Did My Account Get Hacked Into? - Some suspicious issues!!!

Pages: 1, 2
free web hosting

Read Latest Entries..: (Post #17) by Sten on Sep 30 2007, 01:01 AM. (Line Breaks Removed)
ive never used a password manager for anything. i would rather just type in a password my self than letting a program do it for me especially since my computer is shared with the rest of my family.
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Free Web Hosting > Astahost > Hosted Members Support

Did My Account Get Hacked Into? - Some suspicious issues!!!

FirefoxRocks
Ok first of all I had this issue of my cPanel/FTP password not working: http://www.astahost.com/cant-access-cpanel...led-t16945.html.

That raised a warning flag as I didn't change any settings of user authentication, etc.

So then I reset my password using the forum thing under "Free Web Hosting". It supposedly "failed", so I didn't use 10 credits. When I accessed my FTP account to upload some PHP files that I corrected, I found this new directory/file under my public_html folder:

/9xYenBai.Com/UploadMusic/Honey.wma

So I raised security, went to that website http://9xYenBai.Com and couldn't understand Vietnamese, so it didn't look suspicious or anything becuase McAfee SiteAdvisor didn't rate it yet.

Then, I downloaded the WMA music file, scanned it for viruses and found that it wasn't a virus, so I played it in Windows Media Player and the song was in Vietnamese, same as this site.

Now my main concern is that the directory is called UploadMusic, so do you think someone cracked my password and uploaded files to my account?

 

 

 


Reply

Mark420
This sounds very odd indeed! I know Turbo had some issues this week with his Cpanel password also being 
changed for no reason.
Can you have a look at you FTP/Webstats and try to work on whos been visiting your site and look for the wma file in the logs and see if its been downloaded by anyone other than you.
Have you burned a lot of bandwidth this month you cant account for also?

Reply

vujsa
First, you were definitely hacked!
Second, your hosting account has problems!
Third, you need to contact support.

Your site, for whatever reason, was, it looks like, suspended. Your member profile shows you as a HOSTED member but your profile is missing important hosting data!
When an account sites around for awhile without activity, hacker take the site over and use it for their purposes!

Now, between your suspension and member profile errors, when you earned enough credits to unsuspend your account, either the hacker had changed the password or more probable, the error in your member profile prevented you from logging into your account.

So, now that you seem to have some access to the website, you can see the file changes that were made on your account. More than likely, a script like SMF or Mambo allowed a hacker to upload files to your account or even have full control over you public_html folder. It is unlikely that he was able to crack your password.

So, once you get your account issues fixed, then you need to either remove the exploited web script or upgrade it to a more secure version!

These little issues you have, are rather common. Even I have had a similar issue with random files or folders being uploaded to my file system. It was a result of little or no activity on the website along with an exploit in one of the scripts I had installed.

Check this website to see what else they have done to your account:
old.zone-h.org/en/defacements/filter/filter_domain=YOUR_DOMAIN_HERE.COM

vujsa

 

 

 


Reply

FirefoxRocks
My bandwidth is about average for 66% of the month has passed.
I couldn't find the WMA file in the logs as it was downloaded too little times I guess. The only files that I found in the log was the site to my Web Development Portal and the site to XKingdom Center (a game club site).

There weren't any usual numbers of users/hits on the last few days, just about 15 unique users and the average ~150 pages hit.

So I don't know what happened.

Reply

Sten
yay i have had no digital attacks, lol. that site you said vujsa freezes firefox, lol.

well if the problem is caused by being inactive, then i guess ill always stay active. by staying active, does that mean in astahost or your cpanel?

i havent had anything messed around with my account anyway so thats good for me.

Reply

vujsa
QUOTE(Sten @ Sep 23 2007, 01:29 AM) *
yay i have had no digital attacks, lol. that site you said vujsa freezes firefox, lol.

well if the problem is caused by being inactive, then i guess ill always stay active. by staying active, does that mean in astahost or your cpanel?

i havent had anything messed around with my account anyway so thats good for me.

Yeah, the site is really slow to load but it works okay most of the time. I use Firefox there without problem.

Hackers and spammers love inactive website since they can have their way with them for a long time before anyone stops them. Some spammers are even nice enough to leave a removal link in their spam posts on inactive forums so that once you get around to working on your website again, they will stop spamming your site. Just remember, most of them don't care too much is Joe Average clicks on the link, they want the searchbots to see the link!

