Warptweet Posted June 11, 2008 Share Posted June 11, 2008 I've been hacked once again, despite my greatest efforts. PLEASE hack my site, and tell me how you did it, and perhaps even suggestions on how to defend myself from the endless barrage of people who have nothing better to do with their lives other than ruin websites. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/ Share on other sites More sharing options...
helraizer Posted June 12, 2008 Share Posted June 12, 2008 Could you give us a link? Pwetty Pweze. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-563541 Share on other sites More sharing options...
Coreye Posted June 12, 2008 Share Posted June 12, 2008 I'm guessing http://www.uploadpoints.com/. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-563552 Share on other sites More sharing options...
corbin Posted June 12, 2008 Share Posted June 12, 2008 Look for the last mod time on your index file and then look through your Apache access log... Should give you a hint at which page is being exploited. There are of course better ways to find it, but you gave us no information at all.... Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-563649 Share on other sites More sharing options...
Warptweet Posted June 12, 2008 Author Share Posted June 12, 2008 Hmm... SQL injection attempt. However, only files were uploaded, none of my database entries were modified... Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-563657 Share on other sites More sharing options...
Daniel0 Posted June 12, 2008 Share Posted June 12, 2008 Uploads doesn't even work. Neither anonymously nor while logged in. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-563857 Share on other sites More sharing options...
helraizer Posted June 12, 2008 Share Posted June 12, 2008 I think someone found an exploit.. CANT TOUCH DIS HACKARY. ROFL Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-564255 Share on other sites More sharing options...
Daniel0 Posted June 12, 2008 Share Posted June 12, 2008 LOL. Perhaps opening the source for us to review it might help. I don't know if the OP is interested in that though. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-564284 Share on other sites More sharing options...
dsaba Posted June 13, 2008 Share Posted June 13, 2008 Hmm... SQL injection attempt. However, only files were uploaded, none of my database entries were modified... Why don't you log IPS? Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-564789 Share on other sites More sharing options...
helraizer Posted June 13, 2008 Share Posted June 13, 2008 Hmm... SQL injection attempt. However, only files were uploaded, none of my database entries were modified... Why don't you log IPS? If you meant IP address; he does log it. Only from what I can imagine, he's using a hidden field with value="<?php echo $_SERVER['REMOTE_ADDR']; ?>" and thus someone made an identical form pointing to the same place and and sent it with the hidden input value of 'i lurves no ipz'. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-564919 Share on other sites More sharing options...
Guest Xanza Posted June 13, 2008 Share Posted June 13, 2008 Yea, database uploaders are nice, but they are subject to hacks very easily... My advice would be to create a pure php file uploader... You'll be able to specify the files that are allowed to be uploaded, and blacklisted files just as easily only their are no vulnerable databases that can be hacked. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565116 Share on other sites More sharing options...
Warptweet Posted June 13, 2008 Author Share Posted June 13, 2008 It happened again. I have a backup of all files, so it took seconds for me to reboot the site. The new front page was actually quite funny. "CANT TOUCH DIS HACKARY. ROFL" And a video of "Can't Touch This". I actually listened to it a couple of times. I made some tight measures against the hacking.. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565160 Share on other sites More sharing options...
helraizer Posted June 13, 2008 Share Posted June 13, 2008 I think you mean 'was'. Done! See how easy that way? Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565214 Share on other sites More sharing options...
Warptweet Posted June 13, 2008 Author Share Posted June 13, 2008 I fixed the typo Sorry, was in a rush to restore the site. Please try hacking the website. I implement mysql_escape_string to practically every variable in my PHP. Also, for direct links, it direct links to a .php file which sends the direct download. You don't actually know the directory that the file is stored in. And the chances of you guessing it is too low to be considered possible. There are 1.84710571 × 10^89 possibilities Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565262 Share on other sites More sharing options...
ev5unleash Posted June 14, 2008 Share Posted June 14, 2008 Your site got hacked again! Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565310 Share on other sites More sharing options...
Warptweet Posted June 14, 2008 Author Share Posted June 14, 2008 It seems to be so easy for him. I made the upload form a whitelist where you can only upload files with a type that is specified. Regardless, he keeps coming.. I'm confused. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565339 Share on other sites More sharing options...
Guest Xanza Posted June 14, 2008 Share Posted June 14, 2008 Because he's not exploiting your script... He's "going in the back door" via MySQL. Which is why I suggested that you use a pure PHP upload system. :/ Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565370 Share on other sites More sharing options...
Warptweet Posted June 14, 2008 Author Share Posted June 14, 2008 I don't seem to understand what you mean in that, "back door". Almost every variable I can find is using mysql_escape_string. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565389 Share on other sites More sharing options...
Guest Xanza Posted June 14, 2008 Share Posted June 14, 2008 I really think you need to read the php docs http://us.php.net/mysql_escape_string... And again, go with a full php version of your uploader... It's the simplest way for someone of your experience. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565393 Share on other sites More sharing options...
Daniel0 Posted June 14, 2008 Share Posted June 14, 2008 Xanza, that's a bullshit advice. He is better off fixing it. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565420 Share on other sites More sharing options...
Guest Xanza Posted June 14, 2008 Share Posted June 14, 2008 haha, well if you ask me - someone that thinks they are protected by a single php function docent really have the technical knowledge to fix many security holes. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565436 Share on other sites More sharing options...
Daniel0 Posted June 14, 2008 Share Posted June 14, 2008 However, you don't learn it by neglecting it and doing it in another way. You're better off just learning how to protect yourself. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565458 Share on other sites More sharing options...
imdead Posted June 14, 2008 Share Posted June 14, 2008 I Get 403 Forbidden? Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565651 Share on other sites More sharing options...
Warptweet Posted June 15, 2008 Author Share Posted June 15, 2008 HYPER EMERGENCY: I wake up in the morning. Forbidden: Warptweet.com, caramea.com, uploadpoints.com, merandtroy.com, everything. All my sites, all my folder. I can't even access my files from my own highest-access cpanel. They locked down my server. I had to contact my host to fix the problem! I took uploadpoints.com offline. I made a backup and deleted all the files. For some reason, the hackers can STILL edit the index.php! I'm guessing they hid a .php file somehwere in my other directories. Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565772 Share on other sites More sharing options...
corbin Posted June 15, 2008 Share Posted June 15, 2008 Is it possible he figured out your CPanel, FTP, or SSH password? Link to comment https://forums.phpfreaks.com/topic/109810-hack-this-upload-site/#findComment-565779 Share on other sites More sharing options...
Recommended Posts