Jump to content

Hotscripts.com Hacked


Recommended Posts

Apache was running a nobody and I fooloshly left the forums config chmod to 777 file. To this day I am amazed how foolish that was. I religioulsy check things like that.

THat was they config file was easily rewritten dropping the database.

No I only give very limited access rights to mySql users.

Link to comment
Share on other sites

That brings me to another question brooky (or anybody else who knows):

To what do I set the files and folders in my store to not have this happen to me?

Not that I have or ever will have a high traffic site (more so locally I hope) ;)

Link to comment
Share on other sites

Guest johnc2k

i wonder what they actually hacked though my sql or what hmmmmm

spykids have written a variant of the phpbb forum worm which exploits up to one of the very latest version of phpBB.

It will searach through the whole machine/server trying to overwrite web pages with that text.

Chances are hotscripts.com wasnt directly hacked buy one of the other hosted website on the same box was.

John - the security guy ;)

Link to comment
Share on other sites

Chances are hotscripts.com wasnt directly hacked buy one of the other hosted website on the same box was.

Yes that is what seems to have happed on the site. you can read a news post the admin of hotscripts made about it. I think there is a link on there site to it..

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...