multiple sites hacked

Is there something going on at JH or anyone else’s sites? We have had at least 5 customer sites hacked in the past day by “brwsk007”.

Not heard anything else about this so far. There IS A LOT of hacking going on, we have found countless insecure upload pages, allowing asp/asp.net/php pages to be uploaded and then hacking entire ftp level accounts from that.

Looking up that name, I see several account level hacks from that ‘hacker’, on multiple users, looks like he was doing a lot of scanning.

One user alone there has 203 domains that he has listed as hacked. That is a majority of those listed. This user used them for placeholders. But it does look like he was quite active in scanning sites on the ip (many ways to do this, there are reverse lookup sites online), and exploiting those vulnerable.

Since I have seen this, I have checked and found 7 user defacement scripts on different FTP users(some look to have come via frontpage extensions, and some HAVE come via upload scripts allowing asp pages uploaded)

This is not even an exhaustive search, just a rather quick one. I expect to find many more by the looks of it.
And the bad thing is, it looks like this script can also create the index.htm/cfm/asp/php files it is doing, on sites with network service level access, so this is quite advanced, and some people that asked extra permissions for asp.net apps and the like, may have these files there due to it.

I am analyzing the code to see what we can do to help prevent it in the future, the good thing is not everyone asks this, and it doesnt affect all, but it is messy for those that have these files copied in their directories.

Another link, is frontpage. it seems to be a main vector here, I am working to find how on it as well.

We will be replying like this to users, this number (15) may not be final at all as I am still looking, but it is valid info, in any case.

We are finding that there are many accounts with insecure uploaders, or fckeditor old versions that are vulnerable to upload exploits, and in some cases FrontPage extensions that are being brute forced for user/pass combos. The IPs on this server are being tagetted by a hacker, we do not know why, but it is the case, so any such entry he is finding and then putting a script on the page that creates a large amount of index/default files on all domains in the end user account. We have so far found over 15 users affected by this with a vulnerable upload means to put a script to deface a site. We are removing these as we see them and notating those that have so we can followup with a recommendation to change FTP/Frontpage password since it may be brute forced and also to be sure any fckeditor in your site is updated to the latest edition or old edition is removed from the site if you have it.

Now up to 20 users, with uploaders on at least one domain in their account (and that is all it takes) and about 7 more with frontpage user/pass exploited.

I am updating the mail techs will reply, and we’ll restore as needed, but it doesn’t plug the hole, I will be taking an mailing users or resellers of those I am finding issues on.