Suspicious content after html-tag found..site hacked and defaced

See: http://zulu.zscaler.com/submission/show/2aa05fcfc0ea61faf364ab550ed0fa88-1342380830
IP has been defaced, server misused,
“Site has been HaCked By Black Angels”, e-mail and MSN given outside html
IDS alert here: http://urlquery.net/report.php?id=90990
Details here: http://sitecheck.sucuri.net/results/tenntom.org
IDS alerts directed me to the site being hacked. Site gives out the full server version number etc. to the world,
which will make defacement so much easier. See: http://www.ducea.com/2006/06/15/apache-tips-tricks-hide-apache-software-version/
link article author = Marius Ducea
Blackangels. a group of Italian teens, make use of “Cisco Global Exploiter”, to exploit certain vulnerabilities providing simple streams of code to
abuse flaws in Cisco networking kit,

polonus

First, thanks for your information! Mind if I ask how you were notified that this site was hacked?

Is this is a hosting issue? Or some other security issue? YOUR HELP IS MUCH APPRECIATED…

Hi 9561759,

At first I was warned by the IDS alerts via an urlquery.net scan, that made me put the url into a special html viewer which gave away the hack.
The ip could be further verified as belonging to a misused server at a VirusWatch listing, where several domains had been defaced.
Then I did some research on those that performed that specific defacement and got to this group of Italian teenager script kiddies that used this tool,
described here: http://www.vulnerabilityassessment.co.uk/cge.htm (link author Kevin Orrey) to perform their online hoologanism.
If you google “blackangels hacked” you see the connecting pattern is “cisco networking kit flaws probed by streams of code”.
To-day a lot of sites do not have even minimal server and websoftware security and are to be easily hacked or injected with malware.
I posted this to underline the importance of bringing Suricata/Emerging Threats/Snort rule IDS into the scanning of urls to come to an earlier detection of particular issues,

polonus

Thanks. Anytime you need a favor in the dog supplies world, send me a PM. That’s all I got. :wink: Or if you have car trouble in MS, we’ll get you taken care of – Rob Snell

Hi Rob,

The days that you could let the dogs out on defacers are gone, now we have other methods ;D
Hope you could spread the heads-up to small retailers depending on cisco, that they are aware of the illegit use of this pentesting tool in the hands of script kiddies,

polonus aka Damian

Most of the folks I know are using Yahoo! Store, but I have some friends with clients using “cheap” hosting and that seems to come back and bite them. I’ll put the word out. THANKS SO MUCH! – r