Previous Thread
Next Thread
Print Thread
Rate Thread
#67255 02/18/2001 4:14 AM
Joined: Mar 2000
Posts: 305
Member
Member
Offline
Joined: Mar 2000
Posts: 305
ok, i'm frustrated. here is my situation:

1)I have been hacked every month for the past 4 months, and for the last 2 months I've been hacked between the 16th and the 18th (spotlight time).
2)Our main page was downed today (5 admin, we got it back up within an hour).
3)I actually got a PING originating FROM my server last nite when i WAS NOT in any internet programs, my firwall displayed the message as follows:
--->
(TCP Port 1551) from www.oneminuteleft.com (209.249.147.131) (HTTP).
<---

odd huh? I told CWm this right away, he had little explanation either why i was getting pinged from my server.

i just wanna know what's going on. our server claims they are very secure, yet if i navigate thru the directory structure long enuf i can get into any of their hosted public_html folders (not hacking, just clicking "Up" command in WSftp.

what do u think i should do?

Sponsored Links
#67256 02/18/2001 5:15 AM
Joined: Oct 2000
Posts: 91
Member
Member
Offline
Joined: Oct 2000
Posts: 91
What exactly is happening when they hack you?

You have my full sympathy by the way. smile

#67257 02/18/2001 5:25 AM
Joined: Feb 2001
Posts: 2,285
Old Hand
Old Hand
Joined: Feb 2001
Posts: 2,285
My ISP runs a program called CGI-Wrap. It allows me to have my CGI directory set to 705 or similar. Not allowing anyone browsing the server dirsctories access to my CGI. The CGI-Wrap makes the directory act like the permissions are world writeable/executable without the risk of actually being 777. I don't know your server situation, but maybe you can get a Wrap setup for your CGI directory. Anyway... good luck. I've been hacked/deleted before and I know your pain. Hang in there.

#67258 02/18/2001 2:15 PM
Joined: Mar 2000
Posts: 305
Member
Member
Offline
Joined: Mar 2000
Posts: 305
i'm gonna play around a bit, thanx.

what happens when the hack me? usually al our cgi files fall to peices and sometimes the main pages.

#67259 02/18/2001 3:20 PM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
Dude, if you can break out of your directory structure, your host has some MAJOR issues.

If they are REFUSING to take a look at the problems, then your host very simply sucks. Go find a host that's actually competent...


UBB.classic: Love it or hate it, it was mine.
Sponsored Links
#67260 02/18/2001 3:25 PM
Joined: Aug 2000
Posts: 1,290
Addict
Addict
Offline
Joined: Aug 2000
Posts: 1,290
web2010.com offers 1024 bit security. OML, in IE 5.5 your side pop menu hangs and won't clear away..Thought you should know. UBBDEV is having to redo theirs, maybe they can help point ya in the right direction.

[ February 18, 2001: Message edited by: C_P ]


- Custom Web Development
http://www.JCSWebDev.com
#67261 02/18/2001 5:15 PM
Joined: Oct 2000
Posts: 966
Member
Member
Offline
Joined: Oct 2000
Posts: 966
You have my sympathy too, if you've read my recent posts here, you know that something like that happened to me the other day, and it really really really sucks..

I'm thinking one person, or a group of people really have it in for you.. I would recommend moving servers also, you should NOT be able to get into other's sites using wsftp.. Hell, the server I use, I can set it so that a user has access only to their own directory, and not even the rest of my site. So the fact you can get into other's sites, is a terrible problem, and indicative of the overall security in other areas.

The number of attacks suggest this is probably someone you know and who has a grudge against you for some reason.. I'd try to figure out a list of possibilities, and contact the FBI's office that deals with this kind of stuff
http://www.fbi.gov/programs/ipcis/intrusion.htm

That's the only link I can currently find, but try contacting your local field office for assistance.. Might seem like going over the top, but it seems to me that you're at the end of your tether, and the FBI will (hopefully) be able to help you track down who's doing this, since you can reasonably expect another attack sometime soon.

#67262 02/18/2001 8:14 PM
Joined: Aug 2000
Posts: 299
Member
Member
Offline
Joined: Aug 2000
Posts: 299
I've just been hack too, well more like 6 times this month (Check out my site site annoucement). I know how you feel man as I'm just one of the recent victim.

By the way where do I get CGI-Warp?

#67263 02/19/2001 3:12 AM
Joined: Mar 2000
Posts: 305
Member
Member
Offline
Joined: Mar 2000
Posts: 305
our server is scary, but we are under contract for 2 more months. and i know there are people out there attempting too take us out. some of the messages left on our files prove it. i remember last month we were left one in replacement of Ultimate.cgi that said:

"good luck in the competition".

makes me mad.

#67264 02/19/2001 11:43 AM
Joined: Oct 2000
Posts: 966
Member
Member
Offline
Joined: Oct 2000
Posts: 966
So it's probably someone who visits here and was a competitor in the competition? How pathetic..

Sponsored Links
#67265 02/19/2001 2:06 PM
Joined: Feb 2001
Posts: 2,285
Old Hand
Old Hand
Joined: Feb 2001
Posts: 2,285
You can find info on cgiwrap here: http://cgiwrap.unixtools.org/

The home page for the author of cgiwrap is here: http://www.unixtools.org/~nneul/

I didn't set it up myself so I don't have experience with that end of it. My ISP was kind enough to offer cgiwrap as a feature.

#67266 02/19/2001 6:26 PM
Joined: Mar 2000
Posts: 305
Member
Member
Offline
Joined: Mar 2000
Posts: 305
Lucia, i know what u mean. i was angry, but in the same i couldn't stop smiling cause it was so pathetic.

#67267 02/19/2001 6:40 PM
Joined: Jul 2000
Posts: 1,349
Ell Offline
Member
Member
Offline
Joined: Jul 2000
Posts: 1,349
Make sure your host is using the latest version of CGI-wrap (which is hell, by the way. My server runs it, so you have my deepest sympathy). I'm 99% sure there have been security issues with old versions of it..

#67268 02/20/2001 7:17 AM
Joined: Nov 2000
Posts: 168
Member
Member
Offline
Joined: Nov 2000
Posts: 168
Dealing with sysops all the time I've found that mostly when they say there box got "hacked" the screwed it up some how..
On a typical unix machine you should be able to view the entire dir structure of the system but its dynamic and you won't be able to view things like /etc/passwd it will just show an x where the password should be...
And as for the sever pinging you, well if you put a firewall up and just surf the net you'll get ping'd and scan'd by most of the servers you do an http request from...

#67269 02/20/2001 7:19 PM
Joined: Aug 2000
Posts: 299
Member
Member
Offline
Joined: Aug 2000
Posts: 299
Thanks for the CGI-Warp link Stilgar. smile

#67270 02/20/2001 7:31 PM
Joined: Feb 2001
Posts: 2,285
Old Hand
Old Hand
Joined: Feb 2001
Posts: 2,285
my pleasure. Heed Borg's word and make sure you have the latest version.


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)