Forum Moderators: phranque
Again my site is hacked today and I got the following address fron the added page
<snip>
All the images are taken from this site
[edited by: engine at 2:09 pm (utc) on May 27, 2005]
[edit reason] No urls, thanks. See TOS [webmasterworld.com] [/edit]
Are you using any ActiveX objects at all in your pages? I don't know why some of the comments have been made that ASP can't be the problem, but it most certainly can. Like any other dynamic languages, if it's coded incorrectly someone can find a way to abuse it. Additionally ASP and activeX have the dual-edged sword ability to write to both the server and the local computer if programmed to do so.
In the absence of any helpful comments I would hit up Google and the MS site for "security" and "asp security" and see if you come across any documents that may hint at your problem. It sounds like you have enough dynamic things going on that there may be several holes where they're sneaking in.
Also get on those server logs, if your ISP is not helpful in showing you how and where to get at them, you most certainly should consider a new ISP.
Best of luck to you, and shame on those with too much time on their hands.
One thing I finally figured out was that these attacks were genereally accomplished through the admin page, so I moved the admin page to a new location and changed its name.
I used dreamweaver to fix the file references in the software package. Now the person that tries to find the admin page gets redirected to the main page, and so far this has prevented the problem from re-occuring.
Are you using a open-source software package on this site?
try searching for "asp injection" on your favorite search engine to see if there are any relevant articles out there for you
-Greg
If Hosting company can assure you that they have implemented the writing permissions on your directory then there is no way that someone will change your files.
FSO can do everything if there are no writing permissions on foders.
Hope its helpful.
I changed the permissions and now started chaning the password frequently but the site is hacked again.
They don't overwrite the file but added all combinations of default and index files with all the possible extentions. One of that work and my home page disappeared.
which is the most common homepage extension that I can use? is it index.htm? and can they just add the pages and not overwrite? It means is is possible that they can just add and not able to overwrite? This time they add lot ..almost 7-8 pages.