Urgent: Need Help.. my website hacked.... need to find who did it.

larciel

Diamond Member
May 23, 2001
4,590
8
81
well, it's not exactly my site, but my buddy's site.. it was just a small message board, but someone went in and erased ALL messages..

i don't have much experience in network/ip/hack/ field... so any help to catch who did it, and possibly bring back the erased messages, would be Greatly appreciated! .. (maybe some gift ... i'm serious)..

the web-host , i assume, doesn't know alot of hosting/protection, but is there some log even if he didn't set it up? ...

since there are too little facts gathered up right now, i understand it'll be hard to tell which way to go, but please let me know what'd be 'general 101' to catch who hacked a site. and some typical ways .. (stole ip address, probably?)

thank you so much in advance.. i'll update as soon as i get new info!
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
You are going to want an image of the hard drive to work with. All logs with a timestamp of the rough time it happened should be looked at. You should look at all binaries on the system with suspicion and until you can prove they are safe (same as the original) you should not trust them. Using staticly built programs that are not resident on the current system to check for running processes (before shutting down or rebooting) would help out a lot. Check out your IDS logs to see if you have anything suspicious. Basically, the word is check your logs and make sure this was not a "Im using the name of my dog as my password!" problem.

As far as getting the messages back, restore from backups when you are sure the system was not compromised.