Kryptronic Software Support Forum

You are viewing this forum as a guest. Login to an existing account, or create a new account, to reply to topics and to create new topics.

#1 08-02-2005 21:36:22

HDLLC
Member
Registered: 09-04-2004
Posts: 20

Hacked!

Hi-

My CCP store was hacked today - the index and default.html files were replaced and scripts were running on them...  Any ideas as to how I can protect from this?  I had the pro install from this site.  Need to assure a client that this is corrected.

Thanks in advance for any help  you can provide.  Also - I can post the text of the script and am working with my ISP to see if the action was trace-able.

--Jeff

Offline

 

#2 08-04-2005 04:24:23

Steven
Member
Registered: 04-21-2004
Posts: 84

Re: Hacked!

Hello,

Unfortunately there is too little information for us to start with.  We can consider all sorts of things but none of these are going to be helpful to you unless we get more information.

It's in everyone's best interests to find out, so we can all patch ourselves if nescessary.

I'm not sure what the pro-install consists of, but perhaps it was a simple thing like htaccess rules or other software installed on the server that gives directory access.  It's even possible that someone simply gained access by FTP or shell account.

Your webhost should be able to supply you with access logs.  Your ISP aren't going to be extremely helpful in this case.  Popular opensource programs such as Webalizer and Awstats are configured on all good servers. (send me a private msg if you are in the market for a very good webhost and need a recommended referral)

These logs can determine the date and time of abuse, logging the ip address, protocol and port numbers of the offender.  Once you have _this_ information, then you proceed through your ISP.  However realistically it's not a too greater offense IMHO to spark that kind of response from authorities.
 

Offline

 

#3 08-04-2005 08:34:59

TerryA
Member
From: Sanford, Fl
Registered: 07-14-2003
Posts: 1322
Website

Re: Hacked!


As a first line of defense against this, I would make sure that the directory that stores your data and media is password protected.

Offline

 

#4 08-22-2005 10:13:57

webmaster
Administrator
From: York, PA
Registered: 04-20-2001
Posts: 19871
Website

Re: Hacked!

Any changes to your root index.html/default.html pages would have had to been made via FTP or a hack via the web based on exploiting your server's security.  I've seen this happen quite a bit on Microsoft IIS servers where by default anonymous FTP is turned on.

CCP can not be the source of the break in as it does not have access to anything outside it's own directory structure.


Nick Hendler

Offline

 

Board footer