CPU Galaxy: Hacking Discussion
Goto page 1, 2  Next

Post new topic   Reply to topic    CPU-World.com forums Forum Index -> News
View previous topic :: View next topic  
Author Message
Neon_WA



Joined: 08 Nov 2008
Posts: 7146
Location: Margaret River, West Australia

PostPosted: Sun Sep 19, 2010 8:56 pm    Post subject: Reply with quote

the latest addition Laughing

Quote:
Warning: Visiting this site may harm your computer!
The website at www.cpu-galaxy.at appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that hosts malware can infect your computer.


Will send PM just in case your not aware

_________________
There are 10 types of people in this world:
those who understand binary and those who don't. ~Author Unknown
http://www.x86-guide.net/Neon-WA/en/collection.html
Back to top
View user's profile Send private message [ Hidden ] MSN Messenger
naked1300



Joined: 26 Jul 2007
Posts: 837
Location: Austria,

PostPosted: Mon Sep 20, 2010 1:53 am    Post subject: Reply with quote

Shocked thanks for the Info. Where did you got this messege? I checked
the server and all seems to be ok. no attacs??

_________________
INTEL CPU´s, Peripheral,Ram,Eprom... & many Datasheets @ www.cpu-galaxy.at
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website MSN Messenger
Neon_WA



Joined: 08 Nov 2008
Posts: 7146
Location: Margaret River, West Australia

PostPosted: Mon Sep 20, 2010 2:00 am    Post subject: Reply with quote

naked1300 wrote:
Shocked thanks for the Info. Where did you got this messege? I checked
the server and all seems to be ok. no attacs??


Chrome gives me the warning when I try to enter.. same as it did when Avicc got hacked. Took John a bit to find it all and clean the crap out

this page may give you an idea what to look for
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://www.cpu-galaxy.at/&client=googlechrome&hl=en-US

_________________
There are 10 types of people in this world:
those who understand binary and those who don't. ~Author Unknown
http://www.x86-guide.net/Neon-WA/en/collection.html
Back to top
View user's profile Send private message [ Hidden ] MSN Messenger
CPUShack



Joined: 16 Jun 2003
Posts: 34259
Location: State of Jefferson, USA

PostPosted: Mon Sep 20, 2010 2:09 am    Post subject: Reply with quote

naked, look near the top of your php files for base64encoded text

also check all js and html files for alienradar.ru (usually a script tag)

easiest way to do so is use TextPad (or similar) and do a find in files (all ASCII files in your web dir) for that domain

you'll see it, its a common hack

_________________
New for 2025! The CPU Shack has a co-processor!

Visit The CPU Shack of microprocessor history and information.
Back to top
View user's profile Send private message   Visit poster's website AIM Address MSN Messenger
naked1300



Joined: 26 Jul 2007
Posts: 837
Location: Austria,

PostPosted: Mon Sep 20, 2010 3:46 am    Post subject: Reply with quote

Thanks for the Info. I will check that.
_________________
INTEL CPU´s, Peripheral,Ram,Eprom... & many Datasheets @ www.cpu-galaxy.at
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website MSN Messenger
naked1300



Joined: 26 Jul 2007
Posts: 837
Location: Austria,

PostPosted: Mon Sep 20, 2010 6:13 am    Post subject: Reply with quote

You were right John, thanks for your help!!
_________________
INTEL CPU´s, Peripheral,Ram,Eprom... & many Datasheets @ www.cpu-galaxy.at
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website MSN Messenger
CPUShack



Joined: 16 Jun 2003
Posts: 34259
Location: State of Jefferson, USA

PostPosted: Mon Sep 20, 2010 12:58 pm    Post subject: Reply with quote

oh and change your FTP password (thats generally how it happens (brute force FTP hack )
_________________
New for 2025! The CPU Shack has a co-processor!

Visit The CPU Shack of microprocessor history and information.
Back to top
View user's profile Send private message   Visit poster's website AIM Address MSN Messenger
naked1300



Joined: 26 Jul 2007
Posts: 837
Location: Austria,

PostPosted: Mon Sep 20, 2010 1:27 pm    Post subject: Reply with quote

CPUShack wrote:
oh and change your FTP password (thats generally how it happens (brute force FTP hack )


yes, the attac came over ftp. the hole server with 5 websites is infected!!

lot of work now.... Sad

thanks again for your great help.

