4 ms·
A way of detecting if your site was hacked. Worth implementing?
- rovr138 6y agoUsually this is done to include links to other sites so a way of testing is checking key pages for links and testing them or flagging external ones if they’re only supposed to be internal. CloudFlare has 1.1.1.3 which blocks links to porn and malware, so another way is checking the domains against that. It all depends on the kind of defacing you’re seeing and looking to monitor. They could replace a page but they could alter the content as well.
- Akcium 6y agoYou mean if there is links to external sources? Which is the purpose of hacking actually... Then, how to tell users to include all links which are exceptions? Like, it maybe a link to some javascript library or something, and users will always need to update the list. However checking for porn / malware domains is good too, not sure how to get these links database thought... However comparing pictures can handle content changing as well I think
- rovr138 6y agoI don’t know the content strategy for the site, but depending on the site, most link to inner pages. Once you find individual articles, those usually can have external links. This is making a lot of assumptions on the content structure, that’s true. But it would be interesting to analyze. For how to get the links from the database, not for this, but I have used the `urlextract` Python package to find urls. Then you can use `urlparse` to the get the domain. For how to extract this from the database, you’ll have to write some sql to find the tables you want, then you can do a `select * from table`. Then it’s parsing the output, get the urls, get the domain for each. I would probably aggregate all the urls and domains, then at the end actually scan so you can deduplicate entries and not waste time scanning the same domain over and over. - urlextract - https://pypi.org/project/urlextract/ https://pypi.org/project/urlextract/ For the images portion, I’d look into imagemagick compare tool, http://www.imagemagick.org/Usage/compare/ http://www.imagemagick.org/Usage/compare/ You can take a screenshot of a page at the moment you know it’s good, then take daily screenshots. With this tool, you can grab the daily screenshot and compare it with the known good one and the changes are highlighted.
- Akcium 6y agoOh thank you so much, this is indeed cool feedback. Now I'm considering having many options for hack detecting, screenshots/crawling etc. Especially thanks for the imagemagick. When I researched for such libraries, I haven't found a lot of them, so it's treasure
- appliku 6y agoI think it is as complex topic as solving captcha or fighting email spam. You can check screenshots, you can check for new CSS/JS files included in page. That's a start. Also you should track DNS/NS changes. Only screenshots are not enough. What if they redirect users elsewhere? Open new windows (well, browsers fight it themselves, but still). To summarise this: - DNS changes - changes in included JS/CSS files - changes in new outgoing links on a given page. This should be enough for starters
- Akcium 6y agoThen I'll need to make some crawler, which is also not that easy to implement. Maybe it's a good idea to have some kind of complex functionality, broken down to parts: - screenshots - links - DNS - ... so that user can enable/disable them as he needs too
- rovr138 6y agoYou can also use something that’s built already and extend it. I have used in the past linkchecker, https://github.com/linkchecker/linkchecker https://github.com/linkchecker/linkchecker to do crawling too. You can get the report and analyze it however you want.