![]() | All Advertisers |
| Member Services Directory | Classifieds | Reviews | Jobs | Deal Zone | Merchandise | Marketplace | Facebook App | Books, DVDs & Gadgets | Video Vault | Tips & Techniques |
| |||||||
New Reply | Thread Tools | Search this Thread |
| | #1 |
| Lives for gear Joined: Sep 2002 Location: Brazil, Florianópolis/SC
Posts: 1,734
Thread Starter Verified Member | Is your Studio web site safe from hackers?Guess who is messing up Mastering sites...
Hi folks This week I was surprised by a group of folks who tried to mess up my website. Their IPs were tracked as being from web/cable TV companies from the USA and Canada. Please take a serious look at the security of your FTP/web sites. I may post here the IPs and the names of the companies ( although I do not want a lawyer knocking at my door). If it is a problem I may provide them via PM's. Take Care!
__________________ Alécio Costa Studio www.aleciocosta.com http://www.facebook.com/alecio.costa Artist career at: http://www.audiostreet.net/aleciocosta http://www.myspace.com/aleciocosta |
| | |
| | #2 | |
| Gear addict Joined: Nov 2008
Posts: 345
| Quote:
| |
| | |
| | #3 |
| Gear addict Joined: Oct 2006
Posts: 302
|
If someone is doing DoS attacks on your website, they are most likely spoofing the IP as well. So the WHOIS info your picking up on the IP, is whatever they decided to choose as an IP to attack you with. I can guarentee 99.9% that the IP they used to attack your website with, is not the actual IP of the attacker. It's almost the same thing as spam e-mails, The e-mail address of the spammer that ended up in your inbox is not the e-mail or domain that the spammer originated his e-mail from. Not even close. They dont want to get caught, thats the whole point. There could be that .1% chance that you pissed off some IT dude that worked at NBC, and now your paying the price for a week or so.. But seriously, thats probably not the deal here. |
| | |
| | #4 |
| Lives for gear Joined: Feb 2008
Posts: 1,114
|
Yeah, not a DoS. Probably someone that just ran a web search for a substring that is somewhere on your website, for whatever software you happen to be running on it. It's not likely that they know you. It's likely they are just some lame script kiddies. Check to see what the last modified files on your site are, so you can remove backdoors etc. Update whatever software on your site that you use that may have it's version information somewhere (on the page or in the html), to the current version. Then remove any back-doors and new accounts, change your passwords, and move on with your life. Keep your software updated next time. |
| | |
| | #5 |
| Lives for gear Joined: Sep 2002 Location: Brazil, Florianópolis/SC
Posts: 1,734
Thread Starter Verified Member | Agreed
One of the IPs, a cable company from Texas, is an already well known disguise used by hackers. It was published this week in some obscure forum place of the web. |
| | |
| | #6 |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
|
either the IPs are spoofed or the machines have been taken over and turned into a bot-net. Tracing those back is often not possible. However, you may inform those ISPs that their systems may be compromised. If you operate your own dedicated server, I think you know what measures to take. Some of them are: - hardening your system (check running daemons, apply bugfixes etc.) - stateful packet-filtering and/or proxying - implementing an IDS - tripwiring - special care to running services, esp. ftpd - serious logging - logrotation -... If you don't have serious knowlege about those issues, I strongly advise against operating your own root server. It can be dangerous for you and others.
__________________ www.just-mix-it.com |
| | |
| | #7 |
| Lives for gear Joined: Sep 2002 Location: Brazil, Florianópolis/SC
Posts: 1,734
Thread Starter Verified Member |
Thanks, guys. In fact there is a company doing it to me, but might be moving to another one as the contract expires. |
| | |
| | #8 |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
| |
| | |
| | #9 | |
| Lives for gear | Quote:
My mentor has a server for the commercials he produces and it gets attacked 24 hours per day 7 days per week. I was there one afternoon and he had 4000 attempted attacks in one day. Wow. I had no idea it was that bad. Luckily he has a good IT person and a good firewall/software barrier. I cannot imagine what some where like the White House or the Pentagon must go through with people trying to break in.
__________________ -TOM- Thomas W. Bethel Managing Director Acoustik Musik, Ltd. Room with a View Productions Oberlin, OH 44074 www.acoustikmusik.com Doing what you love is freedom. Loving what you do is happiness. | |
| | |
| | #10 | |
| Lives for gear Joined: Feb 2008
Posts: 1,114
| Quote:
Of course now... they have a pretty heavy-duty setup. | |
| | |
| | #11 |
| Lives for gear Joined: Sep 2002 Location: Brazil, Florianópolis/SC
Posts: 1,734
Thread Starter Verified Member |
Seems there are lots of sick minds out there or folks who don´t have top quality sex in their lives.
|
| | |
| | #12 |
| Lives for gear Joined: Feb 2008
Posts: 1,114
|
I'm guessing you just visited Whitehouse.com.... instead of Whitehouse.gov Biiiiiiiiiiig difference. [revisited] ah nevermind. Whitehouse.com isn't a hard-core porn site anymore. now i'm lost (per your comment, not the lack of porn. not that i need porn. lol, i should stop typing. heeheeh.) [/revisited] Last edited by Jesse Graffam; 15th June 2009 at 05:46 AM.. Reason: revisited |
| | |
| | #13 |
| Gear addict Joined: Nov 2008
Posts: 345
| Right on. I run my business from a high-volume website which routinely gets attacked, and sometimes they're successful. But you repair the damage, plug the hole, and move on. Trying to pin the blame on someone is a total waste of time and energy.
|
| | |
| | #14 | |
| PC Moderator |
most of the problems occur with password protection of your account. your ISP is safe like fort-nox and the guy who owns the account has a 6 letter password this takes up to 2 minutes and you are in.use something easy as this: Password checker to check your ISP-password, email password and stuff like that. it's always a good idea to hide any "ADMIN" logins from your mainpage. if you run a CMS (content management system), always upgrade to the latest greatest release of your CMS-soft. that's it. pretty safe life now.
__________________ Quote:
www.georgenecola.com produce & mix it shop.georgenecola.com gear & fun blog.georgenecola.com reviews & gear soundcloud.com | |
| | |
| | #15 | |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
| Quote:
For starting, I recommend checking the books by O'Reilly: O'Reilly Media: Tech Books, Conferences, Courses, News What many people forget: It's not only about your own security. If your system gets compromised, it almost certainly WILL be used to attack other systems. When I was still a network-admin, my systems were routinely attacked by compromised systems operated by someone "who is good with computers", but had no idea of pro-level networking and server-operating. Being able to troubleshoot a DAW or the computers of your friends does not qualify you for operating a public server. Sadly, as with audio products, everybody now can buy a 'root-server-package', even without any qualifications. (you know, those guys are the IT-equivalent to the 'mastering engineers' with a MBox and cracked waves bundle.) | |
| | |
| | #16 | |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
| Quote:
A starting point: Open Source Tripwire - Wikipedia, the free encyclopedia | |
| | |
| | #17 | |
| Lives for gear Joined: May 2008
Posts: 681
| Quote:
.
__________________ HookedOnHardware R E C O R D I N G - S T U D I O S (New studio opening soon!) Music is art, engineering is science...and production is what bridges the two. | |
| | |
| | #18 |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
| |
| | |
| | #19 | |
| PC Moderator |
you are right. I am talking about the sharing hostings. most people I know have shared hostings. your ISP may fail too, but they do regular updates of their software, firewalls and stuff. the weakest point are user passwords stike running a dedicated is a whole different story. I already had my daily O'Reilly-coffee today ![]() cheers Quote:
| |
| | |
| | #20 |
| PC Moderator | |
| | |
| | #21 |
| mymixisbetterthanyours! Joined: Oct 2006 Location: Berlin
Posts: 1,759
| |
| | |
New Reply
Facebook
Twitter
LinkedIn
| Thread Tools | Search this Thread |
| Similar Threads | ||||
| Thread | Thread starter | Forum | Replies | Last Post |
| Recording studio builder web site | solar2 | Photo diaries of recording studio construction projects | 0 | 2nd November 2008 08:11 PM |
| Studio Web Site | Jim Easton | The Good News Channel | 8 | 30th September 2008 01:14 PM |
| Do you/your studio need a web site? | brockf | Product Alerts older than 2 months | 0 | 1st June 2007 03:41 AM |
| so many sites on the web for my music to get promoted : which ones are the best? | cwar05 | So much gear, so little time! | 2 | 7th April 2007 07:29 PM |
| songwriters sites on the web | songman | Work In Progress / Advice Requested / Show & Tell / Artist Showcase / Mix-Offs | 0 | 21st August 2005 08:17 PM |
| |