_________________
INTEL CPU´s, Peripheral,Ram,Eprom... & many Datasheets @ www.cpu-galaxy.at
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website MSN Messenger
CPUShack



Joined: 16 Jun 2003
Posts: 34259
Location: State of Jefferson, USA

PostPosted: Mon Sep 20, 2010 1:39 pm    Post subject: Reply with quote

naked1300 wrote:
CPUShack wrote:
oh and change your FTP password (thats generally how it happens (brute force FTP hack )


yes, the attac came over ftp. the hole server with 5 websites is infected!!

lot of work now.... Sad

thanks again for your great help.


TextPad find and replace will make it easier (I have dont this alot)

And dont feel to bad, 1 out of 100 active websites is currently hacked, 2 out of 3 have been or will be.

_________________
New for 2025! The CPU Shack has a co-processor!

Visit The CPU Shack of microprocessor history and information.
Back to top
View user's profile Send private message   Visit poster's website AIM Address MSN Messenger
Chiefish



Joined: 23 Sep 2007
Posts: 2153
Location: Northwest N.J. U.S.A

PostPosted: Mon Sep 20, 2010 2:47 pm    Post subject: Reply with quote

How did ya know the site was hacked? When I looked I didnt see anything out of the ordinary. I am curious because of my own site of course and would like to know what to keep an eye on.
_________________
"The only reason for time is so that everything doesn't happen at once." A.E.
Back to top
View user's profile Send private message [ Hidden ]
gshv



Joined: 01 Feb 2003
Posts: 7898
Location: Fairfax, VA USA

PostPosted: Mon Sep 20, 2010 4:12 pm    Post subject: Reply with quote

It looks to me that your site doesn't use scripting. You don't need to worry about these types of hacks if your site is HTML-based.

Gennadiy
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website
CPUShack



Joined: 16 Jun 2003
Posts: 34259
Location: State of Jefferson, USA

PostPosted: Mon Sep 20, 2010 4:47 pm    Post subject: Reply with quote

gshv wrote:
It looks to me that your site doesn't use scripting. You don't need to worry about these types of hacks if your site is HTML-based.

Gennadiy


they can still load remote content via js though

_________________
New for 2025! The CPU Shack has a co-processor!

Visit The CPU Shack of microprocessor history and information.
Back to top
View user's profile Send private message   Visit poster's website AIM Address MSN Messenger
gshv



Joined: 01 Feb 2003
Posts: 7898
Location: Fairfax, VA USA

PostPosted: Mon Sep 20, 2010 8:01 pm    Post subject: Reply with quote

javascript by itself cannot write to a file on your server. You need to have a script (PHP, perl, python, etc) to do it. If you don't have any scripts, then it's not possible to upload anything to your site via the web page. I didn't look hard enough, but I didn't find any non-HTML files on Chiefish's website.

Gennadiy
Back to top
View user's profile Send private message [ Hidden ] Visit poster's website
Chiefish



Joined: 23 Sep 2007
Posts: 2153
Location: Northwest N.J. U.S.A

PostPosted: Mon Sep 20, 2010 9:14 pm    Post subject: Reply with quote

That sounds good to me Very Happy , thanks for the insight on this. I dont write anything for my site, just drag and drop, cut and paste stuff. It gets the job done tho. Wink
_________________
"The only reason for time is so that everything doesn't happen at once." A.E.
Back to top
View user's profile Send private message [ Hidden ]
CPUShack



Joined: 16 Jun 2003
Posts: 34259
Location: State of Jefferson, USA

PostPosted: Mon Sep 20, 2010 11:39 pm    Post subject: Reply with quote

gshv wrote:
javascript by itself cannot write to a file on your server. You need to have a script (PHP, perl, python, etc) to do it. If you don't have any scripts, then it's not possible to upload anything to your site via the web page. I didn't look hard enough, but I didn't find any non-HTML files on Chiefish's website.

Gennadiy


True but these hacks are via FTP, not by web interface.

_________________
New for 2025! The CPU Shack has a co-processor!

Visit The CPU Shack of microprocessor history and information.
Back to top
View user's profile Send private message   Visit poster's website AIM Address MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    CPU-World.com forums Forum Index -> News All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Powered by phpBB © 2001 phpBB Group