9
rehman
8y

our website got hacked somebody downloaded the whole source code and sent an email to us.
seems like that person would demand ransom or anything.
We still can't find where is the door ( vulnerability ) through which he pulled all files.

Comments
  • 1
    Oh wow, life is real
  • 0
    @sam9669 surely he doesn't have sever credentials but still he manages to do it
  • 0
    @g-m-f codeigniter, mysql
  • 0
    ma be he first patched the hole haha
  • 0
    @g-m-f latest I guess its 3. Something credentials are changed and didn't found any malicious activity
  • 0
    @g-m-f I'm on this site, how do we use it?
  • 0
    @g-m-f I found only one thing critical, email library of CI and we are not using that
  • 0
    @g-m-f well yes we are using bitbucket, we assuming that he has some door where he uploaded any file through which he could download them all
  • 0
    @g-m-f. Yes its stored in private repo. I have thinked on it before but i don't think so
  • 1
    Silly question: are you 100% sure they have the full source code? Maybe they somehow had access to a small portion of code and now are trying some social engineering on you...
    Have you used third part php libraries on your project? Maybe some of them have some known flaw/vulnerability...
  • 3
    Is your .git folder uploading to your web server? If so that's a very common method of getting access to the code.
  • 0
    If you have the persons email you could reply and ask them to tell you the vulnerability. Maybe they are not malicious.
  • 0
    @dfox yes .git folder is there how do we get data on it?
  • 0
    From it*
  • 2
  • 0
    @dfox okay we don't have directory list enabled, but still I would try these commands
  • 0
    @dfox my command was failed with 404 status
Add Comment