Jump to content

Hacker Alert [ PLEASE READ ]


Recommended Posts

Dear WHMCS Users,

 

To all of you our there be aware of this hacker group who go by the name of "unkn0wn"

I mean there isn't a way of tracking a hacker really as you know they use proxy to launch their attacks. Anyhow thought i would let you know the IP they used was from 31.9.10.88, and they upload a file called "unkn0wn.txt"

 

The content of the file is as follows;

 

########################

# #

# hacked by unkn0wn #

# #

# f.k@live.com #

# #

########################

 

I have reported it to cPanel to see if they are aware of a security floor, Once i have further info on this i will come back and post my findings.

 

Warmest Regards

Link to comment
Share on other sites

Dear WHMCS Users,

 

To all of you our there be aware of this hacker group who go by the name of "unkn0wn"

I mean there isn't a way of tracking a hacker really as you know they use proxy to launch their attacks. Anyhow thought i would let you know the IP they used was from 31.9.10.88, and they upload a file called "unkn0wn.txt"

 

The content of the file is as follows;

 

########################

# #

# hacked by unkn0wn #

# #

# f.k@live.com #

# #

########################

 

I have reported it to cPanel to see if they are aware of a security floor, Once i have further info on this i will come back and post my findings.

 

Warmest Regards

 

simple solution remove the file and then do a whois search of the IP http://whois.domaintools.com/31.9.10.88 which gives you this

 

organisation: ORG-STE1-RIPE

org-name: Syrian Telecommunications Establishment

org-type: LIR

address: Syrian Telecommunication Establishment

Mezzeh Autostard

Fayez Mansour St.

P.O.Box: 35108 Damascus

SYRIAN ARAB REPUBLIC

phone: +963 11 4462560

fax-no: +963 11 373 9765

e-mail:

 

and also

 

NetRange: 31.0.0.0 - 31.255.255.255

CIDR: 31.0.0.0/8

 

so go into your server firewall and block the NetRange and CIDR

Link to comment
Share on other sites

simple solution remove the file and then do a whois search of the IP http://whois.domaintools.com/31.9.10.88 which gives you this

 

organisation: ORG-STE1-RIPE

org-name: Syrian Telecommunications Establishment

org-type: LIR

address: Syrian Telecommunication Establishment

Mezzeh Autostard

Fayez Mansour St.

P.O.Box: 35108 Damascus

SYRIAN ARAB REPUBLIC

phone: +963 11 4462560

fax-no: +963 11 373 9765

e-mail:

 

and also

 

NetRange: 31.0.0.0 - 31.255.255.255

CIDR: 31.0.0.0/8

 

so go into your server firewall and block the NetRange and CIDR

 

Thanks for this advice although i took these steps as soon as the hack attempt was identified. ;)

Link to comment
Share on other sites

Its not a cpanel or whmcs security flaw, they used some poor coded script in your hosting to upload files. Update your hosting software(joomle,wordpress,so on) adn check apache access log files to find a clue about how they could upload files

 

I have emailed my customers and asked them to check their chosen CMS software vendors website for possible security floors in their scripts. So i hope this wont happen in the future ;)

Link to comment
Share on other sites

I know this group, they copied there entire forum from my own, I got there website shut down a few months ago.

 

It's, http://unkn0wn.eu and they used to own http://unkn0wn.ws

 

They are a bunch of script kiddies, that do SQL Injection.

 

They didn't hack your site just in general, they did a massive SQLI on thousands of other sites.. Most likely a 0day exploit for WP.

Edited by nexthost
Link to comment
Share on other sites

I know this group, they copied there entire forum from my own, I got there website shut down a few months ago.

 

It's, http://unkn0wn.eu and they used to own http://unkn0wn.ws

 

They are a bunch of script kiddies, that do SQL Injection.

 

They didn't hack your site just in general, they did a massive SQLI on thousands of other sites.. Most likely a 0day exploit for WP.

 

http://unkn0wn.ws/ is currently parked with http://www.dynadot.com

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated