Go Back  FlyerTalk Forums > Travel&Dining > Travel Technology
Reload this Page >

My website was hacked!

Community
Wiki Posts
Search

My website was hacked!

Thread Tools
 
Search this Thread
 
Old Apr 15, 2007 | 4:16 pm
  #1  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
My website was hacked!

I have a website at www.travelersvideo.com. I check it from time to time to make sure everything is okay and looked at it today. Apparently, my home page (index.htm) was hacked and a bunch of links to various adult sites were inserted. I immediately downloaded the index.htm page to save as reference, and uploaded the clean index.htm. The site is safe if you want to see it.

Reviewing the source code for the hacked index page, I found a bunch of links, along with some java script.

How could this have happened? No one has the password to my account at my web host except me. I don't understand how someone could have gotten access to my index page. Needless to say, I'm pretty ticked off and I'm looking for someone to blame.

Any of you IT gurus have any ideas?

---------------------------------------------

It now appears that all my web pages were hacked. It was easy enough to FTP the non-hacked ones back to the my site, but this is very disturbing. Judging by the dates of the files, there were two separate attacks, one on April 6th, and one on April 14th.

Should I abandon this web host and get another?

Last edited by PTravel; Apr 15, 2007 at 4:25 pm Reason: More info
PTravel is offline  
Old Apr 15, 2007 | 5:21 pm
  #2  
FlyerTalk Evangelist
40 Countries Visited3M100 Nights20 Years on Site
 
Join Date: Sep 2000
Programs: BA, AA, DL, KLM, UA
Posts: 37,489
First thoughts would be with a crappy web hoster that didn't upgrade vulnerabilities in their webserver.
ScottC is offline  
Old Apr 15, 2007 | 7:51 pm
  #3  
 
Join Date: Nov 2002
Location: San Francisco, CA
Programs: US CP, *wood Gold, Marriott gold, Hilton something
Posts: 1,458
Along the lines of what ScottC said, I think some app somewhere on the server was at risk. The potential irony is that this week's Security Now was all about SQL code injection vulnerabilities. Depending on how your hosting company's server is setup, it may not even be your fault. If they only have one instance of SQL running, for instance, and someone else is using a vulnerable app then it could give a malicious hacker access to the entire server...thus your page was just a victim and not even the subject of an attack.

That being said, a little more info would be helpful (not only from a diagnosis standpoint but perhaps to help others)... For instance, almost every budget or even 'business' plans, hosting companies only supply FTP and not SFTP. Since FTP is soooo hackable, that alone could be the problem. Then again, if your run any 'apps' on your page, they could have exploits.

I use Joomla to host some of my sites and I've noticed that the security is good, but not boomproof by far... Anyway, a little more info would be helpful.... and if you hear more from your hosting company, please keep up posted! I think we are all very curious as to what the problem may have been (and how to prevent it).
SpaceBass is offline  
Old Apr 15, 2007 | 7:59 pm
  #4  
 
Join Date: Nov 2002
Location: San Francisco, CA
Programs: US CP, *wood Gold, Marriott gold, Hilton something
Posts: 1,458
you know... I was looking at your site... I'm pretty sure all your photos were hacked and are infected with some henious virus... I'm guessing all your copies are runied too... I guess, I mean I dont mind, if you want I'd be glad to go back and take them again if you need some help...just send me the tickets
SpaceBass is offline  
Old Apr 15, 2007 | 8:50 pm
  #5  
 
Join Date: Jul 2004
Posts: 704
Originally Posted by PTravel
I have a website at www.travelersvideo.com. I check it from time to time to make sure everything is okay and looked at it today. Apparently, my home page (index.htm) was hacked and a bunch of links to various adult sites were inserted. I immediately downloaded the index.htm page to save as reference, and uploaded the clean index.htm. The site is safe if you want to see it.

I just looked at your site.... are you sure you uploaded a new index.htm?

At the end of your </html> tag, there are a bunch of "interesting" links.

Code:
</html><u style=display:none><a href=http://w-z..........
If you didn't do this, then I think your hosting company has some serious problems and you need to look for a new one.

[shameless plug]I recommend Yahoo! web hosting for basic web sites[/shameless plug]
Peetah is offline  
Old Apr 15, 2007 | 8:59 pm
  #6  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by Peetah
I just looked at your site.... are you sure you uploaded a new index.htm?

At the end of your </html> tag, there are a bunch of "interesting" links.

Code:
</html><u style=display:none><a href=http://w-z..........
If you didn't do this, then I think your hosting company has some serious problems and you need to look for a new one.

[shameless plug]I recommend Yahoo! web hosting for basic web sites[/shameless plug]
Unbelievable! It must have been hacked again. I'm definitely changing web hosts tomorrow.
PTravel is offline  
Old Apr 15, 2007 | 9:08 pm
  #7  
 
Join Date: Jul 2004
Posts: 704
Originally Posted by PTravel
Unbelievable! It must have been hacked again. I'm definitely changing web hosts tomorrow.
Looks like your hosting company was hacked

A look at http://msshost.com is well... a mess.
Peetah is offline  
Old Apr 15, 2007 | 9:17 pm
  #8  
Moderator, Hertz; FlyerTalk Evangelist
20 Years on Site
 
Join Date: Nov 2005
Location: KRK
Programs: Many
Posts: 12,723
Interesting.
They probably didnt update the server in a long time. I run my own server, and with cpanel, it auto updates and patches everything. Makes life easy I remember running ensim and it didn't do that.
But you know that your site is popular Go with a big name hosting company is all I can really say. Also the CHMOD (the read/write options) might be set on the main page for anybody to change it. I would recommend changing those (basically in a ftp client right click on the index file)
jason8612 is offline  
Old Apr 15, 2007 | 9:42 pm
  #9  
In Memoriam
 
Join Date: Feb 2000
Location: Easton, CT, USA
Programs: ua prem exec, Former hilton diamond
Posts: 31,801
This is actualy fairly common, we went through it a couple months ago at the office.

