Greenguy's Board


Go Back   Greenguy's Board > Newbie Questions
Register FAQ Calendar Today's Posts

 
 
Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
Old 2006-08-07, 04:05 PM   #3
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
There are two types of exploits where there are defacements like this.

One is an exploit through ftp, so, change your FTP password, etc. This one usually occurs when someone has spyware or a keylogger on their machine that sends this data elsewhere, or has shared the username/password/hostname combo with a software vendor and didn't change it after software was installed.

The other exploit is a web exploit which can come through numerous pieces of software depending on what you were running. Some of the exploits allow remote shell, and if your hosting runs apache in setuid mode (which is an abhorrent security nightmare), files could have been compromised that way.

http://www.greenguysboard.com/board/...ad.php?t=31508

In either case, you need to find out where the exploit happened so that once you do change passwords, etc, it doesn't happen again.

You will need to spend time going over system logs, etc to see where things got changed and then adjust/fix whatever so that it doesn't happen again.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 11:20 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc