D
D
Denis2013-01-05 14:50:31
PHP
Denis, 2013-01-05 14:50:31

How could the site be hacked?

Good afternoon!

Before the New Year, one of the experimental servers was hacked, during which a malicious script was injected into several files.

What we have:

- 3 sites were hacked (from under three different users), although there are several more sites in total. Motive?
- the files were purposefully changed via ftp (in the xferlog log, 12 files from three sites were downloaded and immediately uploaded)

Sat Dec 29 07:24:00 2012 0 ::ffff:188.72.248.226 117 [filename] a _ or [user1] ftp 0 * c
Sat Dec 29 07:24:00 2012 0 ::ffff:188.72.248.226 185 [ filename] a _ ir [user1] ftp 0 * c
Sat Dec 29 07:24:01 2012 0 ::ffff:188.72.248.226 253 [filename2] a _ or [user1] ftp 0 * c
Sat Dec 29 07:24: 01 2012 0 ::ffff:188.72.248.226 337 [filename2] a _ ir [user1] ftp 0 * c

- login via ssh is prohibited in the system

What I would like to know:
- how did the hacking happen - was it a password brute force attack?
- is it possible to see the authorization history via ftp on the standard proftpd settings? auth.log is silent

Answer the question

In order to leave comments, you need to log in

10 answer(s)
V
Valery Selitsky, 2013-01-05
@WaveCut

Epic stories:
Someone with access to ftp caught a Trojan.
Someone who saved the authorization data in the ftp client leaked (for example, caught a Trojan again or shared Program Files on the network)

I
IStudio, 2013-01-06
@IStudio

Is there an option to disable ftp forever and always use ssh?

A
avgaltsev, 2013-01-05
@avgaltsev

Once we were also hacked through proftpd, malicious scripts were introduced into the site. And they hacked not by brute force, we have complex passwords.
We switched to vsftpd, since then we have not broken it yet.

H
howeal, 2013-01-05
@howeal

This is most likely an automated bot that infects websites via FTP. Logins-passwords are stolen by the Trojan.

H
heresik, 2013-01-16
@heresik

This happened to me too today. Exactly the same modification of files.
A few days earlier, Windows 8 defender had removed the virus. Apparently just the same virus stole the passwords.
The passwords were stolen, not brute-forced. the hoster sent logs, there are only my failed login attempts.
Theoretically, after all, you can contact the police for such reasons? For the sake of sports interest, I wanted to write a statement. Purely to find out what they are doing in this case :)
Oh, and the hassle was with changing passwords on everything and everyone, damn it. Post offices, websites, banks, etc.

M
Michael, 2013-01-05
@1099511627776

Are the sites using Basic HTTP Authorization?

S
startsevdenis, 2013-01-05
@startsevdenis

What version of Joomla are you using? Not so long ago, the site was hacked through a crooked applause in Joomla.

E
egorinsk, 2013-01-06
@egorinsk

How many times have people been told, don't save passwords on ftp, don't save them, all trojans first of all climb and pick them out, no, they save them anyway. Well don't complain now.

P
Puma Thailand, 2013-01-07
@opium

Well, as always, passwords with a computer Trojan were stolen from someone, 99 percent of cases are like that.

G
g00dv1n, 2016-04-15
@g00dv1n

The guys from exploit.in probably did their best. (joke).
Most likely they stole passwords from the computer, of course.
But sometimes it just happens that a vulnerable version of FTP is worth it. You can check here https://www.exploit-db.com/

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question