My FTP was hacked, what should I do next?

Need help with your PC or Modding Projects?
User avatar
SpaceBooger
Moderator
Posts: 4420
Joined: Mon Mar 10, 2008 6:40 am
Location: The AK-Rowdy
Contact:

My FTP was hacked, what should I do next?

Post by SpaceBooger »

I use Phpbb (like this site) and Wordpress for most of my sites and just got the following as a trouble ticket from my hosting company:
We regret to inform you that we have found that your FTP password has been compromised. It is likely that it was stolen by a "hacker" (or someone with malicious intent against your account) or a Trojan. This means that your account is now vulnerable to malicious scripts. Your account will be completely cleaned from all known malicious code in the nearest time.

We have changed your FTP passwords to a temporary ones in order to protect your account. You may change them anytime at your hosting control panel. Important: Please do not use the old passwords, as this will only make your account vulnerable again. Please also note that some widespread Trojans have the ability to steal FTP passwords from a user`s local PC`s and send these passwords to hackers (or special bots which were made by hackers). To prevent re-occurrence, please understand that you will need to perform a full anti-viral scan on your local PC (using an in-depth scanner) prior to your next FTP login. We hope that these actions will protect your account from compromise in the future. Thank you for understanding in this matter, and we sincerely apologize for any inconvenience this may cause.
I am running malwarebytes and noticed that avira caught something and quarantined it yesterday... other than changing all my password for sites any other suggestions?
BLOG | BST
Systems Owned: Atari 2600 & 5200, NES, Game Boy (OG, Pocket, Color, GBA & GBA SP), DSi, 3DS, SMS, Genesis, Sega CD,
Nomad, SNES, Saturn, PS1, Dreamcast, XBox, PS2, Gamecube, Nintendo DS, Wii, PSP, PS3, WiiU, XBOX, 360 XBONE & Switch.
Hatta
Next-Gen
Posts: 4030
Joined: Tue May 06, 2008 8:33 pm

Re: My FTP was hacked, what should I do next?

Post by Hatta »

In the future, avoid FTP at all costs. Passwords are transmitted in plain text, so anyone on your network segment or in between you and your host can read your password easily.


It sounds like what happened here is that your home PC got rooted, and they sniffed the password from there. The only safe thing to do when your machine is compromised is to nuke it and reinstall from clean media. You cannot trust a scan on a compromised OS. Rootkits can and do hide themselves in filesystems and lie to the OS about it.
We are prepared to live in the plain and die in the plain!
User avatar
SpaceBooger
Moderator
Posts: 4420
Joined: Mon Mar 10, 2008 6:40 am
Location: The AK-Rowdy
Contact:

Re: My FTP was hacked, what should I do next?

Post by SpaceBooger »

Hatta wrote:In the future, avoid FTP at all costs. Passwords are transmitted in plain text, so anyone on your network segment or in between you and your host can read your password easily.


It sounds like what happened here is that your home PC got rooted, and they sniffed the password from there. The only safe thing to do when your machine is compromised is to nuke it and reinstall from clean media. You cannot trust a scan on a compromised OS. Rootkits can and do hide themselves in filesystems and lie to the OS about it.
Yeah, but I haven't used my FTP (or logged in) in over a month? Do you think all of my passwords are compromised?
BLOG | BST
Systems Owned: Atari 2600 & 5200, NES, Game Boy (OG, Pocket, Color, GBA & GBA SP), DSi, 3DS, SMS, Genesis, Sega CD,
Nomad, SNES, Saturn, PS1, Dreamcast, XBox, PS2, Gamecube, Nintendo DS, Wii, PSP, PS3, WiiU, XBOX, 360 XBONE & Switch.
Hatta
Next-Gen
Posts: 4030
Joined: Tue May 06, 2008 8:33 pm

Re: My FTP was hacked, what should I do next?

Post by Hatta »

Probably. I wouldn't risk it.
We are prepared to live in the plain and die in the plain!
User avatar
Ziggy
Moderator
Posts: 14913
Joined: Mon Jun 09, 2008 5:12 pm
Location: NY

Re: My FTP was hacked, what should I do next?

Post by Ziggy »

Hatta wrote:In the future, avoid FTP at all costs.
I remember my A+ teacher was going on about how much trouble he use to have with his FTP. He said it wasn't worth using. Seems like people will hack it just for the hell of it. Just because they can.
User avatar
SpaceBooger
Moderator
Posts: 4420
Joined: Mon Mar 10, 2008 6:40 am
Location: The AK-Rowdy
Contact:

Re: My FTP was hacked, what should I do next?

Post by SpaceBooger »

From what I understand, there were multiple FTP logins from multiple countries in a short period of time. Thats how they figured out the password was compromised.
So I now have a fresh install of windows 7.
BLOG | BST
Systems Owned: Atari 2600 & 5200, NES, Game Boy (OG, Pocket, Color, GBA & GBA SP), DSi, 3DS, SMS, Genesis, Sega CD,
Nomad, SNES, Saturn, PS1, Dreamcast, XBox, PS2, Gamecube, Nintendo DS, Wii, PSP, PS3, WiiU, XBOX, 360 XBONE & Switch.
User avatar
Xonticus
128-bit
Posts: 755
Joined: Tue Jan 06, 2009 10:11 pm

Re: My FTP was hacked, what should I do next?

Post by Xonticus »

So whats the alternative to FTP?
Got: Atari 2600, Atari 7800Pro, Commodore 64, Odyssey 2, Sega Master System, NES, Genesis Models 1-3, Nomad, Game Gear, Sega CD Model 1, Sega 32x, SuperNES, GameBoys, GameBoy Pocket, GBC, Sega Saturn Model 2, GBA, Nintendo 64, Playstation, Sega Dreamcast, Playstation 2 Slim, Nintendo DS Lite, Xbox 360, Gamecube, PS3 Slim
User avatar
RCBH928
Next-Gen
Posts: 6082
Joined: Wed Apr 02, 2008 6:40 am

Re: My FTP was hacked, what should I do next?

Post by RCBH928 »

i thought ftp was the only way to send files over the internet?
to a host server I mean
User avatar
jeffro11
128-bit
Posts: 574
Joined: Mon Mar 15, 2010 1:27 am
Location: Canada
Contact:

Re: My FTP was hacked, what should I do next?

Post by jeffro11 »

FTPS (over SSL) Everything is encoded. Many hosts however do not support this...
User avatar
RCBH928
Next-Gen
Posts: 6082
Joined: Wed Apr 02, 2008 6:40 am

Re: My FTP was hacked, what should I do next?

Post by RCBH928 »

and you can do this ftps using ur regular ftp program?
like cute ftp?
Post Reply