|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| IT Discussion Forum Having IT issues? Got IT questions? Who doesn't? If you can't get your Apache to work with your MySQL or your php is choking on your ODBC... Let's see if we can help you come up with some ideas. |
Share Thread: & Tags
|
||||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
Hi,
Various of my sites are now giving reported attack website message. I did little research and found that its due to some <iframe> injection in the code of my website. Please suggest if there is any solution to get rid of this message. Thanks... |
|
||||
|
Without visiting your site, I'm thinking that this may have have been implemented using SQL injection in one of your web forms.
When Wige recommends securing your site, a good place to start would be with your forms. They need a data parsing script to strip out illegal characters that might be used to run SQL scripting that messes with your database. Here's an article that might be of use to you: CodeProject: SQL Injection Attacks and Some Tips on How to Prevent Them. Free source code and programming help Good luck. |
|
|||
|
We had a similar problem with IE giving a warning message when using an iframe the message stated that it was a "potential vulnerability / compromise" in the page code - scaring off potential users. Having double checked and triple checked the code; all was fine.
It came down to IE requiring the correct privacy policy permissions to be put in place for the site which sorted the matter. Using the iframe and taking information through it meant establishing the correct policy and this has to conform with the P3P policy standards (for IE to render without popping an error) and we initially, for speed of getting it in place, used the generation tool provided at ....p3pwiz... (cant post full URL due to being a newbe poster). It's worth trying if you've checked your code, ruled out SQL injection, and haven't checked your P3P/come to an answer. Mike. GMP Group Ltd Intuitive Internet Software & Systems |
|
||||
|
I have had a similar problem. This was either an iframe right after the body tag opens, or a js tag right after the body tag opens.
CAUSE: A virus/trojan on my computer - that scraped ftp data. I didn't believe it at first - but when I noticed a trend - that it happened to several webites (different web hosts) that I posted using ftp - then I realized it was true. Even if the virus/trojan was removed recently the damage could already be done - they may already have your ftp info. Some of them Google noticed and flagged as a reported attack website. Some Google didnt notice yet. SOLUTION: 1) Run spyware software on your computer. Something like (free) MalwareBytes works well. 2) Fix websites - as described. Repost any files that were updated lately with a non-infected file. 3) Let Google know that the site is corrected - if Google shows this message. Google provides links to do this when you find such a site. You will probably need to "verify" the site with a meta-tag or a html page upload. 4) CHANGE the ftp password on each of these sites IMMEDIATELY - or it WILL happen again! Last edited by rfuess; 06-12-2009 at 04:17 PM. |
|
|||
|
Quote:
Please check Attorney Medical Malpractice – area of Legal & Professional Medical Malpractice |
|
|||
|
Quote:
Normally the code get inserted in the index pages of the website only. |
|
||||
|
The Google Safe Browsing Diagnostic reports:
Quote:
If you are hosted by LiquidWeb on any kind of managed plan, they should be able to offer assistance - otherwise, now would be a good time to restore from backups and/or complete the audits suggested by prior posters.
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing) |
|
|||
|
thanks all of you... reported attack message is removed no but I am suspicious it may appear again...
|
|
||||
|
If you are on a shared hosting, you will have to ask your host to address this issue. If you have already done a full security auditing of your site and still find that your pages are added with malicious codes, there is a good chance that one of the other sites in the same server may have been compromised.
If you have a full backup, delete the files then the directories and rebuild the entire structure from scratch. Change all the passwords to more robust ones. Set up a monitoring script in another server to check your index page at regular intervals. If there is any change, the script should alert you. That gives you some time before people or robots come calling. If they can still change your code, it is certain that your server is not secure enough. |
|
|||
|
i had exact same problem with sites on goDaddy shared hosting.
i kept cleaning up - going through all the steps described here and more ... and it kept on coming back. ... after few cycles, it stopped ... and has not happened again ... never got to the bottom of the reason ... i think it was security hole of the goDaddy's server. i tested with a site which as no forms, nothing. Just 1 page with skeletal html and still it happened - so form is not the only door they hijack the site. But not sure what exactly causes it. |
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| site update notification project site - does it get the message across | CraigH | Submit Your Site For Review | 3 | 11-18-2008 11:26 PM |
| New Site, - Please attack with constructive critisizm | Mamoon Rashid | Submit Your Site For Review | 5 | 05-25-2006 04:13 PM |
| I think someone is trying to attack my site? | Inspector | Search Engine Optimization Forum | 2 | 05-16-2006 11:56 AM |
| DDos attack on my Norwegian site. | kgun | Internet Security Discussion Forum | 16 | 07-23-2005 07:00 PM |
| Message boards How do I add one to my site | loseriam | Web Programming Discussion Forum | 2 | 01-12-2005 07:57 AM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |