One day last week I woke to find that all of my sites on JodoHost had been hacked. Each site showed an index.html file that had been inserted into my folders referring to SniperTeam (SniperTeam.OrG). I reloaded the correct index pages and planned to find out how this had happened but of course got distracted with work, kids, and sleep.
Today, my JodoHost reseller found all of his sites on his linux server were hacked with the SniperTeam index.html file as well. Since he was at work I fixed most of his sites and thought I should check my own. I found that my sites on JodoHost had been deleted this time. Files, scripts, images, includes - all are gone.
My first concern is to get some help understanding how this is happening - I am running WordPress on a few of my sites - is this a WP exploit of some kind?
Secondly, what is the process and/or cost to request a backup copy of my sites be restored?
submit a ticket, yes there has been some major problems with wordpress recently, even their own site was hacked and people were downloading a compromised version for some days before they noticed.
I’ll get a ticket filled out and get to upgrading wp. Not being a sysadmin I find it a little surprising that someone should be able to jump between sites on the account but that may just be my ignorance showing.
I am not running WP. It must have been a server wide attack as even a domain name that I just registered yesterday and have done nothing with was over written with a new index.php file.
Here is a copy of an .htaccess file that may help some what to keep out many of the hack attempts.
<Files *>
order deny,allow
# Nigerian/African 419 Scammers IP addresses follow:
deny from 12.166.96.32/27 41.220.64.0/20 41.223.248.0/22 61.11.230.112/29 62.56.128.0/17 62.56.235. 62.56.236. 62.56.244.0/22 62.56.248. 62.128.160.0/20 62.173.32.0/19 62.192.128.0/19 62.192.140.250 62.193.160.0/19 63.70.178. 63.73.58. 63.100.193. 63.103.138. 63.103.139.64/26 63.103.140.0/22 63.109.245.168/29 63.109.248.128/25 63.122.154. 64.14.48.128/26 64.110.30. 64.110.31. 64.110.64.16/28 64.110.76.0/23 64.110.81. 64.110.93.16/28 64.110.93.176/28 64.110.147. 65.209.91. 65.209.92. 66.18.64.0/19 66.110.31. 66.178.7.16/29 66.178.7.32/28 66.178.46.0/24 66.178.55. 66.178.62. 66.178.80.176/29 66.178.81.64/29 66.199.241.82 66.205.20. 80.87.64.0/19 80.88.128.0/20 80.88.129. 80.88.130. 80.88.131. 80.88.132.0/26 80.88.132.64/27 80.88.132.104/29 80.88.132.128/26 80.88.132.192/27 80.88.132.224/28 80.88.132.240/29 80.88.133.0/25 80.88.134.0/26 80.88.134.64/29 80.88.136. 80.88.137. 80.88.138.0/25 80.88.138.128/26 80.88.138.192/27 80.88.139.0/25 80.88.139.128/26 80.88.139.192/27 80.88.139.224/28 80.88.140. 80.88.141.0/25 80.88.141.128/27 80.88.142. 80.88.143.128/24 80.88.144.0/23 80.88.146. 80.88.147. 80.88.148. 80.88.149.0/25 80.88.149.128/26 80.88.149.192/28 80.88.150. 80.88.151. 80.88.152. 80.88.153. 80.88.154.32/27 80.88.154.72/29 80.88.154.80/29 80.88.154.96/28 80.88.155.0/25 80.88.155.128/27 80.88.155.160/29
deny from 80.78.18.88/29 80.78.18.96/27 80.78.18.128/29 80.179.102.0/24 80.179.107.64/27 80.179.107.224/29 80.179.128.0/17 80.231.4.0/23 80.247.136.0/24 80.247.137.0/24 80.247.141.32/27 80.247.141.64/26 80.247.141.128/25 80.247.142.0/24 80.247.147.16/28 80.247.147.32/29 80.247.147.64/27 80.247.147.96/28 80.247.151.0/24 80.247.153.0/24 80.247.156.0/26 80.247.156.128/28 80.247.157.0/24 80.247.159.0/24 80.248.0.0/20 80.248.64.0/23 80.248.70.0/20 80.248.64.0/20 80.250.32.0/20 80.255.40.48/28 80.255.40.96/29 80.255.40.112/28 80.255.40.128/28 80.255.40.192/28 80.255.40.224/27 80.255.40.240/28 80.255.43. 80.255.46.0/29 80.255.46.16/28 80.255.46.64/29 80.255.59.19 80.255.59.0/24 81.18.32.0/20 81.18.40.0/24 81.18.42.0/24 81.23.194.0/27 81.23.194.64/27 81.23.194.128/25 81.23.195.0/24 81.23.196.0/25 81.23.196.128/29 81.23.200.0/21 81.24.0.0/20 81.91.224.0/20 81.199.0.0/16 81.199.6.0/24 81.199.7.0/24 81.199.72.0/22 81.199.76.0/24 81.199.82.0/23 81.199.84.0/22 81.199.84. 81.199.85. 81.199.86. 81.199.87. 81.199.88. 81.199.89. 81.199.90.0/24 81.199.94.0/23 81.199.108.0/22 81.199.124.0/22 81.199.240.0/21 82.128.0.0/17 83.229.100.0/23 84.254.188.3 84.254.128.0/18
deny from 155.239.0.0/16 192.116.64.0/18 192.116.128.0/18 192.116.152.0/21 193.110.2.0/23 193.189.0.0/18 193.189.64.0/23 193.189.128. 193.219.192.0/18 193.220.0.0/16 193.220.26.0/24 193.220.30.0/26 193.220.30.64/27 193.220.31.0/26 193.220.31.64/27 193.220.45.0/25 193.220.47.0/25 193.220.77.0/26 193.220.187.0/26 193.220.187.128/27 195.8.22. 195.44.168.0/21 195.44.176.0/21 195.137.13. 195.137.14. 195.166.224.0/19 195.166.237.40 195.166. 195.219.176. 195.225.62.0/23 195.245.108.0/23 196.1.176.0/20 196.3.60.0/22 196.3.180.0/22 196.29.208.0/20 196.38.110.0/23 196.45.192.0/18 196.46.240.0/21 196.46.144.0/22 196.200.0.0/20 196.200.64.0/20 196.200.112.0/20 196.201.64.0/19 196.201.64.128/25 196.201.65.0/24 196.202.160.0/19 196.202.224.0/21 196.207.0.0/20 196.207.128.0/18 196.207.192.0/18 196.207.247.0/24 196.220.0.0/19 204.118.170.0/24 209.88.163. 209.101.84. 209.159.164. 209.159.166.0/24 209.198.240.0/23 209.198.242.16/28 209.198.242.96/29 209.198.242.104/30 209.198.242.108/31 209.198.242.128/27 209.198.246.240/28 212.96.2.0/23 212.96.4. 212.96.28. 212.96.29. 212.96.30. 212.100.64.0/19 212.165.128.0/17 212.165.132.64/27 212.165.135. 212.165.140.16/29 212.165.140.64/26 212.165.140.128/25 212.165.141.0/24 212.165.147.0/26 212.165.147.128/26 212.199.108.0/24 212.199.251.0/24 212.247.93.0/24
deny from 213.136.96.0/24 213.136.116.0/24 213.140.62.0/23 213.150.192.0/23 213.166.160.0/19 213.181.64.0/19 213.185.96.0/21 213.185.106.0/24 213.185.112. 213.185.113.0/26 213.185.124. 213.187.135. 213.187.145. 213.211.128.0/18 213.211.188.0/24 213.232.96. 213.255.193. 213.255.195.0/25 213.255.195.128/27 213.255.198. 213.255.199. 216.72.104.0/21 216.74.187.0/24 216.129.147.128/28 216.129.159. 216.133.174. 216.147.132.144/28 216.147.132.160/28 216.236.200.96/28 216.236.202.96/28 216.236.205.0/24 216.236.222.128/26 216.250.195.0/27 216.250.195.64/26 216.250.221.0/24 216.250.222.0/24 216.252.176.0/24 216.252.177.0/24 216.252.231.0/25 216.252.245.0/24 217.10.163.128/26 217.10.163.192/27 217.10.163.224/27 217.10.166.0/26 217.10.166.64/28 217.10.169.0/24 217.10.170.0/24 217.10.171.0/24 217.10.173.0/26 217.10.182.0/27 217.10.184.0/24 217.14.80.0/20 217.15.124.0/25 217.20.241.0/25 217.20.241.128/29 217.20.241.136/29 217.20.241.144/28 217.20.241.160/29 217.20.241.168/29 217.20.241.176/29 217.20.241.184/29 217.20.241.192/29 217.20.241.200/29 217.20.241.208/29 217.20.242.0/24 217.20.243.24/29 217.20.243.32/27 217.78.64.0/20 217.117.0.0/20 217.146.3.144/28 217.146.3.160/28 217.146.3.176/29 217.146.3.224/27 217.146.4.64/26 217.146.5. 217.146.6.0/25 217.146.6.160/27 217.146.7. 217.146.8.0/25 217.146.9. 217.146.10.128/25 217.146.11.0/25 217.146.12. 217.146.13. 217.146.14.0/25 217.146.15.0/25 217.146.16.0/27 217.146.16.32/29 217.194.140.0/22 217.194.144.0/20 217.20.242.0/27 217.20.242.32/28 217.20.242.48/29
# Tentative CIDR block for 16,777,216 AfriNIC assigned IPs
#deny from 41.0.0.0/8
# Pan Am Sat Nigeria and South Africa
deny from 216.139.160.0/19 216.139.176.136/29
# Added Goldenlines.net.il (Israel) because of Open Proxies used by Nigerian scammers
deny from 80.179.244.0/24
# The CIDRs below are Canadian Satellite ISPs that appear to have reassigned these IP blocks to Nigeria
deny from 64.86.155.0/24 64.201.33.0/24 216.185.79.0/24
# added this German ISP on 5/1/05, probably reassigned to Nigeria: 62.192.128.0/19
# Added Sky-Vision satellite services for African and Eastern European Internet Cafes
deny from 83.229.64.0/18 217.194.144.0/20
# Kenya, Somalia, Zimbabwe, Ghana and some misc Nigerian IPs
deny from 196.200.0.0/16 196.201.0.0/16
# Added New Skies Satellite Service (Nigeria + Africa) on Dec 7, 2005:
deny from 66.178.0.0/17
