| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 6:25 pm Post subject: Server hacked |
|
Showing up in my members online was a "blank" user. All registered users have names and my host confirmed this person logged in as Anonymous.
I've changed my $prefix & $user_prefix but not sure if this will stop them from getting in again?
They were running some sort of external script that pretty much crashed my server for a while. My host said "was like someone was trying to run some script on it and used up ALL the server's memory several times over...like a hundred times"
Is there anything else I can do to stop this?
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
NEMINI Diamond Supporter


Offline Joined: Apr 22, 2004 Posts: 4551
|
Posted: Tue Nov 08, 2005 6:38 pm Post subject: Re: hacker logged in as Anonymous |
|
a blank user does not necessarily mean a hacker ... its been discussed many a time ... its a sessions issue.
_________________ NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org
NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) 1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 6:52 pm Post subject: Re: hacker logged in as Anonymous |
|
Ok, I can agree to that, however when my host see's that our server is pretty much done for due to a script being run through/out of my portal and there's an blank user showing up in the members list and my stats tell me there's been over 900 MB of something going on by an "other/anonymous" login.. kinda makes me wonder
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
NEMINI Diamond Supporter


Offline Joined: Apr 22, 2004 Posts: 4551
|
Posted: Tue Nov 08, 2005 6:54 pm Post subject: Re: hacker logged in as Anonymous |
|
check your server logs to see who that latest visitors are and run the IP's and see if they turn up anything interesting.
_________________ NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org
NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) 1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 7:13 pm Post subject: Re: hacker logged in as Anonymous |
|
Found the culprit in Macedonia - DDOS attack used my site as server entry point to put a script (udp.pl) on the server. Filter is in place to stop that particular script again.
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
dormouse Newbie


Offline Joined: Aug 31, 2005 Posts: 37
|
Posted: Tue Nov 08, 2005 10:43 pm Post subject: Re: hacker logged in as Anonymous |
|
Is this a Dragonfly issue?
dormouse's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.39/4.1.22/4.4.7/9.2.0
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 10:53 pm Post subject: Re: hacker logged in as Anonymous |
|
It was my dragonfly issue only due to the fact that I wasn't aware that I needed to change the $prefix & $user_prefix during install until I started searching through security info around here today. So now I'm trying to work out problems after changing those.
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Tue Nov 08, 2005 10:59 pm Post subject: Re: hacker logged in as Anonymous |
|
Doesn't make sense - DDOS shouldn't get your site hacked, just severely slowed down. They can't even brute force your admin password unless they guess it within 5 attempts.
It does depend on what non-core Dragonfly "add-ons" you have.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Śyama_Dāsa Developer


Offline Joined: Apr 19, 2004 Posts: 2048 Location: Dragonfly CMS Tribe
|
Posted: Tue Nov 08, 2005 11:17 pm Post subject: Re: hacker logged in as Anonymous |
|
and what file did they find that udp.pl had been uploaded by?
have you seen this
_________________ AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM
Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 11:19 pm Post subject: Re: hacker logged in as Anonymous |
|
I hear what you're saying Phoenix, and I agree.. there didn't seem to be any damage done to my site. The problem being that the guy entered through my site - used my site as his doorway to the server.
Biggest question is where did he get in. Which is what brought me back here looking for security info and me coming across the $prefix changes.
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Tue Nov 08, 2005 11:26 pm Post subject: Re: Server hacked |
|
It is just plain absurd - Anonymous cannot login, regardless of what you or your host may think.
"Our records do not indicate an existing user named Anonymous"
And a blank user gives you this,
"Our records do not indicate an existing user named"
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 11:39 pm Post subject: Re: Server hacked |
|
well.. I'm just saying what the server logs reported Phoenix, not out to start anything. I'm just trying to find out how to lock my site down or at least make it a whole lot harder for anyone to gain unauthorized entry.
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Tue Nov 08, 2005 11:42 pm Post subject: Re: Server hacked |
|
Then perhaps you better read what Akamu posted and chase that up because that is the more likely cause.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
snowflake Newbie


Offline Joined: Jul 30, 2005 Posts: 29
|
Posted: Tue Nov 08, 2005 11:52 pm Post subject: Re: Server hacked |
|
sure thing
snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
|
|
| Back to top |
|
 |
Wide Platinum Supporter


Offline Joined: Aug 07, 2004 Posts: 294 Location: Playa Del Rey, CA
|
Posted: Wed Nov 09, 2005 5:10 pm Post subject: Re: Server hacked |
|
| Phoenix wrote: |
| Then perhaps you better read what Akamu posted and chase that up because that is the more likely cause. |
Thats most likely the cause
There have been two (2) scripts going around targeting php vulnerabilites.
Yours has the tell tale signs of one of them.
Not a Dragonfly issue in my opinion
Wide's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Debian/Apache2/MySQL 4.1.15-Debian/PHP4 4.4.2-1build1/9.1.1
|
|
| Back to top |
|
 |
|
|