Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 24
  1. #1
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default Website Hacked

    Hi guy's, first post here.....let me start by saying I know nothing about website stuff but today Friday 13th I find my website has been hacked. I can't log in to cpanel or email.
    My website is:
    www.takingthepic.com
    I'd really appreciate any help or advice please.
    I did a search for hacked sites in this forum but being honest I don't understand any of the terminoligy.
    I have emailed and sent support request to Darken host (my provider) but as yet have had no response.
    Please help.
    TIA.
    Ken.

  2. #2
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Contact me by private message and I will give you a hand with this issue ...

    The DNS server for your domain does resolve but is very poorly configured
    http://www.dnsreport.com/tools/dnsre...kingthepic.com

    If I direct connect to the assigned IP of your shared hosting account,
    http://69.72.144.50/, I get the default Cpanel page which tells me
    the Apache server where your account is located is in fact working.

    The following is the raw connection info for your web site ...
    Code:
    Trying 69.72.144.50...
    Connected to takingthepic.com (69.72.144.50).
    Escape character is '^]'.
    GET http://www.takingthepic.com/
    <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
    <HTML><HEAD>
    <TITLE>302 Found</TITLE>
    </HEAD><BODY>
    <H1>Found</H1>
    The document has moved <A HREF="http://server227.server-center.net/suspended.page/">here</A>.<P>
    <HR>
    <ADDRESS>Apache/1.3.37 Server at www.takingthepic.com Port 80</ADDRESS>
    </BODY></HTML>
    Connection closed by foreign host.
    As you can see, it's attempting to redirect you to some suspended page that doesn't exist
    whenever you connect to your website which explains why your cpanel login doesn't work ...

    YOUR ACCOUNT HAS BEEN SUSPENDED

    The question is whether the suspension was for you or for your provider. If your provider
    is just a reseller, their provider above them may have suspended their entire reseller
    account including all account beneath them (including yours).
    Last edited by Spiral; 07-13-2007 at 06:27 AM.

  3. #3
    Member nyjimbo's Avatar
    Join Date
    Jan 2003
    Location
    New York
    Posts
    1,105

    Default

    Quote Originally Posted by KenCo View Post
    Hi guy's, first post here.....let me start by saying I know nothing about website stuff but today Friday 13th I find my website has been hacked. I can't log in to cpanel or email.
    My website is:
    www.takingthepic.com
    I'd really appreciate any help or advice please.
    I did a search for hacked sites in this forum but being honest I don't understand any of the terminoligy.
    I have emailed and sent support request to Darken host (my provider) but as yet have had no response.
    Please help.
    TIA.
    Ken.
    The most important thing here is to determine if your account was hacked OR the whole server was hacked. If its just you then it would likely be an exploitable script like a forum or php code, but if its the whole server then it could be the host had an exploitable kernel or some server task. I would keep trying to reach your host first so they can determine what level this attack took place.
    "A dog has raised it’s hind leg on the age of nevermore !"
    -- Rolf

  4. #4
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Quote Originally Posted by nyjimbo View Post
    The most important thing here is to determine if your account was hacked OR the whole server was hacked. If its just you then it would likely be an exploitable script like a forum or php code, but if its the whole server then it could be the host had an exploitable kernel or some server task. I would keep trying to reach your host first so they can determine what level this attack took place.
    Thank mate.....I still have had no response from support slips or emails as yet. I do know someone else who uses them and his website is working fine. Sorry if that doesn't mean anything, like I say I know nothing.
    Ken.

  5. #5
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    I have done some digging and have confirmed that your host is actually a reseller
    and not a real hosting provider and it would appear that their own reseller
    account has also been suspended as well.

    That said, it also looks like they have multiple reseller accounts with different
    providers and probably split their hosted accounts between those accounts.

    While some of their sites are up, the one located where you are hosted
    is down just the same as your own account which tells me their provider
    at that location has shut them down either for abuse or non-payment.
    Last edited by Spiral; 07-13-2007 at 07:20 AM.

  6. #6
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Quote Originally Posted by Spiral View Post
    I have done some digging and have confirmed that your host is actually a reseller
    and not a real hosting provider and it would appear that their own reseller
    account has also been suspended as well.
    Well that would account for no response from them as yet BUT not for the porn stuff on my site now.

  7. #7
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Quote Originally Posted by KenCo View Post
    Well that would account for no response from them as yet BUT not for the porn stuff on my site now.
    What do you mean "porn stuff"?

    I have not been able to duplicate any of that and all I get is just
    the attempt to redirect to the non-existent suspended page
    from their upstream provider

    Do you have a full backup of your site?

  8. #8
    Member nyjimbo's Avatar
    Join Date
    Jan 2003
    Location
    New York
    Posts
    1,105

    Default

    Quote Originally Posted by KenCo View Post
    Thank mate.....I still have had no response from support slips or emails as yet. I do know someone else who uses them and his website is working fine. Sorry if that doesn't mean anything, like I say I know nothing.
    Ken.
    Seems an old thread on webhostingtalk.com got revived and there is some bad press about this host as recent as last week:

    http://www.webhostingtalk.com/showthread.php?t=582651
    "A dog has raised it’s hind leg on the age of nevermore !"
    -- Rolf

  9. #9
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Quote Originally Posted by Spiral View Post
    What do you mean "porn stuff"?

