Ask HN: Thousands of compromised websites send their user logins to my website

I might need some help here from my favorite Internet strangers :-)

My personal website (stan.sh), where there is nothing of interest in it, is receiving thousands of POST requests containing login and password of vBulletin users (a forum software for small/medium communities).

The attacker seems to have planted scripts on my server and to this day I have no idea how he managed to do that. These files are quite simple, a single PHP file receives the external POST request made by the compromised vBulletin website and store the login info in a plain HTML file.

I have some file exemples and the PHP culprit file as well, and discussed with compromised website owners. It is quite frustrating for both sides, especially the vBulletin websites. I see many hits from Chinese IPs in my access.log.

My email is stan[ at ]larroque.net, if you faced something similar or if you have tips, I would be grateful!


Comments URL: https://news.ycombinator.com/item?id=23635413

Points: 1

# Comments: 0



from Hacker News: Newest https://ift.tt/2Z3Op7C

Yorumlar

Bu blogdaki popüler yayınlar

Built with Django Newsletter #1

UN chief:16 armed groups have responded to cease-fire appeal