hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Web Hosting : 2 Sites hacked by same guy within 1 week on slhost.com
Reply

Web Hosting Discussions on all aspects of web hosting including past experiences (both negative and positive), choosing a host, questions and answers, and other related subjects. If your service is unavailable, please click here.
Forum Jump

2 Sites hacked by same guy within 1 week on slhost.com

Reply Post New Thread In Web Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 08-29-2006, 04:25 PM
jwg1800 jwg1800 is offline
Newbie
 
Join Date: May 2006
Posts: 19

2 Sites hacked by same guy within 1 week on slhost.com


Two of my sites with Slhost.com have been hacked by the same people within the past week. Is this just a totally crazy coincidence or could it have something to do with Slhost.

Anyone else experiencing any problems?

John

Reply With Quote


Sponsored Links
  #2  
Old 08-29-2006, 04:29 PM
sugarsnow sugarsnow is offline
New Member
 
Join Date: Aug 2006
Posts: 4
i dont know anything about that host but sounds like to me it's possible since its the same hacker and your site maybe the hacker just has something against you personally.. From what I've seen online if someone is determined and good enough, they'll probly get past the best of secuirty. But that's just my 2 cents

Reply With Quote
  #3  
Old 08-29-2006, 06:49 PM
xxkylexx xxkylexx is offline
Web Hosting Evangelist
 
Join Date: Apr 2006
Location: Jacksonville, FL
Posts: 498
Most likly it was just a defacement, which would be vulnerabilities within your code source-- not the host.

Reply With Quote
Sponsored Links
  #4  
Old 08-30-2006, 04:52 AM
Greg Carnegie Greg Carnegie is offline
Newbie
 
Join Date: Aug 2006
Posts: 21
Quote:
Originally Posted by sugarsnow
i dont know anything about that host but sounds like to me it's possible since its the same hacker and your site maybe the hacker just has something against you personally.
I agree, but maybe you were using the same passwords or software, so it wasn't hard for him to hack your another site?

Reply With Quote
  #5  
Old 08-30-2006, 04:57 AM
clanosiris clanosiris is offline
Web Hosting Master
 
Join Date: Jul 2004
Posts: 623
Your issue can also be your php cms or forum is simply out of date. Hackers simply have the ability to do php injection.

I will advise checking for newer release.

If that doesnt work check your permissions usually some users will upload backdoor shell systems if you have 777 or bad permissions within your directories.

__________________
Gazzin Networks - http://www.gazzin.com
Cheap - Affordable Resellers Solutions - Powering Businesses Since 2004!

Reply With Quote
  #6  
Old 08-30-2006, 12:39 PM
mitchalertsite mitchalertsite is offline
New Member
 
Join Date: Aug 2006
Posts: 3
have you had it scanned for vulnerabilities

Reply With Quote
  #7  
Old 08-30-2006, 12:55 PM
Rotfil Rotfil is offline
Newbie
 
Join Date: Feb 2006
Posts: 28
Quote:
Originally Posted by Greg Carnegie
using the same passwords
. Similar IP addresses, and a same password, on the same network, probably just what he was after... How do you now it was the same hacker?.

__________________
Pope Online :: Web Design
www.popeonline.co.uk

Reply With Quote
  #8  
Old 08-30-2006, 01:02 PM
Omega-Mark Omega-Mark is offline
Junior Guru
 
Join Date: Jan 2005
Location: Leeds, England
Posts: 183
left the same mark at a guess

Reply With Quote
  #9  
Old 08-30-2006, 03:50 PM
DamonF DamonF is offline
Junior Guru Wannabe
 
Join Date: Jun 2005
Location: Florida
Posts: 87
Do you have any scripts that are just laying there and not installed correctly? (not chmoded,open vulnerabilities within the script,etc.)

__________________
DamonF
Zertex Designs coming soon

Reply With Quote
  #10  
Old 08-31-2006, 08:36 PM
roby2k roby2k is offline
Junior Guru
 
Join Date: Apr 2002
Location: Wirral/Cheshire/Meresyside
Posts: 203
install mod_security
update all scripts
check http://www.milw0rm.com for any exploits for what you have been using
then ask them to check the server with a rootkit detector
and to do a security audit on their server.

__________________
http://www.gocre8.co.uk - Liverpool Web Design
http://www.outallnite.co.uk - Liverpool Clubbing

Reply With Quote
  #11  
Old 08-31-2006, 08:41 PM
SeriousServers SeriousServers is offline
Web Hosting Guru
 
Join Date: Aug 2006
Posts: 259
Without more information I can not make my conclusions.

It could be someone who knows your sites, and dislikes you.
It could be you use insecure scripts, and they just searched the server / ip's to find holes
It could be a coincidence,

It could be a number of things, what other information can you give us?

Reply With Quote
  #12  
Old 10-02-2006, 11:12 AM
Billiken Billiken is offline
Newbie
 
Join Date: Aug 2005
Posts: 7
Quote:
Originally Posted by SeriousServers
Without more information I can not make my conclusions.

It could be someone who knows your sites, and dislikes you.
It could be you use insecure scripts, and they just searched the server / ip's to find holes
It could be a coincidence,

It could be a number of things, what other information can you give us?
Actually, the hacking has been a problem on SLHost's servers. A couple weeks ago all of my sites on my resller account had anything named index.* were replaced with hacked files. It turned out it was the entire server not just my reseller account. They had been as they put it "Rooted".

They took the server offline, repaired it and restored from backup, I'd lost a day's worth of data but things were back.

What really upset me was when they didn't follow up with the backup and the next morning something had hung up and it did a restore again from the 'pre-hack' data making me loose a second day's set of data.

Since then the hacking issues seem to have been resolved, I had one directory that ended up with an injection happening simply b/c I'd left it as 777 and didn't have an index.html in it. I fixed that and havn't had a problem since. I'm being extremely cautious though as their servers appear to be a steady target (or someone on their servers is at least).

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Parallels Plesk Flaw Left FTC Websites Open to Security Breaches Web Hosting News 2012-02-23 13:32:43
South Korean Domain Registrar Gabia, Epson Korea Websites Hacked Web Hosting News 2011-08-24 14:04:01
Anonymous Hacks Turkish Government Websites to Protest Internet Censorship Web Hosting News 2011-07-07 18:45:33
Hacker Group LulzSec Attacks CIA Website Web Hosting News 2011-06-16 14:19:33


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?