    I have not been able to duplicate any of that and all I get is just
    the attempt to redirect to the non-existent suspended page
    from their upstream provider

    Do you have a full backup of your site?
    I have all the stuff needed to replace my site but can't get into my site....If you force refresh (CTRL and F5) it sometimes takes you to some porn promotion thing.....

  10. #10
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Quote Originally Posted by KenCo View Post
    I have all the stuff needed to replace my site but can't get into my site....If you force refresh (CTRL and F5) it sometimes takes you to some porn promotion thing.....
    I think that one is actually coming from your own computer
    and is a separate unrelated item ...

    You might want to do a complete spyware / trojan scan.

  11. #11
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Quote Originally Posted by Spiral View Post
    I think that one is actually coming from your own computer
    and is a separate unrelated item ...

    You might want to do a complete spyware / trojan scan.
    I have already took those steps just incase using avg and trend micro on-line scan.....I don't get any reports of infection.

  12. #12
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Another photographer is also using Darken host www.dreederuk.com/ and his website is still working. Does that make any sense.

  13. #13
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Quote Originally Posted by KenCo View Post
    Another photographer is also using Darken host www.dreederuk.com/ and his website is still working. Does that make any sense.
    He's off of a different reseller account.

    It looks like for each reseller account, Darken Host setup
    corresponding DNS server addresses with the same base
    name but a different TLD.

    You are hosted out of their reseller account associated
    with the .ORG domain extension

    Dreederuk.com is host out the reseller account associated
    with the .NET domain extension

    (Traces to 2 different sources)

    I have already took those steps just incase using avg and trend micro on-line scan.....I don't get any reports of infection.
    That is virus scanning. I said trojan and spyware!

    The best scanner for that is "PC Doctor" which catches many that others
    won't come close to detecting but is a commercial product.

    The next best choice is "SpyBot:Search and Destroy" which runs circles
    around all the spyware scanners out there except "PC Doctor" and
    is conveniently a free downloadable program.

  14. #14
    Member koolcards's Avatar
    Join Date
    Oct 2003
    Location
    Tampa, Fl
    Posts
    146

    Default

    https://takingthepic.com:2083/ shows a proper cPanel login page but it won't allow you to login? Any error message or is it attempting to send you to that "server227.server-center.net" suspended page?

    http://server227.server-center.net/suspended.page is there because the dopes never changed or set up the server name "server227.server-center.net" (in the fortressitx.com data center in New Jersey) with proper DNS records. cPanel is attempting to send you to a 'suspended' page for which there's no DNS so you end up at a search engine landing page somewhere, which is where your occasional porn page is probably coming from.


    btw, the correct name of your server is "ns1.darkenhosting.org" but they didn't set that up correctly
    Last edited by koolcards; 07-13-2007 at 08:48 AM. Reason: spelling

  15. #15
    Member
    Join Date
    Jul 2006
    Posts
    10

    Default

    Quote Originally Posted by koolcards View Post
    https://takingthepic.com:2083/ shows a proper cPanel login page but it won't allow you to login? Any error message or is it attempting to send you to that "server227.server-center.net" suspended page?

    http://server227.server-center.net/suspended.page is there because the dopes never changed or set up the server name "server227.server-center.net" (in the fortressitx.com data center in New Jersey) with proper DNS records. cPanel is attempting to send you to a 'suspended' page for which there's no DNS so you end up at a search engine landing page somewhere, which is where your occasional porn page is probably coming from.


    btw, the correct name of your server is "ns1.darkenhosting.org" but they didn't set that up correctly
    When I try to login it just gives me the login pop up again...which is why I thought it had been hacked and someone had changed the password. I did try clicking the change password and it tells me that the new password has been sent to the email address on file but I don't recieve anything.
    I really appreciate your help here guy's Many thanks.

    I'm not all that happy with the service from darken host but they are cheap.....I'm a photographer and just spent a fortune on promoting my website at local events etc. I have also emailed a load of clients with samples of there portrait work and now this happens. Does anyone know of a place equally as cheap to host my site?
    Thanks again.
    Ken.

Similar Threads & Tags
Similar threads

  1. Website hacked. how to restore data
    By yogesh_gamer in forum New User Questions
    Replies: 0
    Last Post: 04-30-2011, 03:15 AM
  2. Website Hacked.
    By ManojB in forum Security
    Replies: 13
    Last Post: 11-11-2008, 04:05 PM
  3. Website Hacked.
    By ManojB in forum cPanel and WHM Discussions
    Replies: 13
    Last Post: 11-11-2008, 04:05 PM
  4. Replies: 20
    Last Post: 06-17-2008, 11:59 PM
  5. a website has been hacked
    By Bert W in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-24-2003, 07:52 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube