+ Reply to Thread
Results 1 to 10 of 28
- 07-27-2006 03:15 PM #1Moderator Array
- Join Date
- Jun 2006
- Location
- Selangor, Kuala Lumpur, Terengganu dan Sarawak.
- Posts
- 515
- Thanks
- 0
- Thanked 4 Times in 2 Posts
Hackers Serang Webhosting Providers
A'kum...
Saya telah dapat tahu dari forum luar negara bahawa terdapat hackers yang telah hack ke beberapa Webhosting Provider, latest yang kena ialah:
hostingfree4lifeDOTcom
(saya tak nak link hosting provider tu ke forum kita ni, takut kena tempias)... :shock:
dan juga:
Hackers yang buat tu menggelar diri mereka kumpulan Arslan,- forum webhostingtalk
FatNetwork:
Today we were attacked by the Arslan group as well. It started off by them replacing every index.php file on the server with one that included their defacement message. My colleague and I overwrote those index.php files from a recent backup we had and it fixed the problem.
10 Minutes later the defacements came back and I noticed while refreshing the FTP window I had open the MODIFIED time for the index.php and index2.php files were changing even though I was not uploading anything. So it appears to me that perhaps these guys were running a script that was connected to a cronjob?
Later in the day it appears as though they hit every PHP file on the entire server we are on. This not only included index.php files but every php file on the server had this defacement message. I don't understand how one script such as phpbb or and other script like that would allow someone near root level access on a linux machine coupled with firewalls and what not.
The company we go through is an established business with a few years of experience. They were surprised and confused just as much as we were wondering how this could of happened. The server is at the data center right now under further investigation. All MYSQL data seems to be in tact and untouched which is a good thing.
Has anyone else been attacked by ARsLan and does anyone have a clue as to what may have cuased this or how this could of happened?
I will never understand the motivation behind doing things such as this. It causes nothing but anger and grief.
dan mengaku sebagai orang islam!
(maybe saja nak guna nama islam supaya nampak gempak le)
Ada beberapa websites yang dibawah host provider tersebut sudah kena hack - username, password semua kena access dan website mereka kena 'defaced'.
Kenapalah jadi macam ni?!
Betul2 memburukkan nama islam...
Sekarang kat forum luar negara benda ni topik hangat...Launch Akan Datang: Coming soon on WangCyber! ... berkenaan Twitter!
My Website: www.internetmelayu.com | My Twitter: Twitter.com/pemasaranIM
- 07-27-2006 03:15 PM # ADS
- 07-27-2006 03:30 PM #2
Buruk betul prangai mereka tu..
:cry:
- 07-31-2006 12:29 AM #3Junior Member Array
- Join Date
- Apr 2006
- Location
- Waseda kamo shirenai
- Posts
- 157
- Thanks
- 0
- Thanked 0 Times in 0 Posts
Jangan kata webhosting provider,Microsoft dan Nasa pun kena serang.
Musim2 perang ni kat internet pun diorg angkat senjata. :?
Nasa Hacked
Kita jangan jadi mangsa keadaan cukupla..[/url]
- 07-31-2006 04:04 PM #4Moderator Array
- Join Date
- Jun 2006
- Location
- Selangor, Kuala Lumpur, Terengganu dan Sarawak.
- Posts
- 515
- Thanks
- 0
- Thanked 4 Times in 2 Posts
huhu...
kalo nasa yang ada sistem canggih-manggih tu pun boleh kena hack... apatah lagi orang kecik macam kita ye... :shock:
Buat masa ni memang susah nak lawan hackers ni. But biasanya mereka target website yang high profile, macam website kerajaan, website bisnes yang glamer, news website... but adakalanya website / blog orang biasa pun kena hack juga sebab kebetulan 'hack' yang mereka install tu memang khas untuk 'ganggu' dan kasi malapetaka kat platform tertentu seperti wordpress, blogger,
sometimes pada browser - seperti FireFox, IE or pada apa-apa yang berkaitan dgn Microsoft (Outlook, etc)...
pada phpbb forum, dan seperti yang kat atas tu, pada hosting provider...
kalo fikir.... memang serabut kepala ...Launch Akan Datang: Coming soon on WangCyber! ... berkenaan Twitter!
My Website: www.internetmelayu.com | My Twitter: Twitter.com/pemasaranIM
- 07-31-2006 06:04 PM #5Moderator Array
- Join Date
- Jun 2006
- Location
- Selangor, Kuala Lumpur, Terengganu dan Sarawak.
- Posts
- 515
- Thanks
- 0
- Thanked 4 Times in 2 Posts
testing....
Launch Akan Datang: Coming soon on WangCyber! ... berkenaan Twitter!
My Website: www.internetmelayu.com | My Twitter: Twitter.com/pemasaranIM
- 07-31-2006 06:13 PM #6
uik.?? :shock: tengah test code ke? aa.. jangan main inject2 tau.. tak baik.. :lol:
- 08-02-2006 09:22 PM #7
sql injection , php injection ...
web aku pun pernah ada hacker cuba2 nak masuk ...
slamat aku perasan... banyak plak tuh...
dia sempat upload file script.... tapi tu aku tak iktiraf sebagai hacker la.. sebab directory tu aku mmg set open untuk upload ...
dia boleh scan lubang2 yg open...
hati2
- 09-05-2006 01:02 PM #8
Berdasarkan ape yang aku bace la....tiada cara nk elak serangan crackers ni
wujud langkah2 pencegahan...tapi selagi si crackers2 ni jumpe lubang untuk di exploit....selagi itu la tidak selamat...
n00b2 je yg main dengan injection ni...sekali kite lupe...zasss* merane la jawapnye....
salah satu penyelesain alternatif yg aku bace kt forum luar negare...web hosting provider ni block negare2 'kritikal'....maknenye derang xbagi user2 dari negare kaki brute force ni jd user derang.....russia...vietnam....(Malaysia pn ade woii)
- 09-06-2006 12:05 AM #9WC Premium Array
- Join Date
- Jun 2006
- Location
- ee-poh
- Posts
- 3,902
- Thanks
- 63
- Thanked 75 Times in 45 Posts
huhuu..aku de baca iklan kat majalah PC pasal Uitm nak wat hack competition kan?ke nak create satu sistem yang bleh banteras hackers ni??
tapi aku rasa sure de hackers dari malaysia ni..member aku ade gak la hackers kecil2 lan n besar2 besaran tu tak berani depa nak wat.kang xpasal2 je..takat yang aku tau la..yang aku taktau...tahla...
- 09-06-2006 11:15 AM #10WC Premium Array
- Join Date
- Dec 2005
- Location
- On WorkStation
- Posts
- 1,845
- Thanks
- 6
- Thanked 23 Times in 10 Posts
saje diorang xde keje lain nak wat selain meng'inject' sql utk wat index defacement.. sbb tu kalo ada folder atau directory bubuh index.htm bagi ia tak dapat dibaca lubang2 tuh... pastu kalo yg guna free php scripts pepandailah patch update kalo ada.. jgn tunggu lelama nanti diterjah hackers..
pastu kalo pilih webhosting luarnegara berhati-hatilah sket, kenkadang diorang simpan file malware script dalam server tu anytime je server leh down... bukan ape member aku penah kene sbb byk sgt org pelik2 simpan virus/malware script dalam webhosting diorang sehingga org lain kene tempias..
p/s: sistem yg manusia buat tak pernah perfect.... ada je lubangnyer...
Facebook - Code7 World !
LUBUK RAHSIA TERBAIK - Download Grafik Photoshop, Illustrator, Movie Tanpa Henti !



LinkBack URL
About LinkBacks
Reply With Quote



Bookmarks