Questions on site security

Status
Not open for further replies.

SuperDave2U

New member
Aug 13, 2008
134
6
0
I was contacted by my host today (shared server) that my website has yet again been compromised and now hosts a phising website. After a good amount of time on the phone with support I managed to get the site reactivated with a warning that if it happens again I'll be asked to find a new host.

This is the third time it's happened and each time the files are depositied into a different folder/subfolder.

Can anyone recomend ways of securing my website, or finding the specific files that are allowing these guys to drop these files? I read somewhere that CHMOD 000 all files would be a way to blanket deactivate my site while I figure this out, will that work?

This account hosts 3 personal domains, nothing business related but it would still suck to lose the host.
 


Mainly Wordpress, and Gallery2 but there's plenty of extra garbage in there.

I would install things to try them out and over time forget about them leaving them outdated and open for attacks. I have only myself to blame for that but as I go through and delete the stuff I'm not using anymore I'm wondering what steps should be taken, outside of normal updates, after I get rid of the clutter to keep this from happening again ?
 
If you listed the domain names we could probably figure it out.

Wordpress is one of the most targeted software packages for hijackers, so I'd start by looking there. If your host actually disclosed what they found, it would make this much easier.
 
Here are a few ideas, based on your description that you are mainly using this hosting account for personal use:

Keep an eye on your server logs. Especially things that involve posting to forms. You may want to look into something that blocks or filters POST requests to hosts outside your domain.

Keep up with the email accounts that are used on your domain. Drop any accounts that you know do not belong there. Set up a catch-all address to either blackhole incoming messages or autoreply with a "return to sender - message undeliverable" notice.

Monitor the activity of your ftp accounts. If you are the only one who uses ftp, then you should not have multiple ftp accounts active.

If you are testing scripts or otherwise putting things up there that are only for you, keep them in password-protected subfolders. It might be annoying to have to type in the password, but let your browser save the password and you should only have to enter it once.

Make sure your default indexes are set up properly. It's called different things, depending on your host's software, but if someone goes to a URL that doesn't have a index.htm, index.php, etc, they should NOT be able to see the page that shows the directory listing.
 
Hey guys thanks for the replies. When I got in touch with my host they were really no help with this. I've had my account with them for about two years now and over the time I had put up a ton of apps to test and tweak but eventually lost interest.

Now, looking over a lot of the stuff that I had installed I could see there were a lot of open threats. phpBB installs not up to date, indexes missing, poor folder structures, etc.

What it came down to was an upload script I was developing to use with a private forum. The image upload function didn't have any sort of checks on the files and the attacker managed to upload a copy of nstView which was then used to compromise the rest of the site.

Along with the steps above, I deleted all my old files that were not being used. I cleared old databases, as well as users that weren't in use. Sub domains and redirects were next, emails addresses and other logins came after that.

Lesson learned from this would be to treat my online files as if they were on my computer. They're much more open "online" which makes it even more important to stay on top of things. Thanks for the feedback.
 
Whenever you set up a new script its best to run it through one of many online injection test sites. They will tell you if any of your scripts are vunerable to an injection attack.
 
Status
Not open for further replies.