Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

I don't know who this "globalpoweringgathering" hacker is, but burn in hell, scumbag(s)...

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
Amerigo Vespucci Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 04:18 PM
Original message
I don't know who this "globalpoweringgathering" hacker is, but burn in hell, scumbag(s)...
I have two Websites that got hacked. My Web Host has a big, big bullseye painted on their backs right now (DreamHost)...here's what they wrote on their support blog yesterday afternoon:

Update 6:15pm PST: In a nutshell we suffered an extremely sophisticated attack. It took a while to get things under control enough to see what was going on and then start not only blocking attack vectors but track down and disable software being used to launch attacks from our network as well. Things are almost under control currently and once they are we’ll get a full and detailed report from our network engineers for you. -John

http://www.dreamhoststatus.com/


So what happened? Without knowing for sure, it looks like I had an older installation of WordPress that was exploited by the hacker on two of my sites. They injected a line of script in my HTML pages, and also some malicious code in my PHP files. This means people accessing my site who are running antivirus / anti-malware software are getting legitimate red alerts about attempts to install drive-by malicious programs, and I'm getting blacklisted on Google until I fix it.

I've since changed my FTP password, but I also have to do cleanup and re-submit both sites to Google so that I am no longer on the "Malware Blacklist."

On one site, via Web FTP, I had to open about 30 pages and remove the lines of code they injected. I ran the scanner again and it came up clean.

The other site? About 250 pages, one page at a time. I have about a dozen pages left.

I may end up having to move the sites I have on DreamHost...about 25...because unless they can get that bullseye off their back, this shit is going to keep on happening. I have all of my programs like WordPress sett to auto-update from here on, so maybe that will solve it. Maybe not.

Don't grow up to be Webmasters, kids, unless you love it (I do, that's why I chose it).

:-)
Printer Friendly | Permalink |  | Top
Drale Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 04:32 PM
Response to Original message
1. Hackers are pissing me off lately
I have not been able to play COD with my friends for like 10 days because of them. FUCK HACKERS!!
Printer Friendly | Permalink |  | Top
 
notesdev Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 05:04 PM
Response to Original message
2. Who was actually maintaining that installation
if you were maintaining your own WP files you can hardly blame the host if your files were insecure. You have to do your own maintenance on WP, and they do provide a very simple method for most WP users to do so.
Printer Friendly | Permalink |  | Top
 
Amerigo Vespucci Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 05:47 PM
Response to Reply #2
5. I should have had it set to "update automatically"...
...but this was one of those out of sight, out of mind things, and it bit me, so yeah...I could have taken a simple step to prevent it.

But now I have, and my bigger concern is that if the host is addressing the bigger issue of their being in the crosshairs, great. If it gets too difficult for these assholes to pick off targets, they'll go somewhere else. That except I posted from the DreamHost support blog had nothing to do with me or WordPress on my site. They found themselves on the receiving end of an attack bigger than any they'd experienced before.
Printer Friendly | Permalink |  | Top
 
DavidDvorkin Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 05:07 PM
Response to Original message
3. My wife's site is on Dreamhost
I've been happy with their hosting, but I've been lucky compared to you.

What a nasty experience!
Printer Friendly | Permalink |  | Top
 
sabrina 1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 05:15 PM
Response to Original message
4. I wonder if that is the reason I kept getting
'virus alerts' from what claimed to be Google, telling me they had scanned my computer and it had dozens of dangerous viruses and I should download, (and pay for) the 'fix'. I kept deleting the messages but they are hard to get off your screen. I finally shut down the computer and when I started it up, everything was fine.

I think it began when I went to a website, forget which one to look something up.

Anyhow, since I've had no more problems, I assumed it was just a nasty marketing trick to get people's credit card info.
Printer Friendly | Permalink |  | Top
 
SlimJimmy Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 05:52 PM
Response to Reply #4
6. Sounds like a malware/spyware hack
Go to the following website and read about what you can do. It's a completely free site dedicated to killing those bastards that like to attack us. The following is from the site and could be a possible offender.

http://www.bleepingcomputer.com/virus-removal

When BitDefender 2011 is installed it will be configured to start automatically when Windows starts. Once started it will perform a scan on your computer and when finished state that it is infected with a variety of malware. If you attempt to use the program to remove any of the malware it finds, though, it will state that you first need to purchase the program before it will remove anything. This is a complete scam as the scan results are all fake and many of the listed files are actually legitimate files that if removed could cause problems for your computer. Therefore, do not manually remove any of the items it displays in its scan results.
Printer Friendly | Permalink |  | Top
 
sabrina 1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 06:22 PM
Response to Reply #6
7. Thank you! That's exactly what happened.
I will definitely check out the site. It seems to be gone, but just in case I'd like to know what to do if it comes back.

Appreciate the link very much ~
Printer Friendly | Permalink |  | Top
 
SlimJimmy Donating Member (1000+ posts) Send PM | Profile | Ignore Sun May-01-11 06:48 PM
Response to Reply #7
8. YW. We've all been there at one time or another. (nt)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sat May 04th 2024, 05:35 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC