[Discuss] Another Hacking Alert
#1
Posted July 26 2009 - 09:19 AM
We'd just like to take this time to let you know that we advise you to change your passwords to something with 100% security (you know that little password strength checker in cPanel?)
Your best bet at a good password is using the generator with all characters set to 15+ characters, DaReaper told me he has set his to over 20 characters.
Be Safe! View the original post...
http://tyreus.com/irc.php
#4
Posted July 26 2009 - 03:56 PM
Kevin M - Tyreus.com Chief Executive
kevin@tyreus.com
-----
Visit my Blog at: http://blog.stupidpoodles.com/
#5
#6
Posted July 26 2009 - 07:59 PM
Trinity, on July 26 2009 - 08:10 PM, said:
How would you draw that conclusion from my statement?
It is true, though, that you should change your password on regular intervals.
Kevin M - Tyreus.com Chief Executive
kevin@tyreus.com
-----
Visit my Blog at: http://blog.stupidpoodles.com/
#7
Posted July 27 2009 - 03:44 AM
#8
Posted July 27 2009 - 01:10 PM
DaReaper, on July 27 2009 - 03:44 AM, said:
Well here's a little trick that some people use. Novice hackers usually try every port on a machine to see whether there's a bind behind it. The most easily targeted is either the httpd/web interface on 80 or the MySQL interface. A lot of people actually tends to forget to reset their root password for MySQL, and the default installation doesn't delegate authority back to the mysql user if you run it as a service. On top of that, the remote mysql-admin interface provides an environment execution method meaning they can pretty much do whatever they want on your node. Of course, this isn't likely either.
#9
Posted July 27 2009 - 02:53 PM
leegao, on July 27 2009 - 07:10 PM, said:
u're right but how can you change files on an ftp with a mysql exploit ?
#10
Posted July 27 2009 - 03:33 PM
leegao, on July 27 2009 - 02:10 PM, said:
With a MySQL exploit you could do some damage, but you can't (generally) just edit files.
Kevin M - Tyreus.com Chief Executive
kevin@tyreus.com
-----
Visit my Blog at: http://blog.stupidpoodles.com/
#11
Posted July 28 2009 - 05:29 AM
See this if you want to know more about what is Website defacement : http://en.wikipedia....site_defacement
Well he must have used an exploit to get into to Web server / http protocol at port 80 , since firewalls usually does not block this port for malicious content , since it is left open. Well i probably can tell that he must have been using an IIS hack which is not detected by the firewall .
He must have Found a vulnerability in WordPress which i was using , even though its the latest version . Probably i'll have to wait till the next version comes out
I guess Tyreus should build a multi layer protection system for the server .
1) The attack should be identified at the service request level, probably at the system call or API call invocation. At this stage, the request hasn't executed yet. This is the perfect time since changes to the page have not yet been made. An effective technique is to use system call and API call
2) Administrator (root) resistant—Most hackers first gain privileged rights and then try to deface the site. Therefore, it's good practice to restrict the privileges of the Administrator account on a
Web server machine. Instead of the 'Administrator' account, only a specific predefined user (the Web master) should be allowed to modify the Web site content and configuration. The system should enforce this rule and fail malicious use of the Administrator privileges. interception.
3) Application access control—It makes no sense for an arbitrary application such as a text editor to modify a Web page (even if the user has the adequate privileges).
#12
Posted July 28 2009 - 05:57 AM
You seem to be the only one that has had an issue with Dafacement on WordPress.
1) 2) and 3) -> Things known as Password Authorization, Access Privileges, Firewalls, IP Deny, Brute Force Lockout and much much more are the equivalent of what you said.
How's that for multi-layered protection system?
Again, there is nothing WE can do.

Sign In
Register
Help
This topic is locked
MultiQuote





/
-->