Domains Hacked

Can someone relook at [RS #IJV-89457-993]:

It’s nice that the support rep quickly restored all my sub-domins but that is not really what I was hoping for.

I was hoping someone could tell me how access was gained to my websites.

Its possible someone gained gained access to my FTP but it is also possible access was gained another way.

White Oak Books - White Oak Books still has the the files that were installed:
default.aspx and A-H.html.

In seaching for the info listed on the webpage it seems this has happened to many people but could not find much info on the hack itself and how this particullar hacker gains access.

Andy

Andy,

I have researched this and it is really a windows 2000 issue that is not very fixable at all due to the way asp.net runs on windows 2000, another reason for us to get win5 upgraded ASAP.

However it was all due to an insecure phpbb2 forum that has 0 updates since 2004. Then he uploaded as asp.net app, and about 15 users with asp.net user having full permissions(which is not used anymore and would prevent this if less than full permissions, it likley happened literally years ago). The users with asp.net having full permissions had some sites defaced. We will be getting Win5 over to Windows 2003 very soon, and the urgency of it is being accelerated after this, the 2000 server process model is really not good.

Thank you for researching this.

I assume by ‘he’ you meant someone else and not me since I’ll never used PHPBB2 as far as I know.

If you did mean me someone needs to tell me what I need to do to make it secure.

Andy

Same here, two domains were hacked. We believe that was done through FTP. Live chat is not working at the moment, will try helpdesk for further info.

deepscan, it was NOT done via FTP, it was done with an asp.net script for only users having their whole user with asp.net permissions set to full level(should be set at domain level) the permissions have likely been like this for years now, and the way windows 2000 works asp.net does not have process/user isolation for asp.net, so with incorrect permissions the defacer was able to use a script to edit files outside the originally hacked users folder for about 15 users having “full” permissions at the inherited level from the user directory. Asi mentioned, it was about 15 users in all.

Thank you for your reply Stephen.

I don’t know if that makes any difference but none of the defaced sites are using ASP.NET. Is it related to “ASPSecured” installed on domains?

How can we make sure that this would not happen again?

PS. The reason why I think it was FTP is that there is a connection between defaced sites and I am happy to explain this if you PM me.

deepscan, if you are on win5 that reply was valid, if your domain is on win21, that is a very localized issue and only one user that is repeatedly having their site defaced.

Feel free to PM me, but I know for a fact win5 situation was not FTP, and win21 was not for all the files replaced, not sure on the actual source yet, I have seen it many times however, it is 99.99999% of the time due to a file upload tool allowing all uploads instead of just images, etc