Please any ideas on how I got hacked
Hello,
I would like to know how it could be possible I got hacked. The hackers defaced the company website with a custom html file. I do not allow FTP, or SSH, just AFP.
There were no AFP logs at the time the files were "uploaded" Here are some entries form my log.
/var/log/httpd/access_log.1202342400:88.230.101.222 - - [07/Feb/2008:16:19:34 -0500] "PUT /zk.txt HTTP/1.0" 201 250
/var/log/httpd/access_log.1202342400:88.251.250.240 - - [07/Feb/2008:16:33:29 -0500] "PUT /folio.asp HTTP/1.0" 201 253
/var/log/httpd/access_log.1202342400:78.176.236.85 - - [07/Feb/2008:16:41:03 -0500] "PUT /testhost.htm HTTP/1.1" 201 268
/var/log/httpd/access_log.1202342400:78.176.236.85 - - [07/Feb/2008:16:42:09 -0500] "PUT /index.html HTTP/1.1" 201 266
/var/log/httpd/access_log.1202342400:78.176.236.85 - - [07/Feb/2008:16:42:14 -0500] "PUT /index.html HTTP/1.1" 204 0
/var/log/httpd/access_log.1202342400:78.176.236.85 - - [07/Feb/2008:16:42:33 -0500] "PUT /index.html HTTP/1.1" 204 0
/var/log/httpd/access_log.1202342400:88.238.249.221 - - [07/Feb/2008:16:44:51 -0500] "PUT /testhost.htm HTTP/1.1" 204 0
The index.html is the one that did the damage. Any ideas how they PUT files on my server. My gut says a php exploit. I turned off allowurlfopen, could that have been the hole?
Any ideas would be appreciated.
That your web server was able to write into the web directories was probably the central configuration issue here. This is a Really Bad Idea. The web server can and should have read access, and should not have ownership nor write access, save to specified and potentially protected subdirectories, and then only as required.
The usual trigger with php vulnerabilities is down-revision software; a php-based package that is insecure. Either due to long-standing bugs that have been found, or due to a failure to maintain a current version of the software. (The CMS systems I'm fond of do require some diligence around staying current.)
php code needs to validate its input. More than a few folks do try to jam unexpected data into the php code, seeking to cause it to perform untoward acts. If you review your logs, you'll probably find evidence of cross-site scripting attacks, too. Here's the [Wikipedia XSS|http://en.wikipedia.org/wiki/Cross-site_scripting] article.
There are any number of other attacks against php code, and web masters will tend to use the conf configuration file or the .htaccess file to try to protect against various of these. There are gremlins around the net that look for weak php mail scripts, etc.
As for testing against PUT, look to use +curl --upload-file+ at the shell. There are other ways to do this, though curl is among those built into Mac OS X Server. (telnet, too, can issue PUT, but that's too much like work.)
Similar Messages
-
My adobe garamond font has disapeared from my font book any ideas on how to get it back please?
Got it sorted
-
I am trying to open PDF files from safari, but when I click on them they open in a separate window and the information is encrypted. Any ideas on how to get them to open them in Adobe? Any help please!
The pdf is loading as html code. If you save it, it will download as :
605124.pdf.html
Change the extension to .pdf
And it opens and works perfectly, I just tested it:
Use this link to download it automatically:
http://saladeaula.estacio.br/arquivo.asp?dir=00/1020624/605124.pdf&num_seq=59828 4 -
my macbook's safari wont open. At first it got deleted and so i got it back by bluetooth and now it wont open because of the version of mac OS X update. Any ideas on how to update it or get safari on my mac? It got completly deleted i checked everywhere including applications but its gone. it got deleted :/
Here it is : Safari 5.0.6 for Leopard
-
I have a new Macbook Air, 6 months old, and for the last few days the fan had run continuously, this is the first time it has ever run, and now it won't stop, the fan starts up as soon as I turn it on and the computer seems to running more slowy.The computer is not hot but I am worried it may burn out,.Any ideas on how I can fix this please ?
Hello dwb,
Here is the screen shot, just the top half, there are another 10 pages, but I guess this should enough for you to have an idea of waht is going on, bit small I am afraid. No, I don't have any apps setup to run when I open my computer, the kernel, varies between 290 and 305 per cent ish.
Would that PRAM thing help ? I think it may be the computer itself, well something inside, as this the first time that the fan has ever started running since I have this computer, even when I have 3 or 4 apps running.
Thank you again for your advice,
Regard,
Beauty of Bath -
My music files etc were all located on my old laptop which was stolen. I have just plugged my iphone in to my new computer and it has deleted all my files. Has anybody got any ideas on how to retrieve the files?
WINDOWS?
Connect the iPod to your PC. If iTunes starts syncing (ie erasing) your music automatically, hit the X in the upper right hand corner of iTunes display, to the left of the search box, to stop it.
In Control Panel, Portable Media Devices, double-click your iPod.
In the Tools menu -> Options, in the View Tab, check "Show hidden files and folders."
Navigate to the Music folder. On my 'pod, the full path is
Portable Media Devices\NAME of IPOD (F:)\iPod_Control\Music
Select all the music folders, and drag and drop them into a folder on your hard drive, or directly into iTunes.
And you're done! The iPod music folder structure is strange and inexplicable, but once you move your files into iTunes you can set it to automatically organize your folder by artist and album to clean that up. (To do this, in iTunes Edit menu, choose Preferences and in the Advanced tab, check "Keep iTunes Music Folder organized."
might be out of date worth a try -
Hi guys...I have just got a new computer and want to get my library back up and running on it. However I seem to be missing some of my iTunes music purchases. Any ideas on how to get them back? They show up on my ipad but not my actual itunes account.
Hello there, Capricious13.
There are great pointers in the following Knowledge Base article. Depending on where you see the content and where you want to get it to, this should guide you to putting it in the right place:
Downloading past purchases from the App Store, iBookstore, and iTunes Store
http://support.apple.com/kb/ht2519
Thanks for reaching out to Apple Support Communities.
Cheers,
Pedro D. -
Final Cut Pro X keeps freezing when sharing my work to You Tube, it does about 90% of the upload and then seems to get stuck. Any ideas on how to resolve this please?
this is a perfect question to ask the users in the FCP X forum. Good luck. https://discussions.apple.com/community/professional_applications/final_cut_pro_ x
-
I had Acrobat Standard 9.5 on a laptop that broke. Adobe Acrobat Standard is paid for and all I need. I had to get a new PC (Windows 8.1) and I did downloaded Standard 9.5 but when I went to install it the installer gave me an “Error applying transforms please ensure specified transform paths are valid”. Any ideas on how to fix this?
Rahul,
No error numbers other than the message I mentioned previously.
I tried the transforms repair and it reported no Acrobat product (correct, none yet installed) or no administrative privileges (I am the administrator and have done previous administrative actions).
When I unzip the Acrobat file this is what is in the setup ini file:
[Startup]
RequireOS=Windows XP
RequireMSI=3.0
RequireIE=6.0.2600.0
[Product]
msi=AcroStan.msi
Languages=1033;1031;1036
1033=English (United States)
1031=German (Germany)
1036=French (France)
CmdLine=TRANSFORMS="AcroStan.mst"
[Windows XP]
PlatformID=2
MajorVersion=5
MinorVersion=1
ServicePackMajor=2
[MSI Updater]
Path=WindowsInstaller-KB893803-v2-x86.exe
Thoughts?
Thanks again,
Tom -
Hi, since upgrading to OS6 I am being directed to apple's US store rather than the UK one. Any ideas on how to reset UK store as default, please?
i also am having this EXACT same problem and alot of others seem to be too? i wonder what is going on here! if anyone from apple reads this, maybe it is something you can look into? My mac did not come with a start up disk and i accidently deleted the iphoto app... i have 2 apple I.Ds but i dont use the one originally registered. i am aware i will have to buy the app again in this case so please let me buy iPhoto please! and thanks!
-
my friends mac book pro never got an upgrde that allowed her to have the app store on her dock, now I can't help her to upgrade to OSX mountain lion... any ideas on how to do this?? it's driving me crazy!
Bad choice, since the cost is exorbitant. Snow Leopard ($29 USD) is available from its online store's telesales agents.[1-800-MY-APPLE (1-800-692-7753) or Customer Service and Sales Support at 1-800-676-2775.]
Additionally, you can get a MAS redemption code via the same route. See https://discussions.apple.com/thread/4140947?tstart=0 for details. -
After downloading and trying to install the newest version of i tunes on my pc, I got an error message telling me: unable to locate component MSVCR80.dll. Now I can't use the version I had and obviously not the newest version. Any ideas about how to fix ?
Solving MSVCR80 issue and Windows iTunes install issues.
Thanks to user turingtest2 for this solution.
Solving MSVCR80 issue and Windows iTunes install issues.
If the above doesn’t do the trick entirely, then use the instructions in the following as it applies to the version of Windows you are using:
HT1925: Removing and Reinstalling iTunes for Windows XP
HT1923: Removing and reinstalling iTunes for Windows Vista, Windows 7, or Windows 8
You may be required to boot into safe mode to complete the folder deletion process. -
I switched my number to my daughters iPhone 4 and she got an iPhone 5. When I send txt using iMessage, she is getting a copy of the txt on her phone as well. Any idea on how to stop this?
This occurs when two people share the same apple id for imessage.
settings - message - send & receive - uncheck or remove the apple id.
do the same for start a new conversation. -
I have a bad idea I might of blown up my iPod touch 5th generation battery by a mistake, please any suggestions on how i could try and turn it on? It is completely blank and it had full charge before it shut off. In need of desperate help :-(
Would be very grateful if someone could get back to me
Thank you very much- iOS: Not responding or does not turn on
- Also try DFU mode after try recovery mode
How to put iPod touch / iPhone into DFU mode « Karthik's scribblings
- If not successful and you can't fully turn the iOS device fully off, let the battery fully drain. After charging for an least an hour try the above again.
- Try another cable
- Try on another computer
- If still not successful that usually indicates a hardware problem and an appointment at the Genius Bar of an Apple store is in order.
Apple Retail Store - Genius Bar -
A Headphone jack got stuck in my iPad. Any ideas on how I can get it out?
I was listening to music, and I forced the headphone jack inside, and when I try to get it out, it snapped. any ideas on how I can fix this? can Apple replace my iPad for another one, or can they fix it?
You are the second person tonight that has done this and reported it on here. I would not tell them that you "forced it in" or that could be considered misuse of the iPad!
If there is enough of the "metal part" sticking out of the opening, maybe you could remove the piece with a very small pair of plyers or tweezers - but - if you are not at all comfortable with doing that - then don't do it. Take it to an Apple Store and ask them to remove it for you.
If you do try to remove it - pull straight out from the opening - don't pull out on an angle.
Maybe you are looking for
-
Server 2008 R2 Roaming Profiles
I am trying to get roaming profiles for Win Server 2008 R2 to work. I followed the instructions given by Lanwench at the following link: http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/2e3d27cf-38ec-433d-8bee-2a69a73871a5/ I have
-
hello people,... Facebook app was never my favorite on my BB. It's sluggish, slow, and it simply sucks. Until today,... I've removed my memory card from handheld and voila. Facebook worked GREAT! really fast and as I, and everybody else expect! But t
-
EDI Integration using PI with third party connectors
Hi Experts , I would like to know the extra cost factors associated if going for EDI integration with PI with third party connectors like seeburger . 1. We have NW 2004s ECC installed . Do we need to purchase PI separately? If yes how much will it co
-
Hey, in one of the tools I am currently writing I am displaying data in a JTree. The user can edit the data that goes with the nodes,save the tree (not yet) and load a tree from a local file. Right now I want the user to be able to "reset" the tree.
-
I put a Windows 8.1 Pro desktop into hibernate mode. I cannot understand how it is possible, but the next day the computer is turned on. No one is hitting the power key. The BIOS is NOT configured for scheduled wakeup, and wakeup LAN features ar