Greenguy's Board


Go Back   Greenguy's Board > Programming & Scripting
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2006-06-19, 10:32 AM   #1
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Trojan removal HELP needed

I just got the information that some (maybe all) of my sites seem to be infected with a trojan:

http://www.heathersboobs.com/
http://www.teeny-facials.com/
http://www.pissdrinkingchicks.com/
http://www.backsideteens.com/

Generic Downloader.z trojan

How can I remove it and any idea where it comes from?
frankthetank is offline   Reply With Quote
Old 2006-06-19, 10:37 AM   #2
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
that particular exploit is uploaded through FTP. Your FTP account has been compromised.

Change your FTP password, remove the script at the bottom of the page that runs the iframe:

[code=trojan stuff on your pages]
<script language="JavaScript">
e = '0x00' + '22';str1 = "%99%C1%CA%
blah blah blah
</script>
[/code]

You might have your host run a check to see what other files were modified at the same time. Pattern to look for is:

Login, Get File, Put File, Get File, Put File, Logout

usually no failed password attempts.

Sources for your password leak: People that have installed software for you in the past, anyone that has had FTP access to your machine, possibly any keylogger on your system.

When you give out passwords to people to install software or fix something on your site, set a temporary password, let them do the work, reset the password when they are done. Don't use the same password everywhere. Tommy keeps a black book of his passwords for each different site and sponsor login so that any one that is compromised won't be a security problem for other sites.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2006-06-19, 10:44 AM   #3
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by cd34
that particular exploit is uploaded through FTP. Your FTP account has been compromised.

Change your FTP password, remove the script at the bottom of the page that runs the iframe:

[code=trojan stuff on your pages]
<script language="JavaScript">
e = '0x00' + '22';str1 = "%99%C1%CA%
blah blah blah
</script>
[/code]

You might have your host run a check to see what other files were modified at the same time. Pattern to look for is:

Login, Get File, Put File, Get File, Put File, Logout

usually no failed password attempts.

Sources for your password leak: People that have installed software for you in the past, anyone that has had FTP access to your machine, possibly any keylogger on your system.

When you give out passwords to people to install software or fix something on your site, set a temporary password, let them do the work, reset the password when they are done. Don't use the same password everywhere. Tommy keeps a black book of his passwords for each different site and sponsor login so that any one that is compromised won't be a security problem for other sites.
Thankīs. i already contacted webair to have a look at it. It seems to be a password which I used at sponsor programs and missed to change.

Could this trojan be responsible for dropping sales? My sales crashed at the beginning of May and I didnīt figure out why.
frankthetank is offline   Reply With Quote
Old 2006-06-19, 12:35 PM   #4
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
its possible. There are a number of trojans out there that see sites and replace codes in urls so that they get credit. So, yes, that is within the realm of possibility.

Its also possible that surfers running any antivirus got the warning and backed out of the site.

the last modified time on the first site is May 5th, so, its been there a while and I would consider that a very good possibility that it affected sales.

you can check the dates
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2006-06-19, 12:52 PM   #5
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by cd34
its possible. There are a number of trojans out there that see sites and replace codes in urls so that they get credit. So, yes, that is within the realm of possibility.

Its also possible that surfers running any antivirus got the warning and backed out of the site.

the last modified time on the first site is May 5th, so, its been there a while and I would consider that a very good possibility that it affected sales.

you can check the dates
First of all many thankīs for helping me out. I just called webair who changed the passwords for ftp accounts immediately. Now Iīm killing the script code from nearly all my sites. I hope that only the index.html are infected.

When itīs done webair will check it and I hope itīs clean again.
frankthetank is offline   Reply With Quote
Old 2006-06-19, 08:44 PM   #6
Tommy
NYC Boy That Moved To The Island
 
Join Date: Apr 2003
Posts: 2,940
Send a message via ICQ to Tommy
Quote:
Originally Posted by cd34

Sources for your password leak: People that have installed software for you in the past, anyone that has had FTP access to your machine, possibly any keylogger on your system.
A lot of webmasters have been getting hacked like this

I would bet the source of the password leak is a sponsor
__________________
Accepting New partners
Tommy is offline   Reply With Quote
Old 2006-06-19, 11:07 PM   #7
tickler
If there is nobody out there, that's a lot of real estate going to waste!
 
tickler's Avatar
 
Join Date: Dec 2003
Posts: 2,177
Quote:
Originally Posted by Tommy
I would bet the source of the password leak is a sponsor
Timing is about the same as all these spam emails??? And all the ones that I have been getting are for an address that I setup for a sponsor.
eg. ThatSponsor @ MyDomain.com
__________________
Latina Twins, Solo, NN, Hardcore
Latin Teen Cash
tickler is offline   Reply With Quote
Old 2006-06-20, 03:11 AM   #8
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by Tommy
A lot of webmasters have been getting hacked like this

I would bet the source of the password leak is a sponsor
Yes, you are right. I used the same login / password combination at some sponsors. OK, now I learned that was pretty stupid, but on the other hand I didnīt expect it.

Iīm now using unique login / password combinations, changing the password regularly and my passwords are now complicated and much more difficult to guess.

Not all my sites were infected. Not sure enough to accuse him publicly, though.

Fortunately not even one gallery was modified with the script. The script forced the installation of an "start.exe" which connected to a site hosted at "inhoster.com". I donīt think itīs worth to contact them if you have a look at their site.

The site called us-counter.com and dnv-counter.com belong to a guy from Ukraine and are blacklisted with several records. IPīs from the sites and from the hosting company are pretty much the same.

Iīd like to close down that hoting company for sure. Those behaviour easily ruins the reputation of persons involved.
frankthetank is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:15 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Đ Greenguy Marketing Inc