{"id":331,"date":"2012-02-07T08:04:10","date_gmt":"2012-02-07T08:04:10","guid":{"rendered":"http:\/\/gusclass.com\/blog\/?p=331"},"modified":"2012-02-07T17:13:04","modified_gmt":"2012-02-07T17:13:04","slug":"blog-attack-pt-2-situation-analysis","status":"publish","type":"post","link":"http:\/\/gusclass.com\/blog\/2012\/02\/07\/blog-attack-pt-2-situation-analysis\/","title":{"rendered":"Blog attack!  Pt. 2: What happened?"},"content":{"rendered":"<h1>How a site on my host was <a href=\"http:\/\/www.imdb.com\/title\/tt0113243\/fullcredits\">hacked<\/a><\/h1>\n<p>I wrote previously about <a href=\"http:\/\/gusclass.com\/blog\/2012\/01\/27\/blog-attack\/\">why my site had gone offline<\/a>.\u00a0 I looked a little more into what had happened and here&#8217;s a synopsis.<\/p>\n<h2>Tampering with data<\/h2>\n<p>First,\u00a0a\u00a0script was uploaded using <a href=\"http:\/\/markmaunder.com\/2011\/08\/01\/zero-day-vulnerability-in-many-wordpress-themes\/\">a zero day\u00a0hack in tim thumb<\/a>.\u00a0Tim thumb, an image resizer,\u00a0could be tricked into uploading any file to WordPress and give it +x permissions.<\/p>\n<p>The\u00a0script that was uploaded with +x permissions would test for the availability of the SMTP port (25) then also expose some generic file handling capabilities such as upload.\u00a0 This is pretty much a script that was added with the intent of doing\u00a0something more malicious. I&#8217;m guessing\u00a0that this was mass exploited across vulnerable WordPress sites\u00a0discovered through Google.<\/p>\n<p>Next some random files, ads and html pages, were uploaded to the share.<\/p>\n<h2>Elevation of privelege<\/h2>\n<p>Not satisfied with just having one exploit script propped to my host, the attacker also added a second script which was given a random-looking name. This script was a mailer.\u00a0 The attacker actually uploaded the same script twice, with different seeds &#8211;\u00a0either that or the attacker mistakenly ran the same upload script twice.\u00a0I&#8217;m assuming this script basically gave the attacker a dashboard for loading more scripts or even using my host like an ftp server &#8211; my host then had discovered the offending scripts and he was shut down. At which point my host took me down until they could remove permissions for everything that was compromised.<\/p>\n<h3>Thoughts&#8230;<\/h3>\n<p>Sharing your hosting creates interesting attack vectors. Since my friend&#8217;s site was essentially hosted in a folder on a shared host somewhere, my host was only as secure as their folder.\u00a0I should have done a better job of applying the <a href=\"http:\/\/msdn.microsoft.com\/en-us\/magazine\/cc163519.aspx\">STRIDE model<\/a>\u00a0for thinking about threats &#8211;\u00a0I probably was pretty much vulnerable to the entire gamut\u00a0of bad things that could happen. It also made me think about the power of client-side.\u00a0If everything on my host were JavaScript, nothing on my host would have to have +x.\u00a0If\u00a0all application storage was\u00a0isolated from the web site, that would probably help too.\u00a0It&#8217;s definitely\u00a0time for me to do an audit of my site for\u00a0anything I have that can execute server-side.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How a site on my host was hacked I wrote previously about why my site had gone offline.\u00a0 I looked a little more into what had happened and here&#8217;s a synopsis. Tampering with data First,\u00a0a\u00a0script was uploaded using a zero&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[72,11,44],"tags":[288,43,284],"amp_validity":null,"amp_enabled":true,"_links":{"self":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/331"}],"collection":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/comments?post=331"}],"version-history":[{"count":22,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/331\/revisions"}],"predecessor-version":[{"id":367,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/posts\/331\/revisions\/367"}],"wp:attachment":[{"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/media?parent=331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/categories?post=331"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gusclass.com\/blog\/wp-json\/wp\/v2\/tags?post=331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}