| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
RottGutt Heavy poster


Offline Joined: Feb 24, 2005 Posts: 281 Location: Colorado Springs, CO
|
Posted: Mon Sep 04, 2006 11:25 pm Post subject: Hacked! |
|
I don't know what else to say about this. There was NO transfer of information to any outside party. When I logged onto my WoW site tonight I got this:
So much for CPG-Nuke being secure!
RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
|
|
| Back to top |
|
 |
NEMINI Diamond Supporter


Offline Joined: Apr 22, 2004 Posts: 4551
|
Posted: Mon Sep 04, 2006 11:43 pm Post subject: Re: Hacked! |
|
do you have ANY prrof that it was through cpgnuke that you got hacked? Just because you run cpgnuke and got hacked does not make it cpgnukes fault.
_________________ NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org
NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) 1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
|
|
| Back to top |
|
 |
RottGutt Heavy poster


Offline Joined: Feb 24, 2005 Posts: 281 Location: Colorado Springs, CO
|
Posted: Mon Sep 04, 2006 11:49 pm Post subject: Re: Hacked! |
|
| NEMINI wrote: |
| do you have ANY prrof that it was through cpgnuke that you got hacked? Just because you run cpgnuke and got hacked does not make it cpgnukes fault. |
I don't exactly know how to prove it. I have the site's raw access logs that I will go through. The only access to the site was through the Internet, nobody has accessed it through FTP or any other method in 3 weeks. I believe that in this case that we need to consider CPG-Nuke unsecure to some new access method until it is deemed not true. Unfortunately, I do not have the knowledge on what exactly to do to trace the source of the hack. I have changed the domain's password, erased my public_html folder, and will be re-installing CPG-Nuke tonight. We shall see what happens...
RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
|
|
| Back to top |
|
 |
NEMINI Diamond Supporter


Offline Joined: Apr 22, 2004 Posts: 4551
|
Posted: Mon Sep 04, 2006 11:50 pm Post subject: Re: Hacked! |
|
you on a shared box? dedicated? self run?
_________________ NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org
NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) 1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
|
|
| Back to top |
|
 |
RottGutt Heavy poster


Offline Joined: Feb 24, 2005 Posts: 281 Location: Colorado Springs, CO
|
Posted: Mon Sep 04, 2006 11:58 pm Post subject: Re: Hacked! |
|
| NEMINI wrote: |
| you on a shared box? dedicated? self run? |
Shared box on LunarPages.com. I have already submitted a trouble ticket asking them to trace the source of the attack and press charges. I have also asked them to do a restore of the site with their latest backup.
RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
|
|
| Back to top |
|
 |
NEMINI Diamond Supporter


Offline Joined: Apr 22, 2004 Posts: 4551
|
Posted: Tue Sep 05, 2006 12:02 am Post subject: Re: Hacked! |
|
it's at least as possible someone else on the same server could have been compromised leading to you being hacked as cpgnuke being responsible.
Until more is known anything is possible.
PS: did you patch the known search exploit?
_________________ NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org
NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) 1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
|
|
| Back to top |
|
 |
masterbeta Translator


Offline Joined: May 12, 2004 Posts: 1049 Location: Reading, PA
|
Posted: Tue Sep 05, 2006 12:04 am Post subject: Re: Hacked! |
|
sounds as if lunarpages' server was hacked - not specifically cpg-nuke as your target.
_________________ []D [] []\/[] []D
Check out my bear site - www.insidebear.com
masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
|
|
| Back to top |
|
 |
RottGutt Heavy poster


Offline Joined: Feb 24, 2005 Posts: 281 Location: Colorado Springs, CO
|
Posted: Tue Sep 05, 2006 12:41 am Post subject: Re: Hacked! |
|
| NEMINI wrote: |
it's at least as possible someone else on the same server could have been compromised leading to you being hacked as cpgnuke being responsible.
Until more is known anything is possible.
PS: did you patch the known search exploit? |
That is true. I would hope that they would honest enough to say if that was actually what happened. I will keep ya'll informed as I get new information. Yes, not only did I patch the known search exploit, but I also had all search features turned off on the site.
RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
|
|
| Back to top |
|
 |
Dizfunkshunal Platinum Supporter


