Go to Post Maybe between Art, skimoose, and some of the other intelligent folks on CD (most of us), we can force a redesign of the game.... - EricH [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications > Website Design/Showcase
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 13-06-2007, 23:16
TheOtherGuy's Avatar
TheOtherGuy TheOtherGuy is offline
Unregistered User
AKA: Kevin Forbes
FRC #4183 (Bit Buckets)
Team Role: Engineer
 
Join Date: Jul 2006
Rookie Year: 2006
Location: Tucson, AZ
Posts: 408
TheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond reputeTheOtherGuy has a reputation beyond repute
Website Hacking Problems

Our team (1726) has had a website for some time now, and just recently (sunday) I woke up, checked the website, and it had been hacked. At first it looked like just the index file had been hacked, but after looking around, I realized that several other files had been added or changed in different directories. I've tried deleting all the files I could find that were changed, but every time I reload our index file, it is only several hours before it is changed back. You can see what the hacked page looks like here:

http://www.project1726.org

But PLEASE don't click on any links that may be on there.

I wanted to know if anyone had experience in isolating and removing problems like this? We have continually contacted our hosting service, http://www.globat.com, but even though they delete the changed folders and files, the problem persists.

Any help right now would be extremely appreciated!

Thanks!
-1726 webmaster
__________________

Last edited by TheOtherGuy : 13-06-2007 at 23:48.
  #2   Spotlight this post!  
Unread 13-06-2007, 23:54
Mike's Avatar
Mike Mike is offline
has common ground with Matt Krass
AKA: Mike Sorrenti
FRC #0237 (Sie-H2O-Bots (See-Hoe-Bots) [T.R.I.B.E.])
Team Role: Programmer
 
Join Date: Dec 2004
Rookie Year: 2004
Location: Watertown, CT
Posts: 1,003
Mike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond repute
Re: Website Hacking Problems

Change your password?

EDIT: Appears like its just some guy looking to throw his name here and there. Nothing serious really, just some e-graffiti. Change your password and he'll take the path of least resistance (some other site).
__________________
http://www.mikesorrenti.com/
  #3   Spotlight this post!  
Unread 13-06-2007, 23:57
yodameister yodameister is offline
The Mad Chemist
FRC #2791
Team Role: Teacher
 
Join Date: Jan 2006
Rookie Year: 2006
Location: Latham, NY
Posts: 313
yodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant future
Re: Website Hacking Problems

Changing the password was the first thing we did. We are also going to look into another hosting site.
  #4   Spotlight this post!  
Unread 13-06-2007, 23:59
Randy Randy is offline
Registered User
no team
Team Role: Alumni
 
Join Date: Feb 2003
Location: Atlanta
Posts: 79
Randy will become famous soon enough
Re: Website Hacking Problems

Check your raw access logs to see if a scripted page is being exploited.
__________________
FREE WEB HOSTING for FIRST teams and related organizations.
  • Team sites
  • Image Hosting
  • Video Hosting
Email promo@sevaa.com or click here for details.
  #5   Spotlight this post!  
Unread 14-06-2007, 00:01
sanddrag sanddrag is offline
On to my 16th year in FRC
FRC #0696 (Circuit Breakers)
Team Role: Teacher
 
Join Date: Jul 2002
Rookie Year: 2002
Location: Glendale, CA
Posts: 8,516
sanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond repute
Re: Website Hacking Problems

did you change ALL the paswords related to the account? Are you running any sort of a script or CMS or forum or something with a sercurity hole? But yeah, most likely this would be your host's problem. And if they can't prevent it, you should change hosts.
  #6   Spotlight this post!  
Unread 14-06-2007, 00:03
Mike's Avatar
Mike Mike is offline
has common ground with Matt Krass
AKA: Mike Sorrenti
FRC #0237 (Sie-H2O-Bots (See-Hoe-Bots) [T.R.I.B.E.])
Team Role: Programmer
 
Join Date: Dec 2004
Rookie Year: 2004
Location: Watertown, CT
Posts: 1,003
Mike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond reputeMike has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by Randy View Post
Check your raw access logs to see if a scripted page is being exploited.
Hey, I know you.

