Hacked yesterday!

Support for IntegraMOD 141

Moderator: Integra Moderator

Hacked yesterday!

PostAuthor: Ezra » Fri Sep 28, 2007 2:59 am

Hi all,

My board was hacked yesterday and I'm currently in the proces of reuploading my website. But, somehow they managed to upload php-files to some writeable dirs of Integramod. I think the leak is within the software, because other websites on the same server weren't infected.

I'll attach the post-command that I found in my apache-log. Can anyone say anything about this? And, how can I prevent it from happening again? Thanks!

Greetings,
Ezra
You do not have the required permissions to view the files attached to this post.
Last edited by Ezra on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

Ezra
Newbie
Newbie
 
Posts: 25
Likes: 0 post
Liked in: 0 post
Joined: Mon Apr 03, 2006 2:15 pm
Cash on hand: 0.00

Re: Hacked yesterday!

PostAuthor: CaNNon » Fri Sep 28, 2007 5:18 am

somehow they managed to upload php-files to some writeable dirs of Integramod.



You allowed uploads it could happen, but you would have had to have removed the upload security block on "php file" type. I can see the "post" command and the server answer "200" or giving permission. also it looks like the used your backup folder and you do need to write to that one as it is needed for just that.

When you finish reloading it make sure the filters on upload don't allow any files that could run on the server.

Also if you still have a copy of the file I would like to see it if possible.
Last edited by CaNNon on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
Image
Image
User avatar
CaNNon
Sr Integra Member
Sr Integra Member
 
Posts: 750
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 19, 2007 12:15 pm
Cash on hand: 0.00

Re: Hacked yesterday!

PostAuthor: Ezra » Sat Sep 29, 2007 2:52 am

"CaNNon";p="28621" wrote:You allowed uploads it could happen, but you would have had to have removed the upload security block on "php file" type. I can see the "post" command and the server answer "200" or giving permission. also it looks like the used your backup folder and you do need to write to that one as it is needed for just that.

When you finish reloading it make sure the filters on upload don't allow any files that could run on the server.

Also if you still have a copy of the file I would like to see it if possible.


Hi CaNNon,

thanks for your answer. When I go to the "forbidden extensions panel" in ACP, it says that php, php3 and php4 are automatically forbidden extentions and that you're not able to remove them. Where else should or can I block uploading php-files?

And, unfortnunately I don't have the .script-file for you. Next time I wil save it <img>

Ezra
Last edited by Ezra on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

Ezra
Newbie
Newbie
 
Posts: 25
Likes: 0 post
Liked in: 0 post
Joined: Mon Apr 03, 2006 2:15 pm
Cash on hand: 0.00

Re: Hacked yesterday!

PostAuthor: CaNNon » Sat Sep 29, 2007 9:28 am

If they were disabled.. bad omen!

Next check all your security, Make sure you have everything updated. The latest I have tried for crackerTracker is here [url=http]http://www.integramod.com/forum/viewtopic.php?t=4134[/url]

I would also suggest:
admin > crackertracker > Maintenance and tests >
look at "Security Test" try to update/set as much to safe as Possible.
Last edited by CaNNon on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
Image
Image
User avatar
CaNNon
Sr Integra Member
Sr Integra Member
 
Posts: 750
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 19, 2007 12:15 pm
Cash on hand: 0.00

Re: Hacked yesterday!

PostAuthor: Ezra » Sat Sep 29, 2007 2:01 pm

Damned! Got hacked again...well, maybe still. I got an email from "RSA Anti-Fraud Command Center" that someone is using the webspace for Phising activities against "Citibank". I think they somehow own the server now, because my website is running and they are just making other directory's with files in it (these contain forms and shit). If I delete them, they just reappear minutes later...

I don't know what to do....
Last edited by Ezra on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

Ezra
Newbie
Newbie
 
Posts: 25
Likes: 0 post
Liked in: 0 post
Joined: Mon Apr 03, 2006 2:15 pm
Cash on hand: 0.00

Re: Hacked yesterday!

PostAuthor: CaNNon » Sat Sep 29, 2007 3:07 pm

Contact your host, shut it down. they must have a shell on the box somewhere.
your .nl exploit showing up since 2007-09-27 on that.
I will pm you the link.

Your "http://www[dot]paradise-cafe[dot]nl/"
site is handing out trojans, do not try to connect tru the web! use extreme caution
with ftp too!

9/28/2007 17:49:46 PM AMON file 47pfq9wd.php PHP/Rst.F trojan quarantined - deleted C:Program FilesMozilla Firefoxfirefox.exe. The file was moved to quarantine.
Last edited by CaNNon on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
Image
Image
User avatar
CaNNon
Sr Integra Member
Sr Integra Member
 
Posts: 750
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 19, 2007 12:15 pm
Cash on hand: 0.00


Return to IntegraMOD 141

Who is online

Registered users: App360MonitorBot, Bing [Bot], Google [Bot], Majestic-12 [Bot]