Pages:
Author

Topic: How was I hacked? (Read 1668 times)

newbie
Activity: 42
Merit: 0
April 04, 2015, 07:18:08 PM
#30
You must have better secure password, including characters, letters, numbers.
That is very important in order to be more secure. Also try to change your password once in a while.
what you have suggested would only help if they cracked the password by brute-force which it appears they didnt do
sr. member
Activity: 362
Merit: 261
March 23, 2015, 04:58:43 AM
#29
Could be phpmyadmin vulnerability if your version is out of date.
full member
Activity: 180
Merit: 1003
March 21, 2015, 01:41:16 PM
#28

I would say most likely it was a exploit to gain acess.   Bruteforcing a 17 char password is something you really could not do espically if you are trying against a place online.   Unless just horrible security it would stop IP access if you just keep hitting it with wrong passwords.

Yes I realize now that brute force has a slim chance, I was kind of hoping that it was brute force because then I can fix it relatively easily but now I am not sure how he got access and just trying out everything just hoping to fix the website.
i think your website is vulnerable, are you running a faucet website or something?
Yes something similar, looking out for vulnerabilities and trying to fix them.
legendary
Activity: 1612
Merit: 1001
March 21, 2015, 01:08:56 PM
#27

I would say most likely it was a exploit to gain acess.   Bruteforcing a 17 char password is something you really could not do espically if you are trying against a place online.   Unless just horrible security it would stop IP access if you just keep hitting it with wrong passwords.

Yes I realize now that brute force has a slim chance, I was kind of hoping that it was brute force because then I can fix it relatively easily but now I am not sure how he got access and just trying out everything just hoping to fix the website.
i think your website is vulnerable, are you running a faucet website or something?
member
Activity: 84
Merit: 10
March 21, 2015, 09:28:33 AM
#26
You must have better secure password, including characters, letters, numbers.
That is very important in order to be more secure. Also try to change your password once in a while.
legendary
Activity: 1456
Merit: 1000
March 21, 2015, 08:49:47 AM
#25
Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD



He could be using tor or a VPN. If he was smart he would be but you never know. He could also be using bots to rape the faucet.

Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD



Thanks I will try and contact earnfreebitcoins.com, the tragedy is that a cheaper hacker was able to get complete access to the database but in the end his stupidity saved my bitcoins.

I doubt they will just give out a users IP address to some random person, but hope you track him down. You should look into his address and see if it is spendlinked to others. You might be able to track him down to this forum or some other sites online.

Most likely you will need to turn it into some authority. (IE police or other agency).  They will be able to possibly get information such as IP.

If you do it yourself they will not give you a IP address of someone, most likely.
hero member
Activity: 500
Merit: 500
March 21, 2015, 07:34:51 AM
#24
Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD



He could be using tor or a VPN. If he was smart he would be but you never know. He could also be using bots to rape the faucet.

Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD



Thanks I will try and contact earnfreebitcoins.com, the tragedy is that a cheaper hacker was able to get complete access to the database but in the end his stupidity saved my bitcoins.

I doubt they will just give out a users IP address to some random person, but hope you track him down. You should look into his address and see if it is spendlinked to others. You might be able to track him down to this forum or some other sites online.
newbie
Activity: 42
Merit: 0
March 21, 2015, 07:16:06 AM
#23
hire a group of white hat hackers to test your site out, when they find possible exploits, fix them
member
Activity: 76
Merit: 10
March 21, 2015, 04:37:20 AM
#22
To bruteforce 17 char password it would take years!
full member
Activity: 180
Merit: 1003
March 21, 2015, 03:39:32 AM
#21

I would say most likely it was a exploit to gain acess.   Bruteforcing a 17 char password is something you really could not do espically if you are trying against a place online.   Unless just horrible security it would stop IP access if you just keep hitting it with wrong passwords.

Yes I realize now that brute force has a slim chance, I was kind of hoping that it was brute force because then I can fix it relatively easily but now I am not sure how he got access and just trying out everything just hoping to fix the website.
full member
Activity: 180
Merit: 1003
March 21, 2015, 03:35:40 AM
#20
Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD



Thanks I will try and contact earnfreebitcoins.com, the tragedy is that a cheaper hacker was able to get complete access to the database but in the end his stupidity saved my bitcoins.
full member
Activity: 180
Merit: 1003
March 21, 2015, 03:31:49 AM
#19
SSH (/etc/ssh/sshd_config)

1. Disable root SSH access.
Code:
PermitRootLogin no

2. Disable password-based SSH logins, use public keys instead.
Code:
PubkeyAuthentication yes
ChallengeResponseAuthentication no
PasswordAuthentication no

Learn more about key-based authentication here. Even better, read the whole Linux Crypto post series.


Other services

3. Remove phpMyAdmin. If you need to fuck shit up just log into the database server and issue plain SQL queries using mysql-client. Bottom line: don't expose any service to the internet other than SSH, HTTPS and/or HTTP.

4. Setup a firewall using ufw.


Passwords

5. Change every single password in the system. Follow the Diceware approach to password generation. Use 8 to 10 characters at least. Do write down your passwords. Paper will work, an encrypted file using your (properly stored) GPG key would be even better.

6. Hope for the best.

Thanks done some of them , working on doing others.
legendary
Activity: 1456
Merit: 1000
March 21, 2015, 12:25:29 AM
#18
Hi,
Today my bitcoin based website was hacked. The hacker changed the password of admin and other major accounts and changed the withdrawal bitcoin address of all accounts which had major balance. Though I did not lose any bitcoins as he broke the website by messing up the database and I became aware of the hack. The hacker was able to access my database , I suppose through phpmyadmin but I think he was not able to get ssh root access.

So I want to know how feasible it is to brute force a 17 character password having numbers+characters+symbol or should I look for any other way the hacker may have got in.

Hacker bitcoin address to which all the withdrawal addresses were set: 1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Regards

I would say most likely it was a exploit to gain acess.   Bruteforcing a 17 char password is something you really could not do espically if you are trying against a place online.   Unless just horrible security it would stop IP access if you just keep hitting it with wrong passwords.
hero member
Activity: 518
Merit: 501
Error 404: there seems to be nothing here.
March 20, 2015, 10:07:06 PM
#17
Thats Hackers address?
I found something interesting!

http://earnfreebitcoins.com/address/1A8AzZSQp2oxzdSJeUUpoNmeff9bLQKBRo

Contact the admin of earnfreebitcoins.com for the hackers ip! I don't think the hacker used any software like Tor when he used to visit sites to earn free bitcoins! The hacker is a cheap one! He just earned 0.0000083 from that free bitcoin site xD

legendary
Activity: 1204
Merit: 1001
March 20, 2015, 09:52:38 PM
#16
cuz you's a dumbfuk
rax
member
Activity: 86
Merit: 12
March 20, 2015, 06:42:58 PM
#15
SSH (/etc/ssh/sshd_config)

1. Disable root SSH access.
Code:
PermitRootLogin no

2. Disable password-based SSH logins, use public keys instead.
Code:
PubkeyAuthentication yes
ChallengeResponseAuthentication no
PasswordAuthentication no

Learn more about key-based authentication here. Even better, read the whole Linux Crypto post series.


Other services

3. Remove phpMyAdmin. If you need to fuck shit up just log into the database server and issue plain SQL queries using mysql-client. Bottom line: don't expose any service to the internet other than SSH, HTTPS and/or HTTP.

4. Setup a firewall using ufw.


Passwords

5. Change every single password in the system. Follow the Diceware approach to password generation. Use 8 to 10 words at least. Do write down your passwords. Paper will work, an encrypted file using your (properly stored) GPG key would be even better.

6. Hope for the best.
full member
Activity: 180
Merit: 1003
March 20, 2015, 12:43:33 PM
#14
So I want to know how feasible it is to brute force a 17 character password having numbers+characters+symbol or should I look for any other way the hacker may have got in.

It doesn't matter how long or complex your password is if you've got a keylogger or spyware. Have you scanned your comp for viruses?
Yes nothing there. I keylogger would have caused bigger problems.
member
Activity: 105
Merit: 10
March 20, 2015, 11:55:20 AM
#13
So I want to know how feasible it is to brute force a 17 character password having numbers+characters+symbol or should I look for any other way the hacker may have got in.

It doesn't matter how long or complex your password is if you've got a keylogger or spyware. Have you scanned your comp for viruses?
hero member
Activity: 714
Merit: 500
March 20, 2015, 11:05:58 AM
#12

Have you checked your e-mail address? Has been it compromise or not? Maybe the hacked 'caught' the access to your address and requested a password reset for you admin vps account.

There are no signs that my email has been compromised, since all the changes were made only in database I think he did not get access to my vps account or ssh but only got through phpmyadmin.

A long password takes too long to bruteforce. Hackers usually go for faster and easier ways. if the site is important to you, spend some btc and hire a white hat hacker to hack your site. Then you will know.
Can you suggest someone or where can I find one Smiley

Then yes, the malicious user has granted the access through the phpmyadmin panel. Maybe your password was 'weak' now you should improve your security.
full member
Activity: 180
Merit: 1003
March 20, 2015, 11:05:52 AM
#11
Are you using the latest version of phpMyAdmin? I think an older version had a security bug.
Also is it installed on tje default /phpmyadmim? Try a unique URL. Just to confirm I guess it uses SSL right?
And finally make sure to use .htpasswd besides the normal DB password. Were you already using it?
Have updated everything now, but do not have SSL or .htpasswd

If you think the hacker may have accessed the DB that way you should definitely add those. Regarding SSL a self signed certificate would do, just to prevent your DB password from being sent as plain text.

Thanks will add SSL to the website.
Pages:
Jump to: