Joomla! Discussion Forums



It is currently Wed Nov 25, 2009 4:39 pm (All times are UTC )

 




Post new topic Reply to topic  [ 8 posts ] 
Author Message
 Post subject: Hacker Site Found
Posted: Wed Jul 26, 2006 8:56 pm 
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 5:53 pm
Posts: 1513
Location: Washington D.C. & Baltimore, MD Metro
Hi all,

I have a question for the community, especially for those in the SECURITY know.

I was recently notified by my hosting provider about a hack to one of my sites and while reviewing the logs, I found a URL to a site where the hackers scripts are stored.

I'm not sure if this hacker is "using" this site to store/access his bag of tricks or if the site owner is the hacker.

Advice please?

TIA!
Roger

_________________
Thanks,
Roger

TECHNO PUZZLE: http://technopuzzle.com :: Putting the technology pieces together for you


Top
  E-mail  
 
 Post subject: Re: Hacker Site Found
Posted: Wed Jul 26, 2006 9:02 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Mar 30, 2006 3:48 am
Posts: 70
Location: Northern California
Could be both.  I found links similar to what you found.  The website linked to looked legitimate, but when I did more research I found out that it was not a real company and a cover for hacker attacks.

_________________
FlickrTab Pro for Community Builder
Multiple Random Image Module for Joomla!


Top
   
 
 Post subject: Re: Hacker Site Found
Posted: Wed Jul 26, 2006 9:08 pm 
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 5:53 pm
Posts: 1513
Location: Washington D.C. & Baltimore, MD Metro
If it is the hackers site, then what can be done about shutting it down? I've done a whois search for the domain and that didn't turn up any usefull info.

I don't want to notify the site owner that the site is being used for hacking, just in case it is the hackers site. Don't want to tip him/her/themo off.

_________________
Thanks,
Roger

TECHNO PUZZLE: http://technopuzzle.com :: Putting the technology pieces together for you


Top
  E-mail  
 
 Post subject: Re: Hacker Site Found
Posted: Wed Jul 26, 2006 9:15 pm 
User avatar
Joomla! Intern
Joomla! Intern
Offline

Joined: Thu Mar 30, 2006 3:48 am
Posts: 70
Location: Northern California
You may be able to notify the ISP or Hosting provider, but you will at least need to find that information from a whois or traceroute to the domain.

_________________
FlickrTab Pro for Community Builder
Multiple Random Image Module for Joomla!


Top
   
 
 Post subject: Re: Hacker Site Found
Posted: Thu Jul 27, 2006 1:37 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
Roger,

You need to get the IP address of the server.  This can be done a variety of ways, for example, open a dos prompt on Windows and do "ping http://www.site.com" and it will say something to the effect of pinging 10.10.1.184 or something like that.  Copy that sequence of numbers then go to www.arin.net.  On the right of that page there is an input box to "Search Whois".  This is different than a regular domain whois as it is a whois for IP addresses.  Paste the IP address into that box then click search.  Hopefully it isn't on a major network and it will just take you to a page that shows who is responsible for the IP block, usually an ISP or hosting company and it will show an Abuse contact.  Shoot them an email with all the info you have and the log files and hope they do their job.  If the IP is part of a big network it will say to search some other sites whois registry, go there, enter the IP again in their search box and then you should get the correct information for the abuse contacts.  Then do as before. 

Good luck.  Also, don't expect anything besides an automated reply.  They, including the company I work for, almost never respond as it is generally unnecessary once the problem has been rectified or violated their privacy policies. 

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
 Post subject: Re: Hacker Site Found
Posted: Thu Jul 27, 2006 4:26 am 
User avatar
Joomla! Guru
Joomla! Guru
Offline

Joined: Wed Aug 17, 2005 11:26 pm
Posts: 869
You need to be aware too that the host can only take action if the site is breaking their terms of contract. Cracking is not illegal in many parts of the world and even where it is there are often caveats (like, cracking a site is ok as long as there is no resultant financial damage over $xxxx), so many of these blackhats are able to operate perfectly legitimately.

Some of the sites operate in the "public interest" and have the explots documented "for information" with disclaimers that they are not responsible if the exploit code it taken and used maliciously.

Just thought I would point this out as some get very upset when a host/ISP does not appear to take action.  Many don't even send an automated responder to abuse reports, but that does not mean they do not check them out. There are hundreds of blackhat sites around and many of the crackers defacing Joomla sites are part of "security teams" whose sites provide public information to assist people in tightening up code.  For me, I just accept that cracking happens but I find it quite useful to be able to find exactly what was run to break in. Those that leave links to the exploit, or who give email addresses so they can be contacted, are often quite willing to help close the holes they found.

_________________
For Mambo assistance: http://forum.mambo-foundation.org
Open Source Research & Best Practice: http://osprojects.info


Top
  E-mail  
 
 Post subject: Re: Hacker Site Found
Posted: Thu Jul 27, 2006 11:52 pm 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Sun Aug 14, 2005 8:42 pm
Posts: 182
Location: Stadskanaal, The Netherlands
In my experiece, nobody cares about the facts and proves you have against hackers, crackers or script kiddies (raw access files, error logs, jaddah), unless your very big and can afford to sue. Reports  to official bureaus, agencies or abuse adresses will make you see that fighting them it totally useless.

Just backup the raw log files. They might come in handy some day.

_________________
Free templates: http://www.the-template-shack.com
Personal site: http://www.our-cats-n-dogs.com


Top
   
 
 Post subject: Re: Hacker Site Found
Posted: Fri Jul 28, 2006 9:33 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Mon Dec 05, 2005 10:17 am
Posts: 1318
Location: New Orleans, LA, USA
Trijnie wrote:
In my experiece, nobody cares about the facts and proves you have against hackers, crackers or script kiddies (raw access files, error logs, jaddah), unless your very big and can afford to sue. Reports  to official bureaus, agencies or abuse adresses will make you see that fighting them it totally useless.

Just backup the raw log files. They might come in handy some day.


I have to disagree.  Sure, there are some providers that don't care and probably do nothing but working at a service provider has taught me just how seriously some companies take these reports.  The company I work for actively fights hackers, scammers, spammers, etc. on a daily basis and we are glad to do it because we know that we are making the internet a little bit better for all of us.  However, if you know of a provider that does not work to stop these jokers I highly suggest you refuse to do business with them.  There are better companies out there that could use your support.

_________________
Rob Schley - Open Source Matters
Webimagery - http://www.webimagery.net/ - Professional Consulting Services
JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group