Baccou Bonneville Blogs Eclipse Blog Process Improvement Blog Java Blog Web Design Blog Miscellaneous .NET Blog

09/13/05

English (US)   Hacked  -  Categories: Noteworthy  -  @ 10:34:29 pm
Hacker

Baccou Bonneville web site has been hacked on September 12, 2005. All PHP files had been changed. The index.php file had been changed to a page on the glory of the hacker named "morocco.security.rulz". Another page presented "PHPShell by Macker Version 2.6". This page consists of two programs: Haxplorer, a server side file brower and PHPKonsole, which allows to run commands on the web server (see screenshots).

My thoughts considering this attack:

  • Hopefully, we make use of a Revision Control System (CVS) so that we were able to restore the pages
  • There was probably a lack of precaution in our web page and directory rights
  • The attack is not yet fully explained. It seems that a POST was made on the blog just before the attack started. Is there a security hole in b2evolution?
  • Is it really an exploit to hack the web site of our small company?
  • It's also a proof that our web site exists: it has been hacked.

Update (09/15/05)
The hack is now fully explained. My web hosting provider used PHP safe_mode. For more information about safe_mode, you can read the following article: PHP's safe_mode or how not to implement security by Ilia Alshanetsky. To summarize, do not use safe_mode!

[More:]

Attack screenshots

Hacker signature:

Hacker signature

PHPShell by Macker:

PHPShell

Haxplorer:

Haxplorer

PHPKonsole:

PHPKonsole

Technorati tags:
Leave a comment

Comments:

No Comments for this post yet...

Leave a comment:

Your email address will not be displayed on this site.
Your URL will be displayed.

Allowed XHTML tags: <p, ul, ol, li, dl, dt, dd, address, blockquote, ins, del, span, bdo, br, em, strong, dfn, code, samp, kdb, var, cite, abbr, acronym, q, sub, sup, tt, i, b, big, small>
(Line breaks become <br />)
(Set cookies for name, email and url)
(Allow users to contact you through a message form (your email will NOT be displayed.))
This is a captcha-picture. It is used to prevent mass-access by robots.

Please enter the characters from the image above. (case insensitive)

Pingbacks:

No Pingbacks for this post yet...

powered by
b2evolution

Credits: blog software | web hosting | monetize