I was Hacked

This is where youll find security related information.
Discuss Integramod/phpbb security issues here.

Moderator: Integra Moderator

PostAuthor: ErikG » Sat Aug 26, 2006 3:22 pm

Could it be that it is simply written "down below". As they seem to search via google or some such and look for powered by integramod etc, but here it says powered by kismod.

Could it be so simple?
Last edited by ErikG on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

ErikG
Newbie
Newbie
 
Posts: 5
Likes: 0 post
Liked in: 0 post
Joined: Fri Aug 25, 2006 7:50 am
Cash on hand: 0.00

PostAuthor: Solomon » Sat Aug 26, 2006 3:31 pm

"ErikG";p="14161" wrote:Could it be that it is simply written "down below". As they seem to search via google or some such and look for powered by integramod etc, but here it says powered by kismod.

Could it be so simple?

My latest referrer was http://www.alltheweb.com and the search text was "Powered by KisMod ÂÂÂ © 2004, 2006 The Integramod Group".

I see the only difference here is 2001, 2006, but mine doesnt say KisMod, it said IntegraMOD, so it was found anyways. They use the search engines to find forums to victimize, but I'm sure they know the main url here as well. So no it cant be that simple. I would think they would target this site first then the rest of the sites. It would sure suck if we couldnt get help here because it was down. *knock-on-wood*

You can block referres in the ACP or a better method is to block them in the ".htaccess" file. Information on how can be found here <img> http://www.javascriptkit.com/howto/htaccess14.shtml
Last edited by Solomon on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
[hr]

Solomon
Members
Members
 
Posts: 90
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 8:22 am
Cash on hand: 0.00

Re: I was Hacked

PostAuthor: evolver » Sat Aug 26, 2006 4:25 pm

Euhm, how many of these hacked sites have a link on integraMOD2.com...
...or maybe even still on integraMOD.com ??

No need for Google to find these...
No need for 'Powered by' keywords to find these...

There are easier ways to find integraMOD sites than just by using Google...
And ofcourse, that could also be a very good reason why integraMOD.com hasn't been hacked yet...

Just don't focus at one direction only...
Think about every possibility, because that's how hackers think as well...
Last edited by evolver on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
ImageAlways remember you're unique, just like everyone else.
We are born naked, wet and hungry. Then things get worse.
Don't take life too seriously, you won't get out alive.
User avatar
evolver
Sr Integra Member
Sr Integra Member
 
Posts: 420
Likes: 0 post
Liked in: 0 post
Joined: Mon Mar 27, 2006 12:46 pm
Cash on hand: 0.00
Location: Oostende

Re: I was Hacked

PostAuthor: joescamera » Sun Aug 27, 2006 12:33 pm

Hello - I was also hacked on the 24 and again the 25th (after I'd successfully got my site back and running by replacing the config.php file)

Unfortunately, when "they" hacked me on the 25th, EVERY file and folder was deleted from my host's server. <img> (this was Saturday and have been siteless since).

I received an email from my host this evening after constant chasing, which may or may not help the current issue:


Thank you for contacting us.

Searching your access logs it seems your site was hacked on the 24th
(and again today). I will restore a backup from the night of the 23rd
which should contain everything you are missing. I recommend updating
your phpbb forum to the newest version because it seems that is how they
got in. If you look in your logs folder at the access.log.34.4.gz file
you will see they posted a pomponk.txt file which is actually a php
script used to hack your space. The IP it comes from is 202.138.226.3
which is an Indonesian ip, which has a high rate for these things. I
will let you know as soon as the back is restored.


Obviously I don't want to just start using the software again as is, but am pretty new to "locking down" software etc - can anyone recommend some sensible precautions to make that will enable me to continue using my site for visitors to upload and post, without too much risk to my site / server?

Many thanks.
Last edited by joescamera on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

joescamera
Newbie
Newbie
 
Posts: 1
Likes: 0 post
Liked in: 0 post
Joined: Mon Mar 27, 2006 2:16 pm
Cash on hand: 0.00

PostAuthor: Unregistered » Sun Aug 27, 2006 1:02 pm

Last edited by Unregistered on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
J O N H | P L A Y E R

Unregistered
Sr Integra Member
Sr Integra Member
 
Posts: 254
Likes: 0 post
Liked in: 0 post
Joined: Wed Jun 07, 2006 1:51 pm
Cash on hand: 0.00

Re: I was Hacked

PostAuthor: jwernerny » Sun Aug 27, 2006 2:25 pm

I'm pretty sure these hacks are actually cross contaminations from a master server. The quick and simple way to prevent them may be to obfuscate (hide) the forum source directories and use .htaccess to make it look like things are in the expect location.

I'll explain. Let's say I am a hacker and I have compromised a website with the c99 shell script. If I know that IM1.4.0 is normally installed in "forum" and has open directories of "files," etc., and I am on a host that seems to assign user names in a regular fassion, then I can quickly infect other sights by trying to blindly write into the directories.

For instance, let's say on host "ABC_XYZZY_Hosting.com", I know have found that user are given id's in the form of "user0001", "user0002", "user0003", etc., then I can start randomly trying to write to /home/user0001/forum/files, then /home/user0002/forum/files, etc.

BTW, I got hacked this morning. I found 2 copies of c99 shell, one in files and the other someplace else. I am on WB-Hosting. If you use WB-Hosting, I strongly suggest you check things out and take some steps to make sure the well known directories are not accessible.

- John
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

PostAuthor: jwernerny » Sun Aug 27, 2006 2:35 pm

PS: Once you are hacked, I would suggest creating a new database user name with a new password.
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

Cross contaminations from a master server!

PostAuthor: Michaelo » Sun Aug 27, 2006 3:38 pm

Cross contaminations from a master server!

This is definitely happening, I have come across it earlier today... If some one hack a site they can by the use the c99 shell script (and other scripts), as explained by jwernerny above, screw up any other phpBB/IntegraMod based site on the same server...

It is up to us to be vigilant therefore it is necessary to check you site for any file that should not be there. Note some of these files may have a php extension, if in doubt about a file check you original upload source.

Mike
Last edited by Michaelo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

Re: I was Hacked

PostAuthor: jwernerny » Sun Aug 27, 2006 4:08 pm

Okay, I have just looked at my raw logs. My hacker definitely came through the functions.php exploit, not cross contamination. Still, I would be wary.

- John
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

PostAuthor: gcomfx.com » Sun Aug 27, 2006 5:45 pm

My host shut me down.

my integramod forum was spamming.

includes folder was sending out 4540 emails.

UGH.... I'm trying to get my host to let me put up an announcement page and leave everything else off until a solution is found for all of this.
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

PostAuthor: gcomfx.com » Mon Aug 28, 2006 8:53 pm

Okay guys, I basically killed my cpanel account and started all over. I have yet to upload integramod.

However, in my error log, I'm showing a lot of attempts to get to:

community/phphtmllib/tag_utils/divtag_utils.php

and

community/export.php

Could this be the hackers still looking? I've never seen the directory /phphtmllib before.
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

PostAuthor: InoculateIT » Mon Aug 28, 2006 9:41 pm

[quote=""InoculateIT";p="13996""]
Did you CHMOD the files?

CHMOD all files 644 exept the ones mentioned in the integramod_install_guide_page1.htm

I have never been hacked :)
Last edited by InoculateIT on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

InoculateIT
Newbie
Newbie
 
Posts: 9
Likes: 0 post
Liked in: 0 post
Joined: Mon Jun 12, 2006 6:12 am
Cash on hand: 0.00

PostAuthor: Jacky » Tue Aug 29, 2006 12:10 am

So people with files CHMOD to 644 and folders CHMOD to 755 won't get affected by this?
Last edited by Jacky on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Jacky
User avatar
Jacky
Members
Members
 
Posts: 71
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 20, 2006 7:21 am
Cash on hand: 0.00

PostAuthor: Michaelo » Tue Aug 29, 2006 4:56 am

[url=http]Security updates located here[/url]
Last edited by Michaelo on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Kiss Portal Engine phpbbireland (status: Released)
User avatar
Michaelo
Administrator
Administrator
 
Posts: 1646
Likes: 0 post
Liked in: 0 post
Joined: Sat Mar 11, 2006 5:14 pm
Cash on hand: 0.00
Location: Dublin, Ireland

Previous

Return to Forum Security

Who is online

Registered users: Bing [Bot], Google [Bot], Majestic-12 [Bot]