Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #16  
Old 07-13-2009, 11:37 PM
evdev's Avatar
evdev evdev is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Seattle
Send a message via MSN to evdev
Me too :-\ So, I'm wondering where everyone else is going to migrate? I like having the option of either windows of LAMP hosting, but I'm looking seriously at "random company inserted here"



Note: Don't put other companies names into our forum please

Last edited by Danl : 07-14-2009 at 08:31 AM.
Reply With Quote
  #17  
Old 07-14-2009, 08:36 AM
dvanburen's Avatar
dvanburen dvanburen is offline
Administrator
Admin
 
Quote:
Originally Posted by PinkyBrain
All of my domains are affected. Most of my domains have just a plain index.html file, no other scripts or db running.

This is the 3rd time that I'll need to go do a mass search & replace to remove the malware. I don't understand how it is happening. Is Vortech not running antivirus scan?

We do, it's not a virus. Every single hack has been via FTP with valid credentials.
__________________
David
Vortech, Inc.
Phone: 800.537.4959
http://vortechhosting.com
Reply With Quote
  #18  
Old 07-14-2009, 12:25 PM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
The residue I've found on my infected sites was all javascript based with variable code within the script.
__________________

Lead me not into temptation... I know the short cut... follow me.

Last edited by dpyers : 07-14-2009 at 03:23 PM.
Reply With Quote
  #19  
Old 07-14-2009, 04:47 PM
DVHost's Avatar
DVHost DVHost is offline
The big dog, bites hard!
Vortech Inc. Customer
 
Location: Louisville, KY
Send a message via ICQ to DVHost
Lately I've got one customer that keeps getting all their sites hit with this stupid iframe piece of crap code directed to ru:8080.

I'm about done with all of this.
Reply With Quote
  #20  
Old 08-08-2009, 11:27 PM
datmed datmed is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: chitowb
thanks Dan

If you follow his link Dan thinks your stupid.

Quote:
Originally Posted by Danl
I know your working on it, but please fix the problem.

Last edited by datmed : 08-08-2009 at 11:29 PM.
Reply With Quote
  #21  
Old 08-09-2009, 10:24 AM
Danl Danl is offline
Administrator
Admin
 
datmed, I'd love to help you more but I have no clue what you mean.
Reply With Quote
  #22  
Old 08-10-2009, 03:12 PM
info-me's Avatar
info-me info-me is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Better

Things are much better now, I'll say, because I had been hit pretty bad.

I'm still monitoring all my sites, but so far so good!
Reply With Quote
  #23  
Old 08-30-2009, 01:14 AM
JoshK's Avatar
JoshK JoshK is offline
Administrator
Admin
 
If you or your client is repeatedly getting hit We will be happy to pull the logs for you. Nearly every case of hacking recently has been as david stated before, by the hacker using VALID ftp credentials. We've gone to great lengths (that should not be discussed openly in a semi public forum) to detect hackers loging in compared to actual people, only to find with a month they were ping ponging so to speak off multiple controlled servers at multiple IP's to attempt the same log-ins. We can detect and block them often, but the root of all of it is insecure or stolen passwords.

Many have already discussed here the importance of updating and changing them. Reality is there was a LOT of nasty code going around that could steal saved passwords. Many viral protection programs did not see it until millions were infected. Infected machines often can no longer be trusted to scan their own files even when viral software is updated to look for it. In short the definitions need to reach you BEFORE the virus does, or often viral code is smart enough to work right around your efforts. A few get hit, then those visitors got hit and it snowballed world wide. Some companies swept it under the rug or worked around it, some deny it happened at all. We've been pretty open about it giving what information we have been able to find as we find it.

In short, to keep from being protected use secure strong passwords, change them periodically (I would never let one go longer than 90 days for anything critical) and work from known clean machines and chances are you'll skip this type of attack completely. VERY few people are getting hit anymore and I have seen only a few cases of a re-injection most of which either didn't change passwords, or did not change ALL passwords. Don't forget ftp sub accounts. These are often handed off to a less savy end user, and seem to get hit far more often than the main ftp.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 8 (0 members and 8 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Network Solutions - Where did the "Manage Host Servers" option go? tkraffty Chit Chat Public 3 07-01-2004 03:37 AM
Logging in to admin account using "client login" method... antic Chit Chat Public 4 05-25-2004 09:38 PM


All times are GMT -5. The time now is 06:25 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Vortech Inc. ©2009
Page generated in 1.60907 seconds with 21 queries
[Output: 70.86 Kb. compressed to 65.44 Kb. by saving 5.42 Kb. (7.65%)]