Notices

View Poll Results: Has your website ever been hacked or attacked?

Voters
51. You may not vote on this poll
  • No, never.

    15 29.41%
  • Yes, but the damage was minimal and it just took a few minutes to fix.

    8 15.69%
  • Yes, and it took an hour or two to fix.

    5 9.80%
  • Yes, and it took up to a day to fix.

    3 5.88%
  • Yes, and it took more than a day and less than a week to fix.

    12 23.53%
  • Yes, and it took more than a week to fix.

    5 9.80%
  • Yes, and I gave up on the site that was hacked or attacked.

    3 5.88%
+ Reply to Thread
Results 1 to 20 of 27
Page 1 of 2 1 2 LastLast
  1. MichaelCorfman's Avatar
    MichaelCorfman is offline GPWA Executive Director
    Join Date
    June 2004
    Location
    Newton, MA
    Posts
    2,772
    Thanks
    402
    Thanked 2,370 Times in 850 Posts

    Has your website ever been hacked or attacked?

    I've heard some horror stories over the years about websites being hacked or attacked. Certainly members here have shared stories.

    Have your sites ever been hacked? Or attacked?

    If so, what was involved in recovering? Was it easy or hard?

    Share your experiences, and what you learned in the process, with your fellow webmasters here.

    Michael
    Executive Director, www.GPWA.org
    CEO, CasinoCity.com
    Friend to the Village Idiot
    Reply With Quote Reply With Quote  

  2. michael1981 is offline Public Member
    Join Date
    April 2011
    Location
    Australia
    Posts
    261
    Thanks
    4
    Thanked 46 Times in 37 Posts

    I once had a website hacked about 2 years ago. Someone managed to hack my shared hosting reseller server and redirected my traffic to a malicious attack site. It was really quite shocking, and I had no idea what was going on.

    At first I thought my computer had a virus, until I saw the same thing happening on my friends computer. It only happened when I clicked on my website after searching for it in Google for certain keywords, and it only seemed to happen with Firefox as well. It was very hard to detect since I never usually click on my own website after searching for it in Google. It took about a day to fix, just a matter of upgrading to a better hosting service
    Reply With Quote Reply With Quote  

  3. dfiocch's Avatar
    dfiocch is offline Private Member
    Join Date
    September 2006
    Posts
    95
    Thanks
    13
    Thanked 7 Times in 7 Posts

    Yes, my site was hacked one year ago by a Chinese hacker. It was very easy to recover it because it was "only" a php script injection (about two hours to recover all).
    Reply With Quote Reply With Quote  

  4. baldidiot is online now Private Member
    Join Date
    January 2010
    Posts
    1,509
    Thanks
    196
    Thanked 310 Times in 249 Posts

    The only damage to one my sites was by my host who managed to screw up my VPS so badly it had to be deleted and restored from backups. Who needs hackers when you have incompetent providers!
    Good Bonus Guide - Features sections on sports betting, casino, poker & bingo.
    Baldidiot.net - Baldys affiliate blog.
    Reply With Quote Reply With Quote  

  5. robertmedl's Avatar
    robertmedl is offline Private Member
    Join Date
    February 2006
    Location
    Loveland, OH
    Posts
    353
    Thanks
    62
    Thanked 75 Times in 58 Posts

    A couple of years ago, someone hacked my blog such that the keywords that Google identified for my blog were online pharma keywords, e.g. viagra, etc. I never figured how they did it, but I'm not too skilled in that area. It took me several days to reconstruct my blog entries to remove all the offending content and then several weeks before my intended keywords were correctly identified by Google.
    Reply With Quote Reply With Quote  

  6. slotplayer is offline Private Member
    Join Date
    September 2006
    Posts
    519
    Thanks
    92
    Thanked 139 Times in 115 Posts

    yes in 2008. I had my FTP pane open and could see the malcode migrate to each file as the last modified date would change, one file after another. It inserted some javscript code at the bottom of each page. It wasn't that hard to remove.

    I'm not sure if my local system got infected and I uploaded an infected file or they got in to the FTP program or host provider.

    The last modified date is a quick and easy way of checking if something is amiss.
    Reply With Quote Reply With Quote  

  7. felku's Avatar
    felku is offline Private Member
    Join Date
    May 2011
    Posts
    213
    Thanks
    0
    Thanked 9 Times in 8 Posts

    My question those who were hacked, you were ranking good in Serps?
    Reply With Quote Reply With Quote  

  8. dfiocch's Avatar
    dfiocch is offline Private Member
    Join Date
    September 2006
    Posts
    95
    Thanks
    13
    Thanked 7 Times in 7 Posts

    Quote Originally Posted by felku View Post
    My question those who were hacked, you were ranking good in Serps?
    Yes. First page for a lot of keywords.
    Reply With Quote Reply With Quote  

  9. felku's Avatar
    felku is offline Private Member
    Join Date
    May 2011
    Posts
    213
    Thanks
    0
    Thanked 9 Times in 8 Posts

    ok, it can be that maybe it was the competition. There is a way to prevent this things? I'm new in this and I notice that when you reach some position you get a lot of attention especially for the competition.
    Reply With Quote Reply With Quote  

  10. dfiocch's Avatar
    dfiocch is offline Private Member
    Join Date
    September 2006
    Posts
    95
    Thanks
    13
    Thanked 7 Times in 7 Posts

    Quote Originally Posted by felku View Post
    ok, it can be that maybe it was the competition. There is a way to prevent this things? I'm new in this and I notice that when you reach some position you get a lot of attention especially for the competition.
    Set a very strong password for all your www accounts (hosting,FTP,root access etc...).
    Set up a firewall for your hosting account (contact your hosting company. If you're on a dedicated or VPS, you can setup it yourself). A firewall can help you to prevent hacking attacks and blocking malicious IPs.
    Set up a very strong password for all your POP3 accounts (email). All common attacks come from POP3 bugs.
    Set up a "dedicated" IP for your site.
    Set up correctly your .htaccess or htaccess.txt (if you are on Apache server) to block a lot of common exploits (just search on Google).

    Just some "basics" rules.
    Hope can help.
    Reply With Quote Reply With Quote  

  11. felku's Avatar
    felku is offline Private Member
    Join Date
    May 2011
    Posts
    213
    Thanks
    0
    Thanked 9 Times in 8 Posts

    Great advice, thanks. Now I'm convince that I will change to VPS.
    Reply With Quote Reply With Quote  

  12. allfreechips's Avatar
    allfreechips is offline Private Member
    Join Date
    August 2010
    Location
    Ohio - The taxing state
    Posts
    145
    Thanks
    8
    Thanked 15 Times in 12 Posts

    I got hacked, and that led to some acess to email for the hostin company, in turn led to them getting access to passwords (I hate places that send you the actual password via email) and they transfered 4 of my domains to another registrar. Now, this went un noticed for some time as all my sites are managed from my cms online, and of course i never noticed any change as they did not change content for 5 months, then they changes some aff accounts. This was a hassle but i fixed it and closed the orig hole i had. Now when i fixed the hole via ftp, the changes were not taling effect on the website. So after goining nuts i found they finally moved the server to a new host, totally intact. except i had no more ownership.

    This went on for 6 months of me contacting ICANN and all the registrars and hosts involved. All they said was you transfered the domain there not much we can do!

    Imaging all your work being out of your control! not until I was actually able to contact the new "owner" in Vietnam did I arrange to get the domains back after discussing the inrest Interpol had with my case.

    I still get sick thinking of these times, so one lesson is to monitor your registrars and I actually made it so they neeed a voice password to change any info anymore.
    Allfreechips online casino guide offers online casino reviews from our members. Also our exclusive No Deposit casino bonuses are always up to date. See the latest slot machine reviews at Hotslot and exclusive no deposit casino bonuses as well with a good dose of daily online gambling news
    Reply With Quote Reply With Quote  

  13. felku's Avatar
    felku is offline Private Member
    Join Date
    May 2011
    Posts
    213
    Thanks
    0
    Thanked 9 Times in 8 Posts

    Wow, thanks for sharing your experience.
    Reply With Quote Reply With Quote  

  14. rak's Avatar
    rak
    rak is offline Sponsor Affiliate Program
    Join Date
    January 2011
    Location
    Brisbane
    Posts
    835
    Thanks
    155
    Thanked 202 Times in 164 Posts

    I got hacked because I didnt update my software. The forum software kept timing out when I tried to update it. It got hacked, files were being uploaded and used as a warez link site, bandwidth through the roof, bill went sky rocketing, forum was being pulled apart... took a week to get back under control.

    2 months later.. again. Same thing. I dumped the forum software and never recovered.
    Rakesh Karan - Affiliate Manager
    Skype : rakonskype

    Reply With Quote Reply With Quote  

  15. padovan is offline Private Member
    Join Date
    August 2011
    Location
    Whitby, Ontario, Canada
    Posts
    3
    Thanks
    0
    Thanked 0 Times in 0 Posts

    We got hacked before but they just put some movies on the server so they were easy enough to remove and we fixed the security problem right away.
    Reply With Quote Reply With Quote  

  16. Leo's Avatar
    Leo
    Leo is offline Private Member
    Join Date
    December 2008
    Posts
    99
    Thanks
    50
    Thanked 26 Times in 21 Posts

    I have had hackers enter sites a few times, mostly through php scripts that weren't fully secure.

    If you're using a VPS or server with cPanel then I recommend using the software from configserver.com - they have a few good products including the firewall (free) and exploit scanner (one-time fee).

    Also if you do find that a hacker has managed to change something on your site then I highly recommend getting a professional to check the server thoroughly, because it's possible that a hidden backdoor has been placed and unless you're a security expert then you're not going to find it. Again, configserver.com has a service for this, which I have used and recommend. In fact whenever I get a new VPS the first thing I do is hire them to install all their security software and change the server settings to be more secure, it costs $100 which is a one-time fee, and their software keeps updating itself constantly.

    Yes I sound like an ad for configserver.com but it's because all my servers rely on them, I haven't had any security problems since using their software, and I recommend them to everybody. But since this does all sound tooooo positive, I'll add a negative - their support people can be a bit arrogant at times - but I give them a free pass because they're good at their jobs
    Reply With Quote Reply With Quote  

  17. 32x's Avatar
    32x
    32x is offline Public Member
    Join Date
    October 2009
    Location
    Here
    Posts
    54
    Thanks
    40
    Thanked 9 Times in 7 Posts

    About a year or two ago, I had a blog that was not protected by my Unix framework. It was a Wordpress site that came free with my hosting package. Well, someone hacked it and I was so frustrated that I just did put anything on it again until just recently. It is now a Google blog and I am happier with it, so far..

    I also seem to remember having a few pages hacked, and some ads were embedded into my homepage, before I switched to Unix.
    Reply With Quote Reply With Quote  

  18. LiveCasinoPartners's Avatar
    LiveCasinoPartners is offline Sponsor Affiliate Program
    Join Date
    March 2006
    Location
    Costa Rica
    Posts
    2,065
    Thanks
    132
    Thanked 152 Times in 109 Posts

    Yes, It's still not funny. Someone hacked into my server (affiliate site) and changed the .htaccess file to redirect all of the inner pages to an animal porn site. So clicked on a keyword term in google they are expecting something related to live games, they are given a huge donkey phallus. Nice and classy. I was fortunate that I wasn't banned from google on that site. I quickly learned a lot about proper server configuration. Since then there have been attempts, but so far no one has breached the security.
    Reply With Quote Reply With Quote  

  19. lots0's Avatar
    lots0 is offline Public Member
    Join Date
    November 2003
    Posts
    363
    Blog Entries
    2
    Thanks
    88
    Thanked 122 Times in 80 Posts

    We had an employee(remote tech) of our hosting company inserting redirects, not to pics of donkey dicks, but to his own aff accounts. Cost us a bundle.

    The redirects were well hidden and I hate to say it, well written htaccess files. He was smart enough to take only a percentage of all our click throughs and to cover his tracks well.

    Once we figured out we were hacked (I stumbled across one of his redirects by accident).
    the thief of course knew we found him out, he worked as a 'security' consultant.

    Once he knew we were closing in on him, he started making injection attacks in an attempt to cover his tracks. When that didn't work... the SOB made a hell of an effort to screw us by deleting all our db's.... multiple redundant backups.. don't go anywhere with out them.
    Last edited by lots0; 28 September 2011 at 2:43 am.
    Reply With Quote Reply With Quote  

  20. davemerry's Avatar
    davemerry is offline Sponsor Affiliate Program
    Join Date
    October 2010
    Location
    Essex, UK
    Posts
    668
    Thanks
    276
    Thanked 195 Times in 156 Posts

    Quote Originally Posted by lots0 View Post
    We had an employee(remote tech) of our hosting company inserting redirects, not to pics of donkey dicks, but to his own aff accounts. Cost us a bundle.

    The redirects were well hidden and I hate to say it, well written htaccess files. He was smart enough to take only a percentage of all our click throughs and to cover his tracks well.

    Once we figured out we were hacked (I stumbled across one of his redirects by accident).
    the thief of course knew we found him out, he worked as a 'security' consultant.

    Once he knew we were closing in on him, he started making injection attacks in an attempt to cover his tracks. When that didn't work... the SOB made a hell of an effort to screw us by deleting all our db's.... multiple redundant backups.. don't go anywhere with out them.
    Bloody hell, that is crazy. Do you know what happened to the employee?
    Dave Merry - Affiliate Program Director
    Castle Affiliates - Live Dealer Casino Affiliate Program
    www.castleaffiliates.com | www.castlecasino.com
    Reply With Quote Reply With Quote  

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts