Offline
<span style="color: #CC0000"><span style='font-size: 17pt'>Blank-ity blank hackers!</span> </span> Boy were we lucky tonight (this morning). I have my server setup to email me anytime there are ANY files with executable code uploaded to my server. Usually when I get these emails it just because a member hosting their web site on my server may have uploaded some script file, like a mail form, etc. But this time, it said a file had been uploaded to the images directory in the Knowledge Base program here. The file name was .php (which since it starts with a . means it is a hidden file when the directory is viewed with a standard UNIX ls command with no options.
Anyway, luckily I happened to be sitting here when it was uploaded and I received the warning email, so I immediatly logged into my server and looked at the file with a text editor - it was clear that it was an exploit (backdoor) designed to give the bad guy access to the server. Well, I deleted the file before he could do anything and then I looked in my secure log files and found the IP address that had uploaded the file. I traced the IP to Russia. So, I added the entire BLOCK of IPs from that place to my firewall. Then I did a Google search and learned that I had an older version of the Knowledge Base which had a known security vulnerability in one of the script files, so I have now also upgraded to the latest version which fixers that security flaw.
Boy, staying ahead of the hackers can be a full time job!
Basil
Anyway, luckily I happened to be sitting here when it was uploaded and I received the warning email, so I immediatly logged into my server and looked at the file with a text editor - it was clear that it was an exploit (backdoor) designed to give the bad guy access to the server. Well, I deleted the file before he could do anything and then I looked in my secure log files and found the IP address that had uploaded the file. I traced the IP to Russia. So, I added the entire BLOCK of IPs from that place to my firewall. Then I did a Google search and learned that I had an older version of the Knowledge Base which had a known security vulnerability in one of the script files, so I have now also upgraded to the latest version which fixers that security flaw.
Boy, staying ahead of the hackers can be a full time job!
Basil
Hey Guest!