Offline Joined: Mar 23, 2006 Posts: 2064
|
Posted: Tue Sep 05, 2006 1:59 am Post subject: Re: Hacked! |
|
it wasnt DF the hacker gained access to. theres no way the could change the entire page that way unless they had server access
_________________ Diz Web Design Status: Open (Use of resources requires registration.)
Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Multiple Setups
|
|
| Back to top |
|
 |
alva 1000+ Posts Club


Offline Joined: May 31, 2005 Posts: 1150 Location: The Netherlands
|
Posted: Tue Sep 05, 2006 12:08 pm Post subject: Re: Hacked! |
|
| RottGutt wrote: |
| Yes, not only did I patch the known search exploit, but I also had all search features turned off on the site. |
How about the other official 9.0.6.1 security patches? (Those are more important than the Search thingy as far as I know.)
alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache/5.0.24/5/9.1 CVS
|
|
| Back to top |
|
 |
RedRincon650 Nice poster


Offline Joined: Mar 09, 2006 Posts: 118 Location: Winnipeg Manitoba
|
Posted: Tue Sep 05, 2006 5:32 pm Post subject: Re: Hacked! |
|
You might find th is to be of some interest...
www.stokia.com/news/is...k-info.htm
RedRincon650's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache-2/MySQL-4/PHP-4/CMS-9.1RC2
|
|
| Back to top |
|
 |
djdevon3 Gold Supporter


Offline Joined: Aug 05, 2004 Posts: 4363
|
Posted: Tue Sep 05, 2006 5:43 pm Post subject: Re: Hacked! |
|
That is either the answer or someone using that issue as a coverup. Is lunarpages by chance a subsidiary of godaddy?
djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.33/4.4/4.3.11
|
|
| Back to top |
|
 |
Jordo Newbie


Offline Joined: Jan 31, 2005 Posts: 27
|
Posted: Tue Sep 05, 2006 6:56 pm Post subject: Re: Hacked! |
|
| djdevon3 wrote: |
| That is either the answer or someone using that issue as a coverup. Is lunarpages by chance a subsidiary of godaddy? |
No, but some people keep godaddy as their registrar, even if they host their sites somewhere else.
_________________ Jordo
www.jordomedia.com
Jordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.33/4.0.22/4.3.10/9.0.3
|
|
| Back to top |
|
 |
djdevon3 Gold Supporter


Offline Joined: Aug 05, 2004 Posts: 4363
|
Posted: Tue Sep 05, 2006 7:41 pm Post subject: Re: Hacked! |
|
Having godaddy as your registrar means nothing. The registrar was not hacked godaddy hosting was which is a seperate entity/system.
djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.33/4.4/4.3.11
|
|
| Back to top |
|
 |
Jordo Newbie


Offline Joined: Jan 31, 2005 Posts: 27
|
Posted: Tue Sep 05, 2006 8:06 pm Post subject: Re: Hacked! |
|
| djdevon3 wrote: |
| Having godaddy as your registrar means nothing. The registrar was not hacked godaddy hosting was which is a seperate entity/system. |
According to the article posted here, they were validating it by looking at the registrar. They are assuming that if the registrar is godaddy, then the site is hosted there. This isn't true and a bad assumption.
BUT, I haven't looked at any other articles to find a better written article.
<Edited to add the below>
And rereading the article, they are blaming it on an email script at Godaddy, So I went to the Lunarpages forum, and there's a thread there where multiple sites have been hacked.
Rottgutt,
If you haven't gotten a hold of lunarpages support, go to their forums, to find out the latest.
_________________ Jordo
www.jordomedia.com
Jordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.33/4.0.22/4.3.10/9.0.3
|
|
| Back to top |
|
 |
|
|