Facebook massage

Monday, December 26, 2016

How A Website Is Hacked?

We know that a website has script,database and hosting system.and a computer system serves the contents.Also domain is used to identify a website location.now how a hacker hacks into a website?let's come to the point.a hacker first find out the security hole of the script programmed.If he is able to find it,he exploits the vulnerability.so if there is any ways he find to get into the database info,he get the admin data that he needs to login to the ftp(file transter protocol) or admin panel.once he entered into the ftp he has the full control to hack the site(edit,delete,create).so he defaces the site to alert the admin of the site.if he is able to login to the admin panel and the panel has the functions like ftp,he can do what he wants.but in this case he needs a malicious script that is called "shell".so shell is a script that has the control like ftp.It allows a hacker to get the full ftp access through the script.There are many types of shells.for example : c99;r57;madshell;moonshell etc.there are some private shells too.so thus a website is hacked.Now when a hacker is able to hack 1 site on the server,he can root the server(get the main server access/computer system access) to hack other/all sites in the server.It is called "mass deface(massive deface)".The word "Web Application" is a computer application that manages and maintains the full server.if there is any programming error found by a hacker,he can get to the root.Such vulnerable web applications are called "DVWA(Damn Vulnerable Web Application)".In case a hacker doesn't find any vulnerability,he tries to bruteforce(crack) the login panel of website/ftp(file transfer protocol).If he fails this time,he try to hijack the domain.If fails again then he DOS/DDOS the site to take it down for a few time so that the actual work of the site gets hampered.Also if a hacker can hack the email of the admin,he can reset the password and get into the site(ex. wordpress).If a hacker doesn't have the main ftp control,the site can be restored because the admin has the ftp access and he can delete the shell so that a hacker has no right to hack again(Also,if the vulnerability is patched).If a hacker wants to hack the site again,he has to exploit again(if vulnerability is not patched).he can't hack if the vulnerability is patched.So this is all about how a website gets hacked.Still there are many ways to hack into a website or take that down. 

Written by Choyon Ahmed

No comments:

Post a Comment