perezf Posted September 8, 2006 Share Posted September 8, 2006 hello my website got hacked >:( and i was told they did this using a post in phpthey wrote a file to my server directory they added an index.html to ithow was that possible and how can i stop iti was told it was a php script Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/ Share on other sites More sharing options...
Nhoj Posted September 8, 2006 Share Posted September 8, 2006 Can we get a live preview of your website to take a better look? Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88147 Share on other sites More sharing options...
perezf Posted September 8, 2006 Author Share Posted September 8, 2006 its not in hacked state anymorebut http://2fr3sh.com Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88148 Share on other sites More sharing options...
trq Posted September 8, 2006 Share Posted September 8, 2006 There would be many different ways of doing this. You yourself are using php on your server I assume? Are you using switches with include statements per chance? If so, are you validating your includes beforehand? Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88149 Share on other sites More sharing options...
perezf Posted September 8, 2006 Author Share Posted September 8, 2006 yes i am using switches and what do u mean when you ask if i am validating my includes Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88150 Share on other sites More sharing options...
extrovertive Posted September 8, 2006 Share Posted September 8, 2006 http://www.2fr3sh.com/index.php?page=PricingPerhaps they hacked you after seeing this page and the ratesj/k...Anyways, was this through a form? What chmod do you have for the folder thy hack? Most likely, it's someone who's familar with the structure of your website. Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88154 Share on other sites More sharing options...
perezf Posted September 8, 2006 Author Share Posted September 8, 2006 yes and i havent check the folder settings i should check that give me a sec Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88155 Share on other sites More sharing options...
perezf Posted September 8, 2006 Author Share Posted September 8, 2006 all the write options are disabled to the folders and do y0u think the rates are to high Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88157 Share on other sites More sharing options...
perezf Posted September 8, 2006 Author Share Posted September 8, 2006 lol Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88159 Share on other sites More sharing options...
.josh Posted September 8, 2006 Share Posted September 8, 2006 you are going to have to post the code that has your form, as well as the script that processes it, if that's a seperate script, if you want anybody to give you any kind of real answer. and also, your thread seems to have devolved into a website critique worthy thread. stay on topic or this will be moved there. Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88171 Share on other sites More sharing options...
redarrow Posted September 8, 2006 Share Posted September 8, 2006 I see the problam your using the $_GET statement on all pages are you?and bye the way in essance getting hacked is a terrorable thing but is also a very common thing in computer programming the best way to acheve good results is to valadate all infromation and beetend your the hacker and try and hack your own php codes then add harsh condition to slow the hacking down.it is really hard to stop hacking on any websight the hacker will always get in but try adding lots of valadations.good luck.if so the correct conditein is to valadate the $_GET coditeion like so.the proper coreect link format.[code]<?echo"< a href='index.php?page=home'>Go to home page</a>";?>[/code]a $_GET with a url condition if page=="home" got there else dont.[code]<?phpif($_GET['page']=="home"){header("location: index.php");exit;}?>[/code] Quote Link to comment https://forums.phpfreaks.com/topic/20082-question-on-how-i-got-hacked/#findComment-88180 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.