A A A
Avatar

Please consider registering
guest

sp_LogInOut Log In sp_Registration Register

Register | Lost password?
Advanced Search

— Forum Scope —




— Match —





— Forum Options —





Minimum search word length is 3 characters - maximum search word length is 84 characters

sp_Feed Topic RSS sp_TopicIcon
WAS OPSHOTS HACKED......................?
September 25, 2011
10:44 am
Avatar
nwfedex757

Citizen Geek
Members
Forum Posts: 81
Member Since:
June 17, 2009
sp_UserOfflineSmall Offline

Hi everyone.......Is anyone else having problems with Opshots Photo Gallery section..............I went on this morning ,no problem with home page, went to Photo Gallery section ,clicked on lastest photos and wham, got knocked off the site. A black screen came up saying

                                                    SERVERHackD  by You need to be a member to view our links.

                                                                Bangladesh Hacker

Ive tried a bunch of times on other things like the top photos,comment,same thing happening.. I go to the fourms, that seems ok...................Could this be serious? Other sites on my computer seem ok... Sent Chuck a e-mail to check things out....George

September 25, 2011
1:00 pm
Avatar
redngold
Northeast Ohio

Excentric Geek
Members
Forum Posts: 147
Member Since:
August 22, 2006
sp_UserOfflineSmall Offline

Yes, the server was hacked.  This was posted to the Facebook page:

Server Hacked- September 25, 2011. InMotion hosting, the server that our website is on has been hacked by some big-time hackers. This is effecting not just OPShots, but the thousands of other sites on the server. InMotion is working on the problem and hopes to have it fixed in due time.

September 25, 2011
3:00 pm
Avatar
N960DL

Excentric Geek
Members
Forum Posts: 139
Member Since:
August 14, 2006
sp_UserOfflineSmall Offline

I got that hacked message too at about 13:00 today.  I am trying the site now, at 15:00, and it seems to be back to normal.

September 25, 2011
4:48 pm
Avatar
Mark Plumley
Garfield Heights

Webmaster
Forum Posts: 430
Member Since:
June 15, 2006
sp_UserOfflineSmall Offline

I will get everything formatted the way it was later this evening. Thank you everyone for your patience. This only effected around 30,000 websites. These same hackers have gotten into Google, Yahoo and others. Nothing else better to do I guess?

If at first you don't succeed, skydiving is not for you.

September 25, 2011
6:35 pm
Avatar
Mark Plumley
Garfield Heights

Webmaster
Forum Posts: 430
Member Since:
June 15, 2006
sp_UserOfflineSmall Offline

Everything seems to be back to normal. If anything seems out of place please advise here.

If at first you don't succeed, skydiving is not for you.

September 25, 2011
11:15 pm
Avatar
Chuck Slusarczyk Jr.

Head-Honcho
Forum Posts: 1425
Member Since:
June 15, 2006
sp_UserOfflineSmall Offline

Thanks Mark, great job on getting everything back to normal!  You da man! Cool

 

What a mess that guy caused for thousands of websites today...appears to be a "pro" hacker from what I read.

September 26, 2011
1:24 am
Avatar
Chuck Slusarczyk Jr.

Head-Honcho
Forum Posts: 1425
Member Since:
June 15, 2006
sp_UserOfflineSmall Offline

Okay Ladies and Gents...here is the official word from InMotion Hosting, (the server that OPShots is on) as to what happened with the hack today.  An interesting read, I thought:

 

"As you may be aware, our network, and potentially your server, was the
target of a large scale website defacing attack this morning, Sunday,
the 25th.  The defacement worked by replacing index files in all
public_html directories with the attacker''s index.php.  At this time, it
does not appear to be any more malicious than taking over the web site''s
home page, but we are still reviewing servers at this time.

We understand the method the attacker used to accomplished this and the
main exploit path was through an internal management server that can
control Cpanel on other servers.  The management server was used to
change passwords on the Cpanel servers then login with those passwords.
It does not appear that gaining passwords was a goal or was
accomplished, just password changes were used.  Access to the management
server was gained from an exploited customer''s server that was within
our network.

Though our team moved quickly to disable the internal management server
and limit the exposure of the servers to this attack when it began, it
was a very serious breach and could have been much worse if the hacker
had intended to do more harm.

At this time, we want to be sure you are aware of the attack and your
server''s potential exposure.  Our systems team has moved to repair the
index files, but the automated system is still running and may take a
few hours to finish all sites.

Please you review your sites if you have not already done so.  If you
have a backup of your site, you may upload your index.php files to
correct this. You will most likely need to do this for each directory.
If your site uses an index.html or index.htm, you will need to upload
those files, then delete the index.php.

If you were affected and you need assistance recovering the home page or
other directory indexes, please contact us.

Further, if you feel your server has been targeted more in-depth than
the index.php defacement, please contact us immediately and we will do
an additional scan on your server.

Though it does not appear gaining passwords was an intent of this
attack, it is recommended that you update all of your passwords related
to your server.

Please note, our billing, domain management, and customer tracking
system (AMP) was not targeted, nor was available to the Cpanel
management server.  It is on a separate network and firewall.

Please accept our apologies as we go through this process.  We are very
aware of our failure in this situation and we will provide more details
when we have completed the work of recovery.

Again, please review your server and sites if you have not done so
already.  Reach out to us immediately if you suspect a more in-depth
attack on your server."

Forum Timezone: America/New_York

Most Users Ever Online: 679

Currently Online:
12 Guest(s)

Currently Browsing this Page:
1 Guest(s)

Top Posters:

707guy: 530

yakc130: 351

masseybrown: 318

Corey Betke: 255

nconrad: 249

michi: 205

Member Stats:

Guest Posters: 0

Members: 211

Moderators: 0

Admins: 3

Forum Stats:

Groups: 3

Forums: 15

Topics: 1657

Posts: 7300

Newest Members:

bertita, perla67, Barbarahat

Administrators: Mark Plumley: 430, Chuck Slusarczyk Jr.: 1425, Cole Goldberg: 271

WAS OPSHOTS HACKED......................? | Technical Issues with Website/Forums | Forum