Our site was hacked somehow and blacklisted by Google. I have submitted the site for review again after removing the malicious content, but I want to make sure that I do everything I can to make our site secure once more.
I have changed the password and deleted any pages that contain login forms and also removed the scripts folders.
We do have several temporary MySQL databases that run some of the sites currently under development. Is there something I can search within these databases to make sure there isn’t something hiding in there that can possible re-infect our site?
remove or fix. If you look on google for sql injection + php (or asp or asp.net etc) you will find a lot of tips and tricks that help prevent it before it can happen.
I’m trying to clean up one of my workstations after a pretty nasty virus attack. X( This particular strain of ugly has as one of its features an attack on any local php, html and asp files it finds; it’ll insert an iframe payload on the local file, in the hope that the file will eventually be uploaded to a public server – once live, it’ll continue the fun game of infecting others.
So you may want to check if the problem is with an infection on one or more of the computers that you use for web editing. YMMV.
We have seen this variety as well, it is bad as it comes via legit FTP from the users IP even(we’ve shown some logs to get them to believe it, then run full current AV scan and found it)
one site can affect all under the same user due to group permissions, since other users on the server dont run under the same permissions group as yours they can’t get to other users.
This was explained in the other thread, i am merging the thread as well.
infected networks scan the internet every second of the day looking for vulnerable pages, upon finding them they do multiple POST requests, they also look in google for indexed pages containing keywords of known vulnerable app, upon finding them they hit hard with injections, remote includes, file uploads to unprotected uploaders, etc.
There are many varieties of these attacks but they all stem from an insecure piece of code in an account that then can deface all pages on the account.
They scan in ranges of IPs, I have seen such infected machines as a few VPSes have gotten to be a part of their network for a short time before having to be shutdown temporarily until cleaned up(these come mostly from bad passwords).
Thanks for the info, however I would appreciate an update to my tickets, with possible info on how the infection occurred - ie, starting from which domain etc.
GSU-39455-286 - Opened March 12th - No update since 14:00 GMT on March 12th
BCI-63310-902 - Opened March 13th - No update since opening it at 19:30 GMT
Yep we are working on that for you looking in logs etc. it is time consuming and I am heading this up, just because no reply doesn’t mean no action. i have the other staff generating logs all the time :rolleyes: