This is a first. - preCharge Forums
It shows that you are unregistered. Please register with us by clicking Here
preCharge Forums


Nav Green LeftNav Right
preCharge Forums > Computers & Technology > Computers » This is a first.


Reply
Tcat Right
 
LinkBack Thread Tools Display Modes Tcat Right
Old 01-04-2008   #1 (permalink)
StarLab
Forum Management
 
StarLab's Avatar
 
Join Date: Jul 2006
Location: Ontario, Canada
Age: 47
Posts: 1,465
Send a message via ICQ to StarLab Send a message via MSN to StarLab
Angry This is a first.

Greetings.

I had the extreme pleasure of dealing with a hacker on one of my clients over the last couple days.

Malicious code had been inserted onto his site. This code was a phishing scam (like those fake emails you get from PayPal requesting you to change your password) which launched over 800 emails to unsuspecting banking customers.

They went as far as to setup a fake banking site for people to login to. Once logged in, the login info was then sent to hacker, giving him full access to the customer's account on the true banking site.

Thankfully, the hosting company was right on top of their security and was alerted to the problem immediately. The bad part is the host suspended the web site for 2 days while I dealt with the problem.

Apparently, my client had changed his cPanel/FTP password to something he could remember easily which made his site vulnerable.

I have a download of the "fake" banking site, but it's all compiled javascript. I know this is likely a stupid question, but is there any way to uncompile this? I just want to try and figure out where the login info would have been sent.

All in all, quite the experience.
__________________
Larry
[Torn Elements] - Regaining the passion in design.
[LarryMonte.Com] - Personal Blog (WIP)


"Writing is the most fun you can have by yourself!" --Terry Pratchett
----
Gorgeous On Life - The world from a Cat's point of view!
StarLab is offline   Reply With Quote

Old 01-05-2008   #2 (permalink)
Jerlene
Senior Member
 
Jerlene's Avatar
 
Join Date: Jul 2007
Location: fatshits.com
Age: 23
Posts: 1,250
Send a message via AIM to Jerlene Send a message via MSN to Jerlene Send a message via Yahoo to Jerlene
Default Re: This is a first.

I actually receive quite a few emails like this. There's so many scams like this you'd think there were turn key sites for this kind of things.
You should report it here.
Jerlene is offline   Reply With Quote

Old 01-05-2008   #3 (permalink)
StarLab
Forum Management
 
StarLab's Avatar
 
Join Date: Jul 2006
Location: Ontario, Canada
Age: 47
Posts: 1,465
Send a message via ICQ to StarLab Send a message via MSN to StarLab
Default Re: This is a first.

Well, considering the fake site was disabled moments after the emails went out, I doubt anyone will be taken by it.

Still haven't really got all the details yet anyway.
__________________
Larry
[Torn Elements] - Regaining the passion in design.
[LarryMonte.Com] - Personal Blog (WIP)


"Writing is the most fun you can have by yourself!" --Terry Pratchett
----
Gorgeous On Life - The world from a Cat's point of view!
StarLab is offline   Reply With Quote

Old 01-07-2008   #4 (permalink)
robert
Super Moderator
 
Join Date: Jun 2006
Age: 32
Posts: 1,133
Default Re: This is a first.

I would love to hire a trusted hacker but I feel that the two ideas don't mix ;)
__________________
Hi! Welcome to preCharge.NET
robert is offline   Reply With Quote

Old 01-07-2008   #5 (permalink)
StarLab
Forum Management
 
StarLab's Avatar
 
Join Date: Jul 2006
Location: Ontario, Canada
Age: 47
Posts: 1,465
Send a message via ICQ to StarLab Send a message via MSN to StarLab
Default Re: This is a first.

Quote:
Originally Posted by robert View Post
I would love to hire a trusted hacker but I feel that the two ideas don't mix ;)
lol! Nope I don't suppose they don't.

"Trusted Hacker" is something of an oxymoron, me thinks...

And just to update, the site got hit again. Turns out there was a vulnerability in the bridge I was using to integrate Joomla and Gallery2 allowing the injection of the trojan: PHP/C99Shell.C which opened up a nice little back door.

All fixed now.

I am now on a first name basis with the hosting company's technicians! lol
__________________
Larry
[Torn Elements] - Regaining the passion in design.
[LarryMonte.Com] - Personal Blog (WIP)


"Writing is the most fun you can have by yourself!" --Terry Pratchett
----
Gorgeous On Life - The world from a Cat's point of view!

Last edited by StarLab : 01-08-2008 at 11:49 AM.
StarLab is offline   Reply With Quote

Old 01-08-2008   #6 (permalink)
Jerlene
Senior Member
 
Jerlene's Avatar
 
Join Date: Jul 2007
Location: fatshits.com
Age: 23
Posts: 1,250
Send a message via AIM to Jerlene Send a message via MSN to Jerlene Send a message via Yahoo to Jerlene
Default Re: This is a first.

A lot of big companies such as Microsoft hires hackers.
If it weren't for these hackers, a lot of programs you use would have more holes in them.
Jerlene is offline   Reply With Quote

Old 01-08-2008   #7 (permalink)
StarLab
Forum Management
 
StarLab's Avatar
 
Join Date: Jul 2006
Location: Ontario, Canada
Age: 47
Posts: 1,465
Send a message via ICQ to StarLab Send a message via MSN to StarLab
Default Re: This is a first.

The thing about hacking is that it's usually something that cannot be taught. It requires a certain amount of intuitive thinking. They are thought to be more cleaver than the people who wrote the security programs.

Rumour has it that the FBI will hire the big time hackers for consultation after they've been busted.

And they say crime doesn't pay. It does until you get caught, then it turns into a career. lol
__________________
Larry
[Torn Elements] - Regaining the passion in design.
[LarryMonte.Com] - Personal Blog (WIP)


"Writing is the most fun you can have by yourself!" --Terry Pratchett
----
Gorgeous On Life - The world from a Cat's point of view!
StarLab is offline   Reply With Quote

Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


footer left
All times are GMT. The time now is 12:01 PM.

DISCLAIMER: preCharge Risk Management is not responsible for any opinions, advice or comments expressed on the preCharge Community Forums.
preCharge® is a registered trademark of preCharge Risk Management | chargeback protection | Merchant Account Blog

Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0 RC6

Breast Enlargement | Debt Help | Breast Enlargement | Cheap Computer Parts | Submit articles

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49