How did DigitalMind change my index page?

This is a discussion on How did DigitalMind change my index page? within the Linux Web Servers forums, part of the Web Server and Related Forums category; I happened to notice today that one of my Web sites was hacked. They somehow replaced my index.php with ...


Go Back   Usenet Forums > Web Server and Related Forums > Linux Web Servers

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-06-2005
news@celticbear.com
 
Posts: n/a
Default How did DigitalMind change my index page?

I happened to notice today that one of my Web sites was hacked.
They somehow replaced my index.php with index.html with only the text
"DigitalMind" in it.
Actually, they just inserted index.html, and since my server processes
index.html before index.php, the site displays that.

So, how did they do this? More importantly, how do I prevent it from
happening again?
I guess I can contact my Web host and ask them to set it to only use
index.php as the root page, but can they possibly replace MY index.php
with THEIR index.php in the future?

Thanks for any information!
Oh, if it helps, I'm using RedHat ES 2.1 with Apache 1.3.33 (I believe.)

  #2 (permalink)  
Old 09-06-2005
Kenneth
 
Posts: n/a
Default Re: How did DigitalMind change my index page?

On Tue, 06 Sep 2005 08:47:04 -0700, news wrote:

> I happened to notice today that one of my Web sites was hacked.
> They somehow replaced my index.php with index.html with only the text
> "DigitalMind" in it.
> Actually, they just inserted index.html, and since my server processes
> index.html before index.php, the site displays that.
>
> So, how did they do this? More importantly, how do I prevent it from
> happening again?
> I guess I can contact my Web host and ask them to set it to only use
> index.php as the root page, but can they possibly replace MY index.php
> with THEIR index.php in the future?
>
> Thanks for any information!
> Oh, if it helps, I'm using RedHat ES 2.1 with Apache 1.3.33 (I believe.)


It isn't clear to me from your post if you are running apache on your own
server or on a hosting service. The first thing you should always do when
running something open to the world is keep it up to date. I think 1.3.x
apache is pretty old.

As far as how it was done, there are a lot of possibilities. A bug in
apache, a misconfiguration of apache, a bug in a cgi script or server
include, a security problem somewhere else in the system that allowed
someone to modify files...
Then there are attacks from the "inside"...


 


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 09:26 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0