Go Back   BELLYDANCE CENTRAL - Everything Belly Dance! Welcome to BHUZ - Biggest Online BellyDance Community > More Bellydance! > Technical Forum


I was hacked!!!

Technical Forum


Reply
 
Thread Tools Display Modes
Old 10-03-2007, 06:07 PM   #1
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
I was hacked!!!

My personal website and my online store was hacked. Summer caught it and sent me a note. Why are people so mean? I'm all about NO war...and now so is my website

Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*

Last edited by theesfield : 10-03-2007 at 06:55 PM. Reason: typo..oops
theesfield is online now   Reply With Quote
Sponsored Links

Old 10-03-2007, 06:12 PM   #2
sumayasaahir
Ultimate BHUZzer
 
sumayasaahir's Avatar
 
Join Date: Jul 2003
Location: United States
Posts: 6,641
Oh Hugs! You poor thing, that sucks!
__________________
Hadia Teacher Training Registration is now open!
www.Sumaya-BellyDance.com
sumayasaahir is online now   Reply With Quote
Old 10-03-2007, 06:16 PM   #3
angelique2
Advanced BHUZzer
 
angelique2's Avatar
 
Join Date: Jul 2005
Location: United States
Posts: 1,117
I feel for you,,,, I had it happen to me, not that long ago.
__________________
"Dance is so important in the world. It needs no language. Our bodies speak a language of its own.", - Ibrahim Farrah
angelique2 is online now   Reply With Quote
Old 10-03-2007, 06:38 PM   #4
laura 2
Master BHUZzer
 
laura 2's Avatar
 
Join Date: Aug 2004
Location: United States
Posts: 4,062
Oh no!!!!!!!
__________________
Galatea Middle Eastern Dance - www.galateadancer.com
laura 2 is offline   Reply With Quote
Old 10-03-2007, 06:53 PM   #5
azahara
Official BHUZzer
 
azahara's Avatar
 
Join Date: Oct 2003
Location: United States
Posts: 553
Sorry , some people are just big dumb animals who only feel better by bullying on others .
__________________
zahararaks.com
azahara is offline   Reply With Quote
Old 10-03-2007, 07:28 PM   #6
angelique2
Advanced BHUZzer
 
angelique2's Avatar
 
Join Date: Jul 2005
Location: United States
Posts: 1,117
Is there anyway to get your sites back?
I found out a friend stole my mine. I was able after 2 days got my myspace and email accounts back. Bbut it was a lot of crap trying.......
__________________
"Dance is so important in the world. It needs no language. Our bodies speak a language of its own.", - Ibrahim Farrah
angelique2 is online now   Reply With Quote
Old 10-03-2007, 10:21 PM   #7
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
I haven't a clue. I have no idea what to do. I contacted my web master. He said he would download the site and look into it, but it might take a while. ::sigh::
Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*
theesfield is online now   Reply With Quote
Old 10-03-2007, 11:14 PM   #8
*Shira*
Master BHUZzer
 
*Shira*'s Avatar
 
Join Date: Feb 2006
Posts: 3,470
Do you happen to know whether your web hosting company runs the Microsoft web server, the Apache one, or something else? I've heard that Microsoft ones are easier to hack into than Apache, but I don't know how true that is.
*Shira* is online now   Reply With Quote
Old 10-04-2007, 12:24 AM   #9
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
Webmaster to the rescue! I'm fixed..but he's still trying to figure out how they did it. Apparently they are very sneaky. But I am up and running again. Thanks for the heads up Summer!

Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*
theesfield is online now   Reply With Quote
Old 10-04-2007, 03:11 AM   #10
kharis_UK
Mega BHUZzer
 
kharis_UK's Avatar
 
Join Date: Nov 2000
Location: United Kingdom
Posts: 2,369
Quote:
Originally Posted by theesfield View Post
My personal website and my online store was hacked. Summer caught it and sent me a note. Why are people so mean? I'm all about NO war...and now so is my website

Nilaja
You have a php website. These are notoriously easy to hack.
kharis_UK is online now   Reply With Quote
Old 10-04-2007, 03:16 AM   #11
sabrinabellydancer
Advanced BHUZzer
 
sabrinabellydancer's Avatar
 
Join Date: Jul 2007
Location: United States
Posts: 1,093
so sorry to hear that.
i deal with that stuff every day so can totally empathize.
kudos to your webmaster for getting the fix in so quickly. sounds like a real pro.

re servers: microsoft iis v. linux + apache
there are holes and back doors in every system i have every seen. that is the nature of a human made programing. unfortunately they can all be hacked with the right know-how.

make sure your usernames and passwords are as complex and secure as possible and remember to change your passwords often.

and back up , back up, back up!

ok, that is the end of my computer geek lecture - rant.
glad all is well again.
__________________
sabrinabellydancer.com
all for fun and fun for all
sabrinabellydancer is offline   Reply With Quote
Old 10-04-2007, 06:24 AM   #12
Surida
Advanced BHUZzer
 
Surida's Avatar
 
Join Date: Nov 2006
Location: United States
Posts: 1,138
What a horrible ordeal to have to go through!!! I am SO glad that things are okay for you now.
__________________
Indulge your Spirit!
Surida is online now   Reply With Quote
Old 10-04-2007, 08:37 AM   #13
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
I am utterly clueless when it comes to thiese kinds of things. I am lucky that I know how to update my store with new product and update my website with new info (although my website is still under construction..that's because I am clueless!) So when you tell me I have a php website...I don't know what that means. And my webmaster tells me to back up my website and download raw templetes...I don't know what he is talking about! I feel like such an idiot! I just can't get a grasp on this thing!
Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*
theesfield is online now   Reply With Quote
Old 10-04-2007, 09:43 AM   #14
asim1
I could get used to this!
 
asim1's Avatar
 
Join Date: Jun 2000
Location: United States
Posts: 174
Quote:
Originally Posted by theesfield View Post
I am utterly clueless when it comes to thiese kinds of things. I am lucky that I know how to update my store with new product and update my website with new info (although my website is still under construction..that's because I am clueless!) So when you tell me I have a php website...I don't know what that means. And my webmaster tells me to back up my website and download raw templetes...I don't know what he is talking about! I feel like such an idiot! I just can't get a grasp on this thing!
Nilaja
OK, here's web site 101. Please note that this is all quite generalized:

Essentially, web servers do nothing but copy files over the 'Net. Apache or Microsoft's IIS are at the core of this process, taking commands from (usually) your browser, and sends files (and other data) back to the browser in response. It copies the HTML file, and then copies each image the HTML file refers to; this is part of the reason image-heavy sites will sometimes appear without the images for awhile on slow connections.
PHP is sort-of an add on, or plugin, to Apache or IIS; it allows a program to generate HTML on the web server, as opposed to storing it in a file. This means the website can be modified by a program in response to some kinds of interactions; for example, almost every page on Bhuz is not a HTML file, but the output from a PHP program (you can tell by looking at the link; the ".php" indicates that the PHP program generated the page you're looking at). This is all done on the server, and the PHP code is written in such a way that the web server knows to send it as HTML that your browser can read like a HTML file.
Because it's code that's running in your web server, and your web server has access to the Operating System (like Windows) it's running, you can attack a PHP page, and get it to run stuff on the actual Operating System. Windows, and IIS, have been historically notorious for allowing such attacks, but have become much better over the last couple of years. This is the mostly likely attack vector; someone saw that you're running PHP, and used a weakness in PHP to get to the web server, and then to the Operating System. It's one of a thousand ways to get in, however, and no reason to remove PHP.

Your web guy should at least be upgrading PHP and Apache to the latest versions, and studying how they got in, so as to avoid future attacks along that vector. You really, honestly, shouldn't have to worry about this, and should not feel bad that you don't know -- LOTS of technical people I know aren't aware of how systems can be cracked. It's a lot like finding out how your car's fuel injection works, and is why you look for a good mechanic. :)

Does this help?


----asim, who pays the dancin' bills by developing database-backed web applications in the Security Dept. of a major financial institution.
__________________
See me at APOSTATE: Angry Young Black Man Does Raqs.
asim1 is offline   Reply With Quote
Old 10-04-2007, 10:01 AM   #15
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
I read your whole explaination. And I tried to understand it to the best of my knowledge. I appreciate you taking the time to educate me. Thank you so much! :off to lay my head down..it's spinning from all that techy talk:
Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*
theesfield is online now   Reply With Quote
Old 10-04-2007, 10:45 AM   #16
rakgirl
Established BHUZzer
 
rakgirl's Avatar
 
Join Date: Nov 2006
Location: United States
Posts: 861
you're welcome nilaja. I just wanted to see the store and was very surprised when that came up. Glad it's working now. I'll take a look again.
__________________
"We Are Occupied & Dedicated to the Preservation of the Motion of the Hips," George Clinton, Parliament Funkadelic
rakgirl is offline   Reply With Quote
Old 10-04-2007, 02:10 PM   #17
angelique2
Advanced BHUZzer
 
angelique2's Avatar
 
Join Date: Jul 2005
Location: United States
Posts: 1,117
I am happy that you got your web page back!!!
__________________
"Dance is so important in the world. It needs no language. Our bodies speak a language of its own.", - Ibrahim Farrah
angelique2 is online now   Reply With Quote
Old 10-07-2007, 02:35 AM   #18
shaynaz
Advanced BHUZzer
 
shaynaz's Avatar
 
Join Date: Sep 2003
Location: United States
Posts: 1,288
So did they steal any info or just put up a bunch of nonsense on your site?
shaynaz is online now   Reply With Quote
Old 10-07-2007, 02:37 AM   #19
theesfield
Advanced BHUZzer
 
theesfield's Avatar
 
Join Date: Feb 2005
Location: United States
Posts: 1,214
as far as we know, they just put up a no war message on my site. When we did a search on these hackers, they hack sites by the hundreds and put up their message.

Nilaja
__________________
Nilaja's Calico Garden
*Nilaja's Calico Garden*
theesfield is online now   Reply With Quote
Old 10-07-2007, 07:54 PM   #20
Lucinia
Established BHUZzer
 
Lucinia's Avatar
 
Join Date: Dec 2006
Location: United States
Posts: 982
hugh?
__________________
"Dancer are the athletes of God" Albert Einstien
Lucinia is online now   Reply With Quote
Old 10-08-2007, 02:30 PM   #21
azizaraks
Official BHUZzer
 
azizaraks's Avatar
 
Join Date: Nov 2004
Location: United States
Posts: 448
That's messed up. Sorry to hear that happened to you Nilaja!!
azizaraks is offline   Reply With Quote
Old 10-15-2007, 04:50 AM   #22
Lisa Michelle
Advanced BHUZzer
 
Lisa Michelle's Avatar
 
Join Date: Mar 2004
Location: United States
Posts: 1,177
Good thing you found it before it had been there for too long! Glad it is fixed for you.

And thanks Asim1 for the great techinical advice!

Lisa
__________________
"Do not go where the path may lead; go instead where there is no path and leave a trail." ~ Ralph Waldo Emerson www.AmariseDance.com
Lisa Michelle is online now   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -5. The time now is 11:39 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by