CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

My webby used to ebay Phish with.

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Haircut

Cadet
Cadet


Joined: Jul 26, 2007
Posts: 1
Location: UK

PostPosted: Thu Jul 26, 2007 10:38 am    Post subject: My webby used to ebay Phish with.
Reply with quote

My webby has recently been used to do a bit of ebay Phishing. Thanks to Google I found you guys.

CastleCops Link/eBay_phish499455.html

I'd just like some idea as to how this might have happened. I didn't put it there myself so I guess the webby was hacked, but if folders and files where added I'm guessing this is a bit more then a simple PHP-Nuke hack.

I had PhP-Nuke with latest patches for webby and forum.

I'm posting here as the website providers are being very slow to respond to me, I get the impression they think it’s down to me, I didn't even get a response stating what had happened until I contacted them.

Back to top
View users profile Send private message
IP: 194.237.*.*

Guest






PostPosted: Mon Jul 30, 2007 7:00 am    Post subject:
Reply with quote

No response ... cool.

Luckly you CC'd a friend the original e-mail that you sent. It ended up in my junk folder.

Anyway. I've responded to the original e-mail now and I'm still talking to the providers about getting the log files for you to look at.

I'll let you know if it ever happens.

Back to top
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Jul 31, 2007 6:44 pm    Post subject:
Reply with quote

You'll want to be sure everything is up-to-date, not just PHP-Nuke. For instance your server responded:

HTTP/1.1 200 OK
Date: Sat, 21 Jul 2007 17:23:50 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a-p1 PHP-CGI/0.1b
X-Powered-By: PHP/4.4.4
Content-Type: text/html
Transfer-Encoding: chunked

You'll want to be sure all of those are updated.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
haircut

Guest
IP: 194.237.*.*






PostPosted: Wed Aug 22, 2007 1:16 pm    Post subject:
Reply with quote

I just rent the webspace not the server, that's managed by a company.

I have my website back now but not without a lot of frustration.

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer