Forum Moderators: phranque
I have been facing this problem of one of my sites being hacked twice and I need to take proper and immediate action to prevent that from happening again. I need your help in the form of some useful tips to combat these junk heads.
Some of the steps, I have already taken, Like :
1. Changing the passwords/phrases and making them alpha-neumerical.
2. Password protecting some of the directories.
3. Removing those unnecessary files.
4. Blocking ceratin IP's from ceratin countries.
I don't know, what other steps can be taken to keep it safe from hackers.
Any Technical or Non-Technical - Common sense Approach tips from some experienced and technical webmasters would be very helpful for me.
Thank you very much in advance.
Cheers
[edited by: ideavirus at 4:22 pm (utc) on Aug. 1, 2003]
BTW, cracked is when they are attacked through the boards itself (through an exploit or the install files), while hacked is when the server itself is hacked.
</side note>
Some general guidlines:
- run only the software you need and lock down everything else.
- keep up with security patches on the OS and the software you do run.
- never send your admin or root password in the clear. Use SSH, SFTP, and HTTPS if you have a web-based control panel or even phpMyAdmin, etc.
- have a solid backup and recovery plan.
You really might benefit from getting a security guru to help you lock it down. Good luck.
My admin did check the logs to investigate, how it all happened and did get a lot of clues and the actual IP of the system used to perform such a misadventure.we informed his ISP also about it.
Lucky me, my host takes backups every night and now, my admin makes two copies of my site backups, just in case.
Okay, i have another question : These hackers generally leaves the names of their groups when they hack sites. with those names on hand, is it possible to do much better tracking of the culprit? or can i squeeze any more info using such info?
Thank you for the advice.
Cheers