PDA

View Full Version : Site Hacked by Liz0ziM?


Cky47
07-15-2006, 09:03 PM
Can someone check this out?

I was away on a little vacation and I came back to my site being hacked. All the files are screwed up.

http://www.boardingscene.com

Must have happened last night?

kall
07-15-2006, 09:08 PM
Looking fine to me here. :)

Cky47
07-15-2006, 09:09 PM
I started to fix back the site, but has anyone seem this from the same person yet?

"Hacked By Liz0ziM"

It must have been possibly a targeted hit...

I have backups of it, so he did no harm lol, I just wanna know how he got in and if he has attacked anyone else?

I hate having enemies is all.

kall
07-15-2006, 09:09 PM
Did it include a black screen and a pic of Michael Jackson?

I saw that on a hacked site recently. :(

Cky47
07-15-2006, 09:13 PM
Ok now this is weird... he got my cpanel?

No, all it said was...

"Hacked By Liz0ziM"

In plain text...

Looks to be he only replaced the index files?

I wonder if it was a host targeted attack?

Type Hacked By Liz0ziM into google, he has all types of things hacked...

peterska2
07-15-2006, 09:16 PM
That is very possible especially if it has also affected your cpanel.

Cky47
07-15-2006, 09:22 PM
Yeah... I wonder how he got in though.

:( Thats going to bug me.

At least it seems he just randomly picks websites to exploit, so hopefully no one else will experience this.

I would like to meet the guy though... Heck I would hire him lol

maximux1
07-15-2006, 10:00 PM
Yeah... I wonder how he got in though.

:( Thats going to bug me.

At least it seems he just randomly picks websites to exploit, so hopefully no one else will experience this.

I would like to meet the guy though... Heck I would hire him lol

He likely got in through an insecure script, such as a gallery addon/plugin - there was a nasty exploit in CMG not too long ago - Do you use that?

Likely, if he got in once, he setup shop - and he can get back in unless you figure out how he did it.

You can look for any irregularities with the following string of commands;

cd /usr/local/apache/domlogs;tail -n 5000 * | grep 'ptrace'

find /home/ -name "*.php" -exec grep 'passthru(' {} \; -print

find /home/ -name "*.php" -exec grep -i 'phpshell' {} \; -print

wget ftp://ftp.pangeia.com.br/pub/seg/pac/chkrootkit.tar.gz
tar xvzf chkrootkit.tar.gz
cd chkrootkit*
make sense
./chkrootkit


If you find anything interesting feel free to post back - damned hackers...

Hope this helps some.

Shazz
07-15-2006, 11:33 PM
Internet Explorer cannot display the webpage
________
List of Toyota vehicles (http://www.toyota-wiki.com/wiki/List_of_Toyota_vehicles)

slappy
07-15-2006, 11:41 PM
Actually it appears to be a server problem, rather than a browser problem. FireFox says the server timed out.

Regards,

Cky47
07-16-2006, 02:26 AM
No... I reported it to my host and the are switching me to a new server till they figure out what happened. They think they got in through to shared server and just got my account too.

Now it seems it was a skiddie who found a code and used it.

My host still hasnt fixed whatever happened.

reuben
07-21-2006, 07:46 PM
<a href="http://www.zone-h.org/component/option,com_attacks/Itemid,43/filter_defacer,BiyoSecurityTeam/" target="_blank">http://www.zone-h.org/component/opti...oSecurityTeam/</a>

Take a look at that.

He seems to be a part of "BiyoSecurity Team".