For the past month or so, I have wasted a lot of my time on dealing with hackers! That’s right. Firstly they found a way to exploit my tmp folder on the server and placed an IRC bot called emech. Thanks to Coreix - they noticed some unusual traffic and helped to stop it.

Then they managed to exploit one of my user’s site which had a weak password. I noticed that quickly as whatever they tried to do caused the apache to die.

The last part that got me furious is somehow they managed to write to my htaccess files a few lines of code that was telling google to go and index their site instead:

RewriteEngine On

RewriteBase /
RewriteCond %{HTTP_USER_AGENT} (Googlebot|Slurp|msnbot)
RewriteRule ^ http://dfsg.us/ [R=301,L]

Now that’s cheeky. I have no idea how they did it as the file is accessible for writing only by the owner. There is no way they know my password as if they did, they would have probably done more damage. I guess there is a new php/apache vulnerability which is yet to be reported and a patch made available for it.

For now, I disabled ftp access, installed a few programs to block IP addresses of users who attempt anything suspicious, changed all my passwords, installed a php patch for improved security and I am looking forward to wasting more of my time in due course!

Oh, the same issue has been reported by a guy over here - http://44px.net/blog/2009/02/28/napominayu-prosteyshee-pravilo-teper-i-iz-svoego-opyita

He thinks its the ftp details that got hacked – I looked through my ftp logs – nothing there on my end.

Update 05/03/2009Coreix was kind enough to do a audit on the server and suggested a few extra security measures that I gladly accepted to make the server extra secure. Now I can sleep at night :)

And once again I will comment on how good the Coreix support is – professional, knowledgeable, polite and not trying to rip anyone off! They worked to apply all the security measures and disable the services that were not necesary etc for a good part of the day and I got charged a very reasonable ammount of money for that!

, ,
Trackback

3 comments untill now

  1. .htaccess权限777引起的Google谷歌不收录问题…

    到服务器后台查看访问记录时,可以看到凡是Googlebots的访问全部被301转向了,而baiduspider的访问就是正常的200。
    ……

  2. I have the trouble too. But Luckly only four days when I find it. I don’t know how they did that too. I have asked webmaster , he saw that it’s maybe a bug of WordPress.

    Reply

    Vadim Reply:

    I think you are right – only 2 of my websites were affected and both had wordpress on.

    Reply

Add your comment now

  • Polls

    What do you think is the future of PC cooling?

    View Results

    Loading ... Loading ...
  • Recent Comments

    • feathers: Watercooling is becoming much more mainstream now. A lot of people...
    • Goatboy: I used to use your computer selling business a LOT before it went...
    • Aldo Zanoni: Hello, Vadim. Good work in putting together a server-side...
    • UK Gaming Computers: Another interesting blog entry Vadim. You have a VERY...
    • PC Base unit: Hi Valdim, I do share your thoughts regarding watercooling, and...
  • Categories

  • RSS Bright Side of News

    • eBay Security Guards Shun Free Publicity September 2, 2010
      There was a lot going on at the Santa Clara Convention Center. We were there for the GlobalFoundries Tech Convention. The other activity which is probably of more interest to our readers was an eBay gathering. […]
    • AMD Shows Next Gen Chips: Bulldozer and 1st and 2nd Generation Fusion September 2, 2010
      Chekib Akrout, SVP of the technology group, AMD kicked off the first customer talk at GlobalFoundries' GTC 2010 conference and told us more about their Llano Fusion technology. […]
    • Activision Allows COD: Black Ops Dedicated Servers but There’s a Catch September 2, 2010
      In typical Activision fashion, they have decided to allow PC users to once again use dedicated servers for their multiplayer gaming experience with one major exception. […]
    • ASUS Leaks, GTS 450 Details Revealed September 1, 2010
      In only couple of weeks time, nVidia will unleash its mainstream attack. GF106 comes in the form of a billion transistor part that will occupy 238mm2 of die space. […]
    • HP and Hynix Team on Universal Memory? September 1, 2010
      HP Labs and Hynix Semiconductor, Inc. announced today that they have entered into a joint development agreement with the intent of bringing Memristor technology to market as a viable commercial memory product.  […]
  • Tags