home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Webmastering and Programming
Ask a Tech Support Question (free)!

Hack with prev.php??

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2106
Discussions: 200,948, Posts: 2,379,406, Members: 246,309
Old October 23rd, 2004, 10:42 PM   Digg it!   #1 (permalink)
Perfetc Member
 
VHockey86's Avatar
 
Join Date: Jan 2003
Location: Maryland Suburbia
Posts: 4,334
Hack with prev.php??

This afternoon I got back and went to my webpage... and found this
http://www.andrewpangborn.com
"Hacked by =inside"

My webserver control panel and ssh and ftp and stuff all seemed in tact. The homepage index.htm had been added to the server on Oct 22 around 5pm, so was the picture.

I started looking at server access logs and found POSTs using a "/prev.php" file, which was dated sept 25, although I dont remember ever actually putting any file like that on there. Its rather large at around 88KB. I did a "cat" command via ssh and read the comment at the top, it said something brief about being a php file editing/creating/removing file.

There are repeated POSTs in the log regarding that file, as well as index.htm, all from the same IP at about the time those files are dated.

They look kinda like this:

80.70.227.120 - - [22/Oct/2004:17:56:18 -0400] "POST /prev.php HTTP/1.1" 302 123 www.andrewpangborn.com "http://www.andrewpangborn.com/prev.php?c=e&d=%2Fhomepages%2F22%2Fd107367292%2Fht docs%2Fandrew%2F&f=index.htm" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)" "-"

I don't really know all that much about web security myself... its hosted by a remote server.

None of the content of the page appears to be changed... the regular homepage which is index.php is intact, as is all the content on the pages. No one really visits that site... so I'm not exactly sure of the motive.
I started updating another site of mine,
http://www.morrowindtips.com, which resides inside a subdirectory of the domain that got hacked.

I figure I'll call technical support of the hosting company just to let them know about the incident, any other course of action I should be taking? (or some advice in general)?

Thanks,
Vhockey86
VHockey86 is offline   Reply With Quote
Old October 23rd, 2004, 10:52 PM     #2 (permalink)
Binder Household Butler
 
Join Date: Oct 2001
Posts: 5,442
Most of the cases where web servers are "hacked" are a result of whoever is responsible for server administration not taking the necessary precautions when it comes to configuring the system's services properly. A lot of admins tend to leave a lot of unnecessary services running - which only makes it more convenient for people to gain access w/ malicious intent.

Brandon
brandon184 is online now   Reply With Quote
Old October 25th, 2004, 01:40 PM     #3 (permalink)
Perfetc Member
 
VHockey86's Avatar
 
Join Date: Jan 2003
Location: Maryland Suburbia
Posts: 4,334
hmm, well the same thing has come back today. That prev.php file is back on the site too somehow (after i changed all my ftp passwords and SSH passwords and stuff).

http://php.spb.ru/remview/
Thats the site for the prev.php file that keeps being there...
VHockey86 is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Thread about Anime. BobOmega IMO Community 9531 April 28th, 2009 02:47 AM
PHPNuke Site Rdaws Webmastering and Programming 4 September 26th, 2004 04:20 PM
what exactly are pipelines? hulkMAD Graphics Cards and Displays 8 August 13th, 2004 10:48 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Making Health Care Worse (174)
Is It Just Me? (2937)
The disrespect of Obama by Russian .. (23)
Wireless Televisions. (12)
windows 7 problem (7)
CPU fan stops spinning randomly (8)
Regular Build (6)
Is the PSU I received dead? (12)
radeon x850xt platinum & shader.. (5)
Print spooler problem (15)
HIS HD5770 graphic card question (15)
windows vista security holes (9)
Install XP pro and a Vista laptop ?.. (11)
Dept. of HS: NSA 'Helped' Develop V.. (15)
Recent Discussions
Point and Shoot Camera Suggestions. (3)
How to convert MP3's (4)
Wireless Televisions. (12)
Graphics Card Upgrade Question (3)
Laptop with wireless problem. (2)
Internet Lost (1)
Hp Artist Edition + Matching Bag (0)
My monitor won't turn on after instal.. (0)
Asus P4G8X Mobo (6)
radeon x850xt platinum & shader 3 (5)
Xbox 360 GTA: SA disk error (1)
Is the PSU I received dead? (12)
windows 7 internet problem (5)
Multiple Restarts Required at Boot (0)
BSOD On Startup (ntoskrnl.exe) (2)
Print spooler problem (15)
Have you switched yet? (86)
screen resolution vs monitor size (2)
sms storage to PC (0)
Regular Build (6)
Open With ..... Win7 (0)
java code for fibonacci (1)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (35)
windows 7 problem (7)
CPU fan stops spinning randomly (8)


All times are GMT -4. The time now is 09:34 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28