Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 01:11:11 PM

Pages: [1]   Go Down
  Print  
Author Topic: Site possibly hacked ....  (Read 2135 times)
sbrashear
Newbie
*
Offline Offline

Posts: 1


« on: March 27, 2009, 09:57:44 AM »

My site may have been hacked. I recently found three folders on my website that I didn't put there. Each contains several PHP script files and two contain javascript files. I downloaded the folders to my computer and deleted them from my site.

 I also found the following line in the code of 7 of 8 pages in my root directory: "<?php include('pdfs/manual.pdf'); ?>". The manual.pdf file was not in the PDFs folder. When I discovered it, I thought it I may have mistakenly uploaded it as there were a couple of PDFs that I had mistakenly uploaded. Thinking it was a file that I mistakenly uploaded, I tried to open it and got an error, which makes me think it could be malware. I'm running some scanning software as I write this. I have changed the password to my hosting account and delete the files as well as re-uploaded my website files that had the offending code in it. Here are some screen shots in the event that this might help.






Any advice on what I need to do next is greatly appreciated. I'm not very experience in web design or web management. According to the virus scan I just did I my computer has a trojan:java/agent.b, which I have tried to remove by deleting the java temporary file via the control panel

Thanks
Logged
crashomon
Newbie
*
Offline Offline

Posts: 3


« Reply #1 on: March 30, 2009, 12:42:11 PM »

This has happened to me as well.
I'm on this: acrux Server.

 Grr..!!
Logged
SlvrSurfRidr
Trekkie
**
Offline Offline

Posts: 12



« Reply #2 on: April 20, 2009, 12:02:29 PM »

Same issues - I'm on Sava
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #3 on: April 20, 2009, 12:12:40 PM »

I would suggest the steps mentioned here:

http://wiki.lunarpages.com/Web_Site_Security_Breaches
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
ImageMaker
Newbie
*
Offline Offline

Posts: 1


« Reply #4 on: May 02, 2009, 06:52:24 PM »

same issues here as well + they uploaded files with "porn-type" names in an out of the way folder/location that I didn't notice until my rankings tanked!
I'm on the pallus server.
Logged
SlvrSurfRidr
Trekkie
**
Offline Offline

Posts: 12



« Reply #5 on: May 03, 2009, 11:14:05 AM »

same issues here as well + they uploaded files with "porn-type" names in an out of the way folder/location that I didn't notice until my rankings tanked!
I'm on the pallus server.
Good luck man.  Most hosting companies will help you clean up the carnage - no such luck with LP.  You're best best is to write a couple of Cron jobs to scan constantly for the changes and purge them.  Follow the link above to update passwords, permissions etc ... good luck
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #6 on: May 04, 2009, 04:39:32 AM »

This might also serve as a good reminder to some to backup early and often.  We provide several ways for you to backup your hosting account, as explained here:

http://wiki.lunarpages.com/Backups

Also changing your passwords (NEVER user a dictionary-based word, always use a mix of letters and numbers, all mixed up.  The more complicated, the better) and user names (if the situation calls for it) often can help with this too.  As for the comments of Most hosting companies will help you clean up the carnage, this is not the case.  Here at Lunarpages, we can do as much as we can to help, however - if it was a security related issue with a users PC (such as they were infected with a virus) there is only so much we can do as your web hosting provider.  However, the forums are always here to ask for advice and help in situations like this.
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
whats2
Newbie
*
Offline Offline

Posts: 2


« Reply #7 on: July 12, 2009, 03:28:41 PM »

My site has been hacked as well - Sedna -
first I discovered folders with hundreds of porno urls
then I discovered the javascript code - added just at the end of the head on html pages and at the bottom of some php pages
seemed to get almost every index.xx or home.xx page
after deleting it comes back within a day or two

Still battling this

also know that the JS code is disguised - there are letters added - which then are taken out as code is read making it look like something else

Any ideas how to fix???

signed - tearing my hair out!
Logged
SlvrSurfRidr
Trekkie
**
Offline Offline

Posts: 12



« Reply #8 on: July 12, 2009, 08:33:30 PM »

Unfortunatly LP isn't much help with this stuff.  I had to write custom cron jobs to scan ALL of my directories and systematically clean them.  I also updated all FTP and MySQL passwords, and started denying IP addresses after about 2 months the activity finally stopped
Logged
pharscape
Trekkie
**
Offline Offline

Posts: 12


« Reply #9 on: July 15, 2009, 04:15:54 AM »

Unfortunatly LP isn't much help with this stuff.  I had to write custom cron jobs to scan ALL of my directories and systematically clean them.  I also updated all FTP and MySQL passwords, and started denying IP addresses after about 2 months the activity finally stopped

After you have cleaned up your site then perhaps a script like mine will give you some peace of mind. I have been running it now for two weeks on a 4 hourly cron job without problems.
http://www.lunarforums.com/lunarpages_web_hosting_email_pc_security/site_file_audit_script_anyone_interested_and_is_there_an_alternative-t52871.0.html

Cheers,
Paul
Logged
stwired
Intergalactic Cowboy
*****
Offline Offline

Posts: 63


« Reply #10 on: August 20, 2009, 12:18:53 PM »

So if we have a a back up from a few months ago via control panel we can pay lunarpages to restore it and that will fix any hacked junk put on the server for sure? Even if they added files? Then all I need to do is fix inventory - might be easier than battling this for the first time.

Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #11 on: August 20, 2009, 12:21:54 PM »

Yes we could restore your backup, or check to see if we have one available that hasn't been compromised.  Check this link for more details on how to get that taken care of - http://wiki.lunarpages.com/Backups/Restore .
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: