Site hack (non-php)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • conard
    Junior Member
    • May 2004
    • 12

    Site hack (non-php)

    I've had 2 different accounts (under my root account) hacked (one hacked twice)! Both sites are not PHP or mySQL. Just simple HTML. Looks like the files are ad-ware or something. ihtml, a.exe, etc that are called from other sites. Anyone else experience this and is anything being done about it?

    Thanks,
    Steve
  • Andy
    Senior Member
    • Mar 2004
    • 257

    #2
    Where are these files located?
    Andy

    Comment

    • ChrisTech
      Senior Member
      • Mar 2004
      • 530

      #3
      You should submit a trouble ticket asap so Andrew or his techs can find the issue and clear it up.
      Hosting at Dathorn since March 2003!

      My Interwebs speed on Charter Cable!

      Comment

      • conard
        Junior Member
        • May 2004
        • 12

        #4
        The files have been removed by the client. They were located in the "www" directory. If I can get a list of files then I'll submit them in a trouble ticket. Also, clients bandwidth usage went for ~100MB/month to 2GB/month (account limit).

        Thanks,
        Steve

        Comment

        • sdjl
          Senior Member
          • Mar 2004
          • 502

          #5
          Sounds like your customer isn't being careful with his/her password.
          Get them to check their own PC for spyware or other nasty stuff that could be logging keystrokes and similar.

          David

          p.s. I'm not sure how this relates to the "Script security" thread if it isn't directly linked to a script of some sort..
          -----
          Do you fear the obsolescence of the metanarrative apparatus of legitimation?

          Comment

          • conard
            Junior Member
            • May 2004
            • 12

            #6
            That's possible. But it happened to two different clients.

            Comment

            • sdjl
              Senior Member
              • Mar 2004
              • 502

              #7
              Maybe they're as bad as one another
              Alternatively they could have scripts on their accounts that they don't realise.

              David
              -----
              Do you fear the obsolescence of the metanarrative apparatus of legitimation?

              Comment

              • Jonathan
                Senior Member
                • Mar 2004
                • 1229

                #8
                Since this is not exactly script-related, I'm moving it to General Support.
                My personal opinion is this:

                1. Have them each update/get a good Anti-virius + Ad-Aware (Good program)
                2. If they do not have a firewall, turn on XP's (or get ZoneAlarm [good simple firewall])
                3. Have them each scan their PCs with both.
                4. Change their passwords via cPanel, or you can via WHM (AFTER you clean YOUR PC)
                5. Delete ALL files and reupload backups of some sort; alternative, see #6
                6. If no backups, download each file and check it by hand and scan it before reuploading.
                "How can someone be so distracted yet so focused?"
                - C

                Comment

                • AndrewT
                  Administrator
                  • Mar 2004
                  • 3653

                  #9
                  No one here can tell you what happened exactly with any sort of certainty. We can look into it if you submit a trouble ticket but if anything has been changed since it happened the usefulness of information available will be limited.

                  Comment

                  • conard
                    Junior Member
                    • May 2004
                    • 12

                    #10
                    Thanks guys! I'll keep my eye out and if it happens again I'll provide a detailed file list and description in a trouble ticket.

                    Thanks,
                    Steve

                    Comment

                    • AndrewT
                      Administrator
                      • Mar 2004
                      • 3653

                      #11
                      A file list alone does not help all that much, you would need to submit a ticket with the account username and not touch anything until we've gone over it.

                      Comment

                      Working...