The directory and file uploaded to the site is the hackers calling card. This is how they prove that they hacked your site. Then other hackers can check to see if the calling card is there. For most of them, it is just a game and the leave the calling card without damaging the website. Even the ones that do get a little out of hand usually just rename important files or folders so that the website won't work but the data is still there.

Usually, just uploading the correct backup files then upgrading the program you are using is the solution to the security problem. Rarely do they get into your database and delete or edit data unless they don't like you for some reason.

vujsa

Reply

tansqrx
Here is a related question. If someone else gets hacked on the same server that I am hosted at, how does this affect me? Is the server hardened enough to prevent any cross account hacking. I know that each account is protected from others to a certain extent but once a machine has been taken over can you really trust it?

Reply

vujsa
Well, just like you can't access my account from your account, a hacker can't attack you account from his account.

The server is very well protected but from time to time, users unknowingly open security holes in their account with older scripts or self written scripts. Usually, it is older versions of popular scripts that get hacked into. Since these are generally open source, attackers can study the code and look for holes. Usually by the time a security exploit gets to the hacker mainstream, a new version that protects against the security issue is released. It is of course the job of the website owner or administrator to upgrade the script prior to being hacked.

Self written scripts have to be pretty bad for a hacker to get in through since they probably can't view the source code of the script. They can however use common security holes to probe your website for exploits so be sure to add a little security to your scripts.

vujsa

Reply

FirefoxRocks
The thing is, my website was ACCESSIBLE when cPanel and FTP were down. No files were renamed/changed except for the newer uploaded directory. Also, I wasn't using any content management systems on my website, I was going to install phpBB2 but I didn't get around to uploading that yet.

And the site is pretty active, at least a few members visit it everyday. I regularly check on it also, so I don't see a problem with activity levels.

Reply

BuffaloHELP
FirefoxRocks,

Was your original password found in a dictionary? In another words, was it not combined with numbers and symbols?

If your original password was a combination of words found in a dictionary, please read http://www.trap17.com/forums/index.php?showtopic=51761

And for the rest of AstaHost members, start changing your passwords as I explained in above topic ASAP!!

Reply

Latest Entries

Sten
ive never used a password manager for anything. i would rather just type in a password my self than letting a program do it for me especially since my computer is shared with the rest of my family.

Reply

.:Brian:.
I haven't ever heard of the issues with the firefox password manager vulnerabilities...

I'll have to look into those, in any event the password manager hasn't caused any issues for me so far...

Also I have had trouble with Opera's password manager thing, it just isn't as easy to use as firefox's is for me....Anybody else experience that?

In any event, even when you do use random passwords, if you use them enough you'll remember them... I can have a password like af3h2ls and within a couple of days of using it a couple times a day you'll remember it easily... (and no that is not a password i use for anything, so you don't have to go trying it on my account, as I would never give out a password i use for anything)

Reply

Sten
hmmm... my astahost forum account is found in a dictionary im pretty sure but i cant count on my cpanel password being found in a dictionary.
i do have one password i only use for one site because i dont want to get hacked, it would NEVER be in a dictionary since i made it up and its the most secure password ive ever had, lol

Reply

BuffaloHELP
I do not know... but OpaQue tells me that most of accounts, I had to reset their passwords, were compromised by FTP brute force method. And once passwords were found the perpetrator then accessed those cpanels and started to use up their disk spaces.

I noticed that when I went into each account and saw the last IP to log from 222.252.*.* (the last two values were not consistent). I'm wondering if you noticed out of ordinary IP as the last logged when you finally got into your cpanel...?

Reply

FirefoxRocks
Acutally, there is a vulnerability with Firefox/Flock's password manager. Search Secunia for details, I found this: http://secunia.com/advisories/23046/.

I use Opera's wand, Internet Explorer autocomplete and I don't know if Safari has one or not, but I still use Firefox Password Manager regardless of the vulnerability. Do you think that this has something to do with this situation?

Reply


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

Pages: 1, 2
Recent Queries:-
  1. express scripts being hacked - 208.58 hr back. (1)
Similar Topics

