hi @ all
ich betreibe auf meinen root server um meine domains zu managen und meine homepage VHCS2
das wurde heute nacht gehackt
ich erkläre mal i9ch habe mich gestern ins bett gelegt mein kumpel wolte auf meine homepage
das kamm eine türkische seite also wurden die index datein geändert
nun komm ich nicht mehr als admin in mein vhcs2 denk mal der hat da auch was verändert
was soll ich nun tun um die lücken zu schliessen und des admin pw wieder raus zu finden das ja jetz nich mehr geht
kann mann das irgenwo ändern ???
hab auch hier mal die log datei vieleicht könnt ihr mir sagen wie es dazu kamm meine ip und die des meinigen kumpels tu ich mal mit xx austauschen
wenn es xx war sagt es bitte und welche zeile das war ??
zudem hier mal die auth.log
http://download.station64.de/auth.log
wäre schön wenn einer sagen könnte in welche config mann das admin pw neu setzen kann
Vielen Dank im vorraus
ich betreibe auf meinen root server um meine domains zu managen und meine homepage VHCS2
das wurde heute nacht gehackt
ich erkläre mal i9ch habe mich gestern ins bett gelegt mein kumpel wolte auf meine homepage
das kamm eine türkische seite also wurden die index datein geändert
nun komm ich nicht mehr als admin in mein vhcs2 denk mal der hat da auch was verändert
was soll ich nun tun um die lücken zu schliessen und des admin pw wieder raus zu finden das ja jetz nich mehr geht
kann mann das irgenwo ändern ???
hab auch hier mal die log datei vieleicht könnt ihr mir sagen wie es dazu kamm meine ip und die des meinigen kumpels tu ich mal mit xx austauschen
wenn es xx war sagt es bitte und welche zeile das war ??
Code:
72.30.226.205 - - [13/Jan/2007:00:50:39 +0100] "GET /robots.txt HTTP/1.0" 404 2153 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
74.6.69.115 - - [13/Jan/2007:00:50:41 +0100] "GET /online-shop/catalog/index.php?cPath=23&osCsid=680589b9948efda907aa0f4eb02d196b HTTP/1.0" 404 2172 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
211.52.177.200 - - [13/Jan/2007:04:28:52 +0100] "GET / HTTP/1.0" 200 919 "-" "-"
65.222.187.10 - - [13/Jan/2007:04:50:31 +0100] "HEAD / HTTP/1.0" 200 - "-" "-"
72.30.226.205 - - [13/Jan/2007:06:08:50 +0100] "GET /robots.txt HTTP/1.0" 404 2152 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
74.6.69.225 - - [13/Jan/2007:06:08:51 +0100] "GET /online-shop/catalog/account.php?osCsid=680589b9948efda907aa0f4eb02d196b HTTP/1.0" 404 2173 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
xx- - [13/Jan/2007:06:21:19 +0100] "GET / HTTP/1.1" 200 919 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:06:21:19 +0100] "GET /icons/blank.gif HTTP/1.1" 304 - "http://download.station64.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:06:21:19 +0100] "GET /icons/unknown.gif HTTP/1.1" 304 - "http://download.station64.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:06:21:19 +0100] "GET /icons/compressed.gif HTTP/1.1" 304 - "http://download.station64.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:06:21:19 +0100] "GET /icons/tar.gif HTTP/1.1" 304 - "http://download.station64.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:06:21:21 +0100] "GET /ssun-j2re1.5_1.5.0+update02_i386.deb HTTP/1.1" 200 30494126 "http://download.station64.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:19:45 +0100] "GET / HTTP/1.1" 200 919 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:19:45 +0100] "GET /icons/blank.gif HTTP/1.1" 200 148 "http://84.16.230.39" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:19:45 +0100] "GET /icons/tar.gif HTTP/1.1" 200 219 "http://84.16.230.39" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:19:45 +0100] "GET /icons/unknown.gif HTTP/1.1" 200 245 "http://84.16.230.39" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:19:45 +0100] "GET /icons/compressed.gif HTTP/1.1" 200 1038 "http://84.16.230.39" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:03 +0100] "GET /index.html HTTP/1.1" 404 2152 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/css/vhcs.css HTTP/1.1" 200 4361 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/css/vhcs.js HTTP/1.1" 200 1522 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_background.gif HTTP/1.1" 200 726 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_down.gif HTTP/1.1" 200 44 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/images/background.jpg HTTP/1.1" 200 497 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:04 +0100] "GET /vhcs2/themes/modern_blue/images/login/vhcs_logo.gif HTTP/1.1" 200 820 "http://84.16.230.39/index.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:16 +0100] "GET /vhcs2 HTTP/1.1" 301 234 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:16 +0100] "GET /vhcs2/ HTTP/1.1" 200 3614 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:17 +0100] "GET /vhcs2/images/isp_logo.gif HTTP/1.1" 200 53 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:17 +0100] "GET /vhcs2/themes/modern_blue/images/button.gif HTTP/1.1" 200 112 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:17 +0100] "GET /vhcs2/themes/modern_blue/images/trans.gif HTTP/1.1" 200 43 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:17 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_line.gif HTTP/1.1" 200 51 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:28 +0100] "POST /vhcs2/chk_login.php HTTP/1.1" 302 128 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:29 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3615 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:39 +0100] "GET /vhcs2/lostpw.php HTTP/1.1" 200 4235 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:40 +0100] "GET /vhcs2/include/imagecode.php HTTP/1.1" 200 146 "http://84.16.230.39/vhcs2/lostpw.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:20:50 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3615 "http://84.16.230.39/vhcs2/lostpw.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:07 +0100] "POST /vhcs2/chk_login.php HTTP/1.1" 302 128 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:08 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3615 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:20 +0100] "POST /vhcs2/chk_login.php HTTP/1.1" 302 128 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:21 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3615 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:33 +0100] "POST /vhcs2/chk_login.php HTTP/1.1" 302 128 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:07:21:34 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3615 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
72.30.226.205 - - [13/Jan/2007:09:00:36 +0100] "GET /robots.txt HTTP/1.0" 404 2152 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
74.6.70.83 - - [13/Jan/2007:09:00:36 +0100] "GET /online-shop/catalog/product_info.php?products_id=51&osCsid=680589b9948efda907aa0f4eb02d196b HTTP/1.0" 404 2178 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
xx- - [13/Jan/2007:10:06:26 +0100] "GET /vhcs2 HTTP/1.1" 301 234 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:26 +0100] "GET /vhcs2/ HTTP/1.1" 200 3616 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/css/vhcs.css HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/css/vhcs.js HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx - - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/background.jpg HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/trans.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/images/isp_logo.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/button.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_background.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_down.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/login/vhcs_logo.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:27 +0100] "GET /vhcs2/themes/modern_blue/images/login/content_line.gif HTTP/1.1" 304 - "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:40 +0100] "POST /vhcs2/chk_login.php HTTP/1.1" 302 128 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:41 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3617 "http://84.16.230.39/vhcs2/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:51 +0100] "GET /vhcs2/lostpw.php HTTP/1.1" 200 4236 "http://84.16.230.39/vhcs2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:53 +0100] "GET /vhcs2/include/imagecode.php HTTP/1.1" 200 146 "http://84.16.230.39/vhcs2/lostpw.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
xx- - [13/Jan/2007:10:06:55 +0100] "GET /vhcs2/index.php HTTP/1.1" 200 3616 "http://84.16.230.39/vhcs2/lostpw.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.2)"
219.235.0.118 - - [13/Jan/2007:11:24:42 +0100] "CONNECT msa.hinet.net:25 HTTP/1.0" 405 225 "-" "-"
zudem hier mal die auth.log
http://download.station64.de/auth.log
wäre schön wenn einer sagen könnte in welche config mann das admin pw neu setzen kann
Vielen Dank im vorraus
Last edited by a moderator: