Announcement

Collapse
No announcement yet.

i've been hacked and i dont know what to do

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    i've been hacked and i dont know what to do

    further to my thread dlengines......what????

    i contacted my host (fasthosts) and they have sent me the following instructions. which is fair enough but i really dont know how to do any of this. any help?? PLEASE

    Further to your support call, hacked sites are commonly down to old > content management software being vulnerable. The weaknesses were not > server wide but rather just made it easier on a hacker to compromise > individual end user accounts.>> I suggest the following clean up procedure for both your accounts:>>
    1. check all index pages for any signs of java script injected into their > coding. On windows servers check any "default.aspx" or> "default.cfm" pages as those are popular targets too.>>
    2. Remove any "rouge" files or php scripts uploaded by the hackers into > your account. Such scripts allowed them to make account wide> changes, spam through your account, or spread their own .htaccess files > through all of your domains in that end user.>>
    3. Check all .htaccess files, as hackers like to load re-directs into > them.>>
    4. Change all passwords for that end user account. The cp password, the > ftp password, and any ftp sub accounts. Make sure to use a> "strong" password which includes upper case, lower case, numbers and NO > COMPLETE WORDS OR NAMES!>>
    As what I have told you earlier, it is because of a .htaccess uploaded > into your site why it is being redirected to that url. Please remove that > via FTP

    #2
    here is a recentthread where someone else was helped with a hacked site...

    http://community.actinic.com/showthr...hlight=malware

    this is what you need to start as a start..

    1 change your ftp password
    2 remove all files from the server (keep a record of your last ordr number)
    3 remove contents of siteHTML, previewHTML within site1 on pc

    run virus check on pc, and as many malware/spyware/keylogging detection programs.

    when you are certain there is no vulnerability on your pc, reupload actinic (having put the order number in on the troubleshooting menu).

    Having said that and placed the most likely source of the issue with your pc, there is a slim change the vulnerability lies with your host. We've had several actinic sites move to us recently as their sites had been hacked elsewhere, inc an FH one yesterday. I'm not saying you wont get hacked with us, but at least we will help you pick up the pieces

    Comment


      #3
      Originally posted by pinbrook View Post
      here is a recentthread where someone else was helped with a hacked site...

      http://community.actinic.com/showthr...hlight=malware

      this is what you need to start as a start..

      1 change your ftp password
      2 remove all files from the server (keep a record of your last ordr number)
      3 remove contents of siteHTML, previewHTML within site1 on pc

      run virus check on pc, and as many malware/spyware/keylogging detection programs.

      when you are certain there is no vulnerability on your pc, reupload actinic (having put the order number in on the troubleshooting menu).

      Having said that and placed the most likely source of the issue with your pc, there is a slim change the vulnerability lies with your host. We've had several actinic sites move to us recently as their sites had been hacked elsewhere, inc an FH one yesterday. I'm not saying you wont get hacked with us, but at least we will help you pick up the pieces
      Cool - i'll try that, i seem to have had a bad run with fast hoset and was thinking of changing.

      i have found the .htaccess files that are redirecting the site - i assume it's not as easy as just deleting them and changing my ftp passwords?

      Comment


        #4
        For info:

        A .htaccess file is a small file called ‘.htaccess’ in the root (top) folder of your website. It’s just a text file so you can read it. Check it doesn’t have any entries that point to other websites. Its possible that the .htaccess file isn’t yours, and has been added by the hacker. You can just remove it, or edit out the offending lines.

        Comment


          #5
          Originally posted by caroline View Post
          i have found the .htaccess files that are redirecting the site - i assume it's not as easy as just deleting them and changing my ftp passwords?
          Yes it is that easy to clear the website, but as Jo says, the problem is most likely with your PC.

          I know this isn't a funny situation, but I did have to smile at "rouge" files.

          Comment


            #6
            - i assume it's not as easy as just deleting them and changing my ftp passwords?
            you are correct... you need to fix this properly now, otherwise it will keep happening.

            if the vulnerability stems from your pc - you will simply reupload the problem

            Comment

            Working...
            X