some animals hacked my websites !

cpa_guy

Regular Member
Joined
Aug 11, 2020
Messages
246
Reaction score
202
HOPE YOU ARE WELL,

i was not even aware of it, but thank God that Google notified me with their email.

so, today my namecheap cpanel was a victim of some hackers (animals). i did not have two-factor authentication on my cpanel login,but i did set it up now. im not even sure if they log in just like that,or they are using more advanced inject techniques to get into your website files. so,these animals have uploaded some malicious files on my websites and caused Google Chrome to show the "deceptive site ahead" warning to all my Chrome website visitors. which of course made me issues and i lost a lot of traffic/money because of it. i had to hide some information and emails from the screenshots because i don't want to advertise these animals. there are probably people on this forum who would love to use their "services".
i don't know a lot about web developing, but all i can see that the language is either russian or ukrainian. maybe someone can tell better?
so i have deleted everything and uploaded a backup of my files....and now i have to contact google and wait for them to remove my website from the black-list. hope i don't need to wait long.
and i hope it doesn't happen again. so you guys need to be very careful and check your websites a few times each day...

@BassTrackerBoats Hi man, hope you are well. I tried to hide any sensitive information from the screenshots and i hope that this post does not break any forum rules. I wanted this post to be a nice warning for all people here.


Email from google:

1322222untitled.JPG



And upon checking my hosting,i was shocked. New files were uploaded today:


535511untitled.JPG



Here are a few examples of the files and their content:


u11222222ntitled.JPG
unt3333333334itled.JPG
 

Attachments

  • 11111112untitled.JPG
    11111112untitled.JPG
    62.4 KB · Views: 87
Last edited:
I recommend you to think about "the holes".
You mention Cpanel and Chrome. That is maybe, but you may have "the holes" in your web application. If that is vital to keep site secured you need to invest in security as well as monitoring, so you can fight against the attacks on the go (in real time).
And I see you are aware of backup importance already.
 
Your hosting plays major role in bypass and cross origins i suggest try better hosting and before moving do clean all the malware files. If you need any assistance feel free to ping me.

Thanks :)
 
What hosting are you using? and what type of site is it? is it a shitty script?
You need a well configured secure server with additional security softwares all of these needs advanced configuration which is costly and needs experience and takes a lot of time. if you had one they wouldn't be able to upload shit even with a buggy script this would be very difficult.
Also you need to avoid using buggy web apps with security vulnerabilities.
If the project is serious and complex, you need to be a team and you will have many problems if you are one person. That's why there are so many shitty scripts on CodeCanyon selling at 40 bucks, but most of the programmers don't have any websites or apps of their own!
"Most civil engineers don’t have any bridges of their own.They don’t need one, because it’s a lot of work to build and maintain.."
 
Most times it's the website script that is the culprit.
Have you contacted namecheap hosting live support?
From my experience they are good at helping in most matters.
Since you mentioned it has happened again I have a feeling it's your website script that has some loophole.
If you're Using wordpress then it could be a plugin.
 
That's Russian, not Ukrainian. They even left the name of who made the script and their official website lol. That's pure evil right there.
 
I have been hit with malware on my site once and I had no backup. Felt the pain to the core
 
I have been hit with malware on my site once and I had no backup. Felt the pain to the core
Have you given host access to a third-party?
Malware should be detected and removed automatically before uploading. if you use a good hosting with advanced server configuration, which of course is costly they can't do shit.
Even your personal computer is very important to be secure.
Most of these hacks are due to the negligence of the webmaster himself. If you don't have a very big site, no one will waste their time hacking your site unless it's a stupid bug in your script or there is a basic server misconfiguration and vulnerabilities.
 
I have been hit with malware on my site once and I had no backup. Felt the pain to the core

I had 3 small test sites hacked 4 or 5 years back, through a really cheap, shitty hosting company.
They took zero responsibility but it was clear the access had come through their hosting, as all the themes, plugins etc were different but all genuine and paid and updated.

With hackers like this, I'd like to get my hands on them because a lump hammer to both sets of knuckles means they'd have to type with their feet in the future.
 
Thansk God google reacted fast and removed my website from the Chrome blacklist.
 
With hackers like this, I'd like to get my hands on them because a lump hammer to both sets of knuckles means they'd have to type with their feet in the future.
I stand with you on this but... many powerful hackers are, sadly, backed by governments or the military, they'll decapitate you before you can do anything
 
Back
Top