URGENT : Webserver constantly hacked!

Hi there!
We are a public school and our webservices run on a OSX Server (10.4.10, latest updates done) and serve pages using PHP and mySQL. Due to an SQL Inject problem I can't seem to be able to trace, our website gets constantly hacked by some turkish kiddies who think this is funny, where this always represents a 6 hours job for us to clean the mess up ...
Anyway, it seems (I could oversee by chance an action) that they are using the c99.php script which they inject inside my directory. As we use a CMS, I can't simply writeprotect the directory, thus eliminating these injects. Trying to update the weakpoint seems to be impossible as IMHO this means updating PHP and apache, which is not recommended to do manuallly (we already had trouble with manual procedures and I'm not willing to try again).
Now : Does anyone have the same/similar trouble with these hacks? If so, could it be possible to share these experiences with me? What did you guy do? Would an update to Leopard-Server outrun this? If you are afraid to post, please contact me via EMail, although I think that this topic needs to be discussed openly!
ANY help will be GREATLY appreciated!
Cheers!
marc.

The c99.php exploit uses PHP's 'remote file includes' ability to embed a remote page within your page.
The obvious solution would be to disable that feature. It is an inherent security risk, as you've found, but you'll need to check all other pages on your server to see whether they use the include function.
Your simplest solution may just be to deny remote file includes:
http://uk3.php.net/manual/en/ref.filesystem.php#ini.allow-url-fopen
The other thing to check is how they're uploading files - does your site allow users to upload content?
If so then you may need to implement some kind of filter that sanity-checks pages as they're uploaded. Without knowing your environment it's impossible to tell the best way to do that.
If you don't expect users to be able to upload files, then you need to find out how they're doing that. Are they logging in using some account? If so, revoke that account's privileges. If they shouldn't be using that account (and if they're in Turkey it seems unlikely), then they may have compromised that account, e.g. by guessing the password), so you should check the access logs for any suspicious activity.
You might also want to consider whether or not you expect to get any legitimate traffic from Turkey and just block their IP address from accessing your server at all. It's a poor solution since they can often proxy around any IP address blocks, but it might be worth a start, at least to let them know you're onto them.

Similar Messages

  • I'm so Frustrated!!!

