My site has been defaced

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rod
    Member
    • Mar 2004
    • 65

    #1

    My site has been defaced

    This site is defaced!!!
    NeverEverNoSanity WebWorm generation 12.

    --
    My subdomain using wordpress and the main domain...

    Let me check if other domains were attacked
  • AndrewT
    Administrator
    • Mar 2004
    • 3655

    #2
    What scripts are runnong on the domains?

    Comment

    • rod
      Member
      • Mar 2004
      • 65

      #3
      Im running wordpress 1.2
      Imagevue (a flash gallery)

      Let me check my other scripts


      I lost tons of things!!!


      I also running an old version of pivotlog (a private url)
      Phpbb forums
      Last edited by rod; 12-21-2004, 12:35 PM.

      Comment

      • ErDrRon
        Junior Member
        • Mar 2004
        • 8

        #4
        I also have one user with the same hack.. it has overwritten all of his files. The following message shows on index.html:



        This site is defaced!!!

        NeverEverNoSanity WebWorm generation 9.We are on cpanel25. Any thoughts?

        Ron

        Comment

        • AndrewT
          Administrator
          • Mar 2004
          • 3655

          #5
          Please post a list of the scripts that are on your sites as that is how this is occuring.

          Comment

          • ErDrRon
            Junior Member
            • Mar 2004
            • 8

            #6
            Outside of phpBB the only scripts are those that are installed when originally setting up the site.


            Ron

            Comment

            • AndrewT
              Administrator
              • Mar 2004
              • 3655

              #7
              phpBB is most likely the problem. That is one of the easiest scripts to exploit at this point if it is not upgraded.

              Comment

              • rod
                Member
                • Mar 2004
                • 65

                #8
                looks like phpbb is the script.

                Comment

                • ErDrRon
                  Junior Member
                  • Mar 2004
                  • 8

                  #9
                  It looks like this is the latest iteration of a phpBB exploit. Read the following Security bulletin. I am upgrading his phpBB version to 2.0.11 as we speak.


                  Keep up-to-date with the latest Kaspersky news, press releases, and access media resources.


                  Ron

                  Comment

                  • ErDrRon
                    Junior Member
                    • Mar 2004
                    • 8

                    #10
                    Net-Worm.Perl.Santy.a

                    Dec 21 2004



                    BehaviorNet-WormTechnical DetailsThis worm uses a vulnerability in phpBB, which is used to create forums and web sites, to spread via the Internet. phpBB versions lower than 2.0.11 are vulnerable.

                    The worm is written in Perl, and is 4966 bytes in size.

                    Propagation

                    The worm creates a specially formulated Google search request. This request will give a list of sites running vulnerable versions of phpBB. The worm then sends a request to all sites found, which contains an exploit for the vulnerability. When the server under attack processes the exploit, the worm penetrates the site and gains control. This process is then repeated.

                    The worm scans all site directories, and overwrites files with the following extensions:

                    .asp.htm.jsp.php .phtm.shtmwith the following text:

                    This site is defaced!!!This site is defaced!!!NeverEverNoSanity WebWorm generationUsing MSN to search for sites containing the above strings gives an extensive list of sites; evidence that Santy.a is currently causing an epidemic.

                    Users should note that this worm is not dangerous; it will not infect computers if users view an infected site.

                    Comment

                    • rod
                      Member
                      • Mar 2004
                      • 65

                      #11
                      we dont have a backup right?

                      Comment

                      • -Oz-
                        Senior Member
                        • Mar 2004
                        • 545

                        #12
                        I also got hacked.

                        Andrew: http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046
                        Dan Blomberg

                        Comment

                        • Frank Hagan
                          Senior Member
                          • Mar 2004
                          • 724

                          #13
                          Dathorn is upgrading PHP as soon as the Cpanel upgrade comes through (I asked in a trouble ticket earlier this week.)

                          Comment

                          • Jonathan
                            Senior Member
                            • Mar 2004
                            • 1229

                            #14
                            Originally posted by ErDrRon
                            Net-Worm.Perl.Santy.a
                            The worm scans all site directories, and overwrites files with the following extensions:

                            .asp.htm.jsp.php .phtm.shtmwith the following text:

                            This site is defaced!!!This site is defaced!!!NeverEverNoSanity WebWorm generationUsing MSN to search for sites containing the above strings gives an extensive list of sites; evidence that Santy.a is currently causing an epidemic.

                            Users should note that this worm is not dangerous; it will not infect computers if users view an infected site.
                            Why not use .htaccess to force PHP to phrase, say, .file or some
                            off the wall extention? Maybe the initials of the site?

                            Though for something like forums, it'd not be worth it
                            "How can someone be so distracted yet so focused?"
                            - C

                            Comment

                            • Frank Hagan
                              Senior Member
                              • Mar 2004
                              • 724

                              #15
                              One of my sites got hit ... but the rest appear to be OK. Dathorn has upgraded Cpanel08 to the most recent PHP version that is supposed to protect us, so we'll see.

                              I hope it only affected the index.php files ... if it did them all, we'll have to restore them all! That would be a pain.

                              Comment

                              Working...