Greenguy's Board

Greenguy's Board (http://www.greenguysboard.com/board/index.php)
-   General Business Knowledge (http://www.greenguysboard.com/board/forumdisplay.php?f=10)
-   -   Virus Alert? (http://www.greenguysboard.com/board/showthread.php?t=46240)

Toby 2008-03-26 02:37 PM

Virus Alert?
 
I've gotten a couple of reports from other webmasters that their AV software is tripping when they load the submit page on Well Heeled Women. http://www.well-heeled-women.com/cgi-bin/tgp/submit.cgi

Others have reported no alerts, and I can find nothing in the code that's not supposed to be there.

Is this page setting off alarms for anyone else? Even if it's a false positive I'd like to determine the cause so I can eliminate the issue.

If you do get an alert, please post what OS, AV and browser you are using.

Thanks

CrazySy 2008-03-26 03:48 PM

Loaded your page with no problem.

Bill 2008-03-26 04:30 PM

I got no alert.

Useless 2008-03-26 04:31 PM

It was fine here, Toby. XP Media, AVG, FF and IE.

Toby 2008-03-26 04:38 PM

The two reports I've received so far have both been from webmasters in Europe. Still waiting to hear back what OS, AV and browser combos they were using.

spacemanspiff 2008-03-26 05:10 PM

No problems here.

Twiceshy 2008-03-26 05:22 PM

no problem loading the page here

NY Jester 2008-03-26 07:32 PM

No problems Here Toby, XP -Sp2 , IE 7 EZ Armor and Counter Spy

LeRoy 2008-03-26 07:56 PM

1 Attachment(s)
:(

When I went to the site. My virus warning come up.

I took a picture of my laptop. I took it quick sorry about the poor quality.

If this helps I entered your site through the recip on your submit page. Then it took me to your warning page. When I entered the site I got the virus pop up.

Hope everything is ok

Toby 2008-03-26 09:26 PM

Quote:

Originally Posted by D2222 (Post 395029)
:(

When I went to the site. My virus warning come up.

I took a picture of my laptop. I took it quick sorry about the poor quality.

If this helps I entered your site through the recip on your submit page. Then it took me to your warning page. When I entered the site I got the virus pop up.

Hope everything is ok

Hmmm, so no alert on the submit or on the warning, but an alert on the main gallery page. |banghead|

What OS, AV and browser? and did the alert give any indication of what it had detected?

Toby 2008-03-27 12:41 AM

** UPDATE **

I found the problem, in the process of cleaning files now. Not sure yet how they got access. Here's the code that was inserted. I'm not sure what it does.
Code:



Toby 2008-03-27 09:03 AM

more info:

It's inserts an IFRAME that links to a page with a pretty nasty ActiveX exploit. The code was added to any of my TGP script generated pages across four different domains, a different TGP script on fifth domain on the same box was unaffected.

It seems that a hole in my trade script was the initial access point. They were literally minutes ahead of me updating the trade script to a more secure version.

Give me about 20 minutes in a locked room with the asshat(s) responsible. |club|

LeRoy 2008-03-27 04:02 PM

Shoot I'm late getting back to this thread :( . I was too shy to ICQ you last night ;)

Glad everything is ok. Sorry about the delay in getting the info.

bluebrit 2008-03-28 08:11 AM

Hi Toby. Are you certain you got it all? I just took a quick look at the code you posted and it only seems to target IE5 & 6.

That still leaves IE7, Netscape, Opera etc. It seems strange that someone would hack you for that and not include more code to cover all the other browser types as well.

Just a thought and I hope I'm wrong.

Toby 2008-03-28 08:23 AM

I noticed that in the code too. I think it specifically attacked IE5 and IE6 browsers because they're the ones susceptible to the ActiveX exploit on the redirect URL. That also makes it less likely to be detected right away by the webmaster, since most of us keep our own stuff updated.

I've been through all my sites file by file and am pretty sure I've got it all. I'd already updated the trade script that had the security hole that allowed them access.

I was literally minutes late getting the update installed (released that same afternoon). Time stamp on the uploaded files for the update was 9:02 PM. Time stamp on the modified hack files was 8:50 PM. |banghead|

cd34 2008-03-28 06:05 PM

That virus is added through an FTP account. What makes this one bad is that they have access to the site, go in and modify precisely the few files needed with no errors or password violations, and, after you change it, in a few days they go back.

Change your password, make sure that every time you give your password to a vendor that you change it afterwards. Or, change it before giving it to a vendor and change it back.

Of the exploits we see, about 80% are through poorly coded php, 15% are through spyware/keyloggers/passwords that are given out to someone that has spyware/keylogger. And every 14-18 months, a certain credit card processor that stores passwords in the clear for all of the FTP accounts that they maintain for clients that run a membership site has all of their passwords stolen.


All times are GMT -4. The time now is 06:45 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc