Click to See Complete Forum and Search --> : Site was hacked, this file was in the directory - how can I view?


sparq
06-16-2005, 01:12 PM
Its an ASP page that appears to look for a "request" of some sort to show the information, I dont know ASP and would appreciate some help in figuring out how to view what this page actually does. Thanks!

Changed it to a TXT file to upload... anyone wanna give me a hand at figuring out what this was doing on my server? Mucho gracias! :cool:

sparq
06-16-2005, 03:32 PM
I figured it out, and I removed the file to prevent anyone from getting any ideas with the script. If anyone would like some info please contact me directly.

wmif
06-16-2005, 05:33 PM
wanna just give a quick description of what the page was doing?

sparq
06-17-2005, 08:17 AM
Oh yeah... sure!

Basically what it did was sit in the directory, a special "code" unlocked an area where the hacker would have access to all the files and be able to edit / delete / download anything on the server. Sorta like a file manager script common with a shared web hosting company. But there was also areas that got server specs, info on if SSL was turned on, other server specs, drive info, SQL section and a little more. After I looked at it, its rather basic. Theres also a part in there to create the "hacked" page - which simply tried to force write itself to any directory it could, and it would report back all the successfull / denied directories it wrote to.

Unfortunately our network admin is on vacation this week, and we have definately taken a laid back approach, "why fix it, it hasnt been broken into yet" approach - hey not my job, im just the web developer :p But we will be tightening ship around here and hopefully we wont see any more of this crap.