iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
IT Discussion Forum Having IT issues? Got IT questions? Who doesn't? If you can't get your Apache to work with your MySQL or your php is choking on your ODBC... Let's see if we can help you come up with some ideas.

Share Thread: & Tags

Share Thread:

Tags
attack, malware

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-11-2009, 09:52 AM
WebProWorld Member
 
Join Date: Oct 2007
Location: India
Posts: 92
vinay11111 RepRank 0
Default Reported attack site message

Hi,

Various of my sites are now giving reported attack website message. I did little research and found that its due to some <iframe> injection in the code of my website.

Please suggest if there is any solution to get rid of this message.

Thanks...
__________________
Regards,
Vinay SEO Times | Teddy Bear Factory
Reply With Quote
  #2 (permalink)  
Old 06-11-2009, 10:16 AM
wige's Avatar
Moderator
WebProWorld Moderator
 
Join Date: Jun 2006
Location: United States
Posts: 2,661
wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9
Default Re: Reported attack site message

Where are you receiving the message?

The first step, of course, will be removing the infected code, and securing the server to close whatever vulnerability is allowing the attacker to compromise the site.
__________________
The best way to learn anything, is to question everything.
Reply With Quote
  #3 (permalink)  
Old 06-11-2009, 10:45 AM
Dubbya's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: Nov 2006
Location: Steinbach, Manitoba, Canada
Posts: 1,300
Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4
Default Re: Reported attack site message

Without visiting your site, I'm thinking that this may have have been implemented using SQL injection in one of your web forms.

When Wige recommends securing your site, a good place to start would be with your forms. They need a data parsing script to strip out illegal characters that might be used to run SQL scripting that messes with your database.

Here's an article that might be of use to you:
CodeProject: SQL Injection Attacks and Some Tips on How to Prevent Them. Free source code and programming help

Good luck.
Reply With Quote
  #4 (permalink)  
Old 06-12-2009, 06:54 AM
WebProWorld New Member
 
Join Date: Jan 2007
Posts: 2
GarrickGreen RepRank 0
Exclamation Re: Reported attack site message

We had a similar problem with IE giving a warning message when using an iframe the message stated that it was a "potential vulnerability / compromise" in the page code - scaring off potential users. Having double checked and triple checked the code; all was fine.

It came down to IE requiring the correct privacy policy permissions to be put in place for the site which sorted the matter. Using the iframe and taking information through it meant establishing the correct policy and this has to conform with the P3P policy standards (for IE to render without popping an error) and we initially, for speed of getting it in place, used the generation tool provided at ....p3pwiz... (cant post full URL due to being a newbe poster).

It's worth trying if you've checked your code, ruled out SQL injection, and haven't checked your P3P/come to an answer.

Mike.
GMP Group Ltd
Intuitive Internet Software & Systems
Reply With Quote
  #5 (permalink)  
Old 06-12-2009, 04:13 PM
rfuess's Avatar
WebProWorld New Member
 
Join Date: Nov 2004
Location: San Luis Obispo, CA
Posts: 13
rfuess RepRank 0
Default Re: Reported attack site message

I have had a similar problem. This was either an iframe right after the body tag opens, or a js tag right after the body tag opens.

CAUSE: A virus/trojan on my computer - that scraped ftp data. I didn't believe it at first - but when I noticed a trend - that it happened to several webites (different web hosts) that I posted using ftp - then I realized it was true. Even if the virus/trojan was removed recently the damage could already be done - they may already have your ftp info.

Some of them Google noticed and flagged as a reported attack website. Some Google didnt notice yet.

SOLUTION:

1) Run spyware software on your computer. Something like (free) MalwareBytes works well.
2) Fix websites - as described. Repost any files that were updated lately with a non-infected file.
3) Let Google know that the site is corrected - if Google shows this message. Google provides links to do this when you find such a site. You will probably need to "verify" the site with a meta-tag or a html page upload.
4) CHANGE the ftp password on each of these sites IMMEDIATELY - or it WILL happen again!

Last edited by rfuess; 06-12-2009 at 04:17 PM.
Reply With Quote
  #6 (permalink)  
Old 06-16-2009, 10:32 AM
WebProWorld Member
 
Join Date: Oct 2007
Location: India
Posts: 92
vinay11111 RepRank 0
Default Re: Reported attack site message

Quote:
Originally Posted by wige View Post
Where are you receiving the message?

The first step, of course, will be removing the infected code, and securing the server to close whatever vulnerability is allowing the attacker to compromise the site.
I am getting this message when I open the site in firefox as well as ini google SERPs

Please check Attorney Medical Malpractice – area of Legal & Professional Medical Malpractice
__________________
Regards,
Vinay SEO Times | Teddy Bear Factory
Reply With Quote
  #7 (permalink)  
Old 06-16-2009, 10:44 AM
WebProWorld Member
 
Join Date: Oct 2007
Location: India
Posts: 92
vinay11111 RepRank 0
Default Re: Reported attack site message

Quote:
Originally Posted by Dubbya View Post
Without visiting your site, I'm thinking that this may have have been implemented using SQL injection in one of your web forms.

When Wige recommends securing your site, a good place to start would be with your forms. They need a data parsing script to strip out illegal characters that might be used to run SQL scripting that messes with your database.

Here's an article that might be of use to you:
CodeProject: SQL Injection Attacks and Some Tips on How to Prevent Them. Free source code and programming help

Good luck.
You are right, Its some kind of code injection an Iframe code is added to the website somewhat near the <body> tag and no matter how many time I remove the code it get added in the website.

Normally the code get inserted in the index pages of the website only.
__________________
Regards,
Vinay SEO Times | Teddy Bear Factory
Reply With Quote
  #8 (permalink)  
Old 06-25-2009, 12:33 AM
danlefree's Avatar
WebProWorld Pro
 
Join Date: Jun 2005
Location: Seattle
Posts: 270
danlefree RepRank 4danlefree RepRank 4danlefree RepRank 4danlefree RepRank 4danlefree RepRank 4
Default Re: Reported attack site message

The Google Safe Browsing Diagnostic reports:

Quote:
The last time Google visited this site was on 2009-06-23, and the last time suspicious content was found on this site was on 2009-06-23.
You really should not post links to your site if it may mean that more people are exposed to the infection.

If you are hosted by LiquidWeb on any kind of managed plan, they should be able to offer assistance - otherwise, now would be a good time to restore from backups and/or complete the audits suggested by prior posters.
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing)
Reply With Quote
  #9 (permalink)  
Old 06-27-2009, 01:43 AM
WebProWorld Member
 
Join Date: Oct 2007
Location: India
Posts: 92
vinay11111 RepRank 0
Default Re: Reported attack site message

thanks all of you... reported attack message is removed no but I am suspicious it may appear again...
__________________
Regards,
Vinay SEO Times | Teddy Bear Factory
Reply With Quote
  #10 (permalink)  
Old 06-27-2009, 01:49 AM
NetProwler's Avatar
WebProWorld Member
 
Join Date: Jan 2007
Posts: 90
NetProwler RepRank 2
Default Re: Reported attack site message

If you are on a shared hosting, you will have to ask your host to address this issue. If you have already done a full security auditing of your site and still find that your pages are added with malicious codes, there is a good chance that one of the other sites in the same server may have been compromised.

If you have a full backup, delete the files then the directories and rebuild the entire structure from scratch. Change all the passwords to more robust ones. Set up a monitoring script in another server to check your index page at regular intervals. If there is any change, the script should alert you. That gives you some time before people or robots come calling. If they can still change your code, it is certain that your server is not secure enough.
Reply With Quote
  #11 (permalink)  
Old 10-26-2009, 05:24 PM
WebProWorld New Member
 
Join Date: Sep 2009
Posts: 14
urb100 RepRank 0
Default Re: Reported attack site message

i had exact same problem with sites on goDaddy shared hosting.
i kept cleaning up - going through all the steps described here and more ... and it kept on coming back. ...

after few cycles, it stopped ... and has not happened again ... never got to the bottom of the reason ...

i think it was security hole of the goDaddy's server.
i tested with a site which as no forms, nothing. Just 1 page with skeletal html and still it happened - so form is not the only door they hijack the site.
But not sure what exactly causes it.
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > IT Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
site update notification project site - does it get the message across CraigH Submit Your Site For Review 3 11-18-2008 11:26 PM
New Site, - Please attack with constructive critisizm Mamoon Rashid Submit Your Site For Review 5 05-25-2006 04:13 PM
I think someone is trying to attack my site? Inspector Search Engine Optimization Forum 2 05-16-2006 11:56 AM
DDos attack on my Norwegian site. kgun Internet Security Discussion Forum 16 07-23-2005 07:00 PM
Message boards How do I add one to my site loseriam Web Programming Discussion Forum 2 01-12-2005 07:57 AM


All times are GMT -4. The time now is 01:54 AM.



Search Engine Optimization by vBSEO 3.3.0