Welcome to HostingForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Eeep! I was hacked

 
   Web Hosting Problem Solving Community! (Home) -> Webmaster RSS
Next:  Best Image Size  
Author Message
user274

External


Since: Oct 23, 2003
Posts: 226



(Msg. 1) Posted: Mon Aug 30, 2004 5:46 pm
Post subject: Eeep! I was hacked
Archived from groups: alt>www>webmaster (more info?)

Lately (last 4 or 5 months) I've been just backing up the critical stuff
from the server to CDRoms... but last night I thought I would do a full back
up.

Normally everything fits on one 40GB tape... but much to my surprise the
drive starts beeping me at 1am and asking for a second tape and telling me
its only 60% complete.

So this morning I take a good look around the server... and much to my
surprise I find that somebody stashed some 32GB worth of movies (in German
and Turkish) on my hard drive back in mid May

I figure I can pretty much trace it back to about a 4 week span where I
didn't have any firewall running on the server.

Perhaps even more embarassing (than being hacked... or even running a web
server without a firewall for a month) is that I really chewed out my ISP
back at the end of May becuz I had 3.5Mbs bandwidth but wasn't getting
anywhere near that. As I think about it... the bandwidth really cleared up
whenever I rebooted the modem or the server, so I started doing that almost
daily... but in hindsight it sped things up because I was kicking off all
the people that were on there downloading movies.

 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
spamblocked

External


Since: Sep 14, 2004
Posts: 588



(Msg. 2) Posted: Tue Aug 31, 2004 1:23 am
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Augustus wrote:
 > ...
 > I figure I can pretty much trace it back to about a 4 week span where I
 > didn't have any firewall running on the server.

oh my my - how's your foot?

You are extremely fortunate that your server wasn't further compromised.

At least it's sorted now.

--
William Tasso - read 'em, else the puppy gets it:
<a style='text-decoration: underline;' href="http://www.aww-faq.org/" target="_blank">http://www.aww-faq.org/</a>
<a style='text-decoration: underline;' href="http://www.catb.org/~esr/faqs/smart-questions.html" target="_blank">http://www.catb.org/~esr/faqs/smart-questions.html</a>
<a style='text-decoration: underline;' href="http://groups.google.com/groups?as_ugroup=alt.www.webmaster" target="_blank">http://groups.google.com/groups?as_ugroup=alt.www.webmaster</a><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
kenneth1

External


Since: Jun 30, 2004
Posts: 148



(Msg. 3) Posted: Tue Aug 31, 2004 2:14 am
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On 2004-08-30, Augustus <Imperial.Palace.TakeThisOut@Rome.com> wrote:
 > Lately (last 4 or 5 months) I've been just backing up the critical stuff
 > from the server to CDRoms... but last night I thought I would do a full back
 > up.
 >
 > Normally everything fits on one 40GB tape... but much to my surprise the
 > drive starts beeping me at 1am and asking for a second tape and telling me
 > its only 60% complete.
 >
 > So this morning I take a good look around the server... and much to my
 > surprise I find that somebody stashed some 32GB worth of movies (in German
 > and Turkish) on my hard drive back in mid May

I'm not sure which is worse:

1. You haven't done a full back up since May
2. You haven't done a complete "walk thru" of your hard drive since May.
3. You don't know what's on your hard drive
4. You ran your server without a firewall

Hmmmm

Oh, those movies, they porn. Just curious.

ken<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
user274

External


Since: Oct 23, 2003
Posts: 226



(Msg. 4) Posted: Tue Aug 31, 2004 2:14 am
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Kenneth" <Kenneth RemoveThis @nowhere.special> wrote in message
news:slrncj7d91.maa.Kenneth@localhost.localdomain...
 > On 2004-08-30, Augustus <Imperial.Palace RemoveThis @Rome.com> wrote:
 >
 > I'm not sure which is worse:
 >
 > 1. You haven't done a full back up since May

Maybe... but the only thing on the server is the software for the websites
themselves. If we "lost it all" we could re-install from scratch and
restore the websites and databases from the CDRoms

 > 2. You haven't done a complete "walk thru" of your hard drive since May.

Its been longer than since May Smile

But like I say these files were hidden in the Windows Media Player folder...
thats not something I think I've ever run on the server

 > 3. You don't know what's on your hard drive

I should probably have a better idea of whats a normal "free space" for the
hard drive. We are opening up a second office down in Phoenix so I was
figuring they had made CD images so they could install to laptops to demo
the sites.

 > 4. You ran your server without a firewall

Yeah that was a boo boo... the license on our firewall software expired and
I was trying some new stuff out. But the new firewall was blocking email
from the websites to the mail server and so I just turned the firewall off
until we got it resolved and wound up never getting back to it cuz the thing
seemed to be running smoothly without it.

 > Hmmmm
 >
 > Oh, those movies, they porn. Just curious.

Alas, no. There was no porn... mostly just popular movies that came out on
DVD in the first part of this year.<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
user94

External


Since: Sep 14, 2004
Posts: 2384



(Msg. 5) Posted: Tue Aug 31, 2004 2:28 am
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Kenneth wrote:

 > I'm not sure which is worse:
 >
 > 1. You haven't done a full back up since May

I can't do a full back up. Remote server. Wouldn't do that anyway, just
the non-standard files. The OS can always be restored.

 > 2. You haven't done a complete "walk thru" of your hard drive since

Sod that.

 > 3. You don't know what's on your hard drive

Who does (except Baho)? I have cpanel on a Linux box. There's a whole
stack of guff on the hard drive that means nothing to me.

 > 4. You ran your server without a firewall

Now that I don't do!

