I’ve Been Exploited

---

A couple days ago I noticed I had an unusual amount of traffic to my site from a number of IP addresses beginning with 222. I checked my logs and found out they had installed a backdoor into my Dreamhost user account, which was the web application called C99Shell.

Obviously this is a serious vulnerability (just Google it) and I have worked to eliminate it from my site. Unfortunately, I noticed they had come back — with bash access. How they got it is beyond me, but I’ve taken some steps to prevent them from returning (changing my password, etc.) . I put this out here because the script-kiddies are capable of much more than what they’ve been doing (spamming) whether they know it or not. I’ve ensured that they have _not_ installed any viruses on any of my site, but take care while browsing not to use Internet Explorer, just in case anything _does_ happen. Also be aware that all comments henceforth must be approved by me.

Web 2.0 Bookmarks:These icons link to social bookmarking sites where readers can share and discover new web pages.
  • co.mments
  • del.icio.us
  • De.lirio.us
  • digg
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb

2 Responses to “I’ve Been Exploited”

  1. I’ve Been Exploited Says:

    […] Original post by possum.kicks-ass.org and published by w-plaza This entry is filed under News. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site. Leave a Reply […]

    Using WordPress WordPress 2.0.4
  2. Possum Says:

    I just wanted to point out , for anyone who is concerned, that this problem appears to have occurred with Wordpress 1.5.4 (I think) on a shared hosting Debian machine with what appears to be a buffer overflow via the login interface. I have since upgraded to the latest Wordpress 2.0.5.

    Using Mozilla Firefox Mozilla Firefox 1.5.0.3 on SuSE Linux SuSE Linux
TOP READERS#comments
Kevin^L43
Mary28
tim10
Adam7
The Cheshire Hippie6

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>