Greenguy's Board

Greenguy's Board (http://www.greenguysboard.com/board/index.php)
-   General Business Knowledge (http://www.greenguysboard.com/board/forumdisplay.php?f=10)
-   -   Ever seen spyware that adds itself to html on your computer ? (http://www.greenguysboard.com/board/showthread.php?t=36229)

noooze 2006-11-20 11:57 AM

Ever seen spyware that adds itself to html on your computer ?
 
found this in some html that i have NOT added myself

i know i had some spyware for a few days untill i removed it

this was the line added



what the **** - have you ever seen this before ?

atariFu 2006-11-20 12:22 PM

Thats a nifty trick, probably not new but still interesting. How many html files did it get?

noooze 2006-11-20 12:25 PM

2 pages - and i didnt notice due to a popup blocker - good thing it wasnt online for long.

think it adds itself as you save and close :(

Toby 2006-11-20 12:50 PM

It's most likely being added at the server, not by your PC.

cd34 2006-11-20 12:54 PM

That was added through FTP access to your webserver.

Very common. Your password has been leaked somewhere, perhaps through spyware/keyloggers, or, a vendor that you have given the password to which installed software, and you never changed the password after they were done.

amadman 2006-11-20 02:12 PM

Yeah... this sucks.
Had it happen to me not long ago. (Thanks for the help Sparky!)

Change your password!

Beaver Bob 2006-11-20 02:32 PM

for security, its always best to change your passwords frequently.. every month or two at least.

noooze 2006-11-20 02:58 PM

damn... so someone downloaded my index pages and uploaded them again ?

hmm i'd better change password , go though ftp log, and talk to the police :) one good thing is that i can report it, and if the same ip turns up serveral places, someone might wanna do something about it

WebairVictor 2006-11-20 03:52 PM

too many of them there...

noooze 2006-11-20 03:55 PM

well... sometimes i cant help think - why not try to fight back.. maybe i cant do anything, but what if 2000 like me report it ?

i donno

juggernaut 2006-11-20 10:57 PM

Quote:

Originally Posted by noooze (Post 314148)
well... sometimes i cant help think - why not try to fight back.. maybe i cant do anything, but what if 2000 like me report it ?

i donno

Unfortunatly nothing is going to happen. Ever try and send a email to a "report at com" addy. It goes no place. 1) most people don't even know how to set up multible profiles to check that mail at all time while checking their own. 2) they prob get so filled with mail why would they want to.
Cd will attest that most of this stuff happens when a server admin or host is either sleeping at the wheel and not updating their shit. Not knoweldgeble enough (there are plently running very strong business who can't even spell server let alone manage one correctly). Or just not keeping up to date with the bad guys out there.
In order to change your site someone needs to have write access to the file/folder and that is not to easy to get if the servers permissions are correct and system updated (MS or LX). Or you just give out your password, write it on the bottom of your favor coffee mug or do what most people do and just stick it right on the monitor with a post it note.
If it were me I would be happy of the easy fix. Do a search and replace on the code of all your files. Look over the logs for shits and giggles and block the IP. But fact is they will keep comming from some other place so that is kind of a waste but still a good practice and can't hurt. Me I block all countries that have mostly low to no income. You know the odds of the person comming to your site and paying with their own creditcard is slim. My cam site is open to the world as most of the girls come from countries I would love to block.


All times are GMT -4. The time now is 06:13 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc