Sites Hacked!

Hello,

Just got a nasty notice from Google: Notice of Suspected Hacking on www.thisdomain.com. Looking thru the site I found that there are new and unknown HTML marketing pages under the root of the site. I looked thru some other sites and found the same. Some common file names are “sale”, “ugg”, “timberland”, etc…

These sites are not running Wordpress or any other web site software, they are either HTML or classic ASP mostly for includes. Based on this I believe that these sites have not been hacked programmatically but thru the CP or by FTP. I’ve changed all the CP and FTP passwords to start but they were fairly complex.

Does anyone have additional information on how this occurred or did it happen to other sites? Any suggestions on other actions I should take to prevent this from happening again?

Any help is appreciated!

Quick follow up… All these hacked sites have directories named “a..” and “b..” that cannot be accessed or deleted via FTP. I tried WebShell as well and the directories don’t show up?

If your sites are on an older Windows server, put in a ticket to have the account moved to Windows 2008. You need to look through the files carefully to remove the hacked links, and check for any backdoor files, so that they don’t get transferred with the rest. Sometimes Windows Security Essentials will spot them while you’re downloading through FTP, but not always. You’ll lose Frontpage and WebDav/Web Folder functionality, which is a huge pain for some sites.
Once it’s clean and moved, sign up for Google Webmaster tools and ask Google to reconsider the listing. It can sometimes take them a while, and they won’t if there is still any sign of hacked files.

Thanks for the reply bro!

These sites are likely on an old Windows server, WIN20. I’ve got other sites on these servers that are unaffected but I’d like to make sure this doesn’t happen to them. None require Frontpage or WebDav. Do you think that the old servers are hacked themselves?

I control and manage all these sites, and have local copies of all files so I should be able to re-upload the sites again without too much hassle. A fresh upload shouldn’t include any hacks unless the issue occurred on my local machine but I don’t see the hacked files locally and I’m serious about securing my workstations.

I could also do a diff compare and remove any hacked links, pages, or dirs that are not in the local files. One problem is that I can’t seem to delete or access some directories that were apparently created by the hack.

If it’s a server, FTP, or CP issue then it could happen again after upload even if my files are clean. I’m hoping to get more info on how it actually occurred as well.

Forgot to add, I’ve got Webmaster Tools setup for all these sites as well. Hopefully Google will reconsider the ban sooner than later once I fix the issue.

Did this happen to you? Private message me with any details if needed. Thanks again for your recommendations.

I had a client complain about this too and I’ve removed the ‘result’ of the hack but haven’t addressed the source. Site is a CMS.

CL1-Win23 if anyone cares

Cl1-Win27 is another one that pops up with the links hack on a regular basis

All my Win 2003 accounts have been hacked lately, on multiple servers, whether they had Frontpage enabled, CMSs in use, or whatever. Even if I was the only one with the FTP details, or if they were client accounts. I know it’s not through FTP since it has happened minutes after changing passwords, and the hacking is pretty much daily. Due to the nature of it, most clients don’t notice unless Google does. A good way to spot something is going on is to look at your raw logs. I believe that’s one way Google spot it. They see a sudden rise in site traffic for no legitimate reason, and the pages have many of the known spam links. It took them 3 days to remove the message after I had moved and checked it. (Perversely, WM tools are still complaining I have removed an ‘important page’ on one of my sites; the same one they were saying was hacked! They were still showing results for it in Google search for some time, too, even though I’d asked them to remove it and it was by then a 404.)

You should ask support to remove the non-editable files right away. As a quick workaround, you can make a redirect for it in CP so that it goes to a 404 or whatever. Support have more or less given up on the 2003 servers, though. Stephen says Microsoft are not patching security holes and so the only option is to get them moved. It’s worth doing it yourself if you know all the passwords and email accounts are not a problem (because you can’t take those with you), but you will need to tell your client if they use them, and you should set your DNS for the accounts to as low as possible in preparation for the change (usually a day before.) Otherwise, asking support to do it is the only way and they can move them with the current accounts and databases, but you pretty much lose access for a couple of days, and there will likely be some cleanup and testing to do afterwards.

Hey Penhall, thanks for the reply. I and Jodohost are working to remove the result but it’s still unclear how this occurred. No CMS and very little programming if any on these sites, mostly HTML.

Jodohost reps are saying this is an FTP account specific issue or that a virus was uploaded locally but I think it would have been hard to directly access my user FTP account and none of my MAC or Windows computers have any viruses.

The old FTP password was 10 characters, alphanumeric, mixed case, no dictionary words, and random. The new one I just created is 12 with the same complexity. I haven’t accessed these sites is probably at least 6 months so intercepting FTP data sent in cleartext should have been unlikely. Additionally, none of my clients have the password either.

