Re: Re: [PHP] Possible My Website was hacked... with PHP... please tell me what this is???

This is a discussion on Re: Re: [PHP] Possible My Website was hacked... with PHP... please tell me what this is??? within the PHP General forums, part of the PHP Programming Forums category; Hi guys what does trolling mean? Never heard of it before. Angelo -----Original Message----- From: Joel Rees <joel@alpsgiken....


Go Back   Usenet Forums > PHP Programming Forums > PHP General

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-31-2003
Binc2
 
Posts: n/a
Default Re: Re: [PHP] Possible My Website was hacked... with PHP... please tell me what this is???

Hi guys

what does trolling mean? Never heard of it before.

Angelo

-----Original Message-----
From: Joel Rees <joel@alpsgiken.gr.jp>
To: "Joe Harman" <joe@harmanmedia.com>, <php-general@lists.php.net>
Date: Thu, 31 Jul 2003 16:10:24 +0900
Subject: Re: [php] Possible My Website was hacked... with PHP... please tell me what this is???

Assuming you are not just trolling,

> Fortunatly I don't think they were doing something correctly, cause it
> didn't deface my site like some of the others....


Don't count on it. They only deface servers they don't want to use.

> ...
> everyone can execute shell commands via system(); on your server.
> -> delete the script ;)


Oh, by all means, delete it if you want. But it's not the hole it came
in through, and it's not the real backdoor.

It's so blatent, I'd guess it's a script kiddy or a decoy. Even if it's
a script kiddy, you _want_ to know how it got on the box.

I'd take the box offline, back up all the data and configuration files,
and re-install the whole system and all programs from scratch. Go over
every configuration file with a fine-tooth comb.

If the machine is on a subnet and I controlled the subnet, I think I'd
take the whole subnet down, including the firewall, and clean every
machine up, not putting any machine back on the subnet until it was
clean and any holes patched. If I didn't control the subnet, I'd make
sure the persons who did know there had been a break-in.

And if you have any valuable data, consider it to have been stolen. If
you have credit card numbers, report the possibility of theft to the
credit card companies. Etc.

If you're trolling, go away.

--
Joel Rees, programmer, Systems Group
Altech Corporation (Alpsgiken), Osaka, Japan
http://www.alpsgiken.co.jp


--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php




Reply With Quote
  #2 (permalink)  
Old 07-31-2003
John Manko
 
Posts: n/a
Default Re: [PHP] Possible My Website was hacked... with PHP... please tellme what this is???

trolling!
ha

binc2 wrote:

>Hi guys
>
>what does trolling mean? Never heard of it before.
>
>Angelo
>
>-----Original Message-----
>From: Joel Rees <joel@alpsgiken.gr.jp>
>To: "Joe Harman" <joe@harmanmedia.com>, <php-general@lists.php.net>
>Date: Thu, 31 Jul 2003 16:10:24 +0900
>Subject: Re: [php] Possible My Website was hacked... with PHP... please tell me what this is???
>
>Assuming you are not just trolling,
>
>
>
>>Fortunatly I don't think they were doing something correctly, cause it
>>didn't deface my site like some of the others....
>>
>>

>
>Don't count on it. They only deface servers they don't want to use.
>
>
>
>>...
>>everyone can execute shell commands via system(); on your server.
>>-> delete the script ;)
>>
>>

>
>Oh, by all means, delete it if you want. But it's not the hole it came
>in through, and it's not the real backdoor.
>
>It's so blatent, I'd guess it's a script kiddy or a decoy. Even if it's
>a script kiddy, you _want_ to know how it got on the box.
>
>I'd take the box offline, back up all the data and configuration files,
>and re-install the whole system and all programs from scratch. Go over
>every configuration file with a fine-tooth comb.
>
>If the machine is on a subnet and I controlled the subnet, I think I'd
>take the whole subnet down, including the firewall, and clean every
>machine up, not putting any machine back on the subnet until it was
>clean and any holes patched. If I didn't control the subnet, I'd make
>sure the persons who did know there had been a break-in.
>
>And if you have any valuable data, consider it to have been stolen. If
>you have credit card numbers, report the possibility of theft to the
>credit card companies. Etc.
>
>If you're trolling, go away.
>
>
>



Reply With Quote
  #3 (permalink)  
Old 07-31-2003
Chris Sherwood
 
Posts: n/a
Default Re: Re: [PHP] Possible My Website was hacked... with PHP... please tell me what this is???

I have seen this exact same header before in this list, so I am going to
assume this is a troll

Chris
----- Original Message -----
From: "binc2" <binc2@ctech.ac.za>
To: <joel@alpsgiken.gr.jp>; <php-general@lists.php.net>
Sent: Thursday, July 31, 2003 8:26 AM
Subject: Re: Re: [php] Possible My Website was hacked... with PHP... please
tell me what this is???


Hi guys

what does trolling mean? Never heard of it before.

Angelo

-----Original Message-----
From: Joel Rees <joel@alpsgiken.gr.jp>
To: "Joe Harman" <joe@harmanmedia.com>, <php-general@lists.php.net>
Date: Thu, 31 Jul 2003 16:10:24 +0900
Subject: Re: [php] Possible My Website was hacked... with PHP... please tell
me what this is???

Assuming you are not just trolling,

> Fortunatly I don't think they were doing something correctly, cause it
> didn't deface my site like some of the others....


Don't count on it. They only deface servers they don't want to use.

> ...
> everyone can execute shell commands via system(); on your server.
> -> delete the script ;)


Oh, by all means, delete it if you want. But it's not the hole it came
in through, and it's not the real backdoor.

It's so blatent, I'd guess it's a script kiddy or a decoy. Even if it's
a script kiddy, you _want_ to know how it got on the box.

I'd take the box offline, back up all the data and configuration files,
and re-install the whole system and all programs from scratch. Go over
every configuration file with a fine-tooth comb.

If the machine is on a subnet and I controlled the subnet, I think I'd
take the whole subnet down, including the firewall, and clean every
machine up, not putting any machine back on the subnet until it was
clean and any holes patched. If I didn't control the subnet, I'd make
sure the persons who did know there had been a break-in.

And if you have any valuable data, consider it to have been stolen. If
you have credit card numbers, report the possibility of theft to the
credit card companies. Etc.

If you're trolling, go away.

--
Joel Rees, programmer, Systems Group
Altech Corporation (Alpsgiken), Osaka, Japan
http://www.alpsgiken.co.jp


--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php





--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:16 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0