Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 10-22-2007, 11:24 AM
Ederwainer Ederwainer is offline
Registered User
Junior Member
 
Our sites are being hijacked

Some of the websites we host at Vortech have had some files changed misteriously. Mostly, index, default, login and admin named files, html and asp.

Some misterious snippet of code has been added to several pages of some websites and they call to an outside url where a trojan is detected.

I spent the night clearing some of the pages and two guys are still working hard at it at the office to clean everything up. I even deleted the ftp application I had running on my machine fearing some kind of unauthorizes application is using it to infect the files. Now we're resetting all ftp passwords and not savind them in the ftp configuration anymore.

I could tell by the date on the infected files that files were changed three times in different websites at different times as well, yesterday only.

Funny thing is that all pcs on my network at the office were shut down yesterday. However my pc was running and connected all day.

Nod32 gets updated everyday and If its some kind of virus, I thought it should have stopped it.

I learned this morning that several other servers presented the same problems. Below is an image with the type of code that is being inserted on the files. I inserted the image because Im afraid someone might click on it and without an updated antivirus they might get infected.

If anybody has had any previous experience with it and nailed down the source of the problem, please share it.

Thanks

Eder

Reply With Quote
  #2  
Old 10-22-2007, 07:00 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Just decode the script here and see what it does

http://scriptasylum.com/tutorials/en...de-decode.html

Probably someone dropped a bot into the website through an exploit of some sort, what software are you using on the site?
Reply With Quote
  #3  
Old 10-25-2007, 10:12 AM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Also, check any forms that write. Make sure they don't write html/css/javascript.

Once you decode the message, google it or whatever was displayed for additional info.
__________________
Reply With Quote
  #4  
Old 10-25-2007, 05:09 PM
TheDesigners TheDesigners is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Let us know if you found out what it does and if you tracked down how it got there. Thanks.
Reply With Quote
  #5  
Old 10-25-2007, 05:21 PM
TheDesigners TheDesigners is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Actually, I think I know what it is already - an Iframe injection used to boost hit counters on other websites. That file must have been chmod 777 ???
Reply With Quote
  #6  
Old 10-25-2007, 10:38 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
I suspect windows account so yes would have write permissions by default.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help! Email Hijacked? cleonard Chit Chat Public 5 01-27-2004 06:45 AM
email spoofed/hijacked? jetzkr8 Chit Chat Public 8 09-07-2003 09:55 AM
All my sites are down edvw Chit Chat Public 6 01-10-2003 11:32 AM


All times are GMT -5. The time now is 02:43 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.47548 seconds with 17 queries
[Output: 59.60 Kb. compressed to 55.43 Kb. by saving 4.17 Kb. (6.99%)]