Jump to content

website hacked


Guest

Recommended Posts

my cc3 was hacked this weekend. They managed to delete my images/uploads folder.

The provider says i should update my script, which at the mo ist is, and have folders set no more than 755 and files no more than 644, which coindently was.

So how they managed to get in and delete these files i dont know. I'm gonna need to upload the missing files and hopefully wont get hacked again.

I dont think other folders or files were deleted. BLOODY HACKERS they are just sreknaw (mirrored backward). :w00t:

Link to comment
Share on other sites

Guest vrakas

Sorry to hear this ;)

Perform a search in this forum on how to protect your site.

I will look also to find the threads and post them for you :w00t:

Link removed -- reason: outdated information. -- Sir William

Link to comment
Share on other sites

You need to have your host verify whether the attack/hack came in thru CubeCart or another hole somewhere. I still haven't seen evidence on ANY compromised servers/sites that say it's coming in thru current CubeCart installations.

:w00t:

Link to comment
Share on other sites

I just got notified by my service provider my site was hacked also. They got into images/File directory. Not sure the damage as I won't be able to check it until I get home. This is the first time I have been hacked. I have nother 5 sites with cubecart and will have to check all of them.

Link to comment
Share on other sites

Guest Ken Than

I just got notified by my service provider my site was hacked also. They got into images/File directory. Not sure the damage as I won't be able to check it until I get home. This is the first time I have been hacked. I have nother 5 sites with cubecart and will have to check all of them.

The measure to this problem is that cubecart should set start and close button before and after the file uploading script. Means, to upload file, you have to click START Button, which will chmod images folder to 777 and when finish uploading photos, click CLOSE button, which will set image folder to 644.

What do you guy say?

Link to comment
Share on other sites

  • 2 weeks later...

Ken, that's a nice idea, but in order to do that, the web server user would have to own that folder. If it was the owner, then it would be able to write to the folder unless the permission was set to 555 -- read/execute ONLY for all users. BUT....if the server user owns it, it can change the permissions at will. So how long you figure it would take the hackers to figure out that they needed to search for folders owned by the server user, change them to 777 and then upload what they want.

It's a catch 22. :)

:w00t:

Link to comment
Share on other sites

Guest Coder68

Sir William,

I have two questions then.

1. After I upload the images I need, if I change the folder permissions to 644 or what ever (Im new to Linux.) would that greatly reduce my risk?

2. By owning your own IP and not using a shared IP... does that reduce or eliminate your risk from other websites that are not up to date?

Thanks!

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...