Jump to content

Recommended Posts

One of my first sites got hacked. It's on my server, which seems too not have any other affected sites. The index.php page was overwritten.

 

Right now, there is a plesk placeholder page up, and at the bottom resides a few iframes who's src links have been linked to a rather old IE exploit. It also contains some nasty looking links (nasty as in XXX). I suppose it's remotely possible that I somehow left the plesk placeholder page up by mistake when moving the site from another location, but I really doubt it.

 

The original site was nothing more than a single html page with very very simple php hooks. Bascially, buttons linked to index.php?id=1 kind of stuff. The page just used the id as image sources. Simple. There isn't so much as a contact form on it. So, the question. How in the world did it get hacked? A plesk exploit?

Link to comment
https://forums.phpfreaks.com/topic/47062-hacked/
Share on other sites

Found something in the FTP log. IP Addresses all over the board. Probably spoofed.  >:(

 

I had thought it might be packet sniffing but I haven't updated that site since october of 2005, and the ftp log shows this activity in February of this year..... Any other ideas how someone could have gotten in through ftp?

Link to comment
https://forums.phpfreaks.com/topic/47062-hacked/#findComment-229552
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.