Nov 22, 2009
Pages: 1, 2, 3

All My Sites Here Got Virus! - My Hosting got hacked?

free web hosting

Read Latest Entries..: (Post #26) by The Simpleton on Jun 11 2009, 10:49 AM.
Wow this sure is scary to beginners! This just goes to show how a simple tool like a keylogger/trojan can cause so much devastation. I hope your problems end really soon and your site stays safe as before.If you find out the problem and the solution please tell it here as it might be useful to someone else who might be having the same problem......
read more.
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Open Discussion > MODERATED AREA > Computers > Computer Security Issues & Exploits

All My Sites Here Got Virus! - My Hosting got hacked?

frozen.fish
Hello

Would like to know what happend cause all my index files in the server here got virus? What had just happend?

I am removing all files right now good thing I just made a backup yesterday. I really dont like this. i havent launched my sites yet and now it's been attacked..

Can anyone here explained what had just happend? sad.gif The change was made last night around 10pm GMT+8 when i was not home, my passwords are really really hard to memorize even i dont know them. so how can someone break in.. sad.gif

help please.. this is really alarming.

Comment/Reply (w/o sign-up)

nol
Well if Trap17/Xisto haven't changed anything since I was last here, I've never seen them been attacked, and why somebody would go just into your account and give you a virus is beyond me, I'm sure your computer has a virus/keylogger and that is how it happened, or somehow somebody guessed your password right, so I wouldn't find it hard to believe that this is on your end...

Comment/Reply (w/o sign-up)

frozen.fish
so if i have a virus on my computer and i entered my site thru ftp it can get infected?
so how to get rid of that thing there? like a fresh install or something is that possible?

keylogger? dont think so i use password manager. are they any safe? and password generators..
but i am infected too right now..windows one care and kaspersky spotted a trojan.

Comment/Reply (w/o sign-up)

nol
first you want to fresh start your computer after you do a virus check with avg, norton, or whatever you have, then you want to change all your passwords, maybe freshstart your website or at least install a backup of what you had. That is what I would do anyways.

Comment/Reply (w/o sign-up)

frozen.fish
yes just cleaned things up my proquota.exe got infected and the conflicker came back just this morning but site got infected last night when nobody was online here, just patched up my system too.. ill do fresh install next week maybe..

but how do i do a fresh start on my hosting here?
by the way thanks a lot for your help nol!

Can keyloggers catch passwords from clipboard? im more worried about personal informations right now, if that thing stole datas.. sad.gif
or was if SQL injection attacks?

I really want to know what happend and take steps securing my site.. any inputs are highly appreciated..

Comment/Reply (w/o sign-up)

takerraj
QUOTE (frozen.fish @ Jun 1 2009, 08:49 AM) *
yes just cleaned things up my proquota.exe got infected and the conflicker came back just this morning but site got infected last night when nobody was online here, just patched up my system too.. ill do fresh install next week maybe..

but how do i do a fresh start on my hosting here?
by the way thanks a lot for your help nol!

Can keyloggers catch passwords from clipboard? im more worried about personal informations right now, if that thing stole datas.. sad.gif
or was if SQL injection attacks?

I really want to know what happend and take steps securing my site.. any inputs are highly appreciated..


Just for clarification, can I know how you can say that your site is affected by virus?

 

 

 


Comment/Reply (w/o sign-up)

frozen.fish
html script viruses..
antivirus pops up a prompt
there were unknown codes on the source
file was modified last night all the indexes in the host.
but there are no prompts on the index.php but i can see the virus code was inserted there as well.

Comment/Reply (w/o sign-up)

inverse_bloom
Although i haven't experienced your dilemma and the cause remains vague to me, the first thing i would do is download Kaspersky trial as it is very thorough. A prior warning before installing - if you have ever had AVG installed i believe you will have to delete registry values left over from an AVG uninstall. Kaspersky will continue to refuse installation until this is properly completed.

I would also install spybot if you haven't already and another malware program such as malwarebytes. From there scan everything (including your backup). Do a fresh copy on the server. If problems persist then it would perhaps be wise to contact trap17/Xisto if you haven't already. Sorry that's all i can offer.

Comment/Reply (w/o sign-up)

frozen.fish
im emailing them right now just finished cleaning up the mess..

Comment/Reply (w/o sign-up)

webishqiptar
me once had some kind of problem with viruses, and I saw some really weird pages(porn and spam) getting indexed with my other site pages, and I found those and removed manually through ftp. I am not sure, what happened, but maybe you should try to get a good Antivirus on your computer such as kaspersky and also a good spyware, and never go to lots of sites who contain crack things or similar behavior software.

And since I upgraded to Vista my computer has always less problems regarding security, viruses, spyware.

Comment/Reply (w/o sign-up)

Latest Entries

The Simpleton
Wow this sure is scary to beginners! This just goes to show how a simple tool like a keylogger/trojan can cause so much devastation. I hope your problems end really soon and your site stays safe as before.

If you find out the problem and the solution please tell it here as it might be useful to someone else who might be having the same problem...

Comment/Reply (w/o sign-up)

frozen.fish
Thank you for clearing this up.. atleast now i know what is happening.. ive just rescanned with different scanner since reformatting is not an option for now.. sad.gif and changed ftp passwords as well..

now question is how do i use sFTP? ive accidentally blocked myself now with numerous failed attempts and support is taking a while.. sad.gif
and i hope we could see some guide on how to CHMOD files and folders properly..

Lastly you said it was getting FTP credentials so ive checked my other hosting and only two hosting accounts got hit.. the free ones on other servers are pretty fine, very odd..

I really really hope that was the last..

Comment/Reply (w/o sign-up)

jlhaslip
Got your PM, Downlaoded the source file and found the javascript entry in the file.
It was a series of digits, comma-separated, inside an eval function which translated into an iframe injection onto your page. The Iframe was only 1 px wide by 3 px high, so impossible to find with the eye.
Anyway, the iframe contained a link to a site which will remain un-named. The purpose of this script is still unknown, too, but rest assured that it was a script-kiddie who did this. The Security sites have this code available on them and anyone with any degree of Googleese would be able to find it.
How it got onto your site is anybody's guess, but the very next thing you need to do, before taking another breathe, is to delete any unused FTP accounts, change the passwords to the remaining FTP accounts, change your password of your Hosting Account, and then delete all occurrences of the script snippets in your files. You need to check all of them on your account. Each and every one. There might be a script out there to do that for you, but I could not find it.

And quit hanging around script-kiddies... laugh.gif

reference this link: http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/

Postings around #35 are the ones you need to review. Clearly, it is an FTP issue on your local machine according to the 'experts' on there.

Comment/Reply (w/o sign-up)

Saint_Michael
Instead of having a ton of quoted posts I will just number them based on the order of the post count.

Post #1

First your index files cannot get a virus, impossible, but your website could have been hacked to have a virus or maleware get installed. Of course, it would been nice to have screen shots of all this and of course a link to website to get a better idea whats going on.

As for breaking in, SQL injection, insecured scripts either from bad programming or improper CHMODing of them. XSS attacks could be another possibility or the fact your passwords were easy to guess.

Post #2

Xisto wouldn't do anything of the sorts, and so odds are your site got hack and was used as a portal for someone to upload malware, trojans and virus files. Then when a person visits that site or clicks on a link in that site, the attack will commence. As for the origin odds are your site got hacked somehow from one of the various methods and I doubt a keylogger would have been necessary if the website used a common enough script or coding that can be easily cracked.

Post #3
No, you cannot transmit a virus from your computer to your hosting account as the coding to infect PC's and hosting accounts is quite different in terms of setting it up. Even if you are infected with a virus/trojan/spyware youor security software should have picked it up if it is current or you actually use such security soft.

Besides, reinstalling your computer because of an virus would be a last resort if your security software can get rid of it, and even then it would have to be a brand new virus to get that far.

Password managers wouldn't matter with a keylogger as a keylogger is used to record your key strokes and so it wouldn't even matter that you have that password manager encrypted with a password.

Since you dected a trojan on your computer I can reassure you that it wouldn't transmit to your site, it would be kind of pointless to do so.

Post #4

That is the first think you want to do is clean up your computer of any viruses, but the best removal method is to go into safe mode and have your System Restore points turned off before cleaning. As some like to hide in there and even though you cleaned it out it could show up again.

As for the website itself, usually a backup is a good idea, however, depending on when you made that back your not really solving the problem. However, since I don't know what your website looks like it is hard to say what would be best to properly secure your website.

Post 5

If you did have the conficker virus, it would be next to impossible to clean your computer because of what conficker does. You wouldn't be able to patch your system because Windows Update would be disabled and your security software wouldn't work. So I highly doubt you have the conficker worm on your computer and even then it wouldn't get uploaded to your website because that is not how the worm works.

As for your hosting, that would be tricky to say, of course the first thing I would suggest is not to use password generators. They maybe useful, however, it is best to make your own password by scratch for better security. Also, if your using databases, you want to use a very strong and seperate password as well and that will add another level of security. The reason for that is your don't want to use the same password over and over again because if they find out that is the only password you use, your hosting is screwed.

post #7

Well odds are it was a XSS, SQL injection or a script kiddie who knows those specific scripts well. Again a computer virus will not affecting your hosting account it would be the other way around.

Post #8

Heck you should had reported the problem to xisto support right away and hopefully you did that during this 21 post bonaza. As they need to know this to help better protect their servers and of course block that IP and even report it as well.

Post #11
Odds are they used that site to cover their tracks as they hack your site and booby trap with malware/spyware/trojans and stuff like that.

Post #12
You need to change your passwords ASAP and also remove the scripts that your using. My suggestion would be to start your website over, and not use whatever scripts your using or find better scripts that are better secured. Of course, the best thing to do is to keep on changing your passwords until the attacks stop and by changing passwords I mean not using generators as odds are they might know what generator your using.

Post #14

It all depends on the scripts that your using, and if your using databases along with those scripts as well, and the only sure way to prevent SQL injections is strong passwords and making your scripts unreadable to outside sources, and Chmodding everything properly.

Post #16

Of course they wouldn't be known, but odds are the designers of fluxbb have created a lot of places to get into the software and mess everything up. SQL Injections are possible just because of the lack of security the designers put into there software or that there are too many security holes in the coding it self. Now that I know what is causing all the problems, my suggestion would be to drop that forum and go with something more secured like PHPBB or SMF or AEF and a lot of your problems will go away.

Post #20

#1 correct
#2 unlikely but even then running exe through a hosting account is quite tricky
#3 impossible, they would have to hack the fluxbb website, then upload their own version of the infected forum for that to be possible. Most computer viruses do not work like that and would be kind of stupid to so if they wanted to infect the computer with their goodies.
#4 a possibility

Post #21
#3 the point of running a infected website is not for the owner to dectect that anything is wrong and so while the site could have been running normally for you, odds are your computer was compromise with a silent download through the website ie that trojan you have. As for google it would take more then a day then to have them block your website, however, depending on what browser your using it could difficult to tell if your site was compromise. As not all browsers use the same lists to block potential bad sites.

#4
the designers are ignorant because regardless if its current, most of the time they won't spot their own programmers errors until someone tells them. So odds they have not found either the SQL injection leak or not making sure to properly CHMOD the forum software.

As for the image your posted instead of typing it out for you, here is a link to the reference all the key strokes and stuff. However, since I am not a big security expert I can't really tell you what is doing, for all I know it pick those to to be logged and stuff.

Post #22-23

Yeah it would have been good to have a link to this site and that way we could have had a better time trying to figure out what is/was wrong with your website and offer a better solution.

Comment/Reply (w/o sign-up)

frozen.fish
Ive taken down the virus.. but i can send it to you..

Comment/Reply (w/o sign-up)



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Pages: 1, 2, 3
Similar Topics

Keywords :

  1. Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read
    (10)
  2. Iphone Update Disable Hacked Phones
    (5)
    After reading the article it is obvious what the update was for besides adding in new services and
    updates, however, it took all of what, two weeks to hack the IPhone? So I doubt it will that long
    to figure out what apple change to disable the hack phones. I found this particular quote amusing,
    "...company officials insisted they were "not proactively" trying to make hacked iPhones useless."
    Heck I would if I knew I would be losing millions of dollars a month on a phone that that was hacked
    and used by another phone provider, but like I said earlier it won't take ....
  3. Fight Spam Email
    Link to this script on your Hosting Account (0)
    Have a look and tell me what you think about this little script I have written. The plan is to
    have this page on your website, at least in your web account, and when/if the Spam Bots find your
    account and start scanning the site, they will see this page full of randomly generated email
    addresses which they store into their database and when they go to use the addresses, they are all
    bounced back to them instead of being delivered to real email accounts. The page links back to
    itself, so each time you reload the page they receive another batch of false email addresse....
  4. Image Hosting Can Hurt You
    (17)
    Hello; If you are running a website that offers free image hosting, than this is for you ! If the
    image hosting script you are using is a bit poor, hackers can use this to upload their "php shell"
    and be able to do modifications to your site !!! You might say this wouldn't happen to you !
    ... but it happened with me ... My website is mostly a familly web-site, so all my familly checks
    it, and when the hackers acted ... i got humiliated /sad.gif" style="vertical-align:middle"
    emoid=":(" border="0" alt="sad.gif" /> ... they put "inapropriate pages" on my site ... ....
  5. Cpanel Exploit
    security hole in cPanel to hack the servers of a hosting company (8)
    A pair days ago I read this new on Slashdot: cPanel Exploit Used to Circulate IE Exploit
    QUOTE "In a dangerous combination of unpatched exploits, hackers have used a previously
    undiscovered security hole in cPanel to hack the servers of a hosting company and use hundreds of
    hijacked sites to infect Internet Explorer users with malware using the unpatched VML exploit.
    cPanel, whose hosting automation software is used by many large hosting companies, has issued a fix.
    It's a local exploit, meaning the attacker must control a cPanel account on the target hosti....
  6. List Of Security Sites
    (7)
    List of security sites, I'll try to update the list as soon as I can . with compilations of
    recent security threats, Global Incident Analysis Center (GIAC), GIAC training, and Reading Room
    http://www.sans.org/ http://www.infragard.net/ http://www.cert.org/security-improvement/
    CERT Security Improvement Modules,including general information on firewalls and intrusion
    detectors. excellent set of papers on firewalls, viruses, e-commerce, etc. http://www.icsa.net/
    http://www.gocsi.com/ (Source of the annual "CSI/FBI Computer Crime and Security Su....
  7. Hosting Controller V.6.1 Vulnerability
    Hosting Controller v.6.1 Vulnerability (1)
    Hosting Controller is a complete array of Web hosting automation tools for the Windows Server family
    platform. This vulnerability is on the admin/hosting/addsubsite.asp Attacker can create user and
    host on the target system. Exploit --------- A demonstration exploit URL is provided: h**p://
    /admin/hosting/addsubsite.asp?loginname=Mouse&password=123456 h**p://
    :8077/hosting/addsubsite.asp?loginname=Mouse&password=123456 --> Domain: Username:
    Mailserver: Password: ....
  8. Google.hacked?
    Could you pass the virus? (26)
    Hey all, I hear that google got infected from a virus. Anyone that was trying to look up information
    on google, it would just take you back to the homepage. One of the first things you have to notice,
    to make sure you dont get infected. I got infected heavily. Appearently when it put me back on the
    google homepage, it downloaded a virus onto my computer and now it's in the shop.....

    1. Looking for All, My, Sites, Here, Got, Virus!

Searching Video's for All, My, Sites, Here, Got, Virus!
See Also,
advertisement


All My Sites Here Got Virus! - My Hosting got hacked?

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com