Technical Discussion
  >> Web Design / HTML / Web hosting Forum


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | 3 | [4] | 5 | 6 | (show all)   Print Thread
Standard User deleted
(deleted) Wed 04-Nov-09 17:08:55
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
Sounds like the server has been hit by a malware attack.

Have you looked at your code for Javascript that you've not put there? also check your file times to see when they were updated.

Matt
Standard User TrevorSP
(knowledge is power) Wed 04-Nov-09 17:17:12
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
Done all that Matt, our sites are definately clear now, unless I missed something, which I am sure we didn't because we got very very used to what we were looking for a getting rid of it! After you have done a dozen sites the other 30 odd are dead easy................... !

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.
Standard User deleted
(deleted) Wed 04-Nov-09 17:19:33
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
Google will automatically lift the page warning after a few days..

You can speed this up by requesting it via Google webmaster tools.

https://www.google.com/webmasters/tools/home?hl=en

Matt


Register (or login) on our website and you will not see this ad.

Standard User TrevorSP
(knowledge is power) Wed 04-Nov-09 17:23:16
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
With regard to the file times, if my memory serves me right our first file index.html was changed on 19th September 2009, it is this and the huge increase in the size of the file that first allerted us. Although it looked like we had done it using our username and passwords.

We immediately changed all our passwords for what Microsoft term as "BEST"

Although sites were still got at!

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.
Standard User TrevorSP
(knowledge is power) Wed 04-Nov-09 17:25:01
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
Done that too thanks Matt, although when the pages are updated again, then we go through the whole process.

One that is clean at the moment, basically because I removed everything bar the front page is our personal one www.sodburyhouse.com
This currently shows clear on Google, but give it a couple of days .........................

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.
Standard User deleted
(deleted) Wed 04-Nov-09 17:27:32
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
In reply to a post by TrevorSP:
Although sites were still got at!


If another site on the same server is exploitable - all your sites could be affected. Changing your password will be useless.

Ultimately, you might be better off moving hosts to one that runs slightly better per-user protection helping stop this kind of thing.

Of course, this is purely assumption.. but having been offering hosting for over 6 years - we've seen it all!

Matt
Standard User Taras
(eat-sleep-adslguide) Wed 04-Nov-09 18:33:39
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
In reply to a post by TrevorSP:
I would be obliged if someone would take a look at the two Google reports below to see what they make of them..............
The first shows our now clean website, the second is a report on their server and if anyone can shed any light on what "Client side malware" could do this I would dearly love to know!

----------------------------------------
Google Report One on our website that was infected



----------------------------------------

H E L P

Does this make sense to anyone at all !!!!


Have you at hand either .. a copy of the infected site or webpage or a link to a live working one. ?

_____________________________________________
<randomness>
streaming music - your music - spotify
Everything websites.... soon
My Blog .......... here (still in dev mode)
Me twittering go add
Standard User TrevorSP
(knowledge is power) Wed 04-Nov-09 19:52:43
Print Post

Re: Please help ! ! !


[re: Taras] [link to this post]
 
Should be able to pick one out of the dark and at random......................

Hang on a tad...............

Nothing to do with us, except that it shares our server, all our sites should be 100% clean now! No thanks to the we are well known for our award-winning service and 24x7 live technical support. After more than 7 years in the web hosting industry, we know that our customers are the most important part of our business. With Provider-one.net you can rest assured that you are getting the best overall web hosting value - supported by the best, most experienced people in the industry.

77.75.194.25
www.whynotjewellery.co.uk/

Here is a Goody in all it's glory, you only have to look at the source from the front page, if you could see deeper into the inside of the web site, you would see several folders all called random five letter groups of the alphabet like, abcde or jhfdy etc. In those folders there are usually hundreds of html, htm or php pages that have links to all sorts of disgusting stuff ! ! !


Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.

Edited by TrevorSP (Wed 04-Nov-09 20:09:19)

Standard User deleted
(deleted) Wed 04-Nov-09 21:15:44
Print Post

Re: Please help ! ! !


[re: TrevorSP] [link to this post]
 
Looking at that site, I can't see anywhere that they might be inserting code, so as has been said before, the main server must have been hacked/root access gained. I would suggest moving you sites away from there asap, then taking legal proceedings against your current hosts for breach of contract.
Standard User Taras
(eat-sleep-adslguide) Wed 04-Nov-09 21:51:53
Print Post

Re: Please help ! ! !


[re: deleted] [link to this post]
 
In reply to a post by metalhead41:
Looking at that site, I can't see anywhere that they might be inserting code, so as has been said before, the main server must have been hacked/root access gained. I would suggest moving you sites away from there asap, then taking legal proceedings against your current hosts for breach of contract.


The site is using zencart and with any of the shelf carts you end up with one or more folder 0777. therefor file injection can occour. That would be a client side site hack.

on the main index page

"<u style="display:none;"><a href="http://veteransadv..."

Cropped the url for security reasons but on one of the reoccurring site links I had a look at had a url pointing to

lang/deutsch/tfslc/

and

lang/deutsch/akhfm/

Again typically lang would be set to 0777. thus allowing spammers to add and choose what files to add. Some of the links in one of the pages go to an usa college/uni. The spider web continues.

The two issues i have at the moment is this.

Either the public_html folder was left at 0777 or the index.php was 0777.. So potentially if this was a single case - password compromised or a mishap by the webdesign company.

But based on what Trevor has said that his and other sites have had the same thing done it means the server is compromised either by root access or some malicious files in /tmp

Update:

The index.php has around 300 links to other sites that then link to other sites to keep up the spiderweb of keeping spam links open......

_____________________________________________
<randomness>
streaming music - your music - spotify
Everything websites.... soon
My Blog .......... here (still in dev mode)
Me twittering go add

Edited by Taras (Wed 04-Nov-09 22:11:56)

Pages in this thread: 1 | 2 | 3 | [4] | 5 | 6 | (show all)   Print Thread

Jump to