• Welcome to the new NAXJA Forum! If your password does not work, please use "Forgot your password?" link on the log-in page. Please feel free to reach out to [email protected] if we can provide any assistance.

XJDB got hacked

Harvo

NAXJA Forum User
Location
Chattanooga
Tried to go there to look up some pics and its got an advertisement for the hacker that hacked it complete with music and ugly crazy clown pics.
 
OK...let me be the first to say "How is this modified tech?" :laugh3:

Cool..
 
what kind of hacker goes after a xj picture database
 
looks like he was running PHP-nuke. I'd bet that he didn't have it patched up, and some script kiddie with a shell script found it, then it was pretty much an automated hack. Not a whole lot of skill there. Anyway, if he's got a backup it shouldn't be that difficult. If you see this and need help let me know. Sorry for dorking out on you all.
 
GSequoia said:
Billy.

Are you running it on an IIS server?

For shame!
My own curiosity ed me to who is the site.
He's hosting at@
https://www.opensourcehost.com/
They look to be tailored to MYSql and PHP driven sites, so I doubt they're on IIS. I didn't dig down deep to find what version of PHP nuke he's running, but I would bet that it was a PHP-Nuke vulnerability rather than a server issue. That's more evident by the fact that the hack stayed within the contraints of PHP-nuke. If it was a server hack then the damage probably would have been more severe.
 
my "other" club's website got hacked like that last june. it was something that was planted over 6 months before it executed itself, so the back-up was corrupted as well. took 2 weeks to get a new site buit strictly from memory. i really hope he has his bases covered and doesnt loose all his stuff.
 
sidriptide said:
my "other" club's website got hacked like that last june. it was something that was planted over 6 months before it executed itself, so the back-up was corrupted as well. took 2 weeks to get a new site buit strictly from memory. i really hope he has his bases covered and doesnt loose all his stuff.
Man, no kidding.
He must've had over 100thousand pics on that site.
 
man that sucks!!!!!
freaky scary pic too..
hate that crap
crappers oh i mean hackers...

lol


aaron
 
sad.gif
Bummer deal. To answer the questions... I don't have anything to do with the message the guy was promoting. I'm sure it was just a novice running a scanner and happened to find the vulnerability. I'm not on an IIS server, but it does look a lot like that exploit. I've been asked my my server admin to give him a chance to look before I cover any foot prints, but it doesn't look like the damage is that bad. I do have a backup (since I haven't updated the site in FOREVER) and nobody's information was compromised. Thanks for everybody's concern.
Billy
 
Back
Top