Forum Moderators: travelin cat

Message Too Old, No Replies

Could my iMac be hacked?

         

Jesse_Smith

8:48 am on Nov 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've been going through hacker hell since Tuesday. First they get in to my account on the web host and make a trouble ticket requesting my dedicated server be unpluged and re-sold. I then change the passwords. They also hack my political message board, and cancle one of my domains which is another message board, through Godaddy. Even though the domain was locked, I later noticed every domain but that was was locked, like they unlocked it. Next day they make a second trouble tick, one to downgrade the memory on my server, even though I changed the password to the memebrs area (ev1). Grrr! Next there back at my video game message board. They delete the database! I change the mySQL password and use the back-up from a day or two ago. Next they use accounts to delete threads and move everything around (vBulletin). I then use the back-up again. Today they delete the domain off my server, and edit my profile on another message board. Through out this I change the admin/root passwords a couple of times, and change the domain password before they hack the site by editing the template! So far everything they've messed with has been two vBulletin message boards and one phpbb board, no static sites. So I'm not sure if there geting in using my computer, the server, or are using some php exploit. I even installed Nortin firewall after the two trouble tickets were made.

prairie

1:05 pm on Nov 27, 2004 (gmt 0)

10+ Year Member



Can you be sure it isn't someone close to you that's doing this?

Given what's happened already, if a paper trail of some form has been left by whomever's responsible at the host's end, its time to get the police involved.

encyclo

2:04 pm on Nov 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Who uses or has access to your computer apart from you? Sadly, prairie is probably right - it's 5% chance of being a hacker, 95% chance of being someone you know and trust: family, close friend or business partner.

DerekH

9:14 pm on Nov 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Call the police, and change every password you can.
Check your Mac Firewall is on, but I think this is someone who has access to your keyboard, or to a document with passwords in - there are too many hacks here for it to be done "from the other side".
How would a hacker sitting in a garrot somewhere possibly be able to find all these disparate things? They wouldn't.

Check closer to home, and be prepared, as is regrettable in such cases, to find someone you know has screwed you.

DerekH

Jesse_Smith

9:58 pm on Nov 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Actually, I think some one is using mySQL. I WATCHED them hack one of my message boards index pages, and first it SHOWED THE FILE OF ONE OF THE VBULLETIN FILES! All the hacking they have done to the sites have been ones that used mySQL. They used db_mysql.php to change the index file, and even had my license number in it. I looked at the file on my server but it didn't have the hacked file. I searched the server and didn't find it any where else.

mod_security is what I probably need to install.

# Very crude filters to prevent SQL injection attacks
SecFilter "delete[[:space:]]+from"
SecFilter "insert[[:space:]]+into"
SecFilter "select.+from"

Manual describes exactly what there doing and that's the code that stops it.

MichaelBluejay

2:25 am on Nov 29, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I don't know much about security, but are you transferring files via FTP, rather than SFTP or SSH? My understanding is that passwords are sent in plain text when you do FTP logons or transfers, and hackers can listen in on the communication and get your password that way.

whoisgregg

1:05 am on Nov 30, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



prairie and DerekH are absolutely correct about contacting the police. Don't call the local police or sheriff, you need to contact these two groups:

First, file a complaint with the IC3: [ic3.gov...]
Second, call your local FBI office: [fbi.gov...]

No matter how painful it may be, I recommend doing __nothing__ until you receive instructions from the FBI. Except check your stickymail, I've sent you some additional info. :)

Jesse_Smith

5:34 am on Dec 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I used ftp and SSH. Telnets been disabled. I disable ftp, and they still edit the index!

whoisgregg

8:20 am on Dec 2, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



What's been the advice of the FBI?

Jesse_Smith

3:53 am on Dec 5, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



No response. Another webmaster asked me to link to there boards and with in a few days of doing that, there hacked. I try geting a phpbb hosted with another company for free, and with in a day, that's hacked (different password again). A user of my boards had his site hacked. That's four different servers owned by four different people geting hacked in two weeks! It's like there's some way to hack any mySQL database.

Russ49Checkmate

5:38 pm on Dec 5, 2004 (gmt 0)

10+ Year Member



Interesting discourse ...

Couple of points from a human nature perspective, since you did call the FBI, I'm assuming you're complete surely it's not an inside job. Another point is that it seems you run many many bullitin board services.

We all know that the internet society is full of anti-social people who get punched in the nose alot in real life.

So....

There's just one person doing all this, and it's not just a random attack. They're out to get you for some imagined offense.

Soory good friend, you may have to shut down for a couple years, just until the MORON finds someone else to pick on.

BjarneDM

8:22 pm on Dec 5, 2004 (gmt 0)

10+ Year Member



Please read these threads/news items and then make *damned* sure your ISP has upgraded!

