A frind's site got HACKED...what can be done now??? | FerrariChat

A frind's site got HACKED...what can be done now???

Discussion in 'Technology' started by 308geo, May 6, 2011.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    To anyone that has any knowledge that might help as I am almost sure that SOMEONE has encountered this problem somewhere in the past.

    An old friend of mine from back in high school has (HAD) a forum chat site very similar to FerrariChat here. It was about exotic parrots and similar birds. She also runs a small business centered on birds as well.

    Apparently, she went to the site sometime yesterday, only to find that it had been hacked by some pompous, gloating, a$$-wipe, jerk.

    Here is what was her site. Check out the "in-your-face" condition the site is displaying now:

    http://www.kitkatsparrotchat.com/

    Does ANYONE have ANY idea, clue, or advice as to what can be done to take back control of the site...or if that is even possible? Anyway to track down this POS? Any legal actions or repercussions that could be utilized to her benefit?

    I just figured someone here might be able to offer some help or advice...

    Here is what she has posted on her FB page:

    WHAT IS ON MY MIND...... A LETTER TO THE HACKER THAT TOOK KITKATSPARROTCHAT DOWN.... READ BELOW....

    DEAR HACKER,

    I would like to say that I totally don't understand a hackers need to ruin a persons heart and soul by hacking their hard work and passion in seconds. I want to say to my hacker this, and I don't know if my hacker is reading this or not. But, I would like to say this.... I hope you feel stronger, better, more powerful now that you have control of my Parrot message board, I hope that daily you just smile at yourself in the mirror or the dim light of your computer screen and feel proud of your accomplishment. I do understand it takes skill to do what you do, and can appreciate a dedicated worker bee... BUT, what you did is take down a learning center for bird owners. You took down 3 years of my life and love and passion to help others, and many other peoples passion and hard work too. You destroyed the one thing that still gave me a lot of joy.. Did you know that the persons board you hacked and took down was going through a million tests for cancer? Did you know that in taking my board away I have no place to just get lost in helping and teaching others while I await my demise?? Did you know that you have caused me to cry so many more tears than I thought possible and that feeling like I may not have a long time here in this world that I always thought I would leave the legacy of my board, that I was going to Will it to one of my most dedicated members should I die? Dear Hacker, YOU SUCK and Karma is a *****. Go back to your computer and destroy some more lives, but one day I hope you read this, and know that your game is not with out victims, and that I hope you can sleep at night......

    Just had to get that off my chest!


    Any & all advice is greatly appreciated.

    Thanks for reading.
     
  2. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    #2 308geo, May 6, 2011
    Last edited: May 6, 2011
  3. iamthesimpleone

    iamthesimpleone Formula 3

    Aug 23, 2005
    1,598
    austin, tx
    Full Name:
    Ben
    And the really sad part is, people like this usually don't even know what they're doing. They just get tools online to do all the work for them...

    I hope your friend's webhost has backups. Most hosting companies charge to restore the site though..... :(
     
  4. WJHMH

    WJHMH Two Time F1 World Champ
    Silver Subscribed

    Sep 5, 2001
    26,264
    Panther City, Texas
    Full Name:
    WJHMH
    Damn, that guy is all over the place.
     
  5. iamthesimpleone

    iamthesimpleone Formula 3

    Aug 23, 2005
    1,598
    austin, tx
    Full Name:
    Ben
    and only 18 years old......
     
  6. I.T. Guy

    I.T. Guy F1 World Champ

    Jul 17, 2004
    12,923
    Canada
    Full Name:
    Jason
    It can be fixed.
    She needs a web programmer / database guy to undo what was done, then install the latest version of the bulletin board software that most likely has the exploit the hacker used blocked with a security update.

    :(

    Her web host will give her:
    1) FTP login info
    2) database login info
    3) control panel login info
    4) backup files (we keep hourly backups for 96 hours)

    And it can all be put back. If the web host has no backups she needs to find a new web host (my company does this).

    Good luck!
     
  7. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    Her web host is "Go Daddy"...they told her they can back it up for $150...but they're not absolutely sure that will work (???)
     