# Amsterdam, The Netherlands Versatel Nederland DSL-NAT Customers - Lottery and 419 scammers
deny from 62.59.36.0/22 62.59.40.0/21 62.59.48.0/22 82.93. 82.168.0.0/14
# Italian Satellite ISP for Nigeria added 04/08/2006
deny from 83.137.61.0/24
# Ironlinkus.com Satellite Services (Africa - used by scammers) - added on 08/08/2006
deny from 216.118.252.0/24 216.118.253.0/24
# End Nigerian/African blocklist
# Turkish 419 scammers:
deny from 66.199.224.0/19 72.36.168.153/29 85.98.160.0/20 212.174.113.0/24 88.226.5.0/99
# Turkey Telecom entire CIDRs: 85.98.128.0/17 212.174.0.0/17 - for future blocking
# Added CHINANET Guangdong province network, Beijing, China, on 11/16/05
deny from 219.128.0.0/13 219.136.0.0/15 220.181.0.0/16
# Add other blocked domain names or IP addresses here, starting with "deny from " without quotes
# If you find that you need to poke a hole in the blocklist, for legitimate visitors, follow this example: allow from 123.456.789.0
# Add "allow from" IP addresses, or CIDR Ranges, after all of the "deny from" items, just before the closing Files tag.
# Everything not included within these deny from ranges is PERMITTED by the allow portion of the directive.
</Files>
# This prevents web browsers or spiders from seeing your .htaccess directives:
<Files .htaccess>
deny from all
</Files>
# End of file
php_value register_globals Off
Copy that in notepad and upload to the root of your websites and save as .htaccess
That will block all those ip ranges from accessing your sites. I wish I had that setupon all my sites first and I would not have had a problem maybe.
I had the same thing happen to all of one of my customers sites last week. I have just tried to add ip code above to my .htaccess file but it caused the website loading to fail.
I requested last week that we have a common area to list hacking attempts in to make it easier to share practice, any chance of this happening?
I had an error in adding the last ip address that this hacker came from. I updated the code above. It should be:
Turkish 419 scammers:
deny from 66.199.224.0/19 72.36.168.153/29 85.98.160.0/20 88.226.5.99 212.174.113.0/24
Turkey Telecom entire CIDRs: 85.98.128.0/17 212.174.0.0/17 - for future blocking
The 88.226.5.99 is where I had something wrong. I was trying to set the range in there but it did not work.
I tested now and it should be fine.
Sorry.
I don’t really know if this will protect sites from a similar hacking such as this one as it seems the code is injected into a script with a security problem such as Word Press has now, and then can rewrite files on the server. But I know the deny ips in the .htaccess file can stop any direct attacks from those ip ranges.
Viper1, there is nothing like server-wide attack normally. It happens mostly with where people dont care much about permissions. Most of the cases i’ve noticed had 777 permissions. Also not all of such directories appeared to be needing them. Plus such directories must surely be audited over a certain period of time.
Lets take an example, suppose you have a php application running that needs 777 on a cache directory, you can simply place a .htaccess file in this folder that denies web-access. Since the file belongs to your user permission, even the web-server wont be allowed to over-write this file and thus even if a hacker file is uploaded it will be worthless for him since it cant be excuted atleast from this folder. This saves you from attacks, where hackers upload to your such vulnerable directories once and use it much later.
Another step, a big recommendation, keep track of installated applications and atleast apply all of security updates. This is your best course unless you wish to re-do your site just because you didn’t spent 10 minutes on updating it during the weekend.
Dardalius, I’ll discuss this with Stephen, but it can only a customer-only forum and/or maybe censored. Because such forums take bad shape rather quickly.