Posts: 3,631
Threads: 899
Joined: Dec 2003
Reputation:
0
hi guys
the site was defaced probably due to really old openssl versions etc
heres the servers details
Apache/1.3.29 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.2 PHP/4.3.4 FrontPage/5.0.2.2634 mod_ssl/2.8.16 OpenSSL/0.9.6b
its more than likely rootkitted by now
ive put up a temp index.php page just to alert people that its down but below is a screenshot of the defaced page
cheers
anyweb
<a class="ipsAttachLink ipsAttachLink_image" href="<fileStore.core_Attachment>/post-38-1072184360.png" data-fileid="12">[img]<fileStore.core_Attachment>/post-38-1072184360.png[/img]</a>
Attached Files
Screenshot_1.png (Size: 91.38 KB / Downloads: 0)
Posts: 254
Threads: 66
Joined: Dec 2003
Reputation:
0
Nice. At leas the deface wasn't anything explictive or anything. That's at least a positive side. Thanks for that info, this could be the start of something fun. :P
Sorry to hear about the defacing, but I like a challenge, and I feel like fighting back. Go go go....
[img]<___base_url___>/uploads/emoticons/default_ph34r.png[/img][img]<___base_url___>/uploads/emoticons/default_ph34r.png[/img][img]<___base_url___>/uploads/emoticons/default_ph34r.png[/img][img]<___base_url___>/uploads/emoticons/default_ph34r.png[/img][img]<___base_url___>/uploads/emoticons/default_ph34r.png[/img]
Posts: 3,631
Threads: 899
Joined: Dec 2003
Reputation:
0
478 index.html 's man these guys are assholes...
Posts: 292
Threads: 45
Joined: Dec 2003
Reputation:
0
it looks like everything was up to date. My guess is they got someone's account and got in that way
Posts: 1
Threads: 0
Joined: Dec 2003
Reputation:
0
Hacked? [img]<___base_url___>/uploads/emoticons/default_ohmy.png[/img] lol...... [img]<___base_url___>/uploads/emoticons/default_rolleyes.gif[/img]
Posts: 3
Threads: 0
Joined: Dec 2003
Reputation:
0
Anyweb mate it's your forums you're the one that supposed to help others lol!
Posts: 3,631
Threads: 899
Joined: Dec 2003
Reputation:
0
i got the site back up by
ftping the entire content down locally,
deleting all index.htmls and index.php's that were created
taking a backup of the site from october and overwriting the current one with that and then ftp'ing that all back to the site
seems to work now at least, and the host says the server wasnt rooted, that the hackers exploted a vulnerability (which they wont tell) and all is updated and ok now
thats good for xmas
cheers
anyweb
Posts: 3
Threads: 0
Joined: Dec 2003
Reputation:
0
I meant that this linux n00b is your forums...
What can u and longbow do to secure HTAS' forums and prevent the bored hackers from hacking to our site again?
And thanks a lot to you and longbow for fixing the site :)