Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > MISCELLANEOUS > Lounge

Post Reply
 
Thread Tools
  #1  
Old 01-28-2006, 12:44 PM
eon's Avatar
eon Offline
pixelpost guru
 
Join Date: Nov 2005
Location: Ned
Posts: 280
Send a message via ICQ to eon
hacker

Today someone tried to hack my private-home-server via SSH.
Now I placed his IP 61.218.130.20 in hosts.deny.

List:
61.x.x.x
222.x.x.x
221.x.x.x
220.x.x.x
and
64.95.221.x

Is that enough? Or do I need to restart something?
__________________
Northing.nl
Reply With Quote
  #2  
Old 01-28-2006, 02:56 PM
se.nsuo.us Offline
pixelpost guru
 
Join Date: Dec 2005
Location: Somewhere in India
Posts: 624
I presume you have a proper type firewall?

It is best to close everything (services) except what you really need and that too for known set of IPs
__________________
http://se.nsuo.us - A photoblog of sensual, abstract nudes [may not be work safe for some]
My Pixelpost Addons, Cheesecake-Photoblog Software
Reply With Quote
  #3  
Old 01-28-2006, 03:56 PM
nephoto's Avatar
nephoto Offline
pixelpost guru
 
Join Date: Apr 2005
Location: Calgary, AB Canada
Posts: 102
ya some dickhead hacked my comments on my blog the other night, just made it so that if anyone tried to leave one it would pop up a big red screen talking about how pp's html wasn't secure with a big smiley face. Also if you went to the comments section in the admin panel it would load it as well. I had to delete the image and then I updated from 1.4.2 to 1.4.3 so hopefully that helps.
__________________
we judge ourselves by what we feel capable of doing, while others judge us by what we've already done.
Reply With Quote
  #4  
Old 01-28-2006, 04:23 PM
Connie
Guest
 
Posts: n/a
did you delete that comment in your database, using PHPadmin for example?
Reply With Quote
  #5  
Old 01-29-2006, 11:37 AM
eon's Avatar
eon Offline
pixelpost guru
 
Join Date: Nov 2005
Location: Ned
Posts: 280
Send a message via ICQ to eon
Quote:
Originally Posted by se.nsuo.us
I presume you have a proper type firewall?

It is best to close everything (services) except what you really need and that too for known set of IPs
SSH is a normal service on my server. Is it the right way to use hosts.deny to block ip-ranges?
__________________
Northing.nl
Reply With Quote
  #6  
Old 01-30-2006, 01:26 AM
GeoS's Avatar
GeoS+ Offline
Team Pixelpost
 
Join Date: Apr 2005
Location: Warsaw, Poland
Posts: 3,613
Send a message via ICQ to GeoS Send a message via Skype™ to GeoS
Try to move SSH to some other port then 22 and some over 1024
__________________
photoblog | portfolio | addons | Donate
Reply With Quote
  #7  
Old 01-30-2006, 03:34 AM
se.nsuo.us Offline
pixelpost guru
 
Join Date: Dec 2005
Location: Somewhere in India
Posts: 624
Quote:
Originally Posted by eon
SSH is a normal service on my server. Is it the right way to use hosts.deny to block ip-ranges?
No the proper way is to use IPTables
__________________
http://se.nsuo.us - A photoblog of sensual, abstract nudes [may not be work safe for some]
My Pixelpost Addons, Cheesecake-Photoblog Software
Reply With Quote
  #8  
Old 01-30-2006, 05:15 AM
nephoto's Avatar
nephoto Offline
pixelpost guru
 
Join Date: Apr 2005
Location: Calgary, AB Canada
Posts: 102
Quote:
Originally Posted by Connie
did you delete that comment in your database, using PHPadmin for example?
I had to use the admin panel to delete the image because if I opened the comments in the admin panel it loaded the hack. Afterwards I updated pp and put the image back up again.
__________________
we judge ourselves by what we feel capable of doing, while others judge us by what we've already done.
Reply With Quote
  #9  
Old 01-30-2006, 09:14 AM
GeoS's Avatar
GeoS+ Offline
Team Pixelpost
 
Join Date: Apr 2005
Location: Warsaw, Poland
Posts: 3,613
Send a message via ICQ to GeoS Send a message via Skype™ to GeoS
The best solution is to use some patch which is available at forum.

There are 2 more ways of handling it:
1) use of some MySQL administration tools to delete or replace comment's content (phpMyAdmin, MySQLAdministrator, ...)
2) turn off META redirections in browser and do want you want with this comment (that is future of, i.e. FireFox with webdeveloper plugin)
__________________
photoblog | portfolio | addons | Donate
Reply With Quote
  #10  
Old 01-30-2006, 09:45 AM
eon's Avatar
eon Offline
pixelpost guru
 
Join Date: Nov 2005
Location: Ned
Posts: 280
Send a message via ICQ to eon
gna gna, I think two problems mixed up here
My hacker/server problem and the deface problem. But it is alright.

Port 1024 instand of 22 is no option. With a scanner you can just pickout the port. I need a system that blocks the ip for a while when you try for several times with badluck .
__________________
Northing.nl
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 07:02 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs