![]() |
|
|||||||
| Chit Chat Public Talk about any thing you want! This forum is public. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
|||||||||||
|
|||||||||||
|
Our sites are being hijacked
Some of the websites we host at Vortech have had some files changed misteriously. Mostly, index, default, login and admin named files, html and asp.
Some misterious snippet of code has been added to several pages of some websites and they call to an outside url where a trojan is detected. I spent the night clearing some of the pages and two guys are still working hard at it at the office to clean everything up. I even deleted the ftp application I had running on my machine fearing some kind of unauthorizes application is using it to infect the files. Now we're resetting all ftp passwords and not savind them in the ftp configuration anymore. I could tell by the date on the infected files that files were changed three times in different websites at different times as well, yesterday only. Funny thing is that all pcs on my network at the office were shut down yesterday. However my pc was running and connected all day. Nod32 gets updated everyday and If its some kind of virus, I thought it should have stopped it. I learned this morning that several other servers presented the same problems. Below is an image with the type of code that is being inserted on the files. I inserted the image because Im afraid someone might click on it and without an updated antivirus they might get infected. If anybody has had any previous experience with it and nailed down the source of the problem, please share it. Thanks Eder ![]() |
|
#2
|
|||||||||||
|
|||||||||||
|
Just decode the script here and see what it does
http://scriptasylum.com/tutorials/en...de-decode.html Probably someone dropped a bot into the website through an exploit of some sort, what software are you using on the site? |
|
#3
|
||||||||||||
|
||||||||||||
|
Also, check any forms that write. Make sure they don't write html/css/javascript.
Once you decode the message, google it or whatever was displayed for additional info.
__________________
|
|
#4
|
|||||||||||
|
|||||||||||
|
Let us know if you found out what it does and if you tracked down how it got there. Thanks.
![]() |
|
#5
|
|||||||||||
|
|||||||||||
|
Actually, I think I know what it is already - an Iframe injection used to boost hit counters on other websites. That file must have been chmod 777 ???
|
|
#6
|
|||||||||||
|
|||||||||||
|
I suspect windows account so yes would have write permissions by default.
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Help! Email Hijacked? | cleonard | Chit Chat Public | 5 | 01-27-2004 07:45 AM |
| email spoofed/hijacked? | jetzkr8 | Chit Chat Public | 8 | 09-07-2003 10:55 AM |
| All my sites are down | edvw | Chit Chat Public | 6 | 01-10-2003 12:32 PM |