    Back story ...
    We live in a house with a barn at the end of the garden.  We have converted the barn and are moving into it for the next year (or maybe for ever) whilst we gut and renovate the house. 
    My first book has recently been published and I both urgently and constantly need phone and internet access for marketing it. I have sent out press releases and magazine pitches via email and need to respond immediately to replies. I tweet and use Facebook, Linkedin and other social media, all of which have a positive effect on sales and keeping my name and my book in people's minds.  My agent, publishers and publicist communicate via a joint Dropbox in the cloud which now, of course, is not available to me.
    Even more importantly we have a family member with terminal cancer and need to be in touch with him (so far he is still living alone in his own home inNewcastle) on a daily basis.
    The transfer of the line was arranged for Friday 26th July between 8.00 am and 1.00 pm.
    Friday 26th July
    •                     No-one showed up all morning but in good faith we completed moving our home into the barn. At 12.55 pm our phone line was disconnected and about 15 minutes later I received a text message on my mobile thus ...
    "We are really apologize (sic) that the engineer could not visit your new address to activate the telephone line.  Reason for Delay: Job Delayed with TRAFFIC MANAGEMENT.  Next Update Friday 16 /08/13.  We will keep you updated so that you needn't call us back.  Thank You Bt (sic)"
    •                     We borrowed our neighbours' phone to call the 0800 number (0800 800 150) and were held in a line for about 20 minutes. I then spoke to a very helpful and sympathetic girl in India who gave me the number to call. It was 0800 800 150! 
    •                     I called again and got to talk to a guy in Birmingham who was also very helpful and he got in touch with the engineers who told him that the work could not be done because "it is a very busy road" and they need clearance from the council.  Seemingly they assume a road is quiet till proved otherwise! 
    •                     I asked, of course, for the line to be switched on again but was told this is not possible and I would be updated (just updated mark you, not transferred and connected) on 16th August.
    •                     I asked if there was anyone in charge I could talk to and was told I could write to someone called Warren Buckley or something similar, I think.  I said it was more urgent than that and was told a manager would call me back on my mobile within the hour.  He/she didn't.
    •                     Just after 4.00 pm I called again and spoke to another sympathetic and helpful girl who said she would do her best to arrange for the service to be switched back on sometime Monday (although transferring the line would still not happen till at least the 16th) and would call me back to let me know how she got on.  She didn't. 
    Monday 29th July
    •                     I spoke to a more useful sort of guy who set us up a temporary phone number to our house and suggested I get a dongle for temporary internet access.
    •                     As it happens I had a radio interview arranged for this day to be conducted over the 'phone and as I had to use my mobile with less than perfect reception the interview was cut from fifteen minutes to five. 
    Tuesday 30th July
    •                     I spent the day at the home of a good friend willing to let me take over her internet connection for several hours contacting people saying that I would be out of action for day or two till I got a dongle.  Sadly this information was wrong.  My friend lives 16 miles away so this is not something I can do frequently especially as I don't drive.
    Wednesday 31st July
    •                     I tried to get a dongle but without success as all suppliers say there is not sufficient reception where I live - PL26 7YH.
    •                     Although the account is actually in my name, as I was getting so very upset by this stage, my partner then rang 0800 800 150 and spoke to a girl in Durham who said we could cancel the order and have our old number back with 48 hours,  We could then rearrange the transfer for a later date. This seemed the best answer since I need the internet as soon as possible so, to enable us to do this, she said she'd transfer us to the correct department but unfortunately it was a wrong number!   
    •                     He re-dialled and got to talk to a guy in India who didn't really understand what he was saying but eventually decided he couldn't do what we were asking and indeed said no-one in India could deal with this problem and he couldn't transfer us to anyone who could. 
    •                     We tried again - same result. 
    •                     Third time lucky-ish he got a Scots guy who refused to say where he was but at least they understood each other.  After about half an hour of explanations and discussion he came up with the information that he couldn't deal with it - we needed to speak to Open Reach.  He said he was transferring us to ....
    •                     ... Open Reach, their Indian office, who after about 10 minutes pondering decided to transfer us to ...
    •                     ... Open Reach in Warrington I think  My partner went through the whole thing again, phone number, order number, address, what the problem is, etc. etc and they had a long chat and she was so helpful he asked to have her direct number in case he needed to speak to her again but she said there was no direct number. She did say, however, that in her opinion cancelling the order was not the right thing to do as it would take until at least Monday 5th August to reconnect and probably take our internet provider another 5 working days to reconnect us.  She also said there was no guarantee that we would get our original number back. 
    •                     He was then transferred to Order Management in India, the guy's English was not very good and he kept saying he would "do something to make" my partner speak to his supervisor which eventually he did.
    •                     The supervisor asked for my partner's name, Paul Clementson, and thereafter referred to him as Mr. Poll!   Asked if it would be possible to speed up the procedure and transfer the line within the next few days he said "no".
    Thursday 1st August
    I posted the above in a letter to the BT Correspondence Centre at an address given to me by one of the friendly folk above.
    Saturday 3rd August
    I received the following text ...
    "Hello - this is a message from BT. This is to confirm we will contact you20/08/13 by 20.00 to discuss the delay in activation of your services.  There is no need to contact us as we will not be able to provide you with any more information.  Thank you. Sender 2123001"
    As you see they will call me on 20th August to "discuss the delay in activation of your services" but I may have self destructed with sheer rage and frustration by then!
    So far we have spoken to about 12 different people being held in line over and over again for about 20 minutes per time, repeatedly giving all the details and telling our story.  In the end we heard so many different versions of what could or should happen that we don't know what to believe. 
    The road we live on is fairly busy but nothing out of the ordinary just a single carriageway main road through a village in Cornwall, the telegraph pole is on our side of the road directly outside the house, the line needs to be extended for a few yards down our garden.  We own both properties. 

    That is a beautifully written account and reminds me of my own experience, which is with a line fault.  For some reason it seems that if anything occurs that is out of the ordinary, even just a mistake, then rather than being dealt with as a priority you slip to the bottom of the pile and face a really long wait.
    In my case BT have needed to call in digging contractors three times.  The first time it took 6 days for them to come.  The next visit was after a further 12 days and the third visit will be 24 days thereafter, if it happens on schedule.  One forms the impression of an increasing reluctance to take action, rather than an increasing urgency.    

  • URGENT: Final Cut Pro Constantly Quiting

    Hello Everyone
    I am hoping that you will be able to help me out with this large issue.
    First off I am using:
    Apple Final Cut Pro 5.1.4 within the Final Cut Studio 5
    on an Intel Core 2 Duo 2.33GHz iMac 24" with 3GB of Ram and 512 Video Card from nVidia
    When I open my project file from double clicking on it I can not export, import or open another file, the application quits.
    So my problem is the application is constantly quitting when I go to open a project file from within FCP as well I can not import or export any files, without the application quitting.
    I have tried wiping the preferences using 2 different programs and doing it manually.
    I have tried re-installing FCP following the instructions on the Apple Support web site.
    This is urgent we need this to be working for a film festival and I am stuck.
    please respond.

    Reinstalling FCP would have been my suggestion, that's what I finally had to do a few weeks ago. Preferences usually do not affect this behavior AFAICT. On my systems, quitting without an error box or without an offer to send comments to Apple indicates a bad media file somewhere in the project. So we configure FCP to open into a blank project and then try to figure out what might have been messed up. It is usually one of the last rendered or imported media files.
    Listen, this is not necessarily the best advice. You should wait till you get other suggestions
    So, suggest your sort your scratch folders by date, move everything that was created AFTER YOUR LAST GOOD SESSION to the trash and try it again.
    Warning, FCP can look in the trash so you may have to actually empty it and recreate all of those missing files.
    bogiesan

  • ~URGENT~ Hacked Skype Account ~URHENT~

    Hello, I am Micheal (poppopsea) on Mar 28, my account password was changed as seen here: http://prntscr.com/6xgzvf , I been trying to get the account back since. I have filled out the password recovery form about 20 times and each time I get an email for my ALT account "[Removed for privacy]" I am just about to lose my **bleep** Skype. I believe the same person/people who did this have just hacked my paypal and made payments on it to a fake email under my name. I contacted paypal support who proceeded to screw me over by saying there was no evidence considering the I.P. was private and the email the funds were trandfered to was under my name. These people have royally screwed me. They have stolen my skype, $756.57 from my paypal. And now you people are refusing to give me support. Support says they cant go off I.P. logs even though that should be proof enough that the password change was not me. I have contacted email support, live chat support, and neither have been able to help me. This is my last resort. If I cannot get my skype back I will take legal action, seeing as nothing was done towards a malicious attack. These people have completely **bleep**ed me over. I am sick of nothing being done about this. Help me out please. And I swear if I have to fill out that **bleep** password recovery forum one more time, I am going to go off.

    Sorry guys, I know it can be a bit unpleasant to fill out forms especially when time is of the essence in matters such as these. I can assure you that the Customner Support team which handles compromised accounts can help but are unable to without first getting all the information they need to proceed.
    The compromised account form is a bit different in that it would let the staff know there's an urgent issue and to lock the account at which point they would look into the account history and go from there. Before any of that can occur, they need to verify that the person filing the claim is the actual account holder and that the claim is an authentic one. If there's already a claim in progress, odds are they are already looking into things and is the best that can be done.
    I'm sorry for the delay as sometimes it takes time to process these things.

  • Urgent, hacker attack on our site, BS subscription is off...HELP!!!

    Hi guys,
    We had a hacker attack on our site during the last several days. We solved the issue and stopped the attack, but they ate all our BS subscription for this month and our site is 100% out now!
    Who can we contact to reinforce the subscription for this month? It's super urgent!

    Hi Alexey,
    For subscription question I suggest you contact with Azure support team ASAP. Please try this channel:
     http://www.windowsazure.com/en-us/support/contact/
    Any information, please let me know.
    Regards,
    Will
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • I have had 3 days worth of unauthorised purchases. How can I get my money back?  I have changed my password again and I have disabled my credit card.  My account is constantly getting hacked

    I am sick of getting hacked..... This is the 3rd time my account has been hacked.  This time it has only been for $30-40 but it is very alarming that it is getting hacked at all.  I have changed my password agian to a random thing.   Lets see how long I can stay hacked free this time.  If this continues I may have to put a formal complaint in to Apple.  And maybe only buy non-apple products....
    Ellen

    It's most likely not you, no matter what they say. I have noticed a LOT of fraud with itunes, even with my own account. One time I caught them doing a database restore. I know this because my password automagically reverted back to an old one! I'm an IT guy who helped design DOD classified networks in the mid-pacific. I know security. The best protection for this is to NOT have a credit card listed in iTunes. Use iTunes cards ONLY. It's a pain, but until they step up, it's all you got.

  • URGENT Skype issue with hacking accounts

    Hello,
    I'm Dan, and just about an hour ago, I managed to recover my account after a 30 minute live chat. I run an online business and a lot of my work involves Skype. In other words, Skype is key to my business. All of my partners work through Skype, so without Skype, I'd be in a bit of trouble.
    At 7am this morning, I checked my emails and found I had an email sent to my primary Skype email address stating that my "Registered email successfully changed". Immediately I knew what had happened.
    I contacted Skype support (after having to buy a premium account for £6), they were very helpful but I was not happy about paying £6 due to an issue on Skype's behalf. After my live chat was closed I was told to be sure that I don't get phished or install any kind of virus which may discover my Skype password, I knew that these would not be benefitial due to the circumstance.
    So how does it work?
    Before I begin explaining, I am referring to the person who changed the email as a "hacker".
    So, firstly, the hacker contacts Skype support, I don't know whether it was live or not but they had to contact support. The hacker claims they are me, stating that they forgot their password and you can't access your email either, so your primary email would have to be changed. Ofcourse, there is some verification. The person at the other end of the support chat will ask for some recent activity on your account.
    In my case, the hacker had used multiple VPN's to add me, had added me on several accounts, this was completely oblivious to me, that they were all the hacker. I had accepted these accounts as the contact requests seemed like they were legitimate. So, all the hacker had to say was 1. I added "Micheal Potter" today. 2. I added "Randy Parker" today and so on.
    They may have been asked to verify an address, this wasn't struggle for the hacker. For me, the hacker had to do a simple WHOIS lookup on my domain. The majority of people have their address openly available somewhere, I know for sure that my address is on many forums, websites etc. So just stating your address, is definetely not enough information.
    Shortly after, my email address must have been changed and it is surprising that Skype have not done something about this common flaw in their security.
    How can this be resolved?
    Not allow the changing of emails on accounts - if you have an issue accessing your email. you should have your email provider deal with it.
    Add further verification e.g. phone numbers, secondary emails that they must verfiy, proof of address sent over (you'd never see another company changing information without ID sent from that email address or further verification other than just confirming some account activity.
    Atleast check the IP address the support request was sent from!
    I hope you look into this problem and resolve it immediately.

    I watched as this happened, and many other around the same time. There are guides being sold on how to exploit your support team and steal accounts. I no longer feel safe using skype, and I am really scared right now. I share a lot of very personal things on skype  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    Shame on you,
    xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

  • My Skype id is hacked, Urgent Help Please?

    My Skype id is hacked. Hacker is contacting all my ids. he have changed email id too. please let me know how can i block my Skype id and get it back.
    Also whats the contact number of Skype customer support so that I can call to them?
    Regret is unprofessional.

    Dear Readers,
    Please remember, as our Community Guidelines do explain, this Community is a public website, and is not a branch of Skype Customer Service.  Therefore, first things, first: for your safety and protection, please never, ever include any personally identifiable information such as your real name, Skype account name or password, e-mail address, or a telephone number in a post on a public Community or forum such as this.
    Please see these FAQ articles for next steps:
    https://support.skype.com/en/faq/FA10920/what-can-i-do-if-someone-has-taken-over-my-account
    https://support.skype.com/en/faq/FA12053/how-can-i-recover-my-account-if-it-has-been-suspended
    Regards,
    Elaine
    Was your question answered? Please click on the Accept as a Solution link so everyone can quickly find what works! Like a post or want to say, "Thank You" - ?? Click on the Kudos button!
    Trustworthy information: Brian Krebs: 3 Basic Rules for Online Safety and Consumer Reports: Guide to Internet Security Online Safety Tip: Change your passwords often!

  • URGENT Mod Help needed please. Hacked account and ...

    Please help. My sons account has been hacked and live porn was sent to all his friends along with files that we don't know what is inside.
    We have informed the police because of the porn content but now the hacker is hacking my sons friends and demanding to speak to my son.
    Please help

    Excellent first response.
    Have your son change his account password immediately if not already done.
    Also have him change the password of the registered e-mail address on file as a proactive measure.
    The police know how to contact Skype directly with an official request for assistance if required.
    Hackers typically gain access to peoples' accounts - Skype and otherwise - via password crackers or other password-guessing techniques.
    Run security scans and software updates on your son's computer - run your preferred anti-virus/malware/spyware program using the latest virus signature files available in case your son inadvertently downloaded malware which is allowing the hacker access to the computer.
    If anything else seems amiss or awary, contact a local computer professional for further assistance.
    Was your question answered? Please click on the Accept as a Solution link so everyone can quickly find what works! Like a post or want to say, "Thank You" - ?? Click on the Kudos button!
    Trustworthy information: Brian Krebs: 3 Basic Rules for Online Safety and Consumer Reports: Guide to Internet Security Online Safety Tip: Change your passwords often!

  • Urgent!! Account hacked while signed in

    This far from the usual hacking complaint.
    While I was logged into my account and IMing with a friend, someone sent a message from my own account/username, and I didn't know it was being sent until it already appeared in the window. It appeared mixed in amongst the messages I had actually written. As if someone had just popped in, typed something, and then ran away. What's even more disturbing is that the message included personal information.
    I don't know how this is possible. As far as I know it's not possible for two people to be logged into the same account, however, I didn't send that message myself and yet somehow it ended up in the chat window.
    Can someone clue me in on how this can happen and who might have the type of skill to do something like this?
    Help!! I'm really worried right now!!!

    It's a normal thing for a SKYPE account to get hacked. Infact, Skype actually like it. It helps them charge more to their users than they normally would. SKYPE INVITES YOUR ACCOUNT TO GET HACKED. Solution? Close your account, get a Yahoo Voice account; they're the same VOIP backbone...

  • External DTD in Webserver not found.... Urgent help required

    I have my XML file and its DTD located in the Webserver. I am trying to validate the XML file, but i keep getting the message that DTD not found despite they being in the same Directory...
    Please help...I know i m doing everything correct...
    why the Dtd isn't getting found?

    Specify Dtd as a file url.
    <!DOCTYPE root_element SYSTEM "file://c:/exampleDtd.dtd">

  • URGENT! Hacked Account

    My friend's account has been hacked and it keeps sending out spam messages to others. 
    She has changed the password but it automitically signed off whenever she tried to log-in.
    At the end, she decided to delete the account, but it still appears to be online on skype and keep sending out the spam messages asking people to purchase something online. 
    She can't login to the email anymore so i'm posting the message for her.
    Could somebody please sort this out for her asap as she doesn't want her friends to have any financial loss. 
    Best
    Wil

    Hi, Wil, and welcome to the Community,
    The best she can do is to contact Skype Customer Service directly to report the account is still being used.  They will probably also recommend running a complete software update and patch installation cycle, as well as to run her preferred anti-virus/malware/spyware software suite using the latest virus signature files available.
    We here in the Community do not have the tools to sort these types of account-related issues.
    This FAQ article explains the details:
    https://support.skype.com/en/faq/FA109/i-can-t-sign-in-to-skype
    Regardless of your account type, you’ll need to know your registered email address to recover your username or password. This is the email address you used when you signed up for Skype.
    If you know your registered email address, but want to change it, click here.
    If you don’t know your registered email address, or no longer have access to it, contact Skype Customer Support for further assistance.
    Best Regards,
    Elaine
    Was your question answered? Please click on the Accept as a Solution link so everyone can quickly find what works! Like a post or want to say, "Thank You" - ?? Click on the Kudos button!
    Trustworthy information: Brian Krebs: 3 Basic Rules for Online Safety and Consumer Reports: Guide to Internet Security Online Safety Tip: Change your passwords often!

  • Skype hacked. [URGENT]

    this night, when i was sleeping, i got my skype hacked and he changed my password.
    i don't know how to fix this, and it should be fixed ASAP because i was a trusted member on a forum, if nothing gets done, the hacker can run away with hundreds of dollars.(by scamming other members)
    please help me going through this fast, thanks!
    posting this from the skype [***], the skype that was hacked is '***'
    Skype account names redacted to protect privacy.

    please delete/block my skype, so the hacker can't do anything.
     edit: never mind, i requested a recovery

  • HT201363 My Apple ID is hacked by someone so how can I stop it . It's really urgent

    I Got notification in my mobile from which I come to know that my Apple ID is used by someone else. Pls help me as fast as you can so I can stop fraud

    go to settings, icloud, then click on your name, then change your password

  • Urgent Email hacking

    Someone has been using my email address to create skype accounts. they have created 2 accounts so far. After changing the password for the first they created another. They also added themselves to the account. Their name is saba illahi. skype name is saba.illahi2. Really weird but anyway to stop this? Or find out who is doing this at all?

    report them to [email protected]
    IF YOU FOUND OUR POST USEFUL THEN PLEASE GIVE "KUDOS". IF IT HELPED TO FIX YOUR ISSUE PLEASE MARK IT AS A "SOLUTION" TO HELP OTHERS. THANKS!
    ALTERNATIVE SKYPE DOWNLOAD LINKS | HOW TO RECORD SKYPE VIDEO CALLS | HOW TO HANDLE SUSPICIOS CALLS AND MESSAGES
    SEE MORE TIPS, TRICKS, TUTORIALS AND UPDATES in
    | skypefordummies.blogspot.com | 

Maybe you are looking for