My site defaced - now what?

 
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions
View previous topic :: View next topic  
Author Message
Lawrence
-


Joined: 16 Jan 2003
Posts: 207
Location: Brisbane, AU

PostPosted: Tue Sep 27, 2005 3:28 am    Post subject: My site defaced - now what? Reply with quote

I recently had my site defaced. I'm hoping for help trying to sort out how they did it and how I can block the hole. My setup is as follows:

Abyss X2 2.0.6
Inivision Power Board 1.3 Final
Pivot Blog 1.30 alpha 3: 'Rippersnapper'
Perl is installed for my access stats, and coranto, both of which are password protected by abyss.
PHP is 4.3.1

To my knowledge there are no vulns in these packages, but there's obviously something broken somewhere.

If anyone has a suggestion on how I might track down the exploit I'd love to hear it.

EDIT: I've been told by one of the defacer's crew (They were kind enough to leave their IRC lair in the deface page) that they used a hack in invision's pollrenderer.php

Now to solve that hole...
Back to top View user's profile Send private message Visit poster's website ICQ Number
p3
-


Joined: 17 Jun 2005
Posts: 615

PostPosted: Tue Sep 27, 2005 3:56 am    Post subject: Reply with quote

Check your server logs and see where they were and what they did. My guess is they injected some code that allows them to edit pages.
Back to top View user's profile Send private message Send e-mail
Lawrence
-


Joined: 16 Jan 2003
Posts: 207
Location: Brisbane, AU

PostPosted: Tue Sep 27, 2005 4:34 am    Post subject: Reply with quote

If they used a PHP exploit to do the job there wouldn't be any upload records on the serverlog, would there?

Found the hack. It's a Pivot exploit.
Back to top View user's profile Send private message Visit poster's website ICQ Number
MonkeyNation
-


Joined: 05 Feb 2005
Posts: 921
Location: Cardiff

PostPosted: Tue Sep 27, 2005 8:42 am    Post subject: Reply with quote

DDoSing is your friend.
_________________
Back to top View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger ICQ Number
Arctic
-


Joined: 24 Sep 2004
Posts: 560

PostPosted: Tue Sep 27, 2005 12:47 pm    Post subject: Reply with quote

You got hacked because you used some weird, completly weirdly named PHP script...?

Just do something else for your forum like bMachine, or BoostMachine. It works MUCH better than whatever you are using.
Back to top View user's profile Send private message ICQ Number
cmxflash
-


Joined: 11 Dec 2004
Posts: 872

PostPosted: Tue Sep 27, 2005 1:06 pm    Post subject: Reply with quote

[Removed]

Last edited by cmxflash on Sun Nov 12, 2006 1:15 am; edited 1 time in total
Back to top View user's profile Send private message
aprelium
-


Joined: 22 Mar 2002
Posts: 6800

PostPosted: Tue Sep 27, 2005 1:37 pm    Post subject: Re: My site defaced - now what? Reply with quote

Lawrence wrote:

PHP is 4.3.1

To my knowledge there are no vulns in these packages, but there's obviously something broken somewhere.


PHP 4.3.1 is not the latest version (it was released on February 17, 2003) and there were at least 10 versions released after it, some of them were fixing serious security holes.

So we recommend updating your PHP 4 installation as soon as possible. The latest is 4.4.0.
_________________
Support Team
Aprelium - http://www.aprelium.com
Back to top View user's profile Send private message Send e-mail
cmxflash
-


Joined: 11 Dec 2004
Posts: 872

PostPosted: Tue Sep 27, 2005 2:31 pm    Post subject: Reply with quote

[Removed]
Back to top View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group