Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Design Forum > Web Serving and Management
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Web Serving and Management how to web server support forum

Reply
 
LinkBack Thread Tools
Old 12-12-2005, 09:29 AM   #1 (permalink)
Registered User
 
Join Date: Mar 2005
Posts: 16
OS: xp


Hacked website

Hi

Not sure if I have posted this in the correct place??

Somebody has hacked into a site I manage and has put a page on the server that replaces all the other pages, even the index page, I have checked all the original pages and they are all there and untouched. I have a cgi guestbook running on the site, could this have given access to the hacker, I am reasonably sure they could not have access to the password to enter.
I am using cpanel and have noticed that the page appears when I click on cgimail under the cgi scripts heading.
Any ideas??

Thanks

Malcolm
Malcolms is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 12-12-2005, 11:19 AM   #2 (permalink)
Manager, On the Web
 
E-Liam's Avatar
 
Join Date: Jan 2004
Location: Bracknell, UK
Posts: 929
OS: XP


Hi Malcolm, and welocme to TSF,

I'm not an expert in hacking.. , but my first suspicion would be that somewhere you have set the chmod permission to full read/write/execute (777) on one or more files. That would be the first thing to check. If you want to PM me with a link, to save anybody being curious, I can try and see what access I can get to it.

Or, if you prefer, check the attributes your self, and see which ones are 777. Having set up the site, you'll probably be in a better poition to know if any seem wrong to you.

Cheers
Liam
__________________


My Mother suggested a family outing... so I told her Uncle Bob was gay. (Trevor D.)

Never argue with an idiot! They'll bring you down to their level and beat you with experience.

---------------------------------------------------------------------------------
A member of the Alliance of Security Analysis Professionals since 2004.
E-Liam is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 12-12-2005, 11:33 AM   #3 (permalink)
Manager, Alternative Comp
 
Skie's Avatar
 
Join Date: Mar 2003
Location: Chicago burbs
Posts: 2,194
OS: Gentoo Linux, CentOS, OS X

My System

I would check any and all CGI and PHP scripts that you have on your site. If any of them are out dated/old/not updated, please update them ASAP. Old version of these scripts are a HUGE security risk. All someone needs to do is find an old version of a particular script with a known security hole in it, and they can replace your files, upload what they'd like and even attempt attacking other sites or send spam to make it look like you were guilty.
__________________
Skie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 01:30 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85