 15:54
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by DPS Computing View Post
I had this happen a while ago - and yes it was by a Turkish hacking group doing exactly the same thing to my website hosting. This has no happened in nearly a year now to me but I am on Linux and like Mark says, the security rules have been updated on Linux.

I am sorry to here about your troubles - it only happened to me once so hopefully it is over for you now too!
no worries. they will have a lesson this time
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #7 (permalink)  
Old 02-07-2007, 16:28
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by eukhost.com View Post
no worries. they will have a lesson this time
What are you going to do to them this time?

Last time you completely kicked the persons backside when they were trying to compromise the server security .
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #8 (permalink)  
Old 02-07-2007, 16:41
carsey's Avatar
Senior Member
 
Join Date: Jun 2007
Location: Hunwick, Crook, Durham
Posts: 105
Send a message via MSN to carsey
Default

Try using a FTP client to re-transfer your files to your website hosting. and get rid of the stupid turk stuff.
Reply With Quote
  #9 (permalink)  
Old 02-07-2007, 16:43
Banned
 
Join Date: Jun 2007
Posts: 24
Default

Quote:
Originally Posted by DPS Computing View Post
What are you going to do to them this time?

Last time you completely kicked the persons backside when they were trying to compromise the server security .
Wow! These hackers better learn their lesson.

If you need help I would love to help you.

I know how to hack website hostings!

And I even built a website hosting for all of you to enjoy.

If you need to access a website hosting and it's blocked!

Please visit my website hosting

Proxy site

//LINK REMOVED


Last edited by Ben; 01-08-2007 at 19:18.
Reply With Quote
  #10 (permalink)  
Old 02-07-2007, 16:52
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by thug4life View Post
Wow! These hackers better learn their lesson.

If you need help I would love to help you.

I know how to hack website hostings!

And I even built a website hosting for all of you to enjoy.

If you need to access a website hosting and it's blocked!

Please visit my website hosting

Proxy site

http://endoftheyear.net/

Proxies are usually quite slow when used in this way if they have a reasonable amount of traffic.

And any network admin worth thier salt will figure this out within a day and block the new proxy - this idea has been tried before!! (at places like my college - we found a new proxy and they just blocked it really soon after!)
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #11 (permalink)  
Old 02-07-2007, 17:12
new member
 
Join Date: Apr 2007
Posts: 6
Default

I just noticed the same as freestate on my 2 website hostings hosted here on windows.
EVERY directory even those outside the root had a default.asp, cfm, htm, html and php file and an index.asp, cfm, htm, html and php file.

I just finished removing them all.
This is the third time in 3 weeks that those hackers can get away with it, time for eukhost to sort them out or for me to find another host.

This is the first time any of my website hostings have been hacked in 7 years online.
Reply With Quote
  #12 (permalink)  
Old 02-07-2007, 17:20
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by badger24 View Post
I just noticed the same as freestate on my 2 website hostings hosted here on windows.
EVERY directory even those outside the root had a default.asp, cfm, htm, html and php file and an index.asp, cfm, htm, html and php file.

I just finished removing them all.
This is the third time in 3 weeks that those hackers can get away with it, time for eukhost to sort them out or for me to find another host.

This is the first time any of my website hostings have been hacked in 7 years online.
Mark mentioned in an earlier post that eUKhost are in the process of modifying the security rules on Windows based accounts to make the secure and prevent this type of attack in the future.

Hope that helps .
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #13 (permalink)  
Old 02-07-2007, 19:37
new member
 
Join Date: Apr 2007
Posts: 4
Default

well, my website hosting has been down for about an hour now.

Hopefully this is part of the fix (and it won't take too much longer ... )
Reply With Quote
  #14 (permalink)  
Old 02-07-2007, 20:13
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by freestate View Post
well, my website hosting has been down for about an hour now.

Hopefully this is part of the fix (and it won't take too much longer ... )
I doubt modifying the security rules would take your website hosting down.

Have you tried contacting support for an explanation? Or to see whether it is a symptom of the hacking attempt that you have experienced earlier?
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #15 (permalink)  
Old 02-07-2007, 20:19
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by DPS Computing View Post
I had this happen a while ago - and yes it was by a Turkish hacking group doing exactly the same thing to my website hosting. This has no happened in nearly a year now to me but I am on Linux and like Mark says, the security rules have been updated on Linux.

I am sorry to here about your troubles - it only happened to me once so hopefully it is over for you now too!
turkprotest.com will be removed from registry of ICANN. nothing else besides removing all their domains from registry.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #16 (permalink)  
Old 02-07-2007, 20:23
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by eukhost.com View Post
turkprotest.com will be removed from registry of ICANN. nothing else besides removing all their domains from registry.
I am glad to hear that! Thanks Mark! - these turkish hackers do seem to be getting round a bit hacking multiple forums, website hostings and guestbooks every minute!! Quite scary - seems like there is a lot of them .
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #17 (permalink)  
Old 02-07-2007, 20:27
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by badger24 View Post
I just noticed the same as freestate on my 2 website hostings hosted here on windows.
EVERY directory even those outside the root had a default.asp, cfm, htm, html and php file and an index.asp, cfm, htm, html and php file.

I just finished removing them all.
This is the third time in 3 weeks that those hackers can get away with it, time for eukhost to sort them out or for me to find another host.

This is the first time any of my website hostings have been hacked in 7 years online.
I apologize for this problems you had on this server but we are on top of things and everything will be sorted today itself. I am good with windows servers but I never disturb settings of our windows team. I will get detailed documentation from them of what they have implemented to sort this problem and first thing I am doing is to get the hackers back on their toes.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #18 (permalink)  
Old 02-07-2007, 20:28
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,374
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

let me correct my statement. You cannot call it as hacking as they have managed to run mass exploit to replace index pages and nothing else. They manage to write their index page recursively in all directories but they cannot delete anything.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #19 (permalink)  
Old 02-07-2007, 20:37
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,849
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by eukhost.com View Post
let me correct my statement. You cannot call it as hacking as they have managed to run mass exploit to replace index pages and nothing else. They manage to write their index page recursively in all directories but they cannot delete anything.
Surly we can just "close" this mass exploit then.

Can they only write files called "index" then or just create any file with any name they want and that is it?
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #20 (permalink)  
Old 02-07-2007, 22:42
carsey's Avatar
Senior Member
 
Join Date: Jun 2007
Location: Hunwick, Crook, Durham
Posts: 105
Send a message via MSN to carsey
Default

Have the right CHMOD settings and they shouldnt be able to right to your homepage. But this cannot be helped where write settings are needed.
Reply With Quote