Server Gotcha by Hacker

Paul Ooi, June 29th, 2006

trackback | RSS 2.0

This morning when I access to www.paulooi.com. I saw the picture shown above, I access to all the website I hosted, also the same page coming out. Except Mel’s blog. Then I only found out some very high skills hacker inject index.html into every hosted folder. The files “index.html” started to inject since this morning 7am.

Am still checking how was the file got injected into all the folders. Thanks Mr Hacker.

Beside that, Hey! I am on zone-h list :) and I think Mr Forever is from 85.96.125.3

The Caused
Some of the customer didn’t patch the Mambo/Joomlah to latest version. Please do so please please please, patch your Mambo/Joomlah/Wordpress. If you require me to patch for you, let me know!



23 Responses to “Server Gotcha by Hacker”

  1. Planet Malaysia Says:

    How do you solve the problem? Why kena hack? :P

  2. Paul Ooi Says:

    Remove index.html and waiting the hacker respond in this comment why kena hack :P

  3. SoGua Says:

    eh paul, still dunno where the cause ar?

  4. Paul Ooi Says:

    mambo

  5. farking Says:

    paul, mod_security can help you from this kind of attack even you didnt patch the application. at least it give you another level of protection :)

  6. sam Says:

    i read about this potential risk last week and there was not patch at that time… gosh. i better go find mod_security now… thanks.

  7. Paul Ooi Says:

    mod_security doesn’t help much, it will show you which site got compromise and affect others. Better patch your Mambo/Joomlah Sam :P

  8. JerryWho Says:

    tell Danny this, because he asked us to tell you.

  9. 矮子 Says:

    is this an advertisement for yyps ?

  10. Paul Ooi Says:

    tell Danny this, he asked you to tell me? …

  11. 星空の語 Says:

    jerrywho, i not understand! what do you mean by “tell Danny this, because he asked us to tell you. ”

    i think i very long long long time never talk to you. and i talk to paul everyday. please don’t simply use my name. thanks

  12. Paul Ooi Says:

    ya.. we chat everyday… by the way what is “tell Danny this, because he asked us to tell you” means..?

  13. dino Says:

    “tell Danny this, because he asked us to tell you” = 火星语?

  14. SoGua Says:

    hahaha “tell Danny this, because he asked us to tell you” = 火星语?
    i’m not from 火星 so i cant understand

  15. sam Says:

    well, tell Lai tell Qu no use one. The bottom line is no one patched…

    I remember sending people a link about the file injection vulnerability a week ago (forgot when exactly been travelling a lot). Still everyone kena. tell…

  16. mike Says:

    duh??? what u guys talking bout??? who tell who what about what?

  17. farking Says:

    it didnt tell..it stop it paul.. go read!

  18. geek00L Says:

    Dude, mod_security does give you protection instead of logging capabilities only, you will have to learn how to write the filtering, go play with it.

    mod_security == application firewall in that sense.

  19. langkasuka Says:

    ‘tell’ing …. great hack-graphics…

  20. sam Says:

    Life is a box of chocolate… it gets us confused sometimes. hahaha…

  21. JerryWho Says:

    hahaha… danny! so, you are really god… cannot use your name in vain.

  22. Andrew Says:

    It’s all Max’s fault.

    He is taking revenge because you make him work at THAT company.

  23. Paul Ooi Says:

    when r u taking revenge on me because I made you what at THAT company too

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Latest comments

    • 矮子 poor asssssssssssssssss..(Go)
    • squall take care baby..(Go)
    • luke p.s. i forgot to mentio..(Go)
    • luke the shop should give yo..(Go)
    • Paul Ooi 太过没那么严重..(Go)
    • Chuan Wen (请别讨论敏感话..(Go)
    • Paul Ooi tun mel, tu orang da..(Go)
    • spoonfork Tun Paul, Style Tun ..(Go)
    • 矮子 estonia .....good count..(Go)
    • Chloe hahaha ~ 有同感..(Go)
  • Latest commented posts

  • Most commented posts