You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 34 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - hacked by 66.218.79.40 [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
mcdrum
Nuke Soldier
Nuke Soldier


Joined: Aug 21, 2003
Posts: 12


PostPosted: Thu Aug 21, 2003 6:15 pm Reply with quoteBack to top

Hi all.

I am webmaster-a newbie one- in www.iesjorgemanrique.com, a PHP-Nuke 6.0 site in a linux box, dedicated to an spanish higschool. In 21-August some one has hacked our site. The hack activates itself when the browser goes to www.iesjorgemanrique.com/index.php, the main page. Then appears the main page an quickly the browser goes to an image in l337-zide.net (66.218.79.40). This is an strange site with PHP-Nuke.

I have found 66.218.79.40 listed in some spammers lists, but my sendmail appears to be not relaying nothing yet.

I suspect that this hacker has used some PHP-Nuke vulnerability in version 6.0. The redirection is not in the apache conf files, and not in the database of mysql/nuke.

What do you recommend? My main concern are the users in PHP-Nuke version 6.0 and the more than a hundred webmail users I have in the school.

Thank you for your work

mcdrum

aka juan fernandez
Find all posts by mcdrumView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Thu Aug 21, 2003 6:24 pm Reply with quoteBack to top

Hi sounds like they may have hacked the news or a your account. Best bet is to upgrade to 6.5 with our security fixes.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
jank
Nuke Soldier
Nuke Soldier


Joined: Apr 30, 2003
Posts: 23


PostPosted: Sat Aug 23, 2003 11:39 am Reply with quoteBack to top

[quote="mcdrum"]Hi all.

Quote:
Then appears the main page an quickly the browser goes to an image in l337-zide.net (66.218.79.40). This is an strange site with PHP-Nuke.

I have found 66.218.79.40 listed in some spammers lists, but my sendmail appears to be not relaying nothing yet.


Are you sure? 66.218.79.40 is mail.yahoo.com... As a matter of fact, th whole block is owned by yahoo.

Connecting to whois.arin.net...

OrgName: Yahoo!
OrgID: YAOO
Address: 701 First Avenue
City: Sunnyvale
StateProv: CA
PostalCode: 94089
Country: US

NetRange: 66.218.64.0 - 66.218.95.255
CIDR: 66.218.64.0/19
NetName: A-YAHOO-U23
NetHandle: NET-66-218-64-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.YAHOO.COM
NameServer: NS2.YAHOO.COM
NameServer: NS3.YAHOO.COM
NameServer: NS4.YAHOO.COM
NameServer: NS5.YAHOO.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2002-01-15
Updated: 2002-06-27

TechHandle: NA258-ARIN
TechName: Netblock Admin, Netblock
TechPhone: +1-408-349-7183
TechEmail: netblockadmin@yahoo-inc.com

OrgTechHandle: NA258-ARIN
OrgTechName: Netblock Admin, Netblock
OrgTechPhone: +1-408-349-7183
OrgTechEmail: netblockadmin@yahoo-inc.com

# ARIN WHOIS database, last updated 2003-08-22 19:15
# Enter ? for additional hints on searching ARIN's WHOIS database.
Find all posts by jankView user's profileSend private messageVisit poster's website
bwcbwc
Nuke Soldier
Nuke Soldier


Joined: Jul 25, 2003
Posts: 34

Location: FL

PostPosted: Sun Aug 24, 2003 8:00 am Reply with quoteBack to top

Well mail.yahoo.com would explain why it appears in the spam lists. It also sounds like someone may have hacked a DNS to redirect the IP to l337-zide.net (more likely: l337-zide.net is just a site hosted by Yahoo). There's a fair chance that this site was also hacked and is just one in a chain of victims.
Find all posts by bwcbwcView user's profileSend private message
mcdrum
Nuke Soldier
Nuke Soldier


Joined: Aug 21, 2003
Posts: 12


PostPosted: Sun Aug 24, 2003 4:44 pm Reply with quoteBack to top

Sorry for the delay in answering
I did a search in www.dnsstuff.com to get the info about the IP of "my" hacker.

Today, after reading your post, I have done the same. The thing now is that dnsstuff reports the IP being

66.218.79.140

the arp data and the reverse DNS seems to say that l337-zide.net is a premium service offered by yahoo.

GREAT!!. Obviously there are some DNS servers tricked here

And if you try http://66.218.79.140
you get an error 400-bad request.
But if you try the http://l337-zide.net

you get the site.

I have sent an email to r00t@l337-zide.net, and he-or she-answered me. I hope to understand what happened.

By now I have in an isolated box a new php-nuke version 6.5, with all the patches and fixes I have found here( I was unable of getting the NC securiity 6.5 version at work). My hope is that the only problem in my server is phpnuke, and patching iit, not being hacked that way again.

Thanks for your answers.

mcdrum
Find all posts by mcdrumView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.439 Seconds - 29 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::