[phpbb.com...]
[phpbb.com...]

phpBB 2.0.11 contains fixes for at least three things that can lead to the kind of things you and your associates have been subjected to:

- Fixed unsetting global vars
- Fixed XSS vulnerability in username handling
- Fixed not confirmed sql injection in username handling

Jesse_Smith

8:58 am on Dec 6, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Based on what the hacker has have done to the boards, and what they have renamed member names to, it looks like it's a visitor that has been visiting the boards since about 1997!

Does vBulletin have those bugs?

- Unsetting global vars
- XSS vulnerability in username handling
- Not confirmed sql injection in username handling

The major board geting hacked is vBulletin, and the hackers have been much better at hacking the vBulletin boards than phpbb. I got three different message board sites. There mostly attacking the most populer one, the vBulletin one that's been around since 1997.

HughMungus

9:05 am on Dec 6, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



A Mac-using friend of mine told me today that she's had problems because her computer was "acting as a server" and that people could access her hard drive or something.

BjarneDM

10:40 am on Dec 6, 2004 (gmt 0)

10+ Year Member



A Mac-using friend of mine told me today that she's had problems because her computer was "acting as a server" and that people could access her hard drive or something.

Then she must explicitly have switched something on. A Mac OS X system straight out of the box has no - absolutely no - services/daemons that are exploitable from the outside switched on by default. However, it's very easy to switch something on in an insecure way.

Now, you are just stating that she's had problems. But what kind of problems? More facts, please, otherwise your statement is of no value at all.

[edited by: BjarneDM at 11:10 am (utc) on Dec. 6, 2004]

BjarneDM

11:08 am on Dec 6, 2004 (gmt 0)

10+ Year Member



I've been taking a further look at the problems Jesse_Smith has.

As far as I can see his problems are not at all with his iMac but with his Web Hosting Company that seems to have gotten themselves hacked and a root kit installed.

His web host simply isn't up-to-date on security patches. They are apparently using:
Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_ssl/2.8.12 OpenSSL/0.9.6b mod_fastcgi/2.2.10
1) Apache is at 1.3.33
2) OpenSSL is at 0.9.7e
3) mod_ssl is at 2.8.22
4) mod_fastcgi is at 2.4.0

vBulletin is at 3.0.3 - Jesse_Smiths board is using 3.01
[vbulletin.com...]

I'ld switch web hosting firm very fast if I discovered that they didn't keep up with their security patches. As to which security issues that have been patched you'll have to do your own research.

As to me posting about phpBB that was an error on my side - I had somehow gotten it into my head that the boards were served using phpBB.

whoisgregg

8:39 pm on Dec 6, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've been taking a further look at the problems Jesse_Smith has.

I've looked into this specific situation as well and would add that the sites are all virtually hosted on the same box with a single IP address. So the hacker would have been able to gain access to all the sites after a single successful attack that compromised the box. Plus, the hacker might have realized the widespread damage they could do to Jesse_Smith by doing a reverse IP whois on any of the domains. :(

You need to switch hosts or at least have your host wipe your current server and start new.

Jesse_Smith

4:15 am on Dec 8, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



:::His web host simply isn't up-to-date on security patches.

The 'web host' is me! I'm on a dedicated server!

I think I got it so the hackers can't do anything now. I shut off SSH. It's been over 24 hours now since I did that and they havn't done any hacking. They got root access some how.

Jesse_Smith

5:20 am on Dec 8, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



er I spook too soon! They edited the site again, including deleteing vBulletin files, with SSH and telnet turned off! Now ftp is turned off, again, for the domain.

Marketing Guy

5:31 am on Dec 8, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I had a similar problem to this (on a shared host though, but only hitting one of my sites) - the hacker had installed a php file in a number of directories that gave him remote shell access.

(well, as far as I can tell - I don't know a whole lot about this stuff)

If your hacker had done the same a while ago, you could have inadvertedly backed up the php file - so each time you replace the hacked files you also replaced his file.

Probably not the same problem though, but I'll PM you some specific details all the same.

Scott

BjarneDM

7:22 pm on Dec 9, 2004 (gmt 0)

10+ Year Member



Look, you might have a dedicated machine, but if it has the same set-up as described by me previouly, you are in deep trouble.

And if the central adminstrative server of your web hosting firm has been root kitted you are out of luck, no matter what you do to your own machine: your password has to be stored there somewhere, and they have to have root-access to all of their accounts in order to administer them.

Jesse_Smith

10:10 pm on Dec 10, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member




1) Apache is at 1.3.33
2) OpenSSL is at 0.9.7e
3) mod_ssl is at 2.8.22
4) mod_fastcgi is at 2.4.0

Check them now. I know Apache is now 2.0.46. Though with the server restored two days ago, they allready changed the index page! It probably won't be long before I find out if they got root access again and can still delete stuff.