Web Hosting Talk







View Full Version : Have I been hacked?


lamp
12-26-2004, 12:39 PM
Have I been hacked?

My index page reads the following:

WHICH FILE EXTENSION ARE YOU?

You are .cgi
Your life seems a bit too scripted, and sometimes you are exploited. Still a workhorse though.


Tell me what your thoughts are.

Lamp

Steven
12-26-2004, 12:57 PM
Sounds like you were defaced so yes you were hacked.

Hands-on Mark
12-26-2004, 01:02 PM
That is no default page that I know of....so you where defaced.

picoyak
12-26-2004, 02:06 PM
That's a BBSpot quiz: http://www.bbspot.com/News/2004/10/extension_quiz.php

I'm also .cgi :cool:

Steven
12-26-2004, 02:09 PM
yay im a .doc file!!

lamp
12-26-2004, 02:36 PM
Originally posted by picoyak
That's a BBSpot quiz: http://www.bbspot.com/News/2004/10/extension_quiz.php

I'm also .cgi :cool:

Ok...

So what does all of this mean?


How can I figure out how they got in and how do I get them out?

Lamp

lamp
12-26-2004, 03:02 PM
Does anyone have a clue as to how these people can get in?

/tmp is secured (noexec and the whole works) and /var/tmp points to /tmp.

Your help is REALLY appreciated.

Lamp

Vult-r
12-26-2004, 03:15 PM
Originally posted by picoyak
That's a BBSpot quiz: http://www.bbspot.com/News/2004/10/extension_quiz.php

I'm also .cgi :cool:

I wonder how that quiz came into his index page..

lamp
12-26-2004, 03:20 PM
Originally posted by fac3less
Greetings:

In order to be fully secure you must use internet explorer.
The first step in securing your server would be install microsoft windows 98, special edition.


This is the most useless post I've EVER read on these boards.

Hands-on Mark
12-26-2004, 03:25 PM
I'm a .dll :)

iFuseLiam
12-27-2004, 01:15 PM
I'm a .* (Wildcard) :clap: Yay!

fusioncroc
12-27-2004, 01:50 PM
im .dll as well

serversphere
12-27-2004, 02:10 PM
Wow, I'm an .swf!! Flashy, yet sometimes annoying. My wife would probably agree...

:D

ZoneServ.com
12-27-2004, 02:17 PM
Originally posted by USWEB-Darren
Wow, I'm an .swf!! Flashy, yet sometimes annoying. My wife would probably agree...

:D

Same here :)

RHChristian
12-27-2004, 02:26 PM
Contact rack911.com and get them to secure your server. It seems people have hijacked your thread.

porcupine
12-27-2004, 02:26 PM
You are .gif
Sometimes you are animated,
but usually you just sit there and look pretty.

porcupine
12-27-2004, 02:29 PM
Originally posted by RHChristian
Contact rack911.com and get them to secure your server. It seems people have hijacked your thread.

No, just easily amused :)

picoyak
12-28-2004, 06:59 AM
Didn't mean to hijack the thread. I don't believe the original poster is hacked or defaced. I believe that someone tried to post their quiz results and the markup got kludged. I've seen it happen before with those quiz results depending upon the cms used and how it interprets and renders things that are copied/pasted from those funny quizzes such as Quizilla or BBSpot.

But now since we haven't actually seen his site (or at least I haven't), we don't really know.

So, yeah, I guess someone will have to look at it, and you know it can't hurt if while that someone looks they also give the server a once-over security-wise.