|
|
|
|
|
|
|
|
|
|
|
#1 |
|
a.k.a. Sparky
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
|
that particular exploit is uploaded through FTP. Your FTP account has been compromised.
Change your FTP password, remove the script at the bottom of the page that runs the iframe: [code=trojan stuff on your pages] <script language="JavaScript"> e = '0x00' + '22';str1 = "%99%C1%CA% blah blah blah </script> [/code] You might have your host run a check to see what other files were modified at the same time. Pattern to look for is: Login, Get File, Put File, Get File, Put File, Logout usually no failed password attempts. Sources for your password leak: People that have installed software for you in the past, anyone that has had FTP access to your machine, possibly any keylogger on your system. When you give out passwords to people to install software or fix something on your site, set a temporary password, let them do the work, reset the password when they are done. Don't use the same password everywhere. Tommy keeps a black book of his passwords for each different site and sponsor login so that any one that is compromised won't be a security problem for other sites.
__________________
SnapReplay.com a different way to share photos - iPhone & Android |
|
|
|
|
|
#2 | |
|
Stupid risks make life worth living
|
Quote:
Could this trojan be responsible for dropping sales? My sales crashed at the beginning of May and I didnīt figure out why. |
|
|
|
|
|
|
#3 | |
|
NYC Boy That Moved To The Island
|
Quote:
I would bet the source of the password leak is a sponsor
__________________
Accepting New partners |
|
|
|
|
|
|
#4 | |
|
If there is nobody out there, that's a lot of real estate going to waste!
Join Date: Dec 2003
Posts: 2,177
|
Quote:
eg. ThatSponsor @ MyDomain.com |
|
|
|
|
|
|
#5 | |
|
Stupid risks make life worth living
|
Quote:
Iīm now using unique login / password combinations, changing the password regularly and my passwords are now complicated and much more difficult to guess. Not all my sites were infected. Not sure enough to accuse him publicly, though. Fortunately not even one gallery was modified with the script. The script forced the installation of an "start.exe" which connected to a site hosted at "inhoster.com". I donīt think itīs worth to contact them if you have a look at their site. The site called us-counter.com and dnv-counter.com belong to a guy from Ukraine and are blacklisted with several records. IPīs from the sites and from the hosting company are pretty much the same. Iīd like to close down that hoting company for sure. Those behaviour easily ruins the reputation of persons involved. |
|
|
|
|
![]() |
|
|