Keywords : account, hacked, suspicious, issues

  1. Issues With Vbulletin 3.6.8 P1 With Php 5.2.6
    (0)
  2. Delete Account Please
    (1)
    I can't seem to find a place to delete my account... I am no longer using it anymore. And is it
    possible to delete all my posts and threads made as well? Thanks for the great free hosting!
    Laurence....
  3. Small Issues About Mysql Connector/j 5.1
    (2)
    Hi, all, I just downloaded some versions of mysql Connector/J mysql java driver to test some
    stuffs. There is an issue about the lastest version of 5.1.7. It don't work correctly on older
    version of java 1.3.1. But an older version 5.0.x works without any issue. Hmm... anyone have ideas
    about this ? Testing with 5.1.7 CODE C:\org>java -Xverify:none program Exception in thread
    "main" java.lang.NoSuchMethodError         at
    com.mysql.jdbc.ConnectionPropertiesImpl$BooleanConnectionProperty. (ConnectionProper
    tiesImpl.java:73)         at com.mysql.jdbc.Connect....
  4. How To Enable User Login Security On Windows Vista
    NOT User Account Control (0)
    How to enable User Secure Login on Windows Vista You may have worked in a business,
    educational or other network that uses Windows to log in. With or without being on a domain, most
    business environments "require" you to press the key combination of CTRL + ALT + DELETE prior to the
    log on prompt (the username, password and domain box). This is supposed to enhance login security to
    verify the authenticity of the login box (so that no other malicious software makes a similar box).
    This tutorial will show you how to enable this functionality on Windows XP Home Ed....
  5. Issues With Htc Phone
    (0)
    I have a HTC P3400i PDA which is a newer version of the P3400 model and it comes with Windows Mobile
    6 OS as opposed to P3400's WM5. Using VITO's Audio Touch Notes, I record my calls. The
    problem is that the recorder doesn't seem to record the audio from the other side when the
    speaker is off, or when an earphone/handsfree kit is attached. This problem is not specific to this
    software as other voice recorders are behaving the same way. Another issue I have is with the 2 MP
    Camera. A friend of mine owns a Nokia N72 mobile which also comes with a 2MP camera. B....
  6. Game Key Press Issues
    (0)
    Hi, I'am trying to use actionscipt to write a simple game. But I found tht if I use the
    Key's event system. It's a bit delay ... here is the code, CODE var o = new Object();
    o.onKeyDown = function () {     if (Key.getCode() == 40)     {        _parent.fire._y += 50;     } }
    Key.addListener(o); how do I be able to reduce the delay when press key button on the keyboard
    ? Thank, ....
  7. New Tutorials Have Issues
    Before they are approved tutorials show up, and with confusing errors (2)
    I recently decided to put up a new tutorial. I understand that new tutorials need to be approved
    before they show. Don't mind that at all. However - I noticed in the bottom area of "new
    topics" my tutorial is already showing. Clicking it get the error... QUOTE > Board Message
    Sorry, an error occurred. If you are unsure on how to use a feature, or don't know why you got
    this error message, try looking through the help files for more information. The error returned was:
    Sorry, some required files are missing, if you intended to view a topic, it's possib....
  8. Upgrade Windows Service Pack Issues
    (5)
    Hi, when I try to install windows xp service pack sp2. Every time it goes with backup files and
    registry. It halt up and restart automatically. Anyone know what's caused this ? Thanks,....
  9. User Account Control
    (13)
    I'm sure most of you know about Windows Vista's User Account Control. I was wondering if
    there were any registry settings or anything that I could modify to force the UAC prompt to appear
    when doing these tasks: Clicking the Start button Opening any folder Launching any application
    Adjusting personalization settings Opening a new page in Internet Explorer (by that I mean typing
    in a URL, from Favourites or by clicking a link) Turning off, sleep or restarting the computer
    Modifying the Windows Sidebar Opening any file (mp3, document, anything) There's....
  10. Opensuse Issues
    (4)
    I know it isn't only openSuSE that this issue applies to, but currently I am trying openSuSE and
    I am having problems. I thought I got the hang of using Linux by using the terminal in Ubuntu, but I
    guess not. Now that I know Ubuntu is a Debian-kernel system, I found out that Debian is probably the
    most easy to use, and other types of Linux systems are probably harder to use than Debian. Now can
    anyone tell me the equivalent options on openSuSE for a specific command on Debian GNU/Linux? Here
    is an example of what I encountered: By default, openSuSE includes the K D....
  11. Hacked By Dumansal
    When clicking on FAQ link at top of page (2)
    Hi. Didn't think I'd bring this up because I was sure that you'd be onto it soon
    enough. However, it's still there after a few days. Clicking the FAQ link in either AstaHost
    or Trap17 results in a message "Hacked by DumansaL" followed by a database error. I did a forum
    search for the phrase just now... apparently nothing had yet been posted about it. Regards - Lancer....
