Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Display Modes
  #1  
Old 06-15-2009, 12:27 PM
pixel41 pixel41 is offline
Vortech Inc. Customer
 
help - getting "Warning - visiting this web site may harm your computer!"

Hi, I'm getting a "Warning - visiting this web site may harm your computer!" when I Google quite a few of my hosted sites. I am also now blocked from them at work (we use BlueCoat and it's telling me it's categorized as "Malicious)

DB-PrecisionProducts.com
CS-DS.org
PaperclipCampaign.com

Is anyone else seeing this?

Google's explanation says :
What happened when Google visited this site?

Of the 2 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-06-12, and the last time suspicious content was found on this site was on 2009-06-12.
Malicious software is hosted on 2 domain(s), including bro.tw/, rnw.kz/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including rnw.kz/.

This site was hosted on 1 network(s) including AS16557 (COLOSOLUTIONS).



Any ideas or help would be appreciated.
Reply With Quote
  #2  
Old 06-15-2009, 08:12 PM
jmcgee jmcgee is offline
Vortech Inc. Customer
 
Is this a database driven website? (i.e. is data stored only in static html pages or do you pull data from mysql or mssql using php or asp?)

This happened to me a few months ago when my MSSQL database got hit with a script attack. Basically via unprotected forms, a user or bot was able to inject < script > tags directly into the database tables which in turn showed up in the html back to the browser and generated the warning from google.

Jason
Reply With Quote
  #3  
Old 06-16-2009, 05:54 AM
levseltzer levseltzer is offline
WEBuilder
 
I am getting the same thing on several of my sites, but it is just the "gumblar" (or derivative) exploit/virus/malware, which is described in another thread.

Question: After cleaning up some of my client sites, visitors STILL get this warning. I've gone to the home page and confirmed that the virus (e.g. the script tags) are not there, but they still get the warning when opening the homepage! I had one client clean out their FireFox cache, but they still had the same warning. Is there a "cache" or "memory" somewhere else that needs to be emptied out to tell everyone that the site is now clean?
Reply With Quote
  #4  
Old 06-16-2009, 06:48 AM
jmcgee jmcgee is offline
Vortech Inc. Customer
 
If you are talking about the Google warning in the search results, there is no cache, but you can request them re-check the sites that have the warning. I had to do this once I cleaned mine. If you click on the warning, and follow that link, there should be another link that google provides the "owner" of the website with more information and the steps you can take to request them recheck the site. Good Luck.
Reply With Quote
  #5  
Old 06-16-2009, 09:37 AM
info-me's Avatar
info-me info-me is offline
Vortech Inc. Customer
 
Yes, you can request a re-visit at Google Webmaster Tools.
https://www.google.com/webmasters/tools/

I had to do this for two sites, after cleaning them thoroughly, and they were de-listed in about 12 hours.
Reply With Quote
  #6  
Old 06-16-2009, 09:53 AM
garyrm garyrm is offline
Vortech Inc. Customer
 
Location: Martinsville NJ USA
Send a message via Yahoo to garyrm
I received 3 emails from google. One yesterday and 2 today for 3 of my sites. My virus scanner reported the HTML: IFrame-EJ[Trj] Trojan. I simply ftp'd fresh set of pages.

How does this happen and can it be prevented?
Reply With Quote
  #7  
Old 06-16-2009, 09:59 AM
Danl Danl is offline
BANNED
 
http://25yearsofprogramming.com/blog/20071223.htm

That link should help.
Reply With Quote
  #8  
Old 08-08-2009, 11:27 PM
datmed datmed is offline
Vortech Inc. Customer
 
Location: chitowb
thanks Dan

If you follow his link Dan thinks your stupid.

Quote:
Originally Posted by Danl
I know your working on it, but please fix the problem.

Last edited by datmed; 08-08-2009 at 11:29 PM..
Reply With Quote
  #9  
Old 06-16-2009, 10:24 PM
levseltzer levseltzer is offline
WEBuilder
 
My client says that they are opening the site directly in firefox - not searching for it via google. Firefox then gives a Malware warning. I don't get this warning in my version of firefox (or in MSIE or in safari) and there is no malware on the page (any longer). Is it possible that firefox is doing a lookup to some other location to determine if the page is safe or not?
Reply With Quote
  #10  
Old 06-16-2009, 11:01 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype™ to Silverbug
what antivirus software are they running? there might be a website scanner component installed which is causing this page to be displayed.
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #11  
Old 06-16-2009, 11:48 PM
lux_nova lux_nova is offline
Vortech Inc. Customer
 
levseltzer:

Yes, they are probably on FF3 with security enabled.

Type this into the URL:
http://www.google.com/safebrowsing/d...YOURDOMAIN.COM
Code:
http://www.google.com/safebrowsing/diagnostic?site=YOURDOMAIN.COM
Replace YOURDOMAIN.COM as appropriate. If google shows that the site is flagged, then as far as I know, the latest version of Safari and FF (default settings with security options enabled) should also show a big red annoying pop-up.
Reply With Quote
  #12  
Old 06-17-2009, 01:32 AM
levseltzer levseltzer is offline
WEBuilder
 
Great. At least I now know that there is a connection between FF3 and Google, which would easily explain the error. I have requested the evaluation in google to get the malware flag removed.
Reply With Quote
  #13  
Old 06-18-2009, 10:18 AM
fessman fessman is offline
Vortech Inc. Customer
 
4 of my clients' hosted sites have also gotten hacked in the past 3 days. I've looked over the code and gone through the steps on the previous link (25yearsofprogramming.com), but I don't see how they could be getting in. Is it possible one or more of the servers have been hacked or have a rootkit?
Reply With Quote
  #14  
Old 06-18-2009, 07:31 PM
PinkyBrain PinkyBrain is offline
Vortech Inc. Customer
 
All of my domains are affected. Most of my domains have just a plain index.html file, no other scripts or db running.

This is the 3rd time that I'll need to go do a mass search & replace to remove the malware. I don't understand how it is happening. Is Vortech not running antivirus scan?
Reply With Quote
  #15  
Old 07-14-2009, 08:36 AM
dvanburen's Avatar
dvanburen dvanburen is offline
Administrator
 
Quote:
Originally Posted by PinkyBrain
All of my domains are affected. Most of my domains have just a plain index.html file, no other scripts or db running.

This is the 3rd time that I'll need to go do a mass search & replace to remove the malware. I don't understand how it is happening. Is Vortech not running antivirus scan?
We do, it's not a virus. Every single hack has been via FTP with valid credentials.
__________________
David
Vortech, Inc.
Phone: 800.537.4959
http://vortechhosting.com
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Logging in to admin account using "client login" method... antic Chit Chat Public 4 05-25-2004 09:38 PM


All times are GMT -5. The time now is 04:17 PM.


Vortech Inc. ©2009
Page generated in 1.94047 seconds with 13 queries
[Output: 96.96 Kb. compressed to 88.34 Kb. by saving 8.61 Kb. (8.88%)]