All of my computers and virtual machines run anti-virus software daily and I have never had a virus on any of them. Since I have not uploaded files or connected to these sites in quite a long time it seems unlikely that it came from any of my machines if by some chance they were infected.

I think this is a server issue or maybe some other user has elevated privileges on the server. It appears other users have had the same issue so maybe there is some vulnerability in the CP or other server software that is allowing this to happen.

I’d like to hear more from Jodohost about how this is occurring as well!

There are a few ways, and several times seeing windows 2003 zero day exploits now hitting. sometimes over and over.

We are working to get everyone onto 2008 ASAP (see Win32 thread now), but it is not a simple process, it is a major process and we spend 100+ man hours just in prep before going live.

We cna mvoe anyone to 2008 R2 now, and recommend it! Just ask and we can start. FRONTPAGE IS GONE in 2008. Frontpage is outdated, and been used many times now to exploit. Why? It has some processes that run escalated, and used as a means to access. Those using Frontpage can continue to do so EXCEPT for shared borders and the email bots, which don’t work well anyway.
Frontpage and and will work with FTP and WebDAV, and webdav works in a similar way.

I am not happy with how 2003 is now, but it can’t just up and move overnight, we are working hard to move the entire servers. The major issues in most times are coming from insecure uploaders still however, I see a lot of these when checking on whys, and they then deface multiple domains in the account, and with some exploits, we’ve seen a few that can jump into others, sadly.

Right now there isn’t a lot out about it, we’ve found some of the causes, but the fixes are slim to none, since it all comes via IIS, a firewall doesn’t work because of this, and since it is not isolated to one particular means or methods we cannot block it on application level like URLscan or web application firewalls without really killing legitimate sites as well.

BTW Windows 2008 had WebDAV/Web Folders, that functionality is NOT LOST, and is the recommended way to publish with FP on 2008.

I’ve investigated the original posters issue and found it to be one domain in an account with many domains that is the issue, and then ht the other domains in the same account, getting some details if they even use the app responsible or not, it is ASPSecured and that app used to be preinstalled in the Hsphere early days, but hasn’t been now for at least 6 years :slight_smile:

Hey Stephen, thanks for your input! ASPSecured could be the issue. Seriously, some of these sites are at least 6 years old and haven’t had much done to them in between now and then. None use uploaders that I am aware of and I manage them all exclusively. Some clients just aren’t ready to upgrade ever!

I think all my sites on 2003 servers could and should be moved to 2008 considering the potential issues. The main issues for me would be the contact forms using CDO or older SMPTmailer coms and email. Frontpage and WebDAV aren’t issues.

What’s the best and least interruptive way to migrate 2003 hosted sites to 2008? I already have a plan set up for Win34 but may want to duplicate it to isolate some domains.

I’ve disabled ASPSecured on all the accounts but I would still like to move to 2008. Let me know the best way to migrate them and I’ll do what I can to help on my end. Thanks!

We can simply move the entire account, CDONTS will be the only issue, but we can attempt to let it work even, we do register it but dont promise it will work, CDOSYS will work.

Entire account move is the best way for sure.

Ok, should I just request it in a ticket? All the domains in this account can be moved. It is my Service account as well so could this cause issues?

I think most have been upgraded to CDOSYS so hopefully it won’t be too much work to update and fix.

There are a few other accounts and web sites on Win33 which are complex and may require more work to move but I’d like to move them as well. Can we move one account at a time? When you say account are you talking about account ID in the CP?

  1. Yes request move in ticket for the hostNAME… account. it moves all the hosting services on there, mail and Db stay in place. Service domain is no issue on this.

Win33 sites can be moved as well, no problem, and really shouldn’t be any issue except the CDONTS and possibly frontpage if shared borders or email bot in use.

As I dig into it, Win18 is another one

Penhall, any and all are able to have what has happened here to happen, even 2008, but more limited in a few ways. Whenever an uploader is there that allows asp/asp.net/php etc any accounts in the domain can be hit and have items dropped around.

In general:
I really recommend people only enable languages they USE an no more, don’t turn one everything just because it looks good, it makes more areas of possible problems.

An uploader is probably the commonality however different on each one, whether it be part of the CMS or a classic hand coded ASP one. However, digging around, it looks like an uploader on the SERVER can cause the drops.

Slightly frustrating though that similar sites I have hosted on Win12 or on non-JH servers all together don’t run in to these drops.

George, please move to non 2003, it will be the best short term. It is not something specific to us, there are some bugs out there. Now, I understand frustrations in fact I am getting error on win20 now due to cleaning up the OPs fiels too quickly and needing to do a chkdsk now.