  12. Gimp: Saving As... Issues
    Anybody experiencing compatibility problems (3)
    Hi all you gimp users. I am wondering if you are experiencing problems with your images created in
    GIMP as I am. We here is my story. I take pictures with a camera and upload them to my computer with
    a the camera software. Nothing is changed yet. Then I go to that file location and open the image or
    a copy of the image with GIMP. Then i edit it, add layers, and tweak various settings before saving
    it to .XCF (native GIMP format). Then later I was to export it. I do so as JPEG or TIFF. The
    problem is whatever I create/modify in GIMP, I seem to have trouble opening it ba....
  13. Session Issues
    (1)
    I noticed this yesterday when I tried logging into my site at http://feral.portal.trap17.com/
    QUOTE Warning: Unknown: write failed: No space left on device (28) in Unknown on line 0 Warning:
    Unknown: Failed to write session data (files). Please verify that the current setting of
    session.save_path is correct (/tmp) in Unknown on line 0 I know this isn't my issue because
    /tmp is a global server directory. Anyone else experiencing this?....
  14. Spam Issues...is Astahost Selling Our Addresses?
    (10)
    I have spam in my inbox sent to astahost. @spamgourmet.com. Only astahost got this address, and
    it's not likely some chinese spammers guessed it either. Nor do I post it on any posts, nor is
    it viewable on my profile here on the site. Was there a user db compromise or is someone selling
    email addresses?....
  15. Help On Calc Date Issues !
    (4)
    Hi, all I need going to write a small function that calc some interval from day to day and to
    display it base on their size. For example, if the value was 1 minute or over that it display as x
    min. or if it hours then display it as x hours and so on. Let's say from a day range that has
    been passed 600000 second, than I have to change it to some mins or hours or days and so on.... I
    just get start with use the number of seconds and divide it with 60 and converted to mins, and go on
    up to days. But don't know how to get the next steps on. Any suggest are appr....
  16. My Site Got Hacked!
    (10)
    Recently my web site got hacked. Actually my former hosting provider got hacked and now when I visit
    my site it says that it is owned my some hackers. here is my site, www.fitnesspro.woeps.com My
    site is actually a hosted wordpress blog. I spent many days making it and now everything has gone
    wrong. I even set up an autoresponder. Is there any way that I can backup my site? I can access my
    files from CPANEL and FTP. I did use backup from CPanel and downloaded my site and MYSQL databases.
    But can I use the same backup to restore my whole site (through cpanel backup-r....
  17. Shared Hosting Account Server Update - Known Issues And Solutions
    (34)
    Hi AstaHost hosting members. First of all I would like to thank you hosting members for staying
    patient during these difficult times. Xistosupport.com announced Data Center (DC) migration to
    bigger facility for the growing demand. This is to provide much more reliable service to all free
    web hosting members. However it did not go smoothly as server technicians hoped. Even with their
    relentless efforts to bring the service back online there are some known issues which I'd like
    to address. The first issue is that those with TLD (top level domain) will notice that pi....
  18. Server Load
    Regarding account creation (2)
    Hello, Whenever I try creating a new account, I keep getting the following message: QUOTE The
    Server is a bit under load and creating an account might take too long and create problems. Please
    try later. Is there anything I can do? Regards, Atomic0....
  19. Account Reset
    to get a fresh one again? (5)
    I searched the forum, but didn't really find anything.. is it possible to reset my account, or
    even better to terminate it and get a new one with the same name? that everything would be dropped
    to default, statistics and etc, I sometimes even can see subdomains, which are deleted and
    doesn't even exist and other files, as I rewrote most of my stuff, I would like to make a fresh
    start as well after so much years /biggrin.gif" style="vertical-align:middle" emoid=":D" border="0"
    alt="biggrin.gif" /> my domain name is qzone astahost dot com I know about the http:....
  20. Administrator Account Problem In Microsoft Xp [solved]
    I have lost "my documents" (20)
    I have problem with administrator account ... I created new administrator account with this way:
    start /control panel /account users/new account and than I created a new one ; after this I turned
    off computer . I wanted to have two skypes turned on and my friend suggested me to do so... when I
    turned it on the second day , I coudn't enter with the first administrator ,and I entered with
    the administrator that I had created . I have lost my document folder.. please help me . how can I
    enter or can I enter with that first administrator account?? Can my documents be ....
  21. My Account
    it seems to be suspended? (7)
    I just noticed, that my account on astahost has been suspended, but as I know, I did have enough
    credits and still have, I thought, ok maybe it is due to I moved the domain to another server
    because sometime ago my account didn't work here for sometime and I didn't have time to move
    it back, but I also noticed that I can't connect to my ftp account and I have some files I want
    to have before I can leave the hosting or something, and I can't even access cpanel, I would
    want to access it to take my mysql stuff and raw files and similar stuff, but then again....
  22. Oracle 10g Install Issues
    (27)
    So I'm trying to install 10g on my XP Pro development box, and the install goes fine (I do the
    basic install of enterprise edition, I'm by no means an oracle expert) and when it gets to the
    part where it wants to create a database, the database creation assistant fails saying first that it
    cannot retrieve credentials, and then that it can't connect to ORACLE (I'm assuming this is
    the instance name). Anyone have *any* idea what's going on here?....
  23. How To Add Administrator Account In Logon Screen
    Windows XP (4)
    If you've created an account in addition to the Administrator account in Windows XP, the
    administrator account will not be shown in the Logon Scree, this tutorial explains you how to add
    the Administrator account to the logon screen. If you are using Windows XP Pro follow these steps,
    1. In the Start Menu, select Run. 2. In the Run dialog, type 'regedit' without quotes, to
    start the registry editor. 3. Navigate to the key, HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \
    Windows NT \ CurrentVersion \Winlogon \SpecialAccounts \UserList 4. In the right pane, ri....
  24. Help: XP Pro Admin Account Deleted! Only Guest Access
    (41)
    HELP Administrator account deleted, need help loggin in to my laptop!!! WIN XP PRO Service Pack 2?
    My friend was using my laptop and she says she has no idea what she did but she somehow deleted my
    account (the only account) so now i can only login as a guest andI have no access to my music
    pictures. programs, homework nothing, and I have a Toshiba Portege' laptop, it has no floppy
    disk or cd drive no internet connection, so i have no idea how to fix this, I tried the ctrl+alt+del
    trick but it will not work the default admin, has a password and i have no idea what it....
  25. Need To Hack An Admin Account On Xp... No Problem!
    It's so easy to hack an account you'll be amazed (61)
    Well recently one of my good girl that is a friend got a laptop from her dad. Her dad does websites
    so the laptop was new and worked fine, but needed to be defraged. The one problem, her nor her dad
    knew the admin password. I told her to post her question on Trap 17 and it got answered with in
    minutes. All you have to do is these few steps: 1. Reboot 2. Before the windows logo comes up press
    F11 (Just start clicking it over and over again until the windows logo comes up.) 3. Just sit and
    let it do it's thing and when the login screen comes up click on the Admin icon....
  26. Read/Write Issues After Copying An Access .mdb File
    (3)
    Alright, I'm currently creating an interface program for a MS Access database. I've only
    used Access once in the past but used other DB's a handful of times so I didn't have any
    trouble getting the general program created. My issue arose when I tried to make it so that the
    users needing to use the program can just copy the .exe and the .mdb files and use it. The program
    doesn't require users to share the database but to store their OWN programs information in their
    OWN database, so basically each needs to have their own database with the exact same d....
  27. Free Gmail Account!
    Click here for one. (28)
    As you all know the famous search engine google has come out with many different free utilites
    for the web. One of them including a email service which they have named Gmail. If you want a Free
    Gmail account then just post your email address here on astahost or email me a gmail my address is
    Corvette7@gmail.com. I have 15 invitations left so please email me only if you really want one.
    ....
  28. ATI Radeon 9250 Issues
    I've been working on it for weeks now... (8)
    I recently bought an ATI Radeon 9250 256mb, my computer comes with an nVIDA nforce chipset (Driver:
    nVIDA Geforce 2 Integrated GPU, VGA compatible). It worked great at first but later i started having
    problems. Logan (Deathbringer) helped me get it working again...sortof. What he told me to do was to
    uninstall the previous nVIDA drivers and use a driver cleaner to erase everything the uninstaller
    did not. It made sense, then i was to put the Radeon card in, start in safe mode and uninstall the
    Radeon drivers and clean off all the ATI drivers using the DC again. I restart....
  29. Finding Yahoo Account Creation Date
    is there a legal way of doing so? (1)
    As the topic title says, is there a way to find the date someone created a yahoo account, without
    crossing the hacking boundary?....
  30. Account Suspended
    What happend ? (15)
    Hi, My account is suspended, what happend ?... why do you do me this ?... I not do nothing. Please
    tell me. Thanks.....

    1. Looking for account, hacked, suspicious, issues






*SIMILAR VIDEOS*
Searching Video's for account, hacked, suspicious, issues
advertisement




Did My Account Get Hacked Into? - Some suspicious issues!!!