Outline ·
[ Standard ] ·
Linear+
Exabytes server got compromise or?, webmaster or tech expert pls come in
|
TSxDragonZ
|
Jul 19 2012, 06:54 PM, updated 14y ago
|
|
This few days I saw my website requesting me to run Java or download a PDF file. Its a drive by download, when you visit a site you computer will get infected (If you did't update your computer software eg:Java/Adobe). **Let's cut short the story...** After some investigation I notice that the site is infected with "RedKit exploit kit / BlackHole Exploit Kit" So what I did is get all the domain that hosted under "sphinx" server and did some check and even others site that hosted under "sphinx" was infected. Also I asked my host to remove all my public_html files and I upload a simple index.php and the webpage is still infected. (and I checked the source code on the server is 100% untouched and its clean) but it is reported it contain another iframe. (I also try load the page on another computer, it contain hidden iframe that you need to use the tools like "Inspect Element" in Google Chrome to find that.) http://www.webpagetest.org/result/120719_YY_CEZ/1/details/More Information about this malware and list of others site:http://forum.lowyat.net/topic/2434138I assume more than 100+ sites on this IP is infected. So is the hackers upload the exploit to my files or do you guys have any idea for this problem? NOTE: I DID NOT SAY Exabytes got hacked or what. I just cant figure out why some others site that hosted under the same IP got infected as well, and my sites too!This post has been edited by xDragonZ: Jul 20 2012, 06:45 PM
|
|
|
|
|
|
fridel
|
Jul 19 2012, 06:55 PM
|
|
Promoting ur site?
|
|
|
|
|
|
TSxDragonZ
|
Jul 19 2012, 06:57 PM
|
|
QUOTE(fridel @ Jul 19 2012, 06:55 PM) Do you think I am trying to do that!? Just refer to http://forum.lowyat.net/topic/2434138 , I open a topic at here because I cant really figure out what is the problem and at /k more expert lurking at here.
|
|
|
|
|
|
roimekoi
|
Jul 19 2012, 07:17 PM
|
|
got extra process running?
|
|
|
|
|
|
gs20
|
Jul 19 2012, 07:23 PM
|
|
No I don't get it from what you posted.
One of my client site previously was infected with malware as well (as reported by Google Chrome when you try to access the site).
I found out a code was padded at the end of the index file as well as all .js file. I replaced those files & the malware keep coming back after awhile.
I then change the ftp password & update those files again. The malware no longer come back.
So I conclude it's a FTP password leak.
|
|
|
|
|
|
akmalhisyam
|
Jul 19 2012, 07:27 PM
|
New Member
|
probably jumping.. one of the website on that server got hacked, and then the attacker 'jump' to attack another website on that server..
indon hackers always do this =_="
|
|
|
|
|
|
SUSedwardstevens
|
Jul 19 2012, 07:31 PM
|
|
dns poisoning?
|
|
|
|
|
|
wodenus
|
Jul 19 2012, 07:37 PM
|
|
QUOTE(gs20 @ Jul 19 2012, 07:23 PM) No I don't get it from what you posted. One of my client site previously was infected with malware as well (as reported by Google Chrome when you try to access the site). I found out a code was padded at the end of the index file as well as all .js file. I replaced those files & the malware keep coming back after awhile. I then change the ftp password & update those files again. The malware no longer come back. So I conclude it's a FTP password leak. I found out how too.. there are some trojaned FTP clients out there. FTP passwords are sent in cleartext, if your PC is compromised it's easy to pick out the password, especially since FTP is not a protocol used for anything else. If you've ever sat in a wi-fi enabled cafe snooping on traffic, you can easily see how someone can get the FTP password that way This post has been edited by wodenus: Jul 19 2012, 07:37 PM
|
|
|
|
|
|
bunnyexpert
|
Jul 19 2012, 07:43 PM
|
Getting Started

|
check log files...
This post has been edited by bunnyexpert: Jul 19 2012, 07:44 PM
|
|
|
|
|
|
TSxDragonZ
|
Jul 19 2012, 07:44 PM
|
|
I also notice that some site like jefferson.com.my and thundermatch.com.my also have the malware in their site. The malware will show up randomly. http://jsunpack.jeek.org/?report=edffe0129...5a83da4680332b1http://www.webpagetest.org/result/120719_RX_D4H/1/details/
|
|
|
|
|
|
matiko95
|
Jul 19 2012, 07:47 PM
|
|
browser hijacker, i think it hijack ur ftp password since it broadcast in plain text..
and that exploit are like sniffing hole to open backdoor communication to spyware monitoring program... trace the virus trace the programmer..
|
|
|
|
|
|
wodenus
|
Jul 19 2012, 07:58 PM
|
|
QUOTE(matiko95 @ Jul 19 2012, 07:47 PM) browser hijacker, i think it hijack ur ftp password since it broadcast in plain text.. and that exploit are like sniffing hole to open backdoor communication to spyware monitoring program... trace the virus trace the programmer.. If you use a trojaned FTP client it will likely send the password directly to the hacker lol
|
|
|
|
|
|
gs20
|
Jul 19 2012, 08:02 PM
|
|
I don't think it's a trojaned FTP client but more like a trojan that read saved password from the popular FTP client.
|
|
|
|
|
|
TSxDragonZ
|
Jul 19 2012, 08:09 PM
|
|
QUOTE(gs20 @ Jul 19 2012, 08:02 PM) I don't think it's a trojaned FTP client but more like a trojan that read saved password from the popular FTP client. I'm using filezilla. I dont think so FTP account got hacked. Changed my password yesterday and did s full scan for virus on my computer too. http://thehackernews.com/2012/05/redkit-ex...eb-malware.htmlThis post has been edited by xDragonZ: Jul 19 2012, 08:29 PM
|
|
|
|
|
|
wodenus
|
Jul 19 2012, 08:34 PM
|
|
QUOTE(gs20 @ Jul 19 2012, 08:02 PM) I don't think it's a trojaned FTP client but more like a trojan that read saved password from the popular FTP client. That's possible too. The solution would be to never save your password
|
|
|
|
|
|
VinluV
|
Jul 19 2012, 08:37 PM
|
|
i can say they got compromised before. BIG TIME. so best clean your images and back up your stuff.
pm me to converse. I don't want to blow shit up in public
|
|
|
|
|
|
TSxDragonZ
|
Jul 20 2012, 05:55 PM
|
|
Update :Please DONT purchase from them. Very bad service. Reply tickets too slow and it takes hours for them to reply my ticket. I request account recreate on the same hosting they keep ignoring me and keep saying that the site is clean. But when I check and load my site is still infected even I did online check to verify again. I can prove that all the site hosted under the same server with me is infected.  anyone who wanted to have FTP access to my account to verify this, please PM me. I just put a simple index.php in my FTP and contain nothing else ready, it still contain hidden iframe when you load the site. This post has been edited by xDragonZ: Jul 20 2012, 05:57 PM
|
|
|
|
|
|
SUSedwardstevens
|
Jul 20 2012, 06:01 PM
|
|
i think dns poisoning la brader
crackers hijack the dns server and embed some line when people loading up the site
if you want to play safe, change to 3rd party dns server like cloudflare.com
thats one is free
|
|
|
|
|
|
TSxDragonZ
|
Jul 20 2012, 06:10 PM
|
|
QUOTE(edwardstevens @ Jul 20 2012, 06:01 PM) i think dns poisoning la brader crackers hijack the dns server and embed some line when people loading up the site if you want to play safe, change to 3rd party dns server like cloudflare.com thats one is free I am CloudFlare user, before that I have contacted CloudFlare about this issue. Even using CloudFlare the malware still exists that's why now I using my host DNS to explain tell them about this and they keep say that the site is clean. Here's the latest result scanned few mins ago: http://www.webpagetest.org/result/120720_J4_BH5/1/details/http://wepawet.iseclab.org/view.php?hash=3...2778010&type=js» Click to show Spoiler - click again to hide... « also the malware don't show up many times to a same user, and it show to user that mostly from Europe, But sometime when I load the site it will still contain the malware. I assume more than 100+ website is infected on their server. This post has been edited by xDragonZ: Jul 20 2012, 06:11 PM
|
|
|
|
|
|
SUSedwardstevens
|
Jul 20 2012, 06:13 PM
|
|
is that a windows or linux server?
because i've experience this before on windows server
i'm running IIS with PHP addon and some line meant for ASP script appear on my php script
|
|
|
|
|