the CF stuff has been resolved for a long time now.
It is a case by case issue, the vast majority of the time it is due to the adobe apps password stealing and FTP changes. They may not buy it, but it is the case most of the time. We can provide logs in many cases to show this fact.
(i say many cases, because sometimes people ask a month or two after the fact and it is then very hard to track it down as well)
We continue to be hacked by malware. After months of bringing this to Jodo Host support attention.
All responses said - we’ll give you the logs. And it’s your ftp client.
We were finallly asked to not do anything with the one site. And they locked out our ftp clients by changing the password at site. so we couldn’t access if we wanted to.
The result. Our client’s site is not accessible as it has malware on it again.
This has been ongoing for over four months now. We don’t want to see logs. There is no point in seeing logs. We would just like to know how we can have this appear all the time.
And I highly doubt this is a one-off as we have this site/config used on many other clients some of which are hosted at Jodo as well.
I look forward to a useful response. I know venting on a board isn’t the most professional but I have spent over 30 hours in communication and dealing with this and we have no resolve. Multiply 3o hours of chat/editing by techs and you can see the cost of this is getting out of hand. Might as well consider a paid hosting company at less the cost.
I just replied your ticket. Somebody have your CP access. You need to change CP and All FTP password immediately. I sent you logs of FTP too. You can check details on it.
You have sent us logs for today when we and jodohost tried to resolve this. And we uploaded a new file to overwrite the malware attack as we need to have this site functioning and without the Google Malware notice being served currently. You’ll see the IPS are from yoru staff and us. Try going back to the Sept 25 and a few days prior when we received notice from Google that they are preventing our site from being displayed.
I didn’t mean that you are using Adobe FTP software’s for FTP. Adobe software’s which install on your machine or workstations may infect your domain. You can see details on http://support.jodohost.com/showthread.php?t=16921
[JH #RSW-13255-424]
(Steve, I have sent more communication in this email/ticket communication)
We continue to be hacked when we are not online.
We would really appreciate an escalation and guideance on this. As we mentioned, we have not been online and this is the only site being malware attacked that we have. Other sites at JodoHost and other ISPs are not affected.
you don’t have to be online for it to happen th way this happens is with botnets having the password, I am heading to bed, will check it first thing in the morning.
Stephen,
I want to follow up on this. We have not heard from you and we were asked to wait until logs were reviewed but got no response, and, we are now being asked to do again, what your tech team asked us to do four weeks ago, which we did.
This seems to be not getting resolved. Can you please contact me directly?
i am afraid you do not understand the issue, we asked you to change the Control Panel password for which you refused to do.
no WE DID NOT hack your page, that would be insanely stupid.
you need to change the CP pass because Adobe apps in the past or even currently may have compromised it.
there are a massive amount of exploits using this it was called ‘gumblar’ and it was patched by adobe in almost their entire product line, but many people did not change passwords or never change passwords.
this is clearly being done by FTP, we have sent you logs of it, it is being done but dozens of different IPs, as is the standard when there is a compromised FTP password.
(btw i have changed the pass and set it so it cannot be changed as well)
Stephen,
I never thought you would hack our site and never implied this anywhere.
I am simply as king for responses in which both you and your tech team have said “Wait I’ll get back to you as I check the logs” no response, and your post above simply says you’ll look at it and get back to us. No response.
Your tech team said in mid September that they change the password, lock us out and see what happened. I reluctantly agreed, (see email threads).
And we were still hacked.
Now you are asking us to do the same - change password, which your staff was to do (did) and wait.
However we haven’t heard anything constructive since we were asked to do this (your team locked out our FTP password mid-September) - so effectively we are repeating this step.
Not sure what is going on -but no one can say why this is the only domain that is being affected although we use the same computers for accessing the other sites at JH and other isps without incident.
My request for you to respond is that I get basic CSR replies to my emails that are intended for Manish - and they simply repeat earlier comments - no resolve.
I can see that you are not interested in talking to me personally on this so I will continue to post on the message board. Perhaps it is best to include the text of other emails so people can read and understand what is going on and what stage is causing this frustration.
As you and your team might be equally frustrated, but try explaining what is happening to a client! 1) there site is not functional and continually gets the malware virus and google blacklist. 2) I have no response for them.
YOur team has changed the ftp password etc. and we have no access. HOWEVER
Our site is hacked again -as there is no javascript enabled on the homepage. So if you view the source code, before the closing body you will see the malware code and the malware link.
Obviously it isn’t you, but I am not sure it was ever clean to begin with today, as I did not see the uploaded files corrected before changing the pass today.
however it is not that I ‘am not interested’ in talking to you, but I work behind the scenes in most cases, what is said in the last few is of direct input from me.
I have just checked the logs on FTP and there is NO successful login since I changed the password (and no file timestamp changed, so anything there was pre-existing) this is also why we asked you to change the control panel password, as we wanted to ensure all your passwords were fresh, new, and ‘clean’
5 different IPs have tried unsuccessfully to login since I changed the pass. I am having Arijeet mail that pass to you now. I recommend you have adobe products updated, including acrobat, flash, shockwave, etc on EVERY PC that oyu give this pass, every home/wireless network as well. the pass is random and complex, not going to be brute forced.
I got one of my sites hacked using iframe at the end of html files.
I added ZZZZZ in certain places…
Coming from this site: ZZZZhttp://rbomZZZZce.com/lib/index.php
I’m assuming they guessed/keygenned the password/login.
I’ve maxed out my password to 12 characters, upper/lower case and numbers…unfortunately, HSphere will not accept special characters in the passwords… …z
I now have multiple sites infected with malware. What is the best way to get rid of it? Download and scan, but can with what that will clean the files?
mreplace, if you have all the files in a folder, set that path, do the malware code, replace with on other part just put a space, run it and it will fix all.
changing passes won’t do any good if it is not FTP, we can check FTP logs for you for the dates of the changes and if there is no logs of it, it did not happen by FTP but HTTP.