In any event. Worst case scenario, restore it then reload your backed up
files, easy peasy.

--
Charles Sweeney
<a style='text-decoration: underline;' href="http://CharlesSweeney.com" target="_blank">http://CharlesSweeney.com</a><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
kenneth1

External


Since: Jun 30, 2004
Posts: 148



(Msg. 6) Posted: Tue Aug 31, 2004 12:00 pm
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On 2004-08-30, Charles Sweeney <me RemoveThis @charlessweeney.com> wrote:
 > Kenneth wrote:
 >
 > I can't do a full back up. Remote server. Wouldn't do that anyway, just
 > the non-standard files. The OS can always be restored.

Well, the problem with Linux is restoring the right kernel and other like
files, especially if you've been doing patches etc.

 >
 > Who does (except Baho)? I have cpanel on a Linux box. There's a whole
 > stack of guff on the hard drive that means nothing to me.

Looks like it's me and Baho then. I do keep a constant eye on my hard
drive a rootkit will do that....

But I like your optimistic outlook, it would make any French grandmother
happy <g>

ken<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
kenneth1

External


Since: Jun 30, 2004
Posts: 148



(Msg. 7) Posted: Tue Aug 31, 2004 12:05 pm
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On 2004-08-31, Augustus <Imperial.Palace.DeleteThis@Rome.com> wrote:

  >> 4. You ran your server without a firewall
 >
 > Yeah that was a boo boo... the license on our firewall software expired and
 > I was trying some new stuff out. But the new firewall was blocking email
 > from the websites to the mail server and so I just turned the firewall off
 > until we got it resolved and wound up never getting back to it cuz the thing
 > seemed to be running smoothly without it.

LOL, yeah, I've made that mistake. Seems like all is well, I'll just
do it next week or the week after...but it's running so well, maybe next
month.

ken<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
user94

External


Since: Sep 14, 2004
Posts: 2384



(Msg. 8) Posted: Tue Aug 31, 2004 12:23 pm
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Kenneth wrote:

 > On 2004-08-30, Charles Sweeney <me.DeleteThis@charlessweeney.com> wrote:
  >> Kenneth wrote:
  >>
  >> I can't do a full back up. Remote server. Wouldn't do that anyway,
  >> just the non-standard files. The OS can always be restored.
 >
 > Well, the problem with Linux is restoring the right kernel and other
 > like files, especially if you've been doing patches etc.

I have Linux with cpanel, so the latest versions for a restore are more
than good enough for my purposes.

  >> Who does (except Baho)? I have cpanel on a Linux box. There's a
  >> whole stack of guff on the hard drive that means nothing to me.
 >
 > Looks like it's me and Baho then. I do keep a constant eye on my hard
 > drive a rootkit will do that....

Heh, beg your pardon!

Ah, now checking for rootkits, you didn't mention that. I use chkrootkit
and Rootkit Hunter, daily by cron.

To be honest, I would like to take the Baho/Ken (and others!) approach.
Starting with a bare drive and installing everything manually, and only
that which is needed.

With cpanel, as I said, there is a huge lot of stuff. But it's a
time/motivation thing. If I was to do it, I would like to know it inside
out, which I aint gonna achieve in a few days!

 > But I like your optimistic outlook, it would make any French
 > grandmother happy <g>

That must be where your good nature comes from!

--
Charles Sweeney
<a style='text-decoration: underline;' href="http://CharlesSweeney.com" target="_blank">http://CharlesSweeney.com</a><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
kenneth1

External


Since: Jun 30, 2004
Posts: 148



(Msg. 9) Posted: Tue Aug 31, 2004 8:39 pm
Post subject: Re: Eeep! I was hacked [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On 2004-08-31, Charles Sweeney <me.RemoveThis@charlessweeney.com> wrote:
 >
 > Ah, now checking for rootkits, you didn't mention that. I use chkrootkit
 > and Rootkit Hunter, daily by cron.

I'll have to try rootkit hunter, chkrootkit missed it when I was hit.

 >
 > To be honest, I would like to take the Baho/Ken (and others!) approach.
 > Starting with a bare drive and installing everything manually, and only
 > that which is needed.

Time consuming and tedious, only for the anal minded.

 >
  >> But I like your optimistic outlook, it would make any French
  >> grandmother happy <g>
 >
 > That must be where your good nature comes from!
 >

Hmmm...(sniff, sniff, snnnnnifffff), yep, smells like sarcasm to me

ken<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Eeep! I was hacked 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
"hacked from fowl" ?? - I was just doing updates on a database-driven site I developed, and one of the sections had this: "HACKED FROM FOWL" There are many tables in the database, but only one had this. I did a quick google search and found a couple of other sit...

is my site get hacked? - Hi , i am running a website and nowadays I found some strange files in my ftp area. all files are html files... i am runnig my website in Windows server, IIS + ASP. in IIS i kept index.asp as default file so my site has not defaced.. the one tried this....

aspin.com - asp resource has been hacked - heh - that again amuses me :) Nice to see FrontPage being used for something useful! - http://www.aspin.com/ or if it's been fixed http://www.petergraves.co.uk/aspin.jpg ta for now peter

Lynx website hacked? - WARNING - explicit sexual material follows at the following URL. If you press ? during a Lynx session, you should receive online help through the following URL: http://www.hubbleconstant.com/lynx/lynx_help/lynx_help_main.html However! This is best..

hacked form mailer? - When I receive an email from the form mailer on one of my sites it looks like this. first_name: John Smith RadioGroup1: Member textarea: hi, nice site. But yesterday I had several forms submitted that looked like patsed below. As well as all the..
   Web Hosting Problem Solving Community! (Home) -> Webmaster All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]