We have now had a number of sites hacked with injected code. They range from HTML sites, to ColdFusion sites to classic ASP sites. NO ONE has FTP access to these sites.
The code injection is a series of hidden links and sometimes google analytics rerouting.
This hacks are invisible for the most part and do not necessarily affect the site so you may not even know it’s there unless you view source.
It seems that this might be a system security issue. Has anyone else been experiencing such hacks?
We’ve identified yet another site with nearly the same “canadagoose” hack where links are injected. In one site the file in question was a Cold Fusion file inside a subfolder inaccessible from the front end. It would have to have been via FTP and the info for all of these sites has not be released to Chinese and Russian hackers. One of these sites has Chinese HTML comments within the injected code.
Are there specific types of file to look out for? Last year I had a ton of sites get hacked with a numeric php/htaccess type of deal. That was a pain also.
@JoeS. - yes; I’ve now had 6 of my 11 sites hacked in the last few months, and I know 3 other people that I do business with that host with Jodo who have also had some sites hacked … I actually recommended Jodo to each a few years back. You need to view source of your site pages, then do a find for “http:” and look at all links in the page … anything unfamiliar should be verified. Often a set of malicious links will be inside of a
tag and sometimes inside of a tag, and a style will be set for the
similar to
to hide it. Sometimes, google analytics code will be modified, and sometimes there is just one link to jumpcb.com (a quick find for “jump” will reveal it as I’ve seen this one placed throughout a page in several locations) … this one is normally a link to a 1x1 transparent gif file, perhaps to have the backlink embedded in your site. I now have a couple client sites labelled as “this site may be compromised” in the Google search results … that just can’t happen and my clients feel ok about hosting with me.
What bothers me even further is that JodoHost behaves in such a way that assumes the fault is coming from their clients’ computers or networks when they have absolutely no evidence to support it. A chat agent claimed that JodoHost servers are “secure” when in fact hackers around the world have proven in recent months that NO SERVERS are actually 100% secure, so for them to make these assertions is ridiculous. I find it discomforting that EVERY business partner of mine that hosts (resellers) with JodoHost has had multiple hacked websites, and their standard response is to point out that hackers may have grabbed my FTP info or a virus on my system/network could be the problem or getting in through an insecurity in the actual website could be the cause. While I admit that these could be the case … it seems fishy that everyone I know that resells hosting at JodoHost has the exact same issues … and we have separate accounts and we each manage our own FTP accounts.
I also host with another reseller for WordPress websites, and funnily enough, NONE of those websites has been hacked … I’m using the same FTP software, the same computers, and the same coding practices to secure my websites, and yet, no issues. So what’s left? Looks like it’s possible that the hosting environment might be compromised … maybe … just possibly … perhaps just a little bit?
While i have obscured some of the site’s code to protect the client’s privacy, here are two screen shots that show the link code and some characters inserted in the Google Analytics snippet that break your GA data gathering.
It isn’t always client computers/networks, but many times is, it is also via fckeditor, I saw this exact hack yesterday on an account that came via fckeditor, and I stopped it by disabling the connectors folder from being able to run scripts, as they are highly vulnerable scripts.
The same for wordpress, many bugs in older versions, if your open source app, DNN, Wordpress, etc is over 6 months old, it has holes, that are being actively exploited.
Coldfusion has some similar issues with some apps as well.
The hosting environment is not compromised, that I can assure you.
What is more, multiple domain hosting, while it is good it only takes one site of the domains in your account to access the other domains in the account, as it goes back to FTP root for the final permissions, so say one wordpress site has an addon or core item that has a vulnerable part, or joomla, or many others, it can go back to the ftp root and access other domains in that same account. I’ve seen some that even don’t have the site that was having the vulnerability, and just the others as a way to obscure the ‘work’.
I will be out some today, but you can PM me ticket IDs and I will check them.
chiming in to say i have seen this as well recently on some sites.
change your passwords, scan your PCs.
one site in question had a file uploaded 8 months ago, into the images folder, so didnt know about it till Jodo staff found it. so even though i kept on cleaning up, because the uploader file was still there, they kept getting. so scan your entire online file system too.
yes this is the case, some of these are VERY OLD items from pre-pass changes etc, that are recurring due to old items in place. We are running AV scans and removing found items now, which does include many known hijacks and uploaders that are rogue, this was part of our new policy around the new year.
I believe I actually found this in logs on one of your sites then passed it to the other staff, and this is why I need to know domain details to give the how’s and why’s, otherwise it is purely speculation.
Microsoft is cracking down on the Zeus Trojan botnets, I really hope they make progress, so many people are infected and don’t even know it, then they upload to their sites and it embeds there and they spread infection to other people via their sites This embedding is virutally impossible for us to detect as it is just a link to an active content elsewhere that results in installing the trojan on someones PC.
am update from me: today i found another site that was infected. i decided to download the entire site and go through each folder, manually.
a lot of work, but it paid off.
wait till you hear what i found!
I found about 6 separate hack files in random folders at random depths, with different names. in addition - many of the regular pages of the site were already infected with link collections and some other javascript surprises.
none of this came up in a virus, scan by the way - so i dont know how you will be able to find it.
to help others, here is some info i found:
the files were named: thumbs.asp, links.asp and core.asp.
they all had the code “Leo87546821” in one of the first few lines in the files.
This discussion is from 3 months ago so I hope I’m not bumping something that’s too old but I was wondering, is there some program or script that we can run as resellers to be notified of any changes to our accounts?
Like if a file was uploaded or modified, we would get an email or we can see it on some page?
Or would this only be possible for VPS or server users?