Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Hacked twice in 2 days [Gallery 1.5] :: Archived


Hacked twice in 2 days [Gallery 1.5] :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2, 3  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
Ronin
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Jun 07, 2004
Posts: 475
Location: Calgary, AB
PostPosted: Thu Aug 23, 2007 7:24 pm
Post subject: Hacked twice in 2 days [Gallery 1.5]

Someone is modifying my index.php and tacking an encoded script at the bottom:
Code::
<{script removed}
Anyone know how to deduce anything from this? I've used some of the built in features to try and harden things up. I'm hoping its a stupid CPanel or WHM vulnerability on our dedicated server. Ironically we never use these things I do everything from command line or phpMyAdmin. This is on lunarpages which is about $130 a month for not that great of a machine. Sad

_________________
Cheers,

Ronin
Ronin Technologies
Dragonfly Google Maps Module

Ronin's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Lunarpages Linux / 1.3.37 / 4.1.22-standard-log / 4.4.4 / 9.1.2.5
Back to top
View user's profile Visit poster's website Photo Gallery
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Fri Aug 24, 2007 1:45 am
Post subject: Re: Hacked twice in 2 days

the script will load an iframe with src of
58.65.235.153/~pozitivu/ice/index.php?

you might try upgrading all your server software as well as DragonflyCMS with all DragonflyCMS and 3rd party modules and blocks installed.

I'll really think is an internal hacking attempt then a exploit on any php code, please check your ftp, ssh and apache logs.

http://dns-tools.domaintools.com/?q=58.65.235.153&m=dns wrote:

DNS Lookup For 58.65.235.153

;; Answer received from 216.145.1.3 (105 bytes)
;;
;; HEADER SECTION
;; id = 8170
;; qr = 1 opcode = QUERY aa = 0 tc = 0 rd = 1
;; ra = 1 ad = 0 cd = 0 rcode = NXDOMAIN
;; qdcount = 1 ancount = 0 nscount = 1 arcount = 0

;; QUESTION SECTION (1 record)
;; 153.235.65.58.in-addr.arpa. IN PTR

;; ANSWER SECTION (0 records)

;; AUTHORITY SECTION (1 record)
235.65.58.in-addr.arpa. 10714 IN SOA ns1.hostfresh.com. us1core.hostfresh.com. (
2006101301 ; Serial
7200 ; Refresh
7200 ; Retry
1209600 ; Expire
86400 ) ; Minimum TTL

;; ADDITIONAL SECTION (0 records)

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
Ronin
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Jun 07, 2004
Posts: 475
Location: Calgary, AB
PostPosted: Fri Aug 24, 2007 2:24 pm
Post subject: Re: Hacked twice in 2 days

Sorry, my footer was out of date. I'm actually running 9.1.2.5 CVS on it. We'll definitely be upgrading other stuff ASAP.

_________________
Cheers,

Ronin
Ronin Technologies
Dragonfly Google Maps Module

Ronin's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Lunarpages Linux / 1.3.37 / 4.1.22-standard-log / 4.4.4 / 9.1.2.5
Back to top
View user's profile Visit poster's website Photo Gallery
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Fri Aug 24, 2007 3:01 pm
Post subject: Re: Hacked twice in 2 days

Don't forget to check your logs as well, logs might tell you what happened.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Mon Aug 27, 2007 2:44 pm
Post subject: Re: Hacked twice in 2 days

Unfortunately this is a javascript issue. The script is obsfucated and likely generated on the fly.

A complete review of how this code was XSS'd to your index.php is required to understand "IF" an exploit was used. Your browser could be adding this...

At this point I'd state that anyone with MSF or w3af could do this.

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Sun Sep 30, 2007 10:20 pm
Post subject: Re: Hacked twice in 2 days

Just suffered the same hack myself... again ;( This seems to happen to me every other month now. It has happened on previous versions of CPG and now even with the latest version. This has only happened to CPG.

I tried to look up any evidence in my logs... but unfortunately... they hit the site only an hour before it rotated and the info I needed was deleted.

I have logged into my cpanel and checked the options to archive these logs now and hoping maybe I can capture what they are doing (even tho I will prolly not understand it).

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Mon Oct 01, 2007 5:13 pm
Post subject: Re: Hacked twice in 2 days

scoopy, are you concerned about this?

Sorry to be so bold and brazen in my question but I really don't understand your post. You say this has happened to you but you do nothing about it.

If I was getting hacked every other month I'd be looking into it seriously. I would not allow my logs to be deleted. You should review how to deal with hackers/attackers before questioning getting hacked.

Many folks have liked this article and it may help you:

www.dragonflycms.org/F...=2864.html

In your case I don't know what to suggest other than wiping the site and starting from scratch. Ensure you know the extra's your adding in or installing are secure.

Audit your web host also, make sure they are not the ones getting hacked and they are simply modifying your existing pages so as to spread more malware.

Recent studies in malware shows MANY 'so called trusted' sites such as the recent Bank of India incident, are harboring malware. Using obsfucated javascript 'ensures' that the code is not detected easily by any anti-virus or anti-malware.

Performing frequent code audits can help detect and clean these types of issues from persisting. (Simply download your site then compare it against a fresh copy of the code or your backup)

So what would you like to do?

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Tue Oct 02, 2007 1:04 am
Post subject: Re: Hacked twice in 2 days

Sorry, every other month was an exaggeration (for this site alone).

I looked up the record created by the server's "error_log" file. (this is created because the script being added produces a parse/syntax error) The last time this "hack" occurred was about 5 months ago. Also, the logs have not been deleted. I had the option to save them deselected in cPanel... thus they were not being saved and were rotated on a daily basis.

I upgraded to version 9.1.2.1 after that and that was the last of this hack... or so I thought, until yesterday. Since then... it has happened 3 more times today.

Each time the same error shows up on the site:
Code::
Parse error: syntax error, unexpected '<' in /home/smyp/public_html/index.php on line 133
which provides me with the approximate time of the event.

I scoured the logs (raw, awstats, and webalizer) and the latest visitors log... but can not find any signs of any hacking attempts to account for this code being added to the index page. For example... the popular:
Code::
themes/coppercop/theme.php?THEME_DIR=http://www.tripod.com/bypassid.txt?
which has since been secured up... now only produces nothing except a 404 error.

I also have noted a lot of the following showing up:
Code::
http://showmeyourpix.com/coppermine/addfav/db_input.php
which also produces a 404 error.

Everything else seems to be either genuine visitors or SE traffic.

And I really doubt this has anything to do with the host. Their security is pretty tight... running things like phpsuexec and having user nobody disabled, etc. Plus, I would think their would be more than 1 case like this with them if their was a security problem on their end.

I am not sure where to go at this point to figure out how this is being done... so I can close this hole for good.

thanks,

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Tue Oct 02, 2007 8:20 pm
Post subject: Re: Hacked twice in 2 days

scoopy wrote:
Sorry, every other month was an exaggeration (for this site alone).

Lets try to avoid exaggerations...it will haunt you.

Quote::
I looked up the record created by the server's "error_log" file. (this is created because the script being added produces a parse/syntax error) The last time this "hack"

Can you define the 'hack'? I haven't seen anything except what you've posted below, and I'll come to that in a minute.

Quote::
occurred was about 5 months ago.

Wow! So really we don't know anything relevent about the event since it's so old. Let's stick to current events then.

Quote::
Also, the logs have not been deleted. I had the option to save them deselected in cPanel... thus they were not being saved and were rotated on a daily basis.

So you still have all the logs and everything since always?

Quote::
I upgraded to version 9.1.2.1 after that and that was the last of this hack... or so I thought, until yesterday. Since then... it has happened 3 more times today.

Lets see the attacks...c'mon. We've seen them all... Smile

Quote::
Each time the same error shows up on the site:
Code::
Parse error: syntax error, unexpected '<' in /home/smyp/public_html/index.php on line 133
which provides me with the approximate time of the event.

Ok, but this is not legit. You should not get a parse error on this page. Can you provide details of this and ensure it has not been modified? it would seem to me it has been. According to my copy of this file which for the record is:

$Source: /cvs/html/index.php,v $

$Revision: 9.31 $
$Author: nanocaiordo $
$Date: 2006/11/11 03:12:21 $

And my line 133 is the last line in the file and contains nothing.


Quote::
I scoured the logs (raw, awstats, and webalizer) and the latest visitors log... but can not find any signs of any hacking attempts to account for this code being added to the index page.

Again, this is illegit. You have a typo in your script. If you'd be so kind as to post the entire index.php file of yours here.

Quote::
For example... the popular:
Code::
themes/coppercop/theme.php?THEME_DIR=http://www.tripod.com/bypassid.txt?
which has since been secured up... now only produces nothing except a 404 error.

As it should.

Quote::
I also have noted a lot of the following showing up:
Code::
http://showmeyourpix.com/coppermine/addfav/db_input.php
which also produces a 404 error.

This I'm not following. Where do you see this? Can you provide the exact entry you're seeing?

Quote::
Everything else seems to be either genuine visitors or SE traffic.

And I really doubt this has anything to do with the host. Their security is pretty tight... running things like phpsuexec and having user nobody disabled, etc. Plus, I would think their would be more than 1 case like this with them if their was a security problem on their end.

Sorry this means nothing to me. Nobody is 100% secure. But I'd tend to agree with you unless they user cpanel or plesk. But I will not go into details on these products.

Quote::
I am not sure where to go at this point to figure out how this is being done... so I can close this hole for good.

Some simple things for starters. Do not allow uploading anywhere. Disable HTML email. Remove any themes that have not been given a good reference. Remove any code that pulls data from other sites that has not been cleaned properly.

As for more specifics unfortunately we need details. You have not disclosed anything known or unknown that could be considered an issue, let alone a 'hole'. Perhaps someone else may see something I've missed but we need to get the specifics from you that seem to be causing the problem.

A decent incident report would be a good start.

thanks

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Tue Oct 02, 2007 9:09 pm
Post subject: Re: Hacked twice in 2 days

I thought the OP had defined the results of this "hack" pretty clearly. I have been trying to figure out how someone is able to add code to my index file and thus fix the problem... as I am sure that was the same intention of the OP.

Yes... I still have the "error_log" and No... to any previous HTTP logs. Someone has again somehow modified my index file today and I found the same <script> added to the bottom of the index.

Line 133 was where this HTML code was added by the "script kiddy" which is what breaks the PHP code and produces the error message... instead of the IFRAME or redirection they had intended. The error is then logged and that is what gives me an approx. time of the "hack".

Anyway... I think I may have guessed what me and the OP had in common that could be the reason we both had this same problem and will upgrade that module we both are running on our sites.

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Wed Oct 03, 2007 10:38 pm
Post subject: Re: Hacked twice in 2 days

Guess it was not that module I updated yesterday... they did it again tonight.

So with everything updated and nothing showing in the logs --- where do I go from here ?

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Thu Oct 04, 2007 12:48 am
Post subject: Re: Hacked twice in 2 days

I bet that you and your admins are still using the same password.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Thu Oct 04, 2007 1:30 am
Post subject: Re: Hacked twice in 2 days

NanoCaiordo wrote:
I bet that you and your admins are still using the same password.
If so... wouldn't that leave something in the visitors log that would look like this:
Code::
127.0.0.1 - - [04/Oct/2007:01:21:29 +0000] "GET /admin.php HTTP/1.1" 403 3780 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.7) Gecko/20070914 Firefox/2.0.0.7"
There was nothing like that in today's log.

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Thu Oct 04, 2007 2:09 am
Post subject: Re: Hacked twice in 2 days

They usually get the password of the 1st created admin, and as far i know lot of people use the same password for ftp, pop etc etc.

What I'll suggest you to do is to change all your passwords (df, ftp, ....) again.

See how it goes.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
scoopy
Newbie
Newbie

Offline Offline
Joined: Mar 19, 2005
Posts: 13
Location: /home
PostPosted: Thu Oct 04, 2007 2:28 am
Post subject: Re: Hacked twice in 2 days

OK... have changed all cPanel and DF admin passwords (BTW: just me)... and even the mySQL username and password. I used 3 different passwords too.

Will keep ya' all posted.

_________________
Wanna Play A Game ? | Jazz it up @ the JazzArcade | A Splash of FUN @ the Arcade Splash

scoopy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
nix/1.3.37/5.0.27/5.2.1/9something
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 3
All times are GMT
Go to page 1, 2, 3  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

Aiheesta Lisää...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy