• Howdy! Welcome to our community of more than 130.000 members devoted to web hosting. This is a great place to get special offers from web hosts and post your own requests or ads. To start posting sign up here. Cheers! /Peo, FreeWebSpace.net
managed wordpress hosting

My site HACKED

zerocool786

Active Member
Hi
I run a Boonex script. recently my host blocked my site, because It was sending phishing banking emails. I NEVER DID. So I think my site was hacked. This has happened to me twice past two days.

I would like to know If I delete all the files and re-upload clean files, would that help.
How can I find out who is behind this.
What kind of script uses to send these emails.
Can I block ALL emails sent from my server.

thanks
 
Hi
I run a Boonex script. recently my host blocked my site, because It was sending phishing banking emails. I NEVER DID. So I think my site was hacked. This has happened to me twice past two days.

I would like to know If I delete all the files and re-upload clean files, would that help.
How can I find out who is behind this.
What kind of script uses to send these emails.
Can I block ALL emails sent from my server.

thanks

If you have root access to your server, you can stop the user "Nobody" from sending emails. That will allow you to see where the emails are coming from.

I would never trust Boonex anyway.
 
<html> <body bigcolor=red><DIV> <P><IMG alt="" hspace=0 src=" http://www.abbey.com/CsAppsExp/Abbey/Internet/Abbey/img/home_top_1.gif"; align=baseline border=0></P> <P><FONT face=Verdana size=2><STRONG>Dear Abbey Customers Upgrade</STRONG> </FONT></P> <P align=left><FONT face=Verdana size=2>Due to concerns, for the safety and integrity of the Abbey<BR> account we have issued this warning message.</FONT></P> <P><FONT face=Verdana size=2>It has come to our attention that your Abbey account information needs to be <BR> updated as part of our continuing commitment to protect your account in this year 2008 and to <BR>reduce the instance of fraud on our website. If you could please take 5-10 minutes <BR>out of your online experience and update your personal records you will not run into <BR>any future problems with the online service. </FONT></P> <P><FONT face=Verdana size=2>Once you have updated your account records your Abbey account<BR> service will not be interrupted and will continue as normal. </FONT></P> <P><FONT face=Verdana size=2>To update your Abbey records click on the following link: <BR>
[12:00:27 PM]: </FONT><A href="http://www.internova.net/www.AbbeY.Co.Uk/www.abbey.co.uk/myonlineaccounts2.abbeynational.co.uk/CentralLogonWeb/Logonaction=logon/Logonaaccount=logon/index.htm"; target=_blank><FONT face=Verdana color=#009999 size=2>https://myonlineaccounts2.abbeynational.co.uk/CentralLogonWeb/Logon?action=prepare</FONT></A></P>; <PAgreement if you have any questions. <BR> </FONT><FONT face=Verdana color=#003399 </DIV><FONT face=Verdana size=2>Thank You.</FONT></P> <P><FONT face=Verdana size=1>Accounts Management As outlined in our User Agreement, Abbey will <BR> periodically send you information about site changes and enhancements. </FONT></P> <P><FONT face=Verdana size=1>Visit our Privacy Policy and User

this is what my host gave me
 
There's a lot of those going around mate and your host should know that it happens.
Your best option would be to ask your host to pinpoint where on your account the email script is and remove it.
 
are there any kind logs, that shows which script ran at what time, so I can remove it. my host fixed some of the permission on the folders yesterday.
 
There are logs, they should have checked them anyway, the suspension is most likely a temp thing, so whoever is sending those emails, can't anymore. I would get rid of that Boonex script regardless, it's nothing but a security threat.
 
Just curious folks, You guys are saying that the boonex script is insecure, what kind of issues have you faced?

I have hosted hundreds of them for clients and never had problems none ever ran into these issues... Not saying you have done something different, just wondering if a server was secured properly this wouldnt happen?
 
Back
Top