  8. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    Yes he is...I can't wait for him to hack into the Navy SEALS computers. He can go join bin laden.

    Seriously, he really needs to find something more constructive to do with his time before someone gives him a good head thumping.
     
  9. Gran Drewismo

    Gran Drewismo F1 Rookie

    Jan 24, 2005
    3,778
    Idaho
    Full Name:
    Andrew
    #9 Gran Drewismo, May 6, 2011
    Last edited: May 6, 2011
    Sending an email to a hacker is a bit silly and pointless. It may feel good to the sender but is lost on the hacker. What may work in real life doesn't always work on the internet.


    Best thing to do is restore from a backup. As previously stated, contact the hosting company for assistance.

    IF no backup, then go about changing usernames, passwords, etc and start rebuilding the site.

    Sorry to be all doom and gloom, but I am just speaking from experience over the years.
     
  10. iamthesimpleone

    iamthesimpleone Formula 3

    Aug 23, 2005
    1,598
    austin, tx
    Full Name:
    Ben
    I doubt he has the skill set to get into that. If she has Go-Daddy as a host, I would think their security would be pretty robust. They might have gotten in on her computer and gotten any FTP information saved off of that.

    Did she recently get a virus on her home computer?
     
  11. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    63,343
    Southlake, TX
    Full Name:
    Rob Lay
    as I said on the phone, most likely he just hacked the main index.html page, I doubt any of the database or other files are hacked.

    1) if GoDaddy backup was before time of crash then you will get everything back, including whatever hole they used.

    2) not sure if hacker is monitoring and if back up they will just do the same thing again. I would think about installing safe software and then loading the Db back in. Might not need GoDaddy at all.
     
  12. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    I think she just wrote that as a "wish the hacker could see the damage he's done and maybe feel bad about it"...it was just an open "wish I could make them see this" letter as she has no way to actually contact the hacker.

    Thank you for the phone input, Rob. I hope that is what can be done to fix this mess.

    A friend of mine said "Oh yeah, no problem. You should have called me when this first happened."

    He said he will call her & feels he can get her back in the saddle...waiting to see...
     
  13. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
  14. iamthesimpleone

    iamthesimpleone Formula 3

    Aug 23, 2005
    1,598
    austin, tx
    Full Name:
    Ben
  15. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    Yep it looks like the board is mostly there from what I can tell and he just got the home page as was mentioned, he's probably more of an amateur hacker with scan tools to find vulneribilities and security holes in websites. http://www.kitkatsparrotchat.com/archive/index.php
     
  16. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    Some hacker... using code he stole from Piczo... yeah what a badass he is. He's not a hacker he's a script kiddie.
    -------------

    OP from the sounds of it, all he did is write over your index.php.

    Here is what you want to do.

    1) Figure out how he got in. I know this sounds like goofy advice to give to a layperson... if you could do that you would not be posting here. (granted, but keep reading) It was probably a known exploit of her board software. (if this guy is all over the place, that is the most likely problem, it is doubtful he hacked her machine but have her run malwarebytes just to be sure.)

    1A) One way to learn more about him, even if you're a layperson is to google that stupid message he uploads and check out the sites he exploited. If they all ran 'super deluxe chat 1.0' and 'super deluxe chat' is now on 3.0 that pretty much tells you how he's getting in.

    2) If the archives and the store are there, then I'd guess with about 90% certainty he simply overwrote your index.php file. (you might see, he might have even renamed it but that is doubtful) If that is the case, the first thing you want to do is download the same version she was running, get the index.php out of the zip file and upload it to the server. (rename his first)

    From what has been said on this thread, I'd stick by my guess, you'll have a 90% chance of getting the site back on line basically instantly. This step can do no harm and might pay off big time.

    3 IF THIS WORKS... RUN DON'T WALK to upgrade whatever chat software she runs to the latest version. (NOTE... backup everything including your databases first)

    -----------

    If you need more help or have a question you don't want to ask publicly, feel free to PM me. I've owned a hosting company for like a decade or so.. I'll be more than happy to help you..

    I know Rob is talking to your voice, but if he's busy or similar, I'll back you guys up.
     
  17. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    OP I did step #1 for you. She was(is) running vBulletin v3.7.3. Google tells me there were well documented SQL injection problems known back in 2008. So we pretty much know where to start.

    After maybe 10-15 minutes, I'm 97.321% sure a simple index.php file will get you there.

    Since that is pay software, I can not download the index.php for you. (I was going to attach it)

    You have four choices.

    1) Find an old copy she has somewhere. (any aged backup will work, even the original download file)

    2) Download it from vBulletin / beg for it on their forum.

    3) Get it from another webmaster.

    Since Rob has been here 100 years and very tech savvy, I'd bet a donut, he has an archive of 3.7.X around somewhere.

    If not google the exact vBulletin footer from her archive page and you will find a few thousand webmasters that will gladly help you out for the tip they can easily be hacked.

    The fourth option is to just upgrade vbulletin to the latest stable release but I'd be MUCH more comfortable getting that index back in place first.

    -----------
    and of course reset all passwords etc
     
  18. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    Thank you to all that are posting great advice on how to get this resolved. I really appreciate it.

    Latest: A friend of mine with experience who said he should be able to fix this is working on it, but last I heard, he was waiting to get the correct admin passwords from the person that helped create the site for my friend.

    The site is still down at this time...but hopefully not for too much longer...

    I wish I understood more of this... :(
     
  19. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    To Rob or another admin: I just noticed this...can someone please correct my hack-job attempt at spelling on this thread's title: "A frind's site got HACKED...what can be done now???"

    Please change to: "A friend's site got HACKED...what can be done now???"
     
  20. TG

    TG F1 Veteran

    Oct 26, 2004
    6,290
    Newport Beach, CA
    Full Name:
    Taylor
    A kid from school did just that. He got off free for showing them a thing or two...
     
  21. 308geo

    308geo F1 Rookie

    Nov 13, 2002
    2,751
    Houston, TX
    Full Name:
    George Benton LaFleur
    So Rob....do you happen to have an archive of 3.7.x laying around? :)

    Anyone else? Anyone? Bueller?

    The latest:

    "I have to get the latest or rather more current up date of the Board from Go Daddy, but that will cost $150 and I have to get to a point to shuck out more money with my doctor's appointments and high $$$ testing of late. I'll have to wait until next week to get the back up and then we are going to go from there.

    It also may require upgrading to the newest version of V Bulletin and that is around $500+.

    I could talk to your friend Rory about maybe going with a whole other message board all together, but that likely means I will still loose all of the last three years of the board's life.

    I think there may still be hope to get it back."
     
  22. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    #22 430man, May 11, 2011
    Last edited: May 11, 2011
    Why does she need to pay godaddy $150 to update the board?

    While I would REALLY like to get that index.php file back you don't need it, you can just upgrade. Also I'm pretty confident you could find a tool to migrate your vBulletin to SMF or similar.

    (one google search lead me here) http://www.simplemachines.org/community/index.php?board=134.0

    Here's what you do.... go to Odesk and ask for someone to migrate her from vB to SMF or the board of her choice.

    30 bucks later your problem is solved. No joke.
     
  23. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    63,343
    Southlake, TX
    Full Name:
    Rob Lay
    yes, sounds like Go Daddy is looking for money on a complete backup. I think just the index.php is needed. Unless she had someone else install that should be on her computer. Usually you download version to your PC and then upload to your server. I have all old versions. Looks like I went from 3.7.2 to 3.8. Those are 3 years old. I could see how this would be frustrating and confusing for someone not technical.
     
  24. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    Odds are 3.7.2 would work... or at least enough to confirm that the database was fine.

    If she's not going to pay for a lic upgrade, she's better off migrating to another forum than continuing to run a version with several known exploits.
     
  25. LetsJet

    LetsJet F1 Veteran
    Owner

    May 24, 2004
    9,334
    DC/LA/Paris/Haleiwa
    Full Name:
    Mr.

Share This Page