Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

website defaced by ange78 - screencapture

Loading...

Sign in or sign up now!
1,819
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Apr 3, 2009

I would like to know how ange78 defaced my website so i can prevent it from happening again. It made me feel violated but happy that they didnt do anything harmful. This is the second time I have had a site hacked, the other time they took over my email and used it to send spam.
My webhost, Hostgator, leaves indexes visible by default. This is not good for security measures and unless you are "in the know" you wouldnt know to change your indexes to hidden. I suspect the hackers browse the index for a php form and then do some SQL injection. Any other theories would be greatly appreciated. This was on a fresh wordpress 2.7.1 install and I even had "maintenance mode" enabled so you couldnt see the website without logging in...

Are you guys jerks for giving this labeled-as-is video a ONE STAR or am I a loser for CARING?

Just trying to spread the word and help show people what is going on. For christ's sake I even overlayed a comedy soundtrack for your bloody entertainment. Enjoy your anonymous flaming, losers.

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 3 dislikes

Link to this comment:

Share to:

Uploader Comments (pabbananna)

  • My host also told me that WP is VERY vulnerable. You may also wanna look into a different host. I use InMotion and they're awesome! When this happened to me, I called, they told me exactly where he got in (WP) and in less than 2 or 3 minutes, the original site was restored. Luckily I had recent backups as well... but they did it all for me. Good luck!

  • Yes, I agree. But does the host have much to do with it? I use hostgator and their service is excellent.

    RE: backups: WP backups arent straigforward at all. I guess the only real option is to FTP the whole darned site but on my connection that takes a loooong time.

    Because of these issues I am no longer recommending wordpress to anyone. Time to learn drupal - and its security weaknesses! I wonder if it is more secure or if it just isnt hacked because it isnt as widespread?

  • The main problem is using WordPress. There are a lot of security holes in WP, and once a patch is created and applied, another hole is exploited. Don't really know what the deal is with WP, but the majority of sites hacked by this loser are WP sites. Move to Drupal or Silver Stripe and you should be fine. Just delete ALL references to WP in your server.

    That's my opinion.

  • I agree. My friends business WP site just got hacked too. In their case javascript was injected into the header.php file causing a redirect. Unless you are going to update wordpress constantly along with all the plugins - and deal with update related conflicts/compatibility, it just isnt worth the risk.

see all

All Comments (14)

Sign In or Sign Up now to post a comment!
  • I know how it feels. I created a website which took me like 3 weeks to make. I had loads of Flash games and videos and pics. I finally finished at about 2am and called my mate to tell him. He said, did you put security on it? I said no. I dont need it. He said that I should. I went to bed all happy, then when I went on my website the next day, It was Hacked and Defaced.

  • @CaseClosedEpisodes

    thanks! like this? blog.ericlamb.net/2010/02/the-­horrors-of-c99-php/

    but how do i prevent it in the future?

  • @pabbananna

    Lol I was a complete noob back when I commented on this video >.>

    That guy just SQL Injected your website and uploaded a C99 script.

  • @CaseClosedEpisodes is this possible because of an FTP permission or read/write permission that was left open? You cant upload without having access to ftp and there is an anonymous account enabled by default with hostgator - i thought that might be the problem.

    Thanks for solving the mystery!

  • Yes. Most large hosts, like InMotion, HostMonster and HostGator all have redundant backups in case there's a problem. My host restored everything from their nightly backups.

    I use Drupal on 4 of my sites, and PrestaShop on my eCommerce site. I absolutely LOVE Drupal. All CMS's have their security weaknesses, but Drupal really is one of the most secure CMS's available. WP si by far the most popular, but Drupal is on the top of the list too. Check it out. Theres learning curve, but not bad at all

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more