Answer the question
In order to leave comments, you need to log in
How could the site be hacked?
Good afternoon!
Before the New Year, one of the experimental servers was hacked, during which a malicious script was injected into several files.
What we have:
- 3 sites were hacked (from under three different users), although there are several more sites in total. Motive?
- the files were purposefully changed via ftp (in the xferlog log, 12 files from three sites were downloaded and immediately uploaded)
Sat Dec 29 07:24:00 2012 0 ::ffff:188.72.248.226 117 [filename] a _ or [user1] ftp 0 * c
Sat Dec 29 07:24:00 2012 0 ::ffff:188.72.248.226 185 [ filename] a _ ir [user1] ftp 0 * c
Sat Dec 29 07:24:01 2012 0 ::ffff:188.72.248.226 253 [filename2] a _ or [user1] ftp 0 * c
Sat Dec 29 07:24: 01 2012 0 ::ffff:188.72.248.226 337 [filename2] a _ ir [user1] ftp 0 * c
Answer the question
In order to leave comments, you need to log in
Epic stories:
Someone with access to ftp caught a Trojan.
Someone who saved the authorization data in the ftp client leaked (for example, caught a Trojan again or shared Program Files on the network)
Once we were also hacked through proftpd, malicious scripts were introduced into the site. And they hacked not by brute force, we have complex passwords.
We switched to vsftpd, since then we have not broken it yet.
This is most likely an automated bot that infects websites via FTP. Logins-passwords are stolen by the Trojan.
This happened to me too today. Exactly the same modification of files.
A few days earlier, Windows 8 defender had removed the virus. Apparently just the same virus stole the passwords.
The passwords were stolen, not brute-forced. the hoster sent logs, there are only my failed login attempts.
Theoretically, after all, you can contact the police for such reasons? For the sake of sports interest, I wanted to write a statement. Purely to find out what they are doing in this case :)
Oh, and the hassle was with changing passwords on everything and everyone, damn it. Post offices, websites, banks, etc.
What version of Joomla are you using? Not so long ago, the site was hacked through a crooked applause in Joomla.
How many times have people been told, don't save passwords on ftp, don't save them, all trojans first of all climb and pick them out, no, they save them anyway. Well don't complain now.
Well, as always, passwords with a computer Trojan were stolen from someone, 99 percent of cases are like that.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question