GDPR Cookie Consent by SimpleServe Privacy Script Email saying website hacked ? genuine - AAD Consumer Forum

Announcement

Collapse
No announcement yet.

Email saying website hacked ? genuine

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Email saying website hacked ? genuine

    Hmmm.
    I got the email below this morning.
    Instantly thought it was a scam but to be safe I investigated and the index html file was where they said it would be.
    To be on safe side I've deleted the wordpress database (it was only a test site) and changed my ftp password/hosting login.
    If it's not genuine it's no loss...but what do others think? The education site looks gen.

    Dear Website Administrator,

    We are contacting you to report that your website (edit) has been
    compromised and fraudulent content targeting our client Chase Bank has
    been placed at:

    (edit)/wp-content/themes/update/chaseupdate/index.html


    IP Address: (edit)
    A criminal has placed this fake login page for the purpose of credit
    card fraud and identity theft. Please remove all files related to this
    attack and take action to secure your website.

    We are an Internet security company located in Tacoma, Washington. If
    you are unable to resolve this problem yourself, please contact your
    webhost for assistance.

    Additionally, we invite you to help us and the Anti-Phishing Working
    Group (APWG) in the fight against phishing.

    Please help us to educate consumers who are fooled by this criminal web
    site. You can do this by pointing the illegal URL to an educational page
    at:

    http://education.apwg.org/r/en?ORIGI...randing=497126

    The instructions on how to implement it can be found here:

    http://education.apwg.org/r/how_to.html

    We can be reached 24/7 if you have any questions.

    Best Regards,

    --
    IID -- on behalf of Chase Bank
    Actively Securing the Extended Enterprise

    E-mail: alert@internetidentity.com
    Office: +1.253.590.4100 | Fax: +1.425.699.6597

    II Email Number 191758 II
    Case Number: SIT117883

  • #2
    Re: Email saying website hacked ? genuine

    Internet Identity - Wikipedia, the free encyclopedia

    Company they claim to be seems genuine?

    Wordpress have been the subject of several vulnerabilities in recent times that have allowed hacking of blogs and the placing of malicious content.
    Last edited by Riz; 4 February 2012, 09:37.
    I'm an official AAD Moderator and also a volunteer, here to help make the forum run smoothly. Any views or opinions are mine and not the official line of AAD. Similarly, any advice I have offered you is done so on an informal basis, without prejudice or liability. If in doubt seek advice from a qualified insured professional - Find a Solicitor or go to the National Probono Centre.

    If you spot an abusive or libellous post then please report it by Clicking Here. If you need to contact me, for instance if I've issued you a warning, moved, edited or deleted your post, please send me a message by clicking my username.

    Comment


    • #3
      Re: Email saying website hacked ? genuine

      If you go to the awpg page linked (removed the id) then it tells you not to follow links in emails or call telephone numbers in emails, both of which their email tells you to do!

      Not much on the internet about these emails. The first link to the wp-content directory, was that an existing file and your real url? Just wondering if they might have added something to that index.html to compromise your browser if clicked on? Or to redirect?

      Comment


      • #4
        Re: Email saying website hacked ? genuine

        Hi,
        yeah is was one of my domain names and the url panned out.
        I never click on anything in emails, thankfully. In fact anything that looks dodgy I view in properties/source.
        I just went to my domain and tracked it down internally.
        Wordpress has so many layered folders I couldn't say if it's always been there. It's nothing I've noticed before though, there was also a login.htm and login.php in same folder so looked dodgy.
        All blitzed now though but I'm not doing the redirect they ask for.

        Comment


        • #5
          Re: Email saying website hacked ? genuine

          Its a scam - you as webby would know if your site is hacked - the admin logs tell you..
          I'm the forum administrator and I look after the theme & features, our volunteers & users and also look after any complaints or Data Protection queries that pass through the forum or main website. I am extremely busy so if you do contact me or need a reply to a forum post then use the email or PM features offered because I do miss things and get tied up for days at a time!

          If you spot any spammers, AE's, abusive or libellous posts or anything else that just doesn't feel right then please report them to me as soon as you spot them at: webmaster@all-about-debt.co.uk

          Comment


          • #6
            Re: Email saying website hacked ? genuine

            I've not logged on for months, it was an experiment using a new platform for modding wordpress. No longer needed anyway so I should have dumped it before now

            Comment


            • #7
              Re: Email saying website hacked ? genuine

              Just checked, and a Wordpress install should not have those files.

              If you had them, then yes, you have been hacked in some fashion.
              I'm an official AAD Moderator and also a volunteer, here to help make the forum run smoothly. Any views or opinions are mine and not the official line of AAD. Similarly, any advice I have offered you is done so on an informal basis, without prejudice or liability. If in doubt seek advice from a qualified insured professional - Find a Solicitor or go to the National Probono Centre.

              If you spot an abusive or libellous post then please report it by Clicking Here. If you need to contact me, for instance if I've issued you a warning, moved, edited or deleted your post, please send me a message by clicking my username.

              Comment


              • #8
                Re: Email saying website hacked ? genuine

                Originally posted by Shepherdess View Post
                Hi,
                yeah is was one of my domain names and the url panned out.
                I never click on anything in emails, thankfully. In fact anything that looks dodgy I view in properties/source.
                I just went to my domain and tracked it down internally.
                Wordpress has so many layered folders I couldn't say if it's always been there. It's nothing I've noticed before though, there was also a login.htm and login.php in same folder so looked dodgy.
                All blitzed now though but I'm not doing the redirect they ask for.
                ooops I should have read this first.....

                always manage your own logs, then you'll see any problems.

