Forum Moderators: buckworks

Message Too Old, No Replies

site hacked, what can I do?

         

particleman

2:55 am on Dec 8, 2007 (gmt 0)

10+ Year Member



Hi guys, my site was hacked last week. It could've been really bad, but luckily the hacker only took a walk through my admin pages and clicked some buttons, almost like a bot in my server logs. He did lock me out of my admin pages though which alerted me. It appears to have been a sql injection attack, lesson learned as far as that goes. I have the hackers IP address, it originated in china. Is there anything useful I can do with it as far as reporting it?

ByronM

9:12 pm on Dec 8, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Work with your service provider and do what you can.

For any ecommerce i would recommend a dedicated host or at minimal a vps server where you can manage your site as the only site on the host. Many times on shared hosts the server has been compromised as well.

I'd export your products, start on a new host, re-setup your cart and import your products and start clean and then use some of the free/cheap PCI compliance audits to verify your site as much as possible. Reading through the questionnaire will answer any concerns about what you should be doing to secure your site, data and customer info.

incrediBILL

8:54 pm on Dec 9, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



DITTO - dedicated server, reloaded ecommerce from scratch to make sure they didn't leave any hidden backdoors in your site.

Next time, assuming you don't do international sales or not from certain countries, you need to firewall off CHINA, RUSSIA, ROMANIA, ALBANIA, UKRAINE, NIGERIA... etc. to keep the hackers from easily getting to your site.

If you just sell to the US/CA market I would drop in the entire APNIC, AFRINIC, LACNIC and RIPE into the firewall just to sleep better at night.

lschmidt

3:27 pm on Dec 11, 2007 (gmt 0)

10+ Year Member



Are you at least going to warn us what shopping cart software is so severely outdated that it has an SQL injection exploit?

I know X-Cart recently had an issue with a security exploit, but I don't recall it being an SQL injection.

particleman

10:18 pm on Dec 11, 2007 (gmt 0)

10+ Year Member



I wrote it, hence the lesson learned...