Activity Stream
48,167 MEMBERS
64701 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 4 of 4 FirstFirst ... 234
Results 31 to 37 of 37

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1.     
    #1
    Member
    Website's:
    btjunk.net
    ok i will thanks!
    kiladila Reviewed by kiladila on . Will pay for help solving issue ASAP Have very big problem with rapidleech server: www.leechking.com Somebody with IP 95.211.100.XXX stealing my RapidShare accounts and drainin all traffic from it. I can't do anything even password change not helping. What i have done: first of all reintalled OS to Linux Ubuntu, than changed my root, mysql, admin zone pass. Added extra security to admin zone (additional server side login), changed all RapidShare premium passwords. And nothing, in the next day same fucked IP is showing in Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Member
    Website's:
    kevaldomadia.com eleetgeeks.net
    Simple 2 possibilities:

    1. Your system is compromised, system from where you access your server!
    2. Your server is compromised, backdoored or just shelled.

    Solution for 1
    : Take back up (of individual file and folder), format re-install your OS and then access your server. Don't break your head in solving it.

    Solution for 2: nmap -PN on your server and check for any binded shells! Disable functions like fsockopen, system (leeching should work with them disabled) in php.ini. Look out for files like "shbd" or anything that sounds weird in your 777 folders, including /tmp/ .

    Simple?

  4.     
    #3
    Member
    Website's:
    btjunk.net
    Thanks kd1987 for advices i will look in to it, but i think this is sql injection some where in script...

  5.     
    #4
    Member
    Website's:
    kevaldomadia.com eleetgeeks.net
    If it is sqli that u suspect then, add this line in your .htaccess
    php_flag magic_quotes_gpc on
    relying on this feature is discouraged however, if the claimed "hacker" is one of those scripties who knows only about sqli, x=x auth bypass, lfi, rfi, etc.. then, it will keep him at his bay

  6.     
    #5
    Member
    Website's:
    btjunk.net
    We didn't managed how stealing was done, but after changing rapidleech script from rapidleech plus from zecel.com to original upgraded, problem are gone. So it's seams that rapidleech+ from zecel.com have serious backdoors ir something like this.

  7.     
    #6
    Member
    Website's:
    kevaldomadia.com eleetgeeks.net
    Cheers!

  8.     
    #7
    Member
    Website's:
    btjunk.net
    albertoberto you right. Problem is solved yesterday and reason:
    insert_location() function (download
    system) which reveals premium cookies and base_64 encoded auth-strings to end
    user(s). with simple http debuger.

Page 4 of 4 FirstFirst ... 234

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. captcha solving
    By cyloan in forum Webmaster Discussion
    Replies: 1
    Last Post: 30th Aug 2011, 09:25 PM
  2. any software for auto captccha solving
    By zainbintariq in forum General Discussion
    Replies: 3
    Last Post: 21st May 2011, 05:49 PM
  3. DNS Issue [HELP REQUIRED ASAP]
    By tdsii in forum Server Management
    Replies: 6
    Last Post: 17th May 2011, 02:18 AM
  4. Dot Needs Help ASAP
    By Dotcom in forum Technical Help Desk Support
    Replies: 6
    Last Post: 19th Jul 2009, 01:40 AM

Tags for this Thread

BE SOCIAL