Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-28, 22:53:45

Author Topic: One of customer completely hacked  (Read 2194 times)

0 Members and 1 Guest are viewing this topic.

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
One of customer completely hacked
« on: 2015-04-17, 12:22:10 »
We have one customer which is non-stop hacked.

Usually these were just trojans sending SPAM, but today it got even worse.

Every folder on his account has an info.html file with normal user permissions:

Quote
-rw-r--r--  1 gatek89 gatek89   77 Apr 16 19:18 info.html

and such content:

Quote
<meta HTTP-EQUIV="REFRESH" content="0; url=http://grandscenter.ru/?tr=6475">

But on one domain all php were replaced with this redirection:

Quote
drwxr-xr-x  2 gatek89 gatek89 4.0K Apr 16 19:21 cgi-bin
drwxr-xr-x  2 gatek89 gatek89 4.0K Apr 16 19:21 images
-rw-r--r--  1 gatek89 gatek89  20K Feb 19 01:20 license.txt
-rw-r--r--  1 gatek89 gatek89  33K Mar 27 18:50 lottoland.jpg
-rw-r--r--  1 gatek89 gatek89   77 Apr 16 19:20 readme.html
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-activate.php
drwxr-xr-x  9 gatek89 gatek89 4.0K Apr 16 19:21 wp-admin
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-blog-header.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-comments-post.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-config.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-config-sample.php
drwxr-xr-x  7 gatek89 gatek89 4.0K Apr 16 19:21 wp-content
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-cron.php
drwxr-xr-x 12 gatek89 gatek89 4.0K Apr 16 19:21 wp-includes
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-links-opml.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-load.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-login.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-mail.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-settings.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-signup.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 wp-trackback.php
-rw-r--r--  1 gatek89 gatek89   68 Apr 16 19:20 xmlrpc.php

Example of file:

Quote
cat xmlrpc.php
<?php
header('Location: http://grandscenter.ru/?tr=6476');
exit;
?>

I've checked all passwords, all FTP logs and nothing...
« Last Edit: 2015-04-17, 12:24:32 by Spacedust »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: One of customer completely hacked
« Reply #1 on: 2015-04-17, 12:47:39 »
So. Banned your client.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
Re: One of customer completely hacked
« Reply #2 on: 2015-04-17, 15:05:24 »
Indonesian hackers ;( There was a file with credits...

 


MRatWork Affiliates:    BIGRAF(R) Inc.    House of LMAR    EFARgrafix

Page created in 0.076 seconds with 19 queries.

web stats analysis