UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Shared Hosting

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-04-2008, 16:52
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default Site hacked

My site got hacked yesterday and they injected p0rn links into some pages and also put 100's of porn HTML and redirects in my DIR's.

NickJ said it was accessed (Cpanel) with these IP's
86.149.17.234
59.161.47.187
212.183.227.130
200.55.109.88
190.72.166.212
81.184.151.235

Are these all proxys or waht ? What can be done to report these guy ? Its a Government (allbeit local Gov) but surely tehy can get punished for it ?

Is there even a wway to change my default FTP port to something obscure that only I would know so they cant upload stuff ?

Last edited by Brian : 11-04-2008 at 16:54.
Reply With Quote
  #2 (permalink)  
Old 11-04-2008, 17:07
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 728
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Quote:
86.149.17.234 - abuse@btbroadband.com
59.161.47.187 - bitbucket@ripe.net
212.183.227.130 - abuse@ono.com
200.55.109.88 - bitbucket@ripe.net
190.72.166.212 - bitbucket@ripe.net
81.184.151.235 - ripe-tech@ono.es
Please use the above contacts for abuse complaints.
__________________
UK Professional Website Design.
Discount to eUKhost customers for Website Design Services.

Need to MONITOR your servers (SMS/Text-Message Features Included) - Please see http://monitor.twrwebdesign.co.uk.

TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #3 (permalink)  
Old 11-04-2008, 20:46
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

Thanks, just got around to doing that.
What about having my FTP on an obscure port ?
Reply With Quote
  #4 (permalink)  
Old 11-04-2008, 21:44
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 728
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

What type of web hosting do you have?

VPS, shared hosting etc?
__________________
UK Professional Website Design.
Discount to eUKhost customers for Website Design Services.

Need to MONITOR your servers (SMS/Text-Message Features Included) - Please see http://monitor.twrwebdesign.co.uk.

TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #5 (permalink)  
Old 11-04-2008, 22:00
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,048
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Brian View Post
Thanks, just got around to doing that.
What about having my FTP on an obscure port ?
This is what I could see from FTP logs on the server :-

Quote:
Apr 10 02:59:06 hawk pure-ftpd: (clayton@59.161.47.187) [NOTICE] /home/clayton//public_html/downloads/wallpapers/backup/world-record-cock/hotel-allegro-resort-papagayo.html uploaded (30382 bytes, 3.48KB/sec)
Apr 10 02:59:24 hawk pure-ftpd: (clayton@59.161.47.187) [NOTICE] /home/clayton//public_html/downloads/wallpapers/backup/world-record-cock/dildo-butt-plug.html uploaded (29213 bytes, 2.78KB/sec)
Apr 10 02:59:41 hawk pure-ftpd: (clayton@59.161.47.187) [NOTICE] /home/clayton//public_html/downloads/wallpapers/backup/world-record-cock/gay-man-peeing.html uploaded (28854 bytes, 2.64KB/sec)
You had weak FTP password and someone managed to hack your FTP password to download - inject - upload on your website.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #6 (permalink)  
Old 11-04-2008, 22:02
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 728
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Quote:
Originally Posted by eUKhost.com View Post
This is what I could see from FTP logs on the server :-



You had weak FTP password and someone managed to hack your FTP password to download - inject - upload on your website.
Lol, I don't think it's a good idea to post that publicly on the forums :P
__________________
UK Professional Website Design.
Discount to eUKhost customers for Website Design Services.

Need to MONITOR your servers (SMS/Text-Message Features Included) - Please see http://monitor.twrwebdesign.co.uk.

TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #7 (permalink)  
Old 11-04-2008, 22:17
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

All passwords have been changed, so its far from weak now. But I was thinking what if FTP was on a different port would that not make it impossible to upload stuff, no ?
Reply With Quote
  #8 (permalink)  
Old 11-04-2008, 22:18
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 728
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Well, this is only possible if you have a VPS or Dedicated Server?
__________________
UK Professional Website Design.
Discount to eUKhost customers for Website Design Services.

Need to MONITOR your servers (SMS/Text-Message Features Included) - Please see http://monitor.twrwebdesign.co.uk.

TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #9 (permalink)  
Old 11-04-2008, 22:43
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,048
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by WelshTom View Post
Well, this is only possible if you have a VPS or Dedicated Server?
Thats right. FTP port change will stop cPanel File Manager as well. We can set IP based permission for SSH, FTP, cPanel & WHM access on a VPS or Dedicated Server, but such settings cannot be done on a shared hosting server.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #10 (permalink)  
Old 11-04-2008, 22:45
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

OK well I only repaid for my package in Jan so ill see how much I have left in teh budget to do a VPS. Are they hosted in the US too ?
Reply With Quote
  #11 (permalink)  
Old 11-04-2008, 22:46
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 728
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Nope, VPS and Dedicated servers are situated in the UK.

Edit: However (although I'm not sure), eUKhost may be able to set you one up in the US if that's what you want.
__________________
UK Professional Website Design.
Discount to eUKhost customers for Website Design Services.

Need to MONITOR your servers (SMS/Text-Message Features Included) - Please see http://monitor.twrwebdesign.co.uk.

TWR Web Design
http://www.twrwebdesign.co.uk/
Reply With Quote
  #12 (permalink)  
Old 12-04-2008, 02:30
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

I can only do US mate.
Reply With Quote
  #13 (permalink)  
Old 12-04-2008, 04:25
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

Spoke to Danny in sales and he said they have some in the US. So off to see the City Manager on monday to see how much we have left in the budget.
Reply With Quote
  #14 (permalink)  
Old 12-04-2008, 20:39
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,048
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Brian View Post
Spoke to Danny in sales and he said they have some in the US. So off to see the City Manager on Monday to see how much we have left in the budget.
There should not be any problem on hawk if you keep on changing your FTP password once in a month. Hacker managed to login in first attempt so he must have managed to crack or sniff your password easily. If he had attempted to login with wrong credentials for 3 times then he would have got blocked on the server.

We maintain multiple backups of your account and you can download one backup once in a month from cpanel control panel. please PM your old password as I would like to know how someone could access your account so easily.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
  #15 (permalink)  
Old 12-04-2008, 23:20
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 584
Default

PM sent .
Reply With Quote
  #16 (permalink)  
Old 13-04-2008, 13:56
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,048
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Brian View Post
PM sent .
got it

There should be at least one upper case character and at least one special character in your password. That makes it impossible for hackers to crack your password.

Passwords with same case and numbers can be cracked easily using Brute Force tools.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 09:21.

 

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

knowledgebase articles

popular blog categories