asp backdoor trojan

I’ve found a backdoor trojan that had been uploaded to the cp folder inside a customers web root. Just thought that other resellers might wish to have a look for it as well. The filename is editor.asp
I didnt want to put the full path to it on a public forum but will support know as well. I’ll let the support guys know the full path.

cdog,

We’ve seen it on several domains, AV scans are catching and removing it now.

It looks to be coming via upload scripts, and the cp folder is just a place people ‘don’t look’
not even coming in via asp sometimes, but php as well, and someones not even on that domain, but on other domains on the accounts.

botnets are killing joomla and wordpress right now, ANY old install of them is virtually guaranteed to have trojans, ddos scripts, and defacers on it as of now, 2 weeks back a botnet started hitting google looking for signs of joomla and wordpress and automated now it just auto hacking away at any bugs.

There’s a great article here on hardening wordpress http://codex.wordpress.org/Hardening_WordPress
For my customers joomla seems to be the one that gets hit the most, in this case there wasn’t any wordpress or joomla installs on the customers on the customers website.

Let me know the domain and I will check it, frontpage is getting worse about this as well, and a few cases we’ve seen hpshere set permissions wrong if it is enabled/disabled I thought it was techs when it first happened but later saw the frontpage provisioning process to do it.

2003 is out of support timeframe now as well, and we will see increasing amounts of attacks on it, I’d image over the next months we’ll be dropping in 10 or so 2008 R2 servers and start migrating anyone with even an inkling of interest, just for security sake. Already some items that do ddos exploiting unpatchable areas on 2003 (we are blocking by port lockdowns, but it isn’t 100% effective in some cases)

:frowning: it looks like it may be coming through one of the ancient hsphere preinstall scripts with perl. I just found it on another domain, and that is how it was there. That has been the cause of some near ‘ddos’ like effects on some servers temporarily in the past as well, due to well not, ddos, but guestbook spam, making a page display of 300MB of txt file, being hit multiple times taking gigs of RAM to process.

Pratik and I had already discussed deleting this ‘cp’ folder from all accounts, as there maybe 0.1% of people that use it, I think we’ll start working on that, and should someone need it we can put it back, minus the ancient scripts.

domain is quoted in ticket JH #GJW-84806-920