You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 96 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Sentinel Killed defacing attack. Now what? [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
vcorreia
Nuke Cadet
Nuke Cadet


Joined: Nov 14, 2006
Posts: 1


PostPosted: Mon Nov 13, 2006 4:02 pm Reply with quoteBack to top

Hi,

Thanks once again to sentinel, a recent attack was stopped.

Here goes the info:

Date & Time: 2006-11-13 23:01:02 WET GMT +0000 Blocked IP: 200.153.151.27 User ID: Visitante (1)
Reason: Abuse-Filter
--------------------
User Agent: Mozilla/3.0 (compatible; Indy Library) Query String: www.euroindy.com/portal/modules.php?name=*****REMOVED*****
Get String: www.euroindy.com/portal/modules.php?name=*****REMOVED*****
Post String: www.euroindy.com/portal/modules.php
Forwarded For: none
Client IP: none
Remote Address: 200.153.151.27
Remote Port: 1165
Request Method: GET

I checked the command "*****REMOVED*****" and I saw a tool that defaces websites. It is hosted in this domain, that seems to be an honest domain "*****REMOVED*****"

What can we do more?

I hope this info was usefull. It seems this defacing tool is targeting (mainly) phpnuke websites.
Find all posts by vcorreiaView user's profileSend private message
phpnuke-hosting
Support Mod
Support Mod


Joined: Oct 19, 2004
Posts: 1032

Location: UK

PostPosted: Mon Nov 13, 2006 5:28 pm Reply with quoteBack to top

I have removed several links you put in your post.

They link to a Trojan for the defacing tool, this is not a wise thing to post in PHP-Nuke Forums.

Nothing can really be done about this, although I am about to take a look at the code for the tool and see if there are any unknown exploits this is targetting.

I will report back with my findings in due course, in the mean time if sentinel is blocking it then its doing its job.

Keep your sentinel and phpnuke up-to-date and patched.

PHP-Nuke: 7.6

Patches: 3.2

Sentinel 2.5.03

_________________
www.phpnuke-hosting.com

The Internets Foremost PHP-Nuke Web Host.

Image

Click Here!
Find all posts by phpnuke-hostingView user's profileSend private messageVisit poster's website
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12389


PostPosted: Wed Nov 15, 2006 6:49 am Reply with quoteBack to top

Report to the site hosting the file, as well as the ISP of the offending IP. Maybe they will do something, maybe not. At best, they have not been notified yet.. your message will get them to remove it. At worst, they do nothing.

There have been a flood of attacks against many PHP scripts. Indy-library is just one of the methods.
If you could, PM me the details as well

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.204 Seconds - 219 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::