Hacked again
hey guys,
Just thought i share this with you.
I got hacked again and this time it was after modifying the php.ini(register_globals = Off). and before installing dolphin 6.1.3 patch.
My site must be very importent to be hacked 3 times within the last 2 weeks..have to say, i'm feeling kind importent...LOL
the first 2 times i didn't have the register_globals off.
the last hack had something to do with paypal. who ever hacked my site put in a folder/files under the chat folder(chat/www.paypal.com).
I must have changed cpanel pwd good 3 times but i have a feeling there not using my password to get into my site.
---------------------------------------------------------------------------
emails i received from pay pal
---------------
Hello.
It has come to our attention that a PayPal spoof site has been set up at
removed site info.
We believe that your website has been compromised.
We recommend that you change your password for your web hosting accounts as soon as possible, and then remove the offending material.
If you have any logs or data files that could help us track down the perpetrator of this crime, we would appreciate it if you could forward that on to us.
If you have any questions or need further assistance, please do not hesitate to ask.
Thank you.
PayPal.com
securityalerts@ebay.com============
from Jeff
with email
ftsteam@paypal.com
-------------------------------------------------------------------------
email from: phishcop
Your web server has been hacked and is being used to host this phishing site: removed site info/folder.
Please remove the phishing files and secure your server.
============
from Patrick Klos
with email
admin@phishcop.net
Once their "bot" adds you to their list of vulnerable servers they will hit you again and again.. if you are VERY unlucky they will post a link to the vulnerable file in a hacker forum so EVERYONE will start trying to take a crack at you.
I keep saying "you" but the bottom line is if you are using a shared see more
Once their "bot" adds you to their list of vulnerable servers they will hit you again and again.. if you are VERY unlucky they will post a link to the vulnerable file in a hacker forum so EVERYONE will start trying to take a crack at you.
I keep saying "you" but the bottom line is if you are using a shared see more
and wonder why you get hacked?
like mscott said, its shared hosting, once you have access to any site on a shared host with register globals on, you have access to the 1200 websites that share the same host on that server. no matter if you turn globals off, they gain access via the master settings,
i keep hearing this everyday now .........
so yes I think 100% its cause of it being on a shared server is giving the back door open to all people on that server thats being shared
---------------
Hello.
It has come to our attention that a PayPal spoof site has been set up at
removed site info.
We believe that your website has been compromised.
We recommend that you change your password for your web hosting accounts as soon as possible, and then remove the offending material.
If you have any logs or data files that could help us track down the perpetrator of this crime, we would appreciate it if you could forward that on to us.
If see more
All I ever hear is shared hosting is the problem. True it can be a problem but I wouldn't say they are any more hackable than any other.
These posts above me mention vps and dedicated but they are selling space/services which means they are sharing. So if they are not set right then they are saying they are vulnerable.
It comes down to watching your site, protecting see more
So, GAMEUTOPIA is on point (in my opinion) when steering the blame away from shared hosting see more
I read all the above posts... and my site has also been hacked... i received the same email from "paypal" and it seems that there is no real solution..if the hackers want in they will get in...
Please, dont avoid the question, just give a straight answer. My site is hacked 4 times a day.
I am not an expert at permissions in linux (opensuse to be exact).
What I need to know is what is the linux equivalent to IUSR in windows server? And can i give this user read-only access to my dolphin directory?
An example of the command see more