OP:
Are there any scripts that use ftp? The host should also have a log of who logged into the ftp server and at what time.
__________________
http://www.mikesorrenti.com/
  #7   Spotlight this post!  
Unread 14-06-2007, 00:05
yodameister yodameister is offline
The Mad Chemist
FRC #2791
Team Role: Teacher
 
Join Date: Jan 2006
Rookie Year: 2006
Location: Latham, NY
Posts: 313
yodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant future
Re: Website Hacking Problems

For now we are disabling all forums, blogs, picture uploading capacity, etc. We hope that this will clear up the problem (for now).
  #8   Spotlight this post!  
Unread 14-06-2007, 00:06
sanddrag sanddrag is offline
On to my 16th year in FRC
FRC #0696 (Circuit Breakers)
Team Role: Teacher
 
Join Date: Jul 2002
Rookie Year: 2002
Location: Glendale, CA
Posts: 8,516
sanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by yodameister View Post
For now we are disabling all forums, blogs, picture uploading capacity, etc. We hope that this will clear up the problem (for now).
Oh well there you go. I bet you it was one of those scripts that had a security hole. Were they all current/updated?
  #9   Spotlight this post!  
Unread 14-06-2007, 00:08
yodameister yodameister is offline
The Mad Chemist
FRC #2791
Team Role: Teacher
 
Join Date: Jan 2006
Rookie Year: 2006
Location: Latham, NY
Posts: 313
yodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant futureyodameister has a brilliant future
Re: Website Hacking Problems

Quote:
Originally Posted by sanddrag View Post
Oh well there you go. I bet you it was one of those scripts that had a security hole. Were they all current/updated?
As far as I know they were, but then I'm not the webmaster.
  #10   Spotlight this post!  
Unread 14-06-2007, 01:58
artdutra04's Avatar
artdutra04 artdutra04 is offline
VEX Robotics Engineer
AKA: Arthur Dutra IV; NERD #18
FRC #0148 (Robowranglers)
Team Role: Engineer
 
Join Date: Mar 2005
Rookie Year: 2002
Location: Greenville, TX
Posts: 3,078
artdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by yodameister View Post
For now we are disabling all forums, blogs, picture uploading capacity, etc. We hope that this will clear up the problem (for now).
That won't totally solve the problem, as disabling the photo galleries and forums will only continue to hide the underlying security loophole.

Check your access logs, and see if you can find anything there.

Check the file/folder permissions of the root directory. If it's are listed as 777, this is a security problem. Change (chmod) them to 770 or 755. You can create subfolders with a chmod setting of 777, but only do so where your scripts actually need file creation/deletion/alteration permissions. If all you have in a directory is static HTML files that you alter via FTP, lock down the file permissions for that directory.

If users can upload files through a script, make sure the script is doing proper checks of the file to verify the contents. Check PHPbb or your photo gallery websites for any plug-ins that provide extra security in this department.

Check to make sure there aren't any additional user accounts with administrator privileges. If the hacker found his way into your website, he could have also gained access to your Control Panel, where he could have created a back-door FTP user account with a separate username and password.

I'd suspect that there is some sort of backdoor entrance somewhere (perhaps one exploited by a security loophole in your scripts), especially since you said changing passwords didn't solve the problem. Check everything. FTP. Forums. etc.

And last, but not least, make sure your passwords are secure. Don't pick obvious things. Use lots of 'weird' things like l0w3rcaS3 & uPpeRca5e letters, along with 5pEC!aL cHaR|\CT3r5. Make long passwords. Don't ever store your password anywhere except your head.
__________________
Art Dutra IV
Robotics Engineer, VEX Robotics, Inc., a subsidiary of Innovation First International (IFI)
Robowranglers Team 148 | GUS Robotics Team 228 (Alumni) | Rho Beta Epsilon (Alumni) | @arthurdutra

世上无难事,只怕有心人.
  #11   Spotlight this post!  
Unread 14-06-2007, 03:46
AustinSchuh AustinSchuh is offline
Registered User
FRC #0971 (Spartan Robotics) #254 (The Cheesy Poofs)
Team Role: Engineer
 
Join Date: Feb 2005
Rookie Year: 1999
Location: Los Altos, CA
Posts: 803
AustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond reputeAustinSchuh has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by artdutra04 View Post
Don't ever store your password anywhere except your head.
Or in an encrypted file.

Since I make such long and random passwords as you are recomending myself, I can't ever remember all of them. I just remember the one password to an encrypted file where I store all my other passwords, and then copy and paste the other passwords from the file. If you go this route, make sure that you are using a good pasphrase for the encrypted file, and you trust the software that is encrypting your data. If anyone gets ahold of the file, your passwords would only be as secure as the password to the file and the encryption scheme.

In case anyone is interested, I use gpg to encrypt my stuff.
  #12   Spotlight this post!  
Unread 14-06-2007, 11:05
artdutra04's Avatar
artdutra04 artdutra04 is offline
VEX Robotics Engineer
AKA: Arthur Dutra IV; NERD #18
FRC #0148 (Robowranglers)
Team Role: Engineer
 
Join Date: Mar 2005
Rookie Year: 2002
Location: Greenville, TX
Posts: 3,078
artdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by AustinSchuh View Post
Since I make such long and random passwords as you are recomending myself, I can't ever remember all of them.
Maybe I'm just weird in the sense that I can remember many long, obscure passwords, just like how I can remember pi is 3.1415626535897932384626433832795028841...
__________________
Art Dutra IV
Robotics Engineer, VEX Robotics, Inc., a subsidiary of Innovation First International (IFI)
Robowranglers Team 148 | GUS Robotics Team 228 (Alumni) | Rho Beta Epsilon (Alumni) | @arthurdutra

世上无难事,只怕有心人.
  #13   Spotlight this post!  
Unread 14-06-2007, 11:54
Pat Fairbank's Avatar
Pat Fairbank Pat Fairbank is offline
Circuit Breaker
FRC #0254 (The Cheesy Poofs)
Team Role: Engineer
 
Join Date: Mar 2003
Rookie Year: 2001
Location: San Jose, CA
Posts: 2,132
Pat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond reputePat Fairbank has a reputation beyond repute
Send a message via MSN to Pat Fairbank
Re: Website Hacking Problems

Quote:
Originally Posted by artdutra04 View Post
Maybe I'm just weird in the sense that I can remember many long, obscure passwords, just like how I can remember pi is 3.1415626535897932384626433832795028841...
[offtopic] Except that there's an error in your pi. [/offtopic]
__________________
Patrick Fairbank
Team 254 | Mentor (2012-)
Team 1503 | Mentor (2007-2011)
Team 296 | Alumnus (2001-2004) | Mentor (2005-2006)

patfairbank.com
  #14   Spotlight this post!  
Unread 14-06-2007, 11:56
Gabe's Avatar
Gabe Gabe is offline
Pocket Full of Tools
FRC #0604 (Quixilver)
Team Role: College Student
 
Join Date: Mar 2006
Rookie Year: 2001
Location: California
Posts: 654
Gabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond reputeGabe has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by artdutra04 View Post
Maybe I'm just weird in the sense that I can remember many long, obscure passwords, just like how I can remember pi is 3.1415626535897932384626433832795028841...
3.14159265...
__________________
Team site: Q U I X I L V E R
My favorite tool is my imagination; I’m always finding new ways to use it.
  #15   Spotlight this post!  
Unread 14-06-2007, 13:59
artdutra04's Avatar
artdutra04 artdutra04 is offline
VEX Robotics Engineer
AKA: Arthur Dutra IV; NERD #18
FRC #0148 (Robowranglers)
Team Role: Engineer
 
Join Date: Mar 2005
Rookie Year: 2002
Location: Greenville, TX
Posts: 3,078
artdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond reputeartdutra04 has a reputation beyond repute
Re: Website Hacking Problems

Quote:
Originally Posted by Pat Fairbank View Post
[offtopic] Except that there's an error in your pi. [/offtopic]
Oops. 6 and 9 are right next to each other on the numeric keypad, and Firefox doesn't spell check pi.
__________________
Art Dutra IV
Robotics Engineer, VEX Robotics, Inc., a subsidiary of Innovation First International (IFI)
Robowranglers Team 148 | GUS Robotics Team 228 (Alumni) | Rho Beta Epsilon (Alumni) | @arthurdutra

世上无难事,只怕有心人.
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP! Website hosting problems. Tottanka Website Design/Showcase 27 04-02-2007 22:28
263's Computer Hacking Competition SeanCassidy Chit-Chat 31 29-09-2005 15:11
Using non joystick controls with Operator Interface (Hacking Various Controllers) Astronouth7303 Control System 58 02-02-2005 15:56
Talk about the 'hacking' here. Brandon Martus Chit-Chat 12 08-07-2003 15:53
Hacking The Segway MattK Dean Kamen's Inventions 16 31-07-2002 20:51


All times are GMT -5. The time now is 01:30.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi