hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Web Hosting : Windows Hosting : BEWARE -Sudden Iframe injection attacks, catastrophic results - Help!
Reply

Windows Hosting Information and issues specific to the Windows web hosting platform. Everything unique and dedicated to Windows hosting and the Windows server environment. If your service is unavailable, please click here.
Forum Jump

BEWARE -Sudden Iframe injection attacks, catastrophic results - Help!

Reply Post New Thread In Windows Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-04-2007, 09:22 PM
xuzo xuzo is offline
Newbie
 
Join Date: May 2006
Posts: 5

BEWARE -Sudden Iframe injection attacks, catastrophic results - Help!


All my sites on both my hosting accounts are infected with an iframe.


At the end of the index.html files the malicious code just appeared...suddenly 3 weeks ago.

The host blamed Joomla so I took the appropriate steps:

Upgraded my Joomla to the latest version, changed the whole account username and password, changed the configuration and template to unwriteable.

It stopped the injection for a few days but then it came back.
I would also like to add that 2 other sites on my account, one simple index.html file and an old website I have that is totally HTML with nothing to do with Joomla also got infected.

The iframe also infected a Drupal install I did as a test.

So according to these fact is this a Hosting Company not taking responsibility or can a Joomla site infected spread to other normal HTML sites and different CMS's on the server?

This situation is ruinning me and I strongly suspect it's a Hosting problem and not Joomla.

Any expert opinions from true professionals would be appreciated because if I can prove that it's not a Joomla issue I might take legal action against the hosting company since this has cost me dozens of hours of work and several hundred dollars of lost revenue.

I am attaching the iframe exploit. It installs itself on every index file...in every folder - components, mambots, ect..additionally it attaches itself on any and every kind of addon that has an index.html file.
Thanks

Reply With Quote


Sponsored Links
  #2  
Old 09-04-2007, 10:36 PM
RSNET-John RSNET-John is offline
Web Hosting Master
 
Join Date: Feb 2007
Posts: 1,369
Hmm, sounds like the permissions have been set incorrectly. An exploit on 1 site shouldn't be able access another site on a Windows box because the user accounts have different permissions.

Have you tried a clean install of Joomla?

__________________
ReliableSite.Net LLC >> 1000+ Gbit Premium Only Redundant Network, N+2 Redundant Tier 4 Data Center, 100% Uptime SLA
LOWER YOUR DEDICATED SERVER AND WEB HOSTING COSTS TODAY
Like us on Facebook and see our Dedicated Server Specials for AMAZING DEALS

Reply With Quote
  #3  
Old 09-04-2007, 11:15 PM
Website Rob Website Rob is offline
learning is in the doing
 
Join Date: Sep 2000
Location: Alberta, Canada
Posts: 3,109
This is a concern to many of us Hosters and after some in-depth research of my own, it would seem the most likely cause is that your personal computer is infected. Strange as that may sound, hackers are using a variation of Trojans to infect personal computers and then use your own FTP login information, to change the Index page and/or other targeted pages on your own site.

Please use your Anti-virus program to check your personal computer and advise if anything was found -- including links to Web sites with more information specific to the Virus/Trojan found, like this article. I can only presume (hope) that you have an Anti-virus program but if you don't, you can have computer checked for viruses for free -- using the free HouseCall from TrendMicro. They are a very respected company when dealing with Virus related problems. You can feel secure in using their HouseCall program to access/clean your computer.

__________________
PotentProducts.com - for all your Hosting needs
Helping people Host, Create and Maintain their Web Site
ServerAdmin Services also available


Last edited by Website Rob; 09-04-2007 at 11:19 PM.
Reply With Quote
Sponsored Links
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Application Attacks Common in Cloud Hosting Environments: Report Web Hosting News 2013-03-26 10:48:47
FireHost Report Shows Cross-Site Scripting Attacks Up 160 Percent from Q3 Web Hosting News 2013-01-30 14:43:57
Senate Says No to Cybersecurity Act, White House Says Results Could be 'Catastrophic' Web Hosting News 2012-08-03 11:19:42
FireHost Report Shows SQL Injections Up 69 Percent Over Q1 2012 Web Hosting News 2012-07-24 16:48:13
WHIR TV - Rick from Neustar Discusses DDOS Threats and Defense Blog 2011-09-23 13:52:45


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?