Author Topic: Red-D3v1L Hack  (Read 5791 times)

0 Members and 1 Guest are viewing this topic.

Offline batu544

  • Sr. Member
  • ****
  • Posts: 336
    • View Profile
    • Free Celebrity wallpapers
Red-D3v1L Hack
« on: May 30, 2009, 11:47:29 PM »
Hi All-
              couple of days back when I tried to login into my website as a admin, it suddenly stopped taking my password and when I requested a new password then I didn't get the new password.. So, I checked my database and got to know that my e-mail id and password has been changed. I think this is a some kind of hack.

   Today while searching my site name in google I noticed my website name is also in this list..  http://www.zone-h.org/archive/ip=72.29.71.175   

I finally deleted index.htm file from bhwallpapers.com/wall   folder.

No idea how and why this happened .. Is this happened due to some security hole in 4image. ?

I am still using 1.7.4


Thanks
batu544


Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Red-D3v1L Hack
« Reply #1 on: May 31, 2009, 01:01:52 AM »
1) did you apply ALL bug fixes for your 4images version?
2) did you check your webspace for any suspicious files (files you didn't upload)?
3) did you contact your host administrator for help investigate this?
4) what was in index.htm file?
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline batu544

  • Sr. Member
  • ****
  • Posts: 336
    • View Profile
    • Free Celebrity wallpapers
Re: Red-D3v1L Hack
« Reply #2 on: June 01, 2009, 11:50:14 AM »
1) did you apply ALL bug fixes for your 4images version?
2) did you check your webspace for any suspicious files (files you didn't upload)?
3) did you contact your host administrator for help investigate this?
4) what was in index.htm file?

Hi,
     
1. Not all but I have applied few fixes...
2. no, I didn't find any suspicious file except index.htm
3. No, I have not contacted yet.. :)  I simply changed the e-mail in the database and requested a new password.
4. I can't remember exactly all the sentences .. but   it was something like " you website has been hacked by Red-D3v1L mR5@Hotmail.com....etc etc.. "


Thanks