Page 2 of 5 FirstFirst 1234 ... LastLast
Results 11 to 20 of 44

Thread: Help find hole

  1. #11
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    Had a look at that script. If this was in my server I would have cleaned up everything, with new db, db user etc. It writes to db does it not ?

  2. #12
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    Sems to be a r57shell hack, if that makes sense to anyone.

  3. #13
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Quote Originally Posted by JohnM View Post
    Had a look at that script. If this was in my server I would have cleaned up everything, with new db, db user etc. It writes to db does it not ?
    I've searched through db, no inserts or whatever in sight. I guess there are functions in backdoor for that but they weren't used. Changed passwords and such anyway.

    Will also compare two daily db dumps before and after hack to be sure.

    Sems to be a r57shell hack, if that makes sense to anyone.
    Not to me. :)
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  4. #14
    Otto's Avatar
    Otto is offline On The Rocks
    Join Date
    Apr 2009
    Location
    Memphis, TN
    Posts
    862

    Default

    The r57shell is just the payload, not the hack itself. There's a lot of different scripts like these, which basically give full access to the system. The hack just drops one of them there.

  5. #15
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Ok, just got an alert on repeat attempt.

    Goes exactly same:
    - enters through same service looking for sites on same server;
    - loads home page;
    - goes to login, somehow gets redirected to admin;
    - hits IP block and is sent to 404 (eat that bastard).

    So hole is still there somewhere. :((( If I hadn't hardened access I would be now screwed twice.

    Any idea how can I log details of login attempt to see how the hell he does that?
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  6. #16
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Update - my blog's database is gone. Shit. Now I am really mad.
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  7. #17
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    If your host has 10% hacked sites, its time to move. Its a hackers party in there.

    http://www.google.com/safebrowsing/d...?site=AS:30475

    http://wehostwebsites.com/ doesnt impress me either.
    Last edited by JohnM; 09-01-2009 at 01:22 PM.
    John Myrstad

  8. #18
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Quote Originally Posted by JohnM View Post
    If your host has 10% hacked sites, its time to move. Its a hackers party in there.

    http://www.google.com/safebrowsing/d...?site=AS:30475

    http://wehostwebsites.com/ doesnt impress me either.
    Previous host started clean but now up to some infected sites as well in Google safebrowsing... Can move back there, still have paid time. At elast I didn't get hacked twice in a row there.

    What is second URL? Not either of my hosts.
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  9. #19
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,358

    Default

    I imagine WPWebhost was notified of the second hack attempt with the database deletion? What are they saying on their end? Or are they acting like there is no problem?

  10. #20
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Quote Originally Posted by Jeffro View Post
    I imagine WPWebhost was notified of the second hack attempt with the database deletion? What are they saying on their end? Or are they acting like there is no problem?
    I sent details to guy-possibly-from-security-department, no reply at moment.

    By now I could settle for information that I personally did something retarded and left it wide open. I just want freaking hole found and fixed.
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

Page 2 of 5 FirstFirst 1234 ... LastLast

LinkBacks (?)

  1. 08-29-2009, 01:03 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •