05-01-2006, 04:40 PM | #1 (permalink) |
Registered User
|
My site was hacked
Apparently someone got into my gallery script, and used it to commit credit card fraud.. don't ask me how, I have no idea how that even works.. but I got an email from ebay saying this was taking place and that I should take action right away..
Well anyway as of yet this only means I loose my gallery and my site aswell as all sites hosted by the server are down untill tomorrow. Hopefully this wont develop into anything bigger |
05-02-2006, 11:00 AM | #6 (permalink) |
Registered User
|
This happened to me a couple of years ago - I had noticed a sudden *massive* increase in hits, all from a website that didn't seem to link to mine - I figured it was some kid trying to boost his site-status by doing lots of referral spamming and so didn't give it much thought. Then, months and months later, I tried to get onto my site and it was down - I called the provider who accused me of phishing and said that due to misuse, they'd taken my site down at the request of the police and their various policies.
I don't know what happened, but I guess that the massive load of hits was some automated crack attempt, trying to break into the portion of my site that ran scripts, once a password with rights was found, they loaded up a fake banking site, and then had a bunch of spam sent out, asking people to fill in their credit card details - you know, the usual scheme. Anyway, the moral of the story is, I guess, if you have access, or are responsible for a site that is open to the internet, make sure that any usernames and passwords are strongly secure - mixes of letters, numbers and 'other' characters. It took about 3-4 months for them to break my password on my site - but it was a simple one - with properly secure password, it could take years and years. |
05-14-2006, 02:48 PM | #8 (permalink) |
Lover - Protector - Teacher
Location: Seattle, WA
|
That's an absolutely ridiculous assumption. Fifteen digit alphanumeric randomized passwords nonwithstanding, there are hundreds of exploits for common web software that don't involve brute-force hacking of a password at all.
Just because you have a good password doesn't make you immune for "hundreds of years."
__________________
"I'm typing on a computer of science, which is being sent by science wires to a little science server where you can access it. I'm not typing on a computer of philosophy or religion or whatever other thing you think can be used to understand the universe because they're a poor substitute in the role of understanding the universe which exists independent from ourselves." - Willravel |
05-14-2006, 08:55 PM | #10 (permalink) |
Insane
|
Jinn, yotta: Two words: Rainbow Tables.
MikeSty: Make your password a combination of lower, uppercase letters, punctuation and numerals. You can only go so far, but the longer the password, the better.
__________________
"You looked at me as if I was eating runny eggs in slow motion." - Gord Downie of The Tragically Hip |
05-18-2006, 06:43 AM | #12 (permalink) | |
Lover - Protector - Teacher
Location: Seattle, WA
|
Amen trache
Yotta: Quote:
__________________
"I'm typing on a computer of science, which is being sent by science wires to a little science server where you can access it. I'm not typing on a computer of philosophy or religion or whatever other thing you think can be used to understand the universe because they're a poor substitute in the role of understanding the universe which exists independent from ourselves." - Willravel |
|
Tags |
hacked, site |
|
|