I've been hacked!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Nick Robinson
    Junior Member
    • Jun 2004
    • 11

    #1

    I've been hacked!

    At some point today my website, www.maine-street.com , was hacked. It wasnt very cleaver or anything, but it happened (First time too). Id like to figure out who did it and bring the site back up, and hopefully have everything restored. The site was just a PHPBB forum, soit may have been an exploit in that software. can anyone give me some help? Thanks a lot. I already submitted a trouble ticket so to get the ball rolling in getting the person who did it.
  • Nick Robinson
    Junior Member
    • Jun 2004
    • 11

    #2
    I downloaded .lastlogin from FTP and it says

    AC9CDA73.ipt.aol.com

    Comment

    • Nick Robinson
      Junior Member
      • Jun 2004
      • 11

      #3
      I changed the front page so it doesnt have the 'hacked' index file. All the other pages have the same message:

      This site is defaced!!!
      NeverEverNoSanity WebWorm generation 9.

      Which you can see here:



      A google search of NeverEverNoSanity brings up 0 results....

      Comment

      • conard
        Junior Member
        • May 2004
        • 12

        #4
        I had the same thing happen to my site, postwhore.net.

        Comment

        • ChrisTech
          Senior Member
          • Mar 2004
          • 530

          #5
          There is another thread on the forums about this. A security patch came out in mid nov that fixed this issue. People need to patch their forums.
          Hosting at Dathorn since March 2003!

          My Interwebs speed on Charter Cable!

          Comment

          • -Oz-
            Senior Member
            • Mar 2004
            • 545

            #6
            Chris, you're wrong. I got hacked with phpbb 2.0.11.

            This is big and Andrew needs to upgrade php to handle it: http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046

            I got hacked as well.
            Dan Blomberg

            Comment

            • sdjl
              Senior Member
              • Mar 2004
              • 502

              #7
              Originally posted by Nick Robinson
              I downloaded .lastlogin from FTP and it says

              AC9CDA73.ipt.aol.com
              That hostname should be unique to the user. I think AOL employs a unique hostname basis rather than a unique IP system.
              You could probably report it

              David
              -----
              Do you fear the obsolescence of the metanarrative apparatus of legitimation?

              Comment

              Working...