ASP Free Lounge
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsOtherASP Free Lounge

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old September 13th, 2006, 08:16 AM
Gibson98 Gibson98 is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Jun 2005
Posts: 43 Gibson98 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 8 m 29 sec
Reputation Power: 4
Need Help With Hacking

Hi,

I have a problem. My website is being hacked using some sort of hacking kit. There are a few ASP files being uploaded to my images folder(not sure how) and then they can be opened and view all my files on my site. These files can be editted/deleted/uploaded/downloaded etc.

The files are named:

swart.asp
cyberspy.asp
r57.asp

and a few more.

The passwords for my site are kept secure, are long and contain numbers and letters etc and have never been given out.

How are these files being uploaded without this information?

Hope you can help

Many thanks

Joe

Reply With Quote
  #2  
Old September 13th, 2006, 02:36 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
Click here for more information.
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,781 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 45 m 55 sec
Reputation Power: 470
PM me the link to your site and I can do some testing on it to determine what vulerabilities your site might have.

Reply With Quote
  #3  
Old September 13th, 2006, 02:37 PM
pws1970 pws1970 is offline
Contributing User
ASP Free Loyal (3000 - 3499 posts)
 
Join Date: Aug 2005
Posts: 3,250 pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 20017 Folding Title: Starter FolderFolding Points: 20017 Folding Title: Starter Folder
Time spent in forums: 4 Weeks 1 Day 4 h 5 m 50 sec
Reputation Power: 363
Quote:
Originally Posted by Gibson98
Hi,

I have a problem. My website is being hacked using some sort of hacking kit. There are a few ASP files being uploaded to my images folder(not sure how) and then they can be opened and view all my files on my site. These files can be editted/deleted/uploaded/downloaded etc.

The files are named:

swart.asp
cyberspy.asp
r57.asp

and a few more.

The passwords for my site are kept secure, are long and contain numbers and letters etc and have never been given out.

How are these files being uploaded without this information?

Hope you can help

Many thanks

Joe


Sounds as though they may have used brute force to break your ftp password - I know you said it was alphanumeric but even then that doesn't make it totally secure plus they may have broke the administrators account for your domain.

You need to lock down your site - password protect folders, if you have complete control of the server then in IIS there is a ftp manager where you can only allow ftp access from your IP.

Reply With Quote
  #4  
Old September 14th, 2006, 05:30 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,737 Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)  Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1Folding Points: 377762 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 5 h 41 m 46 sec
Reputation Power: 1914
if you have page where you allow visitors/users to upload stuff, probably
they're using this page. you must check the uploaded files before saving
them to disk!

Reply With Quote
Reply

Viewing: ASP Free ForumsOtherASP Free Lounge > Need Help With Hacking


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT