Current location: Hot Scripts Forums » General Community » The Lounge » One Of My Website is Hacked Repeatedly, What is the Best Thing To Do?


One Of My Website is Hacked Repeatedly, What is the Best Thing To Do?

Reply
  #1 (permalink)  
Old 07-02-09, 09:55 PM
Julie Viola Julie Viola is offline
Newbie Coder
 
Join Date: Dec 2008
Location: Canada
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
One Of My Website is Hacked Repeatedly, What is the Best Thing To Do?

Hi friends,

One of my website is being hacked three times already in the past two weeks. I noticed it yesterday that it has been hacked again so I simply Upload and publish it again. But just now, It's been hacked again.
What should I do? It's really annoying me now to say the least..

I need some advice and help. the site is تم الاختراق من قبل كاسبر هكر

Thanks
Julie Viola
__________________
Julie ViolaComputer Training
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #2 (permalink)  
Old 07-03-09, 04:07 AM
Nico's Avatar
Nico Nico is offline
Community Leader
 
Join Date: Sep 2005
Location: Spain
Posts: 8,067
Thanks: 11
Thanked 87 Times in 82 Posts
Change all passwords. FTP/cPanel, etc...

And what exactly are they doing to your site?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #3 (permalink)  
Old 07-03-09, 06:26 AM
wirehopper's Avatar
wirehopper wirehopper is offline
-
 
Join Date: Feb 2006
Posts: 2,516
Thanks: 20
Thanked 109 Times in 106 Posts
Sorry, but I'm not going to a site that's been hacked. Too easy to get some nasty malware.

Find all the applications that are running on the site and check for security issues at Secunia.com. Blogs, chat applications, some content management systems, etc. often have vulnerabilities that are exploited over and over until they are upgraded.

If there is a custom application on the site, it may have security issues. They must be addressed. An audit is available at PHP Security Consortium.

It is also possible that there is a file on your server that is allowing someone else to upload code. Until you remove it, they will control the server.

I'm assuming it an HTML site on shared hosting, you have one account on a publicly accessible server. In that case, my recommendation would be to download ALL the files from the www or public_html account (or whichever directory index.html is in) and all the subdirectories. Then, look at them on your PC. If there are any files you didn't put there, delete them. Another approach would be to delete everything and put a clean copy up.

You could also contact the hosting company for help. They will be reluctant to delete any files, because they aren't familiar with your site - but they also want to protect their server.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #4 (permalink)  
Old 07-03-09, 09:20 AM
End User's Avatar
End User End User is offline
Level II Curmudgeon
 
Join Date: Dec 2004
Posts: 3,027
Thanks: 14
Thanked 35 Times in 33 Posts
You really need to look at the log files to determine what's the point of entry for the hack. Somewhere in the log are some lines showing malicious commands, SQL injection, etc etc. Until you know what the point of entry is, I think it would be a waste of time to just keep republishing the site over and over. It'll just get hacked over and over.
__________________
I don't live on the edge, but sometimes I go there to visit.
-------------------------------------------------------------------------
Sanitize Your Data | Oracle Date & Substring Functions | Code Snippet Library | [url=http://www.codmb.com/Call Of Duty[/url]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #5 (permalink)  
Old 07-03-09, 10:29 PM
Julie Viola Julie Viola is offline
Newbie Coder
 
Join Date: Dec 2008
Location: Canada
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
My website is a static html and i do not have any other applications that goes with it. Its a simple static website.

I really do appreciate all your advices and knowledge in dealing with such problems. I am really sorry though that I was not able to reply to your advices right away as I have to do very important family stuffs.

BTW. It was just the home page that was having the bad stuffs and all the rest of the pages are okay.

Again, thanks a lot Nico, WireHopper and End User....
I Do appreciate your time and effort in helping find solutions to my problem,.

Julie Viola
__________________
Julie ViolaComputer Training
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #6 (permalink)  
Old 07-04-09, 12:11 AM
wirehopper's Avatar
wirehopper wirehopper is offline
-
 
Join Date: Feb 2006
Posts: 2,516
Thanks: 20
Thanked 109 Times in 106 Posts
If it is just HTML, the most likely issue is that the file is being corrupted during transfer.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #7 (permalink)  
Old 07-04-09, 11:47 AM
Boraan's Avatar
Boraan Boraan is offline
Coding Addict
 
Join Date: Jul 2007
Location: Clayton, NC
Posts: 292
Thanks: 0
Thanked 1 Time in 1 Post
Hey aside from a perl programmer I'm a network security and IDS specialist. Hack prevention, threat assessment, firewalls, etc. email me please. I need to know if you have access to your logs and what kind of system your sites is hosted on. I also need a time frame of when the hack occurred. If you have access to those logs I should be able to tell you how your site was hacked, where they entered, etc. and help you set up your server config to prevent it from happening again. DO NOT reply with that information here. message me please
__________________
Dexter Nelson
Techdex Development & Solutions
========================
Internet Marketing For Programmers | Free Market Research in 15 Minutes or Less
My Software: Hotscripts Softpedia software.techdex.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #8 (permalink)  
Old 07-04-09, 01:07 PM
Julie Viola Julie Viola is offline
Newbie Coder
 
Join Date: Dec 2008
Location: Canada
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
Wirehopper, do you mean when I publish the site contents. Because I do update the site recently as i added a few pages.
My host is GoDaddy.com and I do not have the log files applied yet. I have to subscribe to it and apparently there is a fee for getting those visitors IP addresses.

Thanks
Julie Viola
__________________
Julie ViolaComputer Training
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #9 (permalink)  
Old 07-04-09, 01:21 PM
Boraan's Avatar
Boraan Boraan is offline
Coding Addict
 
Join Date: Jul 2007
Location: Clayton, NC
Posts: 292
Thanks: 0
Thanked 1 Time in 1 Post
eew. godaddy. enough said. If you want I can let you borrow some of my server space and I can keep track of your log files to see where the attacks are coming from, no charge
__________________
Dexter Nelson
Techdex Development & Solutions
========================
Internet Marketing For Programmers | Free Market Research in 15 Minutes or Less
My Software: Hotscripts Softpedia software.techdex.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
  #10 (permalink)  
Old 07-05-09, 07:23 PM
ddd ddd is offline
New Member
 
Join Date: Jul 2009
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Hi Julie,

Some simple advice to you:

-Change all your passwords. That's the easiest method for them to keep modifying it.
-Upgrade your system. If you are running wordpress, make sure you are on version 2.8.
-If you have any script (cgi, php, etc) remove them until you are sure they are safe.
-Check your system for new accounts and remove them.

After you are done, start monitoring your site: A suggestion is the free Sucuri information security (BETA) that alerts whenever your site is changed/hacked/blacklisted/etc.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiShare on FacebookShare on Stumble UponShare on Twitter
Reply With Quote
Reply

Bookmarks

Tags
website hacked


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
100 ways to get more traffic jorokolarov The Lounge 12 12-06-07 08:20 PM
FS: Prozilla Memberships (Turnkey Sites) - $10-15 less than Retail! rockergrrl General Advertisements 0 08-11-04 01:05 AM


All times are GMT -5. The time now is 12:37 AM.
vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.