                I check ours several times a day - JUST in case

                Glad you sorted it
                I'm the forum administrator and I look after the theme & features, our volunteers & users and also look after any complaints or Data Protection queries that pass through the forum or main website. I am extremely busy so if you do contact me or need a reply to a forum post then use the email or PM features offered because I do miss things and get tied up for days at a time!

                If you spot any spammers, AE's, abusive or libellous posts or anything else that just doesn't feel right then please report them to me as soon as you spot them at: webmaster@all-about-debt.co.uk

                Comment


                • #9
                  Re: Email saying website hacked ? genuine

                  Originally posted by rizzle View Post
                  If you had them, then yes, you have been hacked in some fashion.
                  Not as bad as our DDos attacks though
                  I'm the forum administrator and I look after the theme & features, our volunteers & users and also look after any complaints or Data Protection queries that pass through the forum or main website. I am extremely busy so if you do contact me or need a reply to a forum post then use the email or PM features offered because I do miss things and get tied up for days at a time!

                  If you spot any spammers, AE's, abusive or libellous posts or anything else that just doesn't feel right then please report them to me as soon as you spot them at: webmaster@all-about-debt.co.uk

                  Comment


                  • #10
                    Re: Email saying website hacked ? genuine

                    Originally posted by Shepherdess View Post
                    I've not logged on for months, it was an experiment using a new platform for modding wordpress. No longer needed anyway so I should have dumped it before now
                    I've never seen the fascination in WP - never really "done it" for me before. I think we're also adding a module on our hosting platform for users to plug-in but not something I'll be doing
                    I'm the forum administrator and I look after the theme & features, our volunteers & users and also look after any complaints or Data Protection queries that pass through the forum or main website. I am extremely busy so if you do contact me or need a reply to a forum post then use the email or PM features offered because I do miss things and get tied up for days at a time!

                    If you spot any spammers, AE's, abusive or libellous posts or anything else that just doesn't feel right then please report them to me as soon as you spot them at: webmaster@all-about-debt.co.uk

                    Comment


                    • #11
                      Re: Email saying website hacked ? genuine

                      Thanks Rizzle...I googled the chaseupdate folder name too and nothing.

                      Thankfully never had to deal with a DOS attack Niddy. (My websites aren't likely to be targeted except maybe by a sacked drummer )

                      The platform I was testing was called Gantry...quite useful for presenting wp as a website rather than a blog.

                      Comment


                      • #12
                        Re: Email saying website hacked ? genuine

                        Speaking of drummers....My OH has loads of musician contacts on facebook.
                        One of them shared this pic yesterday. I think it's hilarious!
                        What's even funnier is that it got loads of (predictable) comments, but NONE of them got it. One was even trying to see where the second pair was...
                        Attached Files

                        Comment


                        • #13
                          Re: Email saying website hacked ? genuine

                          Originally posted by Shepherdess View Post
                          Thanks Rizzle...I googled the chaseupdate folder name too and nothing.
                          I did and found a few references.

                          Mostly where people reported that they had received fake bank emails asking them to log on to their bank at a dodgy url with that in it's address.

                          e.g. a direct attempt to obtain bank log on details, which is the opposite of the warning you got.

                          Not confined exclusivelyto Wordpress urls/folder either. Seems that they will try to plop a folder with that name/content anywhere they can on a server.

                          One example with pics of the phish email and fake login.

                          Account Maintenance - Chase Phishing Scams - MillerSmiles.co.uk
                          I'm an official AAD Moderator and also a volunteer, here to help make the forum run smoothly. Any views or opinions are mine and not the official line of AAD. Similarly, any advice I have offered you is done so on an informal basis, without prejudice or liability. If in doubt seek advice from a qualified insured professional - Find a Solicitor or go to the National Probono Centre.

                          If you spot an abusive or libellous post then please report it by Clicking Here. If you need to contact me, for instance if I've issued you a warning, moved, edited or deleted your post, please send me a message by clicking my username.

                          Comment


                          • #14
                            Re: Email saying website hacked ? genuine

                            Originally posted by Shepherdess View Post
                            Speaking of drummers....My OH has loads of musician contacts on facebook.
                            One of them shared this pic yesterday. I think it's hilarious!
                            What's even funnier is that it got loads of (predictable) comments, but NONE of them got it. One was even trying to see where the second pair was...
                            lol. Suppose would only make sense to anyone has done some sort of code.
                            I'm an official AAD Moderator and also a volunteer, here to help make the forum run smoothly. Any views or opinions are mine and not the official line of AAD. Similarly, any advice I have offered you is done so on an informal basis, without prejudice or liability. If in doubt seek advice from a qualified insured professional - Find a Solicitor or go to the National Probono Centre.

                            If you spot an abusive or libellous post then please report it by Clicking Here. If you need to contact me, for instance if I've issued you a warning, moved, edited or deleted your post, please send me a message by clicking my username.

                            Comment


                            • #15
                              Re: Email saying website hacked ? genuine

                              Well googled, Rizzle!
                              Presumably that page is what would have shown up on my domain.

                              Comment

                              Working...
                              X