Help - Search - Members - Calendar
Full Version: Hotscripts.com Hacked
CubeCart Forums > General > General Discussion
Al
http://www.hotscripts.com
Al
Thats site must make a fortune out of advertising.
Orionjoel
Hmmm i wonder what they lose from advertising every hour they down like that.
Al
They have 4,000 users on the site at a time... The amount of impressions those ads get is astonishing.

One sale for a hosting company brings $40 - $50 they must get quite a lot of those every day. Let alone those who pay to adertise on the site.
Orionjoel
Hmmm quite interesting maybe i know what business i should be in wink.gif
magicexpress
LOL!! Sucks for them.
chris g
lol...spykids. What a lame hacking name.
OskMedia
i wonder what they actually hacked though my sql or what hmmmmm
OskMedia
brooky how did they hack ur server that one time , i prolly think it was an injection but how did they do it , jw
Al
Apache was running a nobody and I fooloshly left the forums config chmod to 777 file. To this day I am amazed how foolish that was. I religioulsy check things like that.

THat was they config file was easily rewritten dropping the database.

No I only give very limited access rights to mySql users.
akumanz
OMFG ROFL. LOOOOOOOOOOOOOOOL
Mobie
That brings me to another question brooky (or anybody else who knows):

To what do I set the files and folders in my store to not have this happen to me?
Not that I have or ever will have a high traffic site (more so locally I hope) wink.gif
Al
Just make sure admin/config.inc.php is set to 644 if you have a unix type system.
johnc2k
QUOTE(OskMedia @ Mar 6 2005, 09:04 PM)
i wonder what they actually hacked though my sql or what hmmmmm

spykids have written a variant of the phpbb forum worm which exploits up to one of the very latest version of phpBB.
It will searach through the whole machine/server trying to overwrite web pages with that text.
Chances are hotscripts.com wasnt directly hacked buy one of the other hosted website on the same box was.

John - the security guy biggrin.gif
OskMedia
damn lol who are these poeple
afksky
QUOTE
Chances are hotscripts.com wasnt directly hacked buy one of the other hosted website on the same box was.


Yes that is what seems to have happed on the site. you can read a news post the admin of hotscripts made about it. I think there is a link on there site to it..
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.