Aussie Bloggers Forum
*
* *
Home
forum
Help
Search
Login
Register
Chat
Welcome, Guest. Please login or register.
August 01, 2010, 01:06:03 am

Login with username, password and session length
Search:     Advanced search
45953 Posts in 3789 Topics by 1206 Members Latest Member: - Ben-123 Most online today: 11 - most online ever: 275 (December 30, 2007, 07:51:23 pm)
Forum Rules
Recent Posts
[October 06, 2009, 10:10:11 am]

[October 06, 2009, 10:05:49 am]

[October 06, 2009, 04:00:34 am]

[October 04, 2009, 03:32:49 am]

[October 01, 2009, 07:15:38 am]

[September 29, 2009, 03:55:23 pm]

[September 29, 2009, 03:54:31 pm]

[September 29, 2009, 03:53:26 pm]
Themes

Members
Total Members: 1206
Latest: Ben-123
Stats
Total Posts: 45953
Total Topics: 3789
Online Today: 11
Online Ever: 275
(December 30, 2007, 07:51:23 pm)
Users Online
Users: 0
Guests: 10
Total: 10

Visit the Aussie Bloggers Blog

Pages: [1]
Print
Author Topic: Warning - Blog Hackers Active  (Read 701 times)
squadron
Riotous Chook
Top Sort
*****
Posts: 230



« on: June 11, 2009, 10:53:36 am »

I've had 2 blogs today defaced. The title becomes hacked by p@3t_b@y and they put some redirect script into the main page.

Any ideas how to stop this?  The redirect takes you to:
Code:
http://www.poet-boy.webs.com/index.htm

I am running WordPress 2.7.1

Modified by Gem so that link is not clickable - if they are hacking blogs we don't want them to get extra hits because of it
« Last Edit: June 11, 2009, 10:59:13 am by Gemisht » Logged

Did you ever find Bugs Bunny attractive when he put on a dress and played a girl bunny?
SEO Packages
Australian Defence News
Australian Web Directory
goatlady
Administrator
Deadset Legend
*****
Posts: 817


\m/


WWW
« Reply #1 on: June 11, 2009, 11:07:50 am »

What plugins do you have that are common to these two blogs?
Logged

goatlady
Administrator
Deadset Legend
*****
Posts: 817


\m/


WWW
« Reply #2 on: June 11, 2009, 11:08:47 am »

Also, what kind of hosting do you have? What permissions do you have set on your wp-content directories? Do you allow user signups on the site?
Logged

squadron
Riotous Chook
Top Sort
*****
Posts: 230



« Reply #3 on: June 11, 2009, 02:06:34 pm »

It's cpanel hosting on some server overseas. The permissions were set to 777 which I have changed to 755.

I can remember setting them to 777 when I was trying to get some confounded plug-in to work (lesson learned).

I have also set IP deny to the  address: 77.88.30.* from which the hacking came from. Somewhere in the Russian Federation.

Thanks for pointing me to the right spot.

I did a Google search on some unusual text they defaced my page with. I don't feel too bad now, there are 56,000 other sites that have been hacked by these guys !  I now suspect a mysql exploit rather than a Wordpress exploit.
« Last Edit: June 11, 2009, 02:19:49 pm by squadron » Logged

Did you ever find Bugs Bunny attractive when he put on a dress and played a girl bunny?
SEO Packages
Australian Defence News
Australian Web Directory
goatlady
Administrator
Deadset Legend
*****
Posts: 817


\m/


WWW
« Reply #4 on: June 11, 2009, 11:39:00 pm »

It's cpanel hosting on some server overseas. The permissions were set to 777 which I have changed to 755.

I can remember setting them to 777 when I was trying to get some confounded plug-in to work (lesson learned).

Ah, that's a bugger, that one. We host now with Hostgator and they have this awesome security modification which lets WordPress write files itself even when they're set to 755 (it lets PHP temporarily change the permissions to 777 and then sets it back again automatically) - makes life so much easier and more secure. But I've been caught out by the 777 thing more times than I care to remember rsad
Logged

squadron
Riotous Chook
Top Sort
*****
Posts: 230



« Reply #5 on: June 14, 2009, 03:47:16 pm »

I've found the source of the hacking. A group of Turkish hackers having a competition. Below is the e-mail I sent off to the Turkish Telco. I don't know if will do any good, but it's worth a shot. I stuck the url listed below in Google translator (Turkish to English), to work out what was going on.

=================

Subject: Hacking from address 88.248.49.157

A user on IP address 88.248.49.157 has been defacing web sites around the world.

You can see evidence of these activities at   http:// mirror.darkedition.com /

I had several web sites defaced over the last few days. The IP address was 88.248.49.157.

One of the attacks happened at 13th June 2009 00:51:22 GMT

I hope you can do something about these people.
Logged

Did you ever find Bugs Bunny attractive when he put on a dress and played a girl bunny?
SEO Packages
Australian Defence News
Australian Web Directory
Pages: [1]
Print
Jump to:  

Show unread posts since last visit

Visit the Lazy Bloggers Post Generator - Our present to you. Happy Birthday To Aussie Bloggers Forums!

Visit the Lazy Journalists Plane Story Generator - Another present to you. Enjoy!

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
Oxygen / TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page July 30, 2010, 06:37:58 am