Author Topic: Website not yet restored from defacement?  (Read 1160 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Website not yet restored from defacement?
« on: September 02, 2015, 12:02:24 PM »
See: http://toolbar.netcraft.com/site_report?url=http://kachina-tech.com
IP being attacked: http://www.ip-finder.me/82.80.232.34/
Unable to properly scan your site. HTTP Errors Returned. park.io link,
consider: -http://XXXXXXXX/www.profit.io from -ux51.oos-hosting.net ->
https://www.mywot.com/en/scorecard/ux51.oos-hosting.net?utm_source=addon&utm_content=rw-viewsc
-> http://toolbar.netcraft.com/site_report?url=http://park.io
See: https://urlquery.net/report.php?id=1441187273413
IP was updated by -http://www.traderadiatorsdirect.co.uk hitachi? host appears down!
AS with a lot of PHISHING going on: https://urlquery.net/report.php?id=1441187273413
IP Sensor SSH Botnet infested: https://virustracker.net/82.80.232.3
Attackers just need 1 user with a weak password to get in, read here:
https://blog.sucuri.net/2013/07/ssh-brute-force-the-10-year-old-attack-that-still-persists.html

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: September 06, 2015, 12:54:15 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Website not yet restored from defacement?
« Reply #1 on: September 02, 2015, 01:36:49 PM »
Another site recovering from defacement but with excessive GoDaddy web server info proliferation: see code: -http://XXXXXX/www.webbersites.com
Index of /

Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/1.0.1e-fips mod_bwlimited/1.4 Server at www.webbersites.com Port 80
See: http://toolbar.netcraft.com/site_report?url=http://www.webbersites.com
Vulnerable: http://www.leakedin.com/2014/11/24/potential-leak-of-data-targeted-website-775/

polonus
« Last Edit: September 06, 2015, 12:52:50 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!