Using different issues in security, people are hacking into ISP's and making global changes to all the websites they can get access to. It doesn't need your username or password, it's just going directory by directory on the server making changes. It almost always happens on weekends so it goes unnoticed until the business day on Monday.

Your host needs to stop it, so drop them a note if you haven't done so already and let them know. If you use your host to keep any personal files like passport copies or anything like that so you can access them, consider they may have been compromised, and get them off there.

It's not fun to fix, but they go from host to host doing this.
cordelli is offline  
Old Apr 15, 2007 | 10:14 pm
  #10  
FlyerTalk Evangelist
 
Join Date: Oct 2000
Posts: 15,788
"Middleware" is my nominal area of expertise. While I can't comment specifically on what happened to your site, I see almost daily announcements of security vulnerabilities for web serving and associated software. Most of these are never seen by the public and are fixed before they can be exploited by hackers.

If your web host is not on top of things on a daily basis they are simply relying on "security through obscurity" to prevent attacks.

If they haven't been -extremely- proactive in communicating with you about the problem, I would seriously think about finding another host for your domain,.
birdstrike is offline  
Old Apr 15, 2007 | 10:48 pm
  #11  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by Peetah
Looks like your hosting company was hacked

A look at http://msshost.com is well... a mess.
Unfortunately, it's more than a mess. There's some pretty scary stuff up there. That's why I'm calling the FBI tomorrow morning.
PTravel is offline  
Old Apr 15, 2007 | 10:57 pm
  #12  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by jason8612
Interesting.
They probably didnt update the server in a long time. I run my own server, and with cpanel, it auto updates and patches everything. Makes life easy I remember running ensim and it didn't do that.
But you know that your site is popular Go with a big name hosting company is all I can really say. Also the CHMOD (the read/write options) might be set on the main page for anybody to change it. I would recommend changing those (basically in a ftp client right click on the index file)
I checked -- only the owner, i.e. me, has read/write, everyone else is read.

My site isn't that popular. I suspect everyone hosted on the server got attacked this way.

One thing I'm considering: My webpages were hacked to include links to both porno sites and some legit services. I've tracked a couple of the legit services down. These are direct links, not the usual pay-per-click through Google, so at some point they must have employed some service to spread their name around. I'm seriously thinking of writing them a letter advising them that, as principals for whatever agent did this, they're liable for violation of 15 U.S.C. Sec. 1125(a) (Section 43(a) of the Lanham Act) and demanding an accounting and damages or I'll sue (I do these kinds of law suits all the time).

It might be interesting.
PTravel is offline  
Old Apr 15, 2007 | 11:02 pm
  #13  
Original Poster
FlyerTalk Evangelist
 
Join Date: Mar 2004
Location: Newport Beach, California, USA
Posts: 36,062
Originally Posted by cordelli
This is actualy fairly common, we went through it a couple months ago at the office.

Using different issues in security, people are hacking into ISP's and making global changes to all the websites they can get access to. It doesn't need your username or password, it's just going directory by directory on the server making changes. It almost always happens on weekends so it goes unnoticed until the business day on Monday.
Interesting. That explains why only my webpages were changed, but not other .htm pages that internal defaults, e.g. "404 Not Found" and the like. What amazes me is it happened at least twice, as I had uploaded cleaned versions an hour or so before Peetah noticed my site was compromised again. Judging by the change dates of the files, there were three separate attacks -- one last week, one on Saturday, and then the one tonight. I just checked and everything looks okay now.

Your host needs to stop it, so drop them a note if you haven't done so already and let them know. If you use your host to keep any personal files like passport copies or anything like that so you can access them, consider they may have been compromised, and get them off there.
It's not fun to fix, but they go from host to host doing this
I did just that -- sent two trouble tickets and pulled off my passport copy. Hmmm. There are a bunch of photos of FlyerTalkers from one of BJ's Redwood Grill Dos still up.

Last edited by PTravel; Apr 15, 2007 at 11:08 pm
PTravel is offline  
Old Apr 15, 2007 | 11:06 pm
  #14  
Moderator, Hertz; FlyerTalk Evangelist
20 Years on Site
 
Join Date: Nov 2005
Location: KRK
Programs: Many
Posts: 12,723
Interesting. they use cPanel.
I use cPanel.
I better check my security.....
jason8612 is offline  
Old Apr 15, 2007 | 11:07 pm
  #15  
FlyerTalk Evangelist
 
Join Date: Oct 2000
Posts: 15,788
Your site upgraded to Apache 1.3.17 today. That is the latest legacy security release. The previous site update was to 1.3.33 on January 12th.

The current release of Apache is 2.2.4
birdstrike is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.