HomeUnityBlogs
 
 
Robin

I think my site was hacked

Hello all,

 

I have a feeling my site was hacked. Frined from this site is helping me with this probblem and hope to get it resolved soon.

 

I though i share this with you and to let you know what i found if anyof you run into the same probelm.

 

I fouund the following in my cron job

/home/website/public_html/updates/y2kupdate >/dev/null 2>&1

I also found a folder called update whcih i renamed it to update??  and in it i noticed file names that Boonex would never use example f%^$.

can i del. this folder???

 

and the jobs i setup at the time of installation are all gone.

since i didnt put the above job in the cron i also removed it...

 

bad
9
good
 
 

Comments

Bramin
Bramin(positive) 131 days agocomment permalink
 
Now this blog exemplifies CONSTRUCTIVE criticism by pointing out a security issue and sharing the info she has for the rest of us to use so we do not get clobbered like she may have been. Thanks, Robin, and keep us all posted if you find any more information or if you have any questions that anyone might be able to answer which might help you out.
 
bad
0
good
 
View 1 replies to this comment
 
sammie
sammie 131 days agocomment permalink
 
ok so your host was hacked, that means your dolphin site was the cause of your ineptitude in choosing hosting that was below the minimum requirements.
way to go
blame it all on dolphin, never blame yourself and lack of knowledge
 
bad
0
good
 
View 1 replies to this comment
 
Robin
Robin 131 days agocomment permalink
 
Sammie, you need to read my comment again.

And stop being soo hostile....

my posting was to share my experience and I never actually said "Dolphin was hacked".
I posted a few things i found which was causing the problems so in the event this happens to somoene else in the future maybe they can keep this posting in mine for background information.
 
bad
1
good
 
 
praveenkv1988
praveenkv1988 131 days agocomment permalink
 
Dolphin is not using the above mentioned crons and dirs. So it will be a hacking attempt.
 
bad
1
good
 
 
sammie
sammie 131 days agocomment permalink
 
dolphin was never and will never be writen for shared hosting.
you have shared hosting. your shared hosting is what caused your site to be vulnerable, not dolphin, dolphin has passed security testing, ok we can say that no security is perfect, but if you host your site on a host that has far below the minimum requirements, we can safely say you are mostly to blame

cronjobs are set to 666 while you install them then at the end of the install you reverse them to 644
then they can not be changed, unless your server was corrupt before, or hacked after the install.

most servers are hacked by (script kiddies) using old tools to prove they can hack, so they can join a boys club.
its kinda like trying to prove they can ge inside some pussy because they are cool and can talk their way into anything.
when infact, any smart girl would know they cant bluff their way out of a wet paper bag
 
bad
2
good
 
View 1 replies to this comment
 
DosDawg
DosDawg(positive) 131 days agocomment permalink
 
robin,
not to jump on a band wagon here, but your post says "my site was hacked" which would lead those of us on here with "dolphin sites" would presume you were referring to your "dolphin site" since you posted that on the boonex/dolphin blog. by any chance was this attended to by your hosting provider? the server needs to be scanned, as it is my belief that if this was done, and you cant find any shell files on your portion of the shared server, then the hosting provider needs to scan and clean the server, its still vulnerable if the server has not been cleaned.

so maybe your post should have been my hosting account was hacked, oh well just my thoughts.

later,
DosDawg
 
bad
3
good
 
 
nurke
nurke 130 days agocomment permalink
 
My "dolphin" was hacked too. And I use hostforweb. vps.
Boonex guys say its the host problem, hostforweb says its the script.
Boonex says the host need to disable register_globals, host says I have to do it.
I have provided a link from my records( abuse notice) in one of earlier posts, looks like the hacker sent emails form aurora2.hosting4less.com.
xxxxxx
To: jclt@iecc.cambridge.ma.us
Subject: Aviso Importante.
X-PHP-Script: balkanlink.net/ray/modules/global/inc/content.inc.php for 201.86.181.91
From: Alto-AtendimentoBB <BancodoBrasil.gov.com@aurora2.hosting4less.com>
Reply-To: Alto-AtendimentoBB@server.balkanlink.net
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
xxxxxxxx

Now you tell me;
who is giver...who i receiver?
 
bad
0
good
 
View 1 replies to this comment
 
Dwain
Dwain(positive) 130 days agocomment permalink
 
All of my dolphin scripts were hacked, too, but it's ok, I know it was all my fault or the fault of my server or maybe it was because I am a man and I like pussy.... what ever my short coming..... I was also hacked.

My host also says it's the script.

Now can we please return to some semblance of sanity and unity and can the attitudes?
 
bad
0
good
 
 
makako
makako 11 days agocomment permalink
 
My site has been hacked for russian guys...My index page has been changed (redirection to this russian site...http://www.netalant.narod.ru/links.txt ... I upload the original page again and the problem are fixed).... but the hosting company said..." the problem is the script"....this action send all my traffic (my site have pagerank=3) at the hackers site...that is the custion...
 
bad
0
good
 
 


Post a Comment

Please login to post a comment.

This Post
 
 
Robin Blog
All Blogs
Found a bug? Have a suggestion? We really value your feedback!
 
© 2008 BoonEx Ltd
ABN 27 127 966 581
 
PET:0.717558145523