New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1133
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Web site has been hijacked by 008k.com

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests
View previous topic :: View next topic  
Author Message
KevinE

Guest






PostPosted: Thu Apr 15, 2004 2:31 pm    Post subject: Web site has been hijacked by 008k.com
Reply with quote

It's a php web site and I am pretty sure that every current update from Nukecops has been applied to the site and now I have a high-tech review site popping porn pictures and the grab and snatch and never let you go routine. I haven't a clue about the best way to do debug a virus infected web site or even where to start looking. The redirect happens on the home page if that is anyhelp at all and according to Kapersky they are using a VB trojan of sort which must be embedded into one of the files.

Anyone offer and clues I am now on day 4 without a site and my server company says that it is my problem since I run PHP.

Thank
Back to top
Blast

News Admin
News Admin
Premium Member
Premium Member


Joined: Sep 20, 2003
Posts: 1820
Location: A Kiwi in Sydney, Australia

PostPosted: Thu Apr 15, 2004 10:51 pm    Post subject:
Reply with quote

Is it happening on the homepage (index.php) only?
or is it happening on other pages as well?

Can you PM me the website

cheers...

_________________
Blast
---------------------------
"Timing is the essential factor in the success of any raindance"
---------------------------
Back to top
View users profile Send private message Send email Visit posters website
KevinE

Guest






PostPosted: Sat Apr 17, 2004 12:47 pm    Post subject:
Reply with quote

I ended up locking the door on the site after making two more repairs from backup they came and trashed over the course of two nights again. I was able to do a bit of searching on the net and found this tasty tidbit of information and I think this is the source of where my trouble came from.

http://telexxx.persianblog.com/

One trick they did use was to create addition GOD account on all SQL databases so they could play with them as they wanted to when they wanted to. The funniest part was my server company told me the first time they got in was through my site the second and third was through them and they asked me to leave since they now think PHP is a security risk, now perhaps I do as well.
Back to top
Blast

News Admin
News Admin
Premium Member
Premium Member


Joined: Sep 20, 2003
Posts: 1820
Location: A Kiwi in Sydney, Australia

PostPosted: Sat Apr 17, 2004 4:48 pm    Post subject:
Reply with quote

That would be a shame if you felt that following along with PHP wasn't worth pursuing due to someone hacking your site. Lets face it if the hackers got in through your server maybe the server is the security risk not PHP,
(or for that matter, your site)

This site is run with PHP and has stood the test of time
But in the end it comes down to what you are comfortable with

Hope it works out
cheers...

_________________
Blast
---------------------------
"Timing is the essential factor in the success of any raindance"
---------------------------
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests All times are GMT - 5 Hours
Page 1 of 1

 
 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops