Ask HN: Thousands of compromised websites send their user logins to my website
I might need some help here from my favorite Internet strangers :-)
My personal website (stan.sh), where there is nothing of interest in it, is receiving thousands of POST requests containing login and password of vBulletin users (a forum software for small/medium communities).
The attacker seems to have planted scripts on my server and to this day I have no idea how he managed to do that. These files are quite simple, a single PHP file receives the external POST request made by the compromised vBulletin website and store the login info in a plain HTML file.
I have some file exemples and the PHP culprit file as well, and discussed with compromised website owners. It is quite frustrating for both sides, especially the vBulletin websites. I see many hits from Chinese IPs in my access.log.
My email is stan[ at ]larroque.net, if you faced something similar or if you have tips, I would be grateful!
Comments URL: https://news.ycombinator.com/item?id=23635413
Points: 1
# Comments: 0
from Hacker News: Newest https://ift.tt/2Z3Op7C
Yorumlar
Yorum Gönder