Jump to content

I was hacked after all! Advice required


fettlebox

Recommended Posts

Nothing.  I put it down to my me but couldn't figure out how. 

 

I have a similar scenario to the link post - from the logs

hack00.JPG

 

hack00a.JPG

 

I have no added hooks but these snippets.  Not an area of the site I've been in before.  Got the google one as posted in the linked post.  Do I delete these?  There are in includes/extra but the 2 smaller ones seems to have been created after I beefed up the password & upgraded.  Part of the new CC?

hack01.JPG

hack01a.JPGhack02.JPGhack03.JPG

I have found the parasites php files but can't figure out where it's inmages are stored.

/images/images/jiaju57.php?/imagegen.ashx?class=default&width=960&image=/media/264643/woman-drinking-coffee-in-bed-1920x800.png

 

Link to comment
Share on other sites

The IP and actions are 100% suspect !  The IP address is a TOR exit node - a well known way of hiding the actual IP address of the hacker and all three snippets are suspect.  I haven't decoded the "Google" snippet but my guess would be that it facilitates further access.  All three snippets need to be deleted from within CubeCart and the includes/extra directory but I believe that due to the extra time that has passed, they were able to add extra back doors into your site and you will need to look very closely at your whole site structure.

Ian

Link to comment
Share on other sites

I changed the password the same day I was hacked - on Friday.  The password is auto-generated & random.  There is no further access logged outside of my own IP.  

The only back doors I have any knowledge of are on houses!  How much does it cost to have the structure checked?  If this is possible please PM me!

 

Thanks

 

 

Link to comment
Share on other sites

Is your install stock? If so, you could use file difference software and compare a download of your site against the stock code. I use BeyondCompare to do that, as I have heavily edited code. It's pretty straight forward IF your site is stock. It will run a compare and quickly show you which files are different.

As for paying, you could pay CC to do it.

https://www.cubecart.com/technical-support

Link to comment
Share on other sites

5 minutes ago, Dirty Butter said:

Is your install stock? If so, you could use file difference software and compare a download of your site against the stock code. I use BeyondCompare to do that, as I have heavily edited code. It's pretty straight forward IF your site is stock. It will run a compare and quickly show you which files are different.

It will certainly show stock files that are different or altered and will also help to highlight files in stock directories that are not in the standard distribution but it is certainly not foolproof once hacked.  His site had a large number of files uploaded all over the directory structure, many hidden in obscure directories that you wouldnt compare this way - such as in the image sub-directories and cache etc

Ian

Link to comment
Share on other sites

Quote

many hidden in obscure directories that you wouldn't compare this way - such as in the image sub-directories and cache etc

That makes sense - those files would not be in stock even in a good install, so no way to compare. Sounds like your best course of action is to pay to have it fixed. Sorry.

Link to comment
Share on other sites

  • 4 months later...

I have seen reports of /default#.php where # is a number, but this is widespread. So much so, that I think Google is finding these links elsewhere (as opposed to links on your site that point to this URL of your site), and when Google tries them, Google gets a 404 reponse with a web page that needs a page resource that ends in .php.

This is what I think, and may be completely off-base.

Anyway, do Google's "What can I do about it?" help topic.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...