All my accounts on win24 have a new file appearing: Editor.asp usually in a folder called _notes/
Sometimes index.asp is edited, too.
This is across different accounts, different clients. The same happened last week on an account at win28, and has happened before. Windows Security Essentials spots the file as a threat in FTP download.
Can support run a virus check on this server as a matter of urgency, and remove these files and block whatever accessed them? Clearly the problem is server wide.
this isn’t a server wide hack, it is FTP level hacks due to FTP passwords stolen or due to outdated apps. I will check the details further, but I know I’ve seen this happen multiple times.
I have seen some botnets hitting php pages that look simple but allow smtp mail bounces as well, quite a bit. most of these accounts have multiple domains and a single one being vulnerable puts the ensite account as risk, then the bots hit at the same time.
I have blocked the IPs however. going forward we’ll be dropping in more 2008 R2 servers and encouraging people to move, MS is not fixing new issues that come up on 2003 unless it is kernel level, and Parallels is not touching 2003 anymore, so 2003 won’t gt php 5.3 or anything else, and also won’t have a migration path to their new multi server management.
Edit: just to confirm, I just checked 10 accounts and over 30 domains, none of them had these files in random check.
Those possibilities don’t seem to account for it. Out of 4 accounts one doesn’t have php or any kind of common app. The others have Movable Type which is kept strictly up to date. One account FTP is known only to me and has been changed 3 times in the last week. I keep a very close eye on it and my system is scanned regularly. (And if it was my ftp, they only hit one particular server out of the 20 or so that I use, which would be odd.) Yet these 4 accounts on the same server were all hit about the same time in the same way.
The only thing they do have in common is Frontpage, which unfortunately my clients use, at least for Web Folders. Given we don’t have Secure FTP there isn’t much choice there, and supposedly webdav is more secure than ftp. It would seem moving to 2008 is the most sensible thing to do at this point, but moving multiple domains, email and databases on large accounts is not particularly easy.
Bro, I found those you mentioned and did remove them. I found a total of 9 accounts accounts with expanded permissions for everyone having write access to some domain folders. I think it is a tech or app giving too many permisions.
The everyone permissions allowed a defacer script to put files there. I am going to send a mass mail to the staff about not giving everyone permisisons to anything, it is not good, even if a client wants it for an app to work, it should be network services at most.
BTW, you don’t have to manually move 2003 to 2008, it is same automated process as any other move, email db etc untouched.
Frontpage extensions suck, and are a security EXPLOIT waiting to happen. The main sharepoint process pool even runs as the windows system. It incidentally, does NOT work on 2008. People stuck on frontpage, are going to have to change before long, simple as that.
Just as a note now, in the same shift as my last reply, all the permissions were fixed by removing everyone, if you have a site can’t access some data it may need some attention, but NOT everyone on the domains.
To follow-up, it hasn’t made any difference to my sites. I’m sure I’ve never needed ‘everyone’ permissions on any of them, and can’t imagine why they would need it (why would they?) If it fixes the problem, it should be done on all the Windows servers as far as I’m concerned.
The EVeryone Permissions setting is coming when using the FrontPAge admin tool I have learned. so if ever we have to manually set a permission or from email address, in frontpage admin, it is getting ‘everyone’ applied by it.
There is nothing we can really do here except to note it and ensure not having it. there is no patch or change or anything to be done. We just did a permisisons reset on the accounts seeing it and moved to normal permissions without everyone, just the users FTP group.