Community Forums

Important Notice:

Two sections of this forum are available only to registered customers. In order to receive access to the Customer Forums and ResellerCentral Forums, you must first register on these forums or login to your existing forum account. If you are an existing HostNine customer, be sure to register using the email address on file for your billing profile.

Go Back   HostNine Community Forums > H9 General Forums > Lounge / Off Topic > Web Development

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-13-2007, 07:11 PM
surfbob surfbob is offline
Newbie
 
Join Date: Feb 2007
Posts: 6
Default 777 chmod issues

Yes, the dreaded 777 chmod issues strikes again!!!

While making a few edits to my vbulletin forum (it`s upto date), my heart sank when I noticed a bunch of .php files (file name was a string of randomly generated numbers) & modified .htaccess files in the root of number of directories and their subfolders. This was in all the 777 folders throughout the said website.

I decided to look into another domain I host, low and behold these damned files were there too. In fact they`re in every 777 folder throughout my reseller account (all the domains).

I know 777 permissions are the ultimate sin, but I hear about using phpsuexec and all these other geek talk things, but it seems like a heck of a lot of trouble with scripts possibly breaking.

Now I have the fun task of clearing out all these random php and htaccess files. A real pita because they are all named differently. Jeez if they were all named "hack.php" I could kill them in one shot

Now the thing is, a script must be insecure because these bozos need some level of access first to exploit the 777 folders? I assume an insecure script on one domain can effect the other domains I host in my reseller account? I don`t have a level of geekiness to understand scripts and security yet.

Whew, I have no idea where to start Thankfully, "touch wood" no major files ie: index have been modified or anything.
Reply With Quote
  #2  
Old 05-14-2007, 06:00 AM
H9Ben
Guest
 
Posts: n/a
Default

Is this only happening with your VB install? Also not to worry, they cannot do much at all with uploaded PHP scripts due to open_basedir, mod_security, and other various security.
Reply With Quote
  #3  
Old 05-14-2007, 10:03 AM
surfbob surfbob is offline
Newbie
 
Join Date: Feb 2007
Posts: 6
Default

Nope these files (both php and htaccess) can be found in every 777 chmod folder throughout my reseller account, yes that`s every domain. Meaning I have no idea which script is vulnerable.

I know my own vb install is upto date, and I`ve updated an Invision install for a client last night. I guess I`ll just have to have an extra pair of eyes.
Reply With Quote
  #4  
Old 05-14-2007, 10:09 AM
eddus eddus is offline
Junior Guru Wannabe
 
Join Date: May 2007
Posts: 51
Default

support guys should see if there is another case on the same server cause that could means, you are getting hacking visitors inside the server.
Reply With Quote
  #5  
Old 05-15-2007, 12:20 PM
jrawly jrawly is offline
Web Hosting Master
 
Join Date: Jan 2007
Location: Manchester, UK
Posts: 670
Send a message via ICQ to jrawly Send a message via AIM to jrawly Send a message via MSN to jrawly Send a message via Yahoo to jrawly
Lightbulb

Quote:
Originally Posted by surfbob View Post
Now I have the fun task of clearing out all these random php and htaccess files. A real pita because they are all named differently. Jeez if they were all named "hack.php" I could kill them in one shot
You could setup some kind of monitoring script that would "ignore" all the files that should be there, and either mail you, or delete the files that shouldn't
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 04:55 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

Host Nine

Our mission began in 2006. Thousands of awesome clients later, we are now one of the most popular hosters in the world.
Most of this is because of our fantastic support. Join us, you'll be glad you did - that's a given.