• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Jeff Mikels

…biblical Christianity without conservative idolatry…

  • Home
  • All My Sermons
  • My Blog
    • Longer Articles
    • Christian Leadership
    • Spiritual Health
    • Tough Questions
    • Geekery
    • All Posts
  • About Me
    • My Books
    • My Church
    • FAQ
  • Show Search
Hide Search
Home/Front Page/My home server was hacked!

My home server was hacked!

I’m posting this here to hopefully warn other people who are running mythtv on a home server. Here is what happened:

NOTE: Unless you know Linux a little, this won’t make sense.

On my home server, I was running a web server (apache2) on port 80 and sshd on port 22. I had both of them open to the world so that I could access my home server from anywhere with an Internet connection. The only problem with the setup I know of is that when I installed mythtv, it created a user called mythtv and gave that user shell access.

(If you have any standard users on your linux system, make sure they are using non-standard passwords!)

So, this fellow from IP 86.122.48.37 logged into my computer via ssh as mythtv and I’m guessing the default password. Once in, he created a public_html directory in the mythtv home directory. All files in that directory would be accessible by the url http://[MY_IP]/~mythtv. (By the way, I got his IP address from my access logs, and I got his email address from his php scripts. His email is delablow@yahoo.com.)

Then, he copied two phishing sites into that directory (ebay and paypal) along with an instance of PHP-Mailer. I’m guessing that he sent out the scam emails from PHP-Mailer on December 10 (while I was in Chicago) and my access log shows people falling for the scam by December 11. I haven’t yet figured out how many people were scammed, but I got a LOT of hits on my server.

Then, someone told ebay, ebay told Insight, and yesterday, my modem was blocked. I didn’t hear any details until I called them this morning and they told me there was a phishing server running on my IP address.

Well, I’m pretty irritated at myself for leaving my system so open, glad that the hacker wasn’t able to compromise my own system, but mad that many people got scammed.

I’ve closed down my system for now, and I don’t know if I’ll open up the ports again.

I hope no one loses any money on this.

Written by:
Jeff Mikels
Published on:
December 13, 2006
Thoughts:
3 Comments

Categories: Front Page, Geekery, Home Media System

Previous Post: « My Doctrinal Statements are Online
Next Post: Science v. Religion »

Reader Interactions

Comments

  1. Mary Martin

    December 19, 2006 at 3:53 pm

    I don’t know much about linux but I do know about paypal and ebay. On my work email I constantly get messages from both wanting me to click and update information because of something I did and my accounts are blocked. Is this the same thing as getting an email from a bank asking to update your account info because of a problem?

    Reply
  2. Jeff

    December 20, 2006 at 12:27 pm

    It may be the same thing, Mary.

    Here are a couple of tips to make sure you don’t get scammed:

    When you have a link in your email program, don’t just click on it unless you are certain you know where it will take you. Instead, if you get an email from ebay or paypal or some bank, go to that company’s home page and log in to your account normally. If the email was telling you the truth, your account page should also give you the same information as was in the email. If it doesn’t, then ignore the email, or better yet, report it to ebay, paypal, the bank or whatever company it was claiming to be.

    Reply
  3. Robert Valiant

    July 3, 2007 at 7:32 pm

    Thanks for posting. Just happened to me, too.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Articles

Dear Christian Conservative: Vote Your Conscience

Today is Super Tuesday meaning that a large number of states are having their primaries for the Presidential election. Currently, for …

Continue Reading about Dear Christian Conservative: Vote Your Conscience

Let’s Talk about Salvation: Part 2

Salvation and Forgiveness in the Gospel of John In my previous post, I considered a large number of passages in the synoptic gospels (Matthew, …

Continue Reading about Let’s Talk about Salvation: Part 2

Let’s Talk About Salvation and Forgiveness: Part 1

I've been thinking a lot about this idea recently: What would it look like if we were as eager to forgive as Jesus was? This is a tough …

Continue Reading about Let’s Talk About Salvation and Forgiveness: Part 1

Evangelical Idolatry

I've been going through a dilemma. The question on my mind is this: How do I talk about my book with people who don't know me all that …

Continue Reading about Evangelical Idolatry

Explore more

Footer

About Me

Jeff Mikels • 765-404-0807

Copyright © 2025 · Log in

  • Home
  • Blog
  • About Me
  • FAQ
  • Contact