RC India

General Topics => Chatter Zone => Topic started by: gbisht on February 11, 2012, 11:47:55 PM



Title: Does anyone seen rcelectro.com ?? Its Hacked
Post by: gbisht on February 11, 2012, 11:47:55 PM
Hi,

Does anyone seen www.rcelectro.com its hacked by some Pakastani and calling him " Shadow008 & H4x0rL1f3"

Whats wrong with them ??


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: Dharmik on February 11, 2012, 11:56:46 PM
it's probably sql injection nothing else and they are calling them hackers. Vivek sir needs to change that script.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: gbisht on February 11, 2012, 11:58:57 PM
Dharmik.....I think they forget what they are......

Vivek Sir.....live ur site soon...with better script..... :thumbsup:


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: VC on February 12, 2012, 12:00:48 AM
Some sick jerk - V.K. will resurrect the site in no time at all.

Bet my derriere that this hacker is not from either Pakistan or Bangladesh. ;D


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: Dharmik on February 12, 2012, 12:13:18 AM
as i remember this is 2nd time happened to rcelectro. i have been dealing with such attacks since 2007 even of the worst when someone gain access to the directory using shell script and uploaded whole phising site of one airline company. nothing over internet 100% secure but it seems that the script has lots of security holes.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: RcBazaar on February 12, 2012, 12:36:28 AM
i hope the site will be up soon...


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: KALYANPRODHAN on February 12, 2012, 01:05:17 AM
Hey,
Sequence of PHP and html has been changed by the hacker in Apache service (?) or the DB content has been added. However if you want the site,
Just go to
http://www.rcelectro.com/index.php (http://www.rcelectro.com/index.php)

And
Don't enter with username and passcode. Just browse.
As, the DB needs to be corrected(?).


Thanks


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: anandp on February 12, 2012, 09:20:07 AM
The website is UP and running again !!!


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: H-energy on February 13, 2012, 08:02:11 AM
I've been to some RC website hacked by some Freedom Pakastani too.
I don't know what they can do with hacked to free their country.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: anandp on February 13, 2012, 08:03:42 AM
@H-energy - i am not sure if they do it or not

but +1 what you said :)


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: KALYANPRODHAN on February 13, 2012, 08:43:49 AM
Most time the declared persons don't do that.
And even trying to a smallest RC Store, Next to impossible.
Again to the popularity & Alexa ranked like this, I don't believe.

But as he is damaging some LHS's high profit business from his dedication to RC, he is the prime target to them. So, they can post in the hacker's forum to ask for hacking for security vulnerability, as owner of the Site (Assuming the culprit cannot do this). So, it may happen again from any other loophole, I assume.

But, Vivek, please don't put up too-much concentration in hack proofing Site instead RC.

And I request you to write in your homepage that
"Small site dedicated to RC for supplying the RC items cheaper than other. It may be easily hacked, but please don't do that as hacking this site, poor RC enthusiasts will not get the items cheaper." - Vivek Kumar Singh

or as something as you wish, so that other will not invite hacker claiming ownership of your site. Side by side the hackers will not do the changes to a weak site as they want reputation of their work.

It's a simple solution and no hacker even the student won't do that where they are well informed.

It's my personal opinion. You may differ.
:hatsoff: RCBazaar, pointing at right time.
:hatsoff: About your selection, RapidSSL, the most trusted Scripting Host among Hackers/Crackers community over a decade.

-KalyanProdhan


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: Dharmik on February 13, 2012, 09:25:07 AM
I completely agree with Kalyan sir. Anyone can easily get into it but it could be serious matter because hacker can misuse information of registered customers fetching from database. I am just worried about that otherwise site can be restored from backup.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: anwar on February 13, 2012, 11:44:33 AM
A lot of issues can be avoided if the appropriate security patches and upgrades for the cart software (Zen cart, OS Commerce etc) are applied in time.  Some of these are notorious for having security issues, and keeping up with their security patch release schedule is a must.  Proper configuration of PHP settings (php.ini) and web server folder permissions are also a must. 

Despite all this, there are still holes that are currently unknown to general public (called "zero day vulnerabilities"), and no site can be considered foolproof.  But we have to do our part, so that the "script kiddies" can be kept out, and only "true hackers" can do the damage.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: anwar on February 13, 2012, 01:01:41 PM
Another layer of protection is using things like Suhosin.

http://www.hardened-php.net/suhosin/


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: raja2k5 on February 13, 2012, 01:41:59 PM
Well said Anwer sir.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: rcpilotacro on September 04, 2012, 09:20:00 AM
this is what i saw today, cute


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: satyagupta on September 04, 2012, 09:55:18 AM
SQL injection again. :banghead:

Vivek ji add some security modules or components. Dont know much about joomla..


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: raja_mastana on September 04, 2012, 10:09:15 AM
Its a major issue - question of customer privacy.
Not going to register there again. Its happening frequently with rcelectro.
God knows how the hacker will use the customer information, its scary


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: satyagupta on September 04, 2012, 11:12:18 AM
So raja here is what you do, create a dummy email id i have this with inbox.com or live.com with a random mail id. like obamahere@inbox.com :giggle: and use this to register on every site or forums this is what i usually do for most of the sites (which i think is unsafe and can be cracked)


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: raja_mastana on September 04, 2012, 11:22:03 AM
Good tip Satya, I have already done something like that, but still eCommerce sites still have our valid phone number, address, name, age etc. Cant fake these values.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: satyagupta on September 04, 2012, 11:26:01 AM
ya man... :o this did not clicked me. I hope his db is fine, just files were affected :'(


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: iamahuman on September 04, 2012, 03:24:21 PM
On a side note, Gusty( hope you don't mind me calling you that), you're using IE? Why!?!

Is it just me or has VK's activity on RCI come down?


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: rcpilotacro on September 04, 2012, 05:06:52 PM
a.Gusty( hope you don't mind me calling you that), b.you're using IE? Why!?!
a. not at all b. maintained by sys admin :) chrome at home , safari on mac


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: sandeepm on September 04, 2012, 06:04:22 PM
yes, its hacked....


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: iamahuman on September 04, 2012, 08:31:10 PM
.. maintained by sys admin ....
That makes sense.


Title: Re: Does anyone seen rcelectro.com ?? Its Hacked
Post by: vksingh on September 13, 2012, 09:36:50 PM
Dear All,
Because of lot of hacking activities on the server, I have changed the server and the cart system. Now there are dedicated administrator for the website and website is more secure now.
Thanks for your support
RCelectro
Vksingh