Welcome Guest, Not a member yet? Register   Sign In
I think my website got hacked
#1

Hi,

I've uploaded an opening page for my project which is CI and it was working for a month as well, suddenly yesterday I release that my website is down (screenshot web.jpg) and then I was checking my FTP and I saw many random files are located to my FTP (look at the second screenshot).
--when I deleted the random files, will generate automatically after few minutes!

My code details:
I have only an input to get email address.
I'm using CSRF, XSS and all validation about the input.
Also I trim the input value.
I'm using active records to save data to my database.

I tried to talk to my server's tech support.
I was talking to 6 person to solve the problem.

They mentioned "if you remove the files will be fine" and another person said "the issue is not from us and your coding has problem". Another person said "That most hackers use some kind of encryption to mask there hacks." Another person said "But there is files that actually use legitimate encryption , thus they are pulled into the searchs." And the last person who solved the problem and make my website live again was saying "the issue was about the Php version. You were using 5.4 and I updated to 5.6".

I told him but still I can see the random files in my FTP.
When I was asking him "that means this issue won't happen again? He said no" !

I'm pretty confuse about what was the real reason?
If i got hacked, what's the solution to protect ?
If it was Php version, why before yesterday was working well?

The tech support never reply to my questions.

Anybody can help me in this?
I appreciate if anyone share some security articles with me (not only CI security). I need to protect this project 100% , coz we will have transactions and important data and important users. We don't wish to loose them.

Thanks a lot.

Attached Files Thumbnail(s)
       
Reply


Messages In This Thread
I think my website got hacked - by ardavan - 12-15-2015, 06:24 PM
RE: I think my website got hacked - by skunkbad - 12-15-2015, 07:17 PM
RE: I think my website got hacked - by ardavan - 12-15-2015, 07:23 PM
RE: I think my website got hacked - by skunkbad - 12-15-2015, 07:24 PM
RE: I think my website got hacked - by Php - 12-15-2015, 09:05 PM
RE: I think my website got hacked - by ardavan - 12-15-2015, 10:13 PM
RE: I think my website got hacked - by ciadmin - 12-15-2015, 11:31 PM
RE: I think my website got hacked - by ardavan - 12-16-2015, 05:44 AM
RE: I think my website got hacked - by kenjis - 12-16-2015, 01:12 AM
RE: I think my website got hacked - by ardavan - 12-16-2015, 05:58 AM
RE: I think my website got hacked - by ciadmin - 12-16-2015, 08:04 AM
RE: I think my website got hacked - by ardavan - 12-19-2015, 08:00 PM
RE: I think my website got hacked - by kenjis - 12-16-2015, 03:15 PM
RE: I think my website got hacked - by Martin7483 - 12-17-2015, 01:45 AM
RE: I think my website got hacked - by ardavan - 12-19-2015, 08:08 PM
RE: I think my website got hacked - by Diederik - 12-17-2015, 02:06 AM
RE: I think my website got hacked - by Martin7483 - 12-17-2015, 02:28 AM
RE: I think my website got hacked - by Diederik - 12-17-2015, 03:35 AM
RE: I think my website got hacked - by Martin7483 - 12-17-2015, 03:45 AM
RE: I think my website got hacked - by mr_pablo - 12-21-2015, 09:01 AM
RE: I think my website got hacked - by Martin7483 - 12-22-2015, 02:05 AM
RE: I think my website got hacked - by mr_pablo - 12-22-2015, 02:59 AM
RE: I think my website got hacked - by Martin7483 - 12-22-2015, 02:10 AM
RE: I think my website got hacked - by Martin7483 - 12-22-2015, 04:14 AM



Theme © iAndrew 2016 - Forum software by © MyBB