ZOMG I was Hacked!

January 13th, 2010 by [re-arrange] Leave a reply »

No. This is serious business. I am not kidding. I was hacked! laughing

Okay, the better term is defaced. Not hack. Alright, not even defaced too much anyway. What he did (assuming that Rapcik0 is a man; not sure if this Turkish guy is a woman – I doubt that but hey, Trinity was being thought as a man. Okay stop thinking!) was changed my title post to HTML code that redirect to his site.

And the way he got to edit my title post is caused by the reset password vulnerability. Looks like he injected some SQL into the password reset function, and it give access to him. Then he changed the password of my WordPress account.

Damn.

I thought this hole was fixed prior to WordPress 2.8.6!

Okay fine. I went to cPanel, checked if he got that access, and apparently not. Reset all my password, and then changed the database. Got my access back, so I upgrade again to the latest WordPress. Then I undo his change. At first I thought he put the redirection on the index.php, but apparently not. That’s when I realized it was at the post title.

Done!

P/s: Lesson learn – a good precaution is always use strong password, upgrade the security and apply the fixes, yada yada yada. Thank you for this reminder, Rapcik0.

Advertisement


Malaysia Web Hosting





14 comments

  1. NJay says:

    whoa~! (mouth wide open coz i don’t understand a single thing except ‘hacked’winking
    huhu..

  2. NJay says:

    (mengapakah tibe2 keluar kenyit mata di situ?)

  3. y0nd13 says:

    do u think u are secured? kalo tak contactla aku

    harge boleh dirunding… LOL

  4. [re-arrange] says:

    nia: haha. try tanya jo dia paham kot. kirenye efek dia adalah, bila ko masuk page aku ni dia kuar page dia. Itulah redirect. happy keluar kenyit mata pasal ko typo ; dengan ) hahaha tongue

    yondie: hahahaha LOL. i dont make money on this blog, and it is not that mission critical. so i know its not secured but dont want to spend money on this. got free consultation or not? tongue

  5. schult says:

    wow! hebatnya beliauuuuu.hihi

  6. kucing kertas says:

    wu wi.
    takotnye. brrr. brrr. *efek menggigil. huhuhu…

    seriesly, sggh hebat beliau. *ulang kata2 syuhada.
    dan tak paham pape jgk mcm nia. tongue

  7. [re-arrange] says:

    syud & eme: lek2.. jgn la takut2. mereka2 ni dah mmg takut pompuan (mostly), nnt kang korg takut dgn mereka, bertambah pule populasi ghey. HAHAHAHA. tongue

  8. kucing kertas says:

    OH PLIS! LIKE I CARE.
    opss.. caps lock plak. (pdhal sengaje. tongue)

    asalkan x amek bf ai sudah. thehehe.. big grin

  9. ekin says:

    errrr….same gak, tak faham. hee hee

  10. mangifera says:

    ni mesti sebab ko ada link dgn munir ni. dia try hacked blog ko pulak. hehehhee. he maybe doing it just for the LULZ. tongue

  11. [re-arrange] says:

    eme: hahaha. kalau mereka berghey dgn bf yu cmne? heeeee heeeee heeee~~

    syg: takpe, tak perlu faham tongue

    dueng: aku dgn munir mmg under host company yg sama. aku rasa dia target host company tu la. mebi. oh btw ini hackers yg berlainan. Tp lawa juga dia wat page dia HAHAHAHAHA.

    It is a lul. I don’t mind getting it once a while.. ehe

  12. Obefiend says:

    wordpress tak best

    jom blogger

    /bakar

  13. zac says:

    haha i can understand the first line only loerrrrrrr

    *bukak blk textbook zaman2 1st yr ke ape ke haha*

Leave a Reply