I was trying to setup adwords for a site, and got a google mesage that the site was black listed for malware. Found nothing except in the source of one page an iframe with this link:
bastard.bij.pl/main.php?page=8f059b09cd0e2f70
I took the site off line, Uploaded a "fresh" modx copy, restored and all was good.
I only found that this could be done over FTP, the host however wrote they did not find anything and that it is due to the content of the site. Site is on EVO 1.05 I had emo emial obsufication (deleted that btw) and MetaX and Wayfinder.
Anyone has an idea or suggestion of what to do to prevent this?
Do you have reflect.php left over from an earlier version?
Well that could have been it. Site was setup on 0.9.6 and yesterday I upgraded from 1.04 to 1.05. And I did delete reflect on other sites. Just not here, maybe.
-
☆ A M B ☆
- 711 Posts
Do you know which files were affected? If you found similar malware code in each sub folder on index.php or index.htm then this would have been an attack via FTP where a script connects and loops through all the folders downloading the index files adding the extra code and re uploading.
If many of these were affected they won't appear to your host as hack attempts as the hacker would have logged in without any failed logins, I have seen this quite a few times before and the route cause was a trojan key logger on a users PC where they connected with FTP.
If the files are quite random or you found extra ones added it's most likely the reflect script.
Aaron
Hi Aaron and BobRay,
thanks for the answers. I wiped the FTP and reinstalled with a fresh Modx copy. Why is reflect still there or is the current 2.1 version not affected by this exploit?
ANyway I saw in the database dump of the site in question, that the Reflect version is 2.1 too. That dump was from january this year, so active yesterday. Could have been that?
I exported the site and the line of code was only on one exported page. DId and do not find anything in the files nor a strange htaccess modification. Sure hope it s not a local active bit of malware.
Thanks, Frank.
-
☆ A M B ☆
- 711 Posts
Hi Frank,
Sounds like you have it all fixed now, without seeing the original files its hard to say, but just to be on the safe side run a full virus check on any PC which used your FTP log-in details and also reset them.
This is the most common hack method we see here at onesmarthost.
Thanks Aaron
Hi Aaron,
virus, spyware and malware scans have been running all night without revealing very dangerous threats.
Lets hope this is the end of the problem,
Frank.
Also the hannahskincare.co.uk site (runs with you, no?) seems unaffected.
-
☆ A M B ☆
- 711 Posts
Hi Frank,
I never realized when replying to you that you host some of your sites with us. I've checked the Hannah site for you and this looks fine it is on 1.0.3 and could do with upgrading to just be on the safe side.
Was your infected site hosted with us? if so drop me an email aaron [at] onesmarthost.co.uk and I will check through the logs to find the exact route cause.
Thanks Aaron
Hi Aaron,
It s the only site that runs on your servers. The site owner did choose not to yearly pay a small fee for upgrades etc. guess I ll do it anyway. Frank.
-
☆ A M B ☆
- 711 Posts
Hi Frank,
If you think the site will work OK with an upgrade just let me know and I can extract the set-up and run it direct on the server for you.
Thanks Aaron