Hacked

I noticed today that a html page was placed in the root of one of my clients sites.

LORD.htm

It had a black background with the words:

Hacked by LORD - Turkish Hacker

Luckly, nothing else seems to have been changed. This was on wincf.
Now changing passwords on all client accounts.

I found this on another site, but same thing.

please PM me with the domains and I will check the logs for you this guy hits 1000’s of vulnerable CF and ASP sites, and a few PHP sites as well.

I tell you, when does it stop… X( X( X( X( X( X(

he hit us aswell..

Isn’t there a way to get this guys IP number and stop this crap…

It won’t do any good, I have found it a number of times and it is dial up or random, many times from a proxy or a hacked server.

I know of about 12-15 sites on our servers “lord” has hacked, every time it has been from an outdated web application or even sometimes an unknown hole that later got patched after giving the logs.

yea makes sense, we just have to ride it out, hackers will usually leave and move around and go elsewhere after they have their fun…

I wanted to make sure we are under customer only discussion, I didn’t want to post that and he would never leave… 8)

Well the only way to really prevent them is to be a freak on updates, make sure you have the latest updates for php/asp/asp.net app.

however the downsides to that are the updates manytimes bring bugs and when something is “just working” why change it, then you get hit with a hack :frowning: A catch 22

Yep, just like spam, you can’t win anyway you look at it… This is the life of doing business online… X( …

I have learn my lesson many times with new updates, I usually will wait 4- 6 months to a year before installing updates…

Include me as being hacked also..here’s a screenshot:

http://www.timeforweb.com/hpage3.gif

I’m off to correct this one and check on others..Stephen I will PM you the domain.

unless you have the same software on other domains, that will be the only domain affected, it happened on 7/30/2006 I am going to get details for you, I will send via PM, if you want to make pubilc it may be good for education of others :slight_smile:

If you have frontpage extensions on, be sure they have a complex password.

Thanks Stephen!

Basically I think you have pretty much stated that FrontPage extensions can be exploited due to certain vulnerabilities. Although I am a proponent and heavy user of FrontPage..I will be glad when Expression is released to the public as rumor has it there will be no more extensions. As a matter of fact Microsoft has pulled the download from their site of the 2002 extensions. (Although that has many people in an uproar due to the many 1000’s of sites and hosts that use them)

Personally though I believe Expression will leap-frog over Dreamweaver when it is released..it really is very cool..and all of the deprecated things like tags etc. will be gone..producing everything via .css and compliant coding as well.

Expression uses FTP :slight_smile: I have it here in front of me :smiley:

You know .. the best bet is to ban the country/(state) until their government get’s off it’s butt and send this people to prison for life.

That would be Brazil, we have a few too many users from Brazil to take that step :slight_smile:

Although I agree it would be great to find a way to ban this kind of nonsense..I just don’t see it happening. You would think those fools would want to turn their abilities into generating some money..rather then messing around with other people like that.

Besides we can’t really go after them until we finish the job with lawyers 1st! :rockon:

You can’t stop these ------ they are mostly young don’t need to make money and on a mission. Their high is to see how many hacks they can get through…

THere is to many out there, just unbeliable… :laser:

2 of my clients sites were hacked, one yesterday and one today from same hackers. Both sites were on win8. What worries me is they managed to change CP passwords.
Both sites didn’t have any CMS, forum or other scripts. One site had plane html files and other asp files.
How is this possible?