Calguns.net  

Home My iTrader Join the NRA Donate to CGSSA Sponsors CGN Google Search
CA Semiauto Ban(AW)ID Flowchart CA Handgun Ban ID Flowchart CA Shotgun Ban ID Flowchart
Go Back   Calguns.net > GENERAL DISCUSSION > Technology and Internet
Register FAQ Members List Calendar Mark Forums Read

Technology and Internet Emerging and current tech related issues. Internet, DRM, IP, and other technology related discussions.

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 03-23-2013, 11:43 AM
stilly's Avatar
stilly stilly is offline
I need a LIFE!!
 
Join Date: Jul 2009
Location: Achieved God Status on 11/28/2022
Posts: 10,674
iTrader: 51 / 100%
Default Website was hacked with iframe and php bd I think, where can I educate myself?

long story short a website that was put up for a small local business was hacked, they gained access to the .htaccess file and inserted something there, they edited the rollover.js file in the assets directory and inserted an iframe line there.

What I did in response:

replaced ALL of the website with a fresh copy just to be safe.

BUT, about a day or so later it was infected again.

SO, I dug a little deeper and did this:

saved the rollover.js file and viewed it compared to a clean one, found the malware string as the first line or two. replaced the bad file with a clean one, did some research and generated a NEW htaccess file and replaced the one that was there. I also found a base_64 encoded php file named default.php (lazy asshats) and I did not think that there was any need to have a php file that was base_64 encoded (back in mac days of newsgroups) so I renamed that as defaultpossiblyinfected.php or I just removed it period. It was not in the root directory, but with the htaccess file. I also saw that there was one user listed in the htpassword or whatever it is called file and the user and pass did not match what I had changed anything to, the user matched, but the pass was different, I think that might have been an old PW, but the site has had a new PW assigned to it and I also used my ftp client to remove WRITE access to all of the web files and I think even some of the other files in the urchin5 directory are also write protected. When I generated a new htaccess file I think I was able to somewhat protect the htaccess file and some other stuff.

Is this sufficient? I hate that it happened on my watch and I have this feeling that there is more that I can do to lock the site down. It is being run from AT&T webhosting (not my choice, it is free) and oh I just realized that I will need to change the password for the ftp backup that takes place each week at the store. Anyways, it is an apache server I believe and I found a few sites that talk about the htaccess site but I think I need a good ebook on how to lock down a website like that. I only have one php script and it looks like that file was not messed with but it is used to send an e-mail for a contact form.

On top of that I followed the domain listed in the iframe trj and found it belonged to some asshats in west africa (ZA). I found a reference to a file there, so I made a DOC file with the link and then saved it as a htm file and then opened it and saved the file that was mentioned and then I opened it up to view it. It is an odd file, it is differently named then what the html file is on the link, but it looks like some sort of google_com or something that has a lot of google stuff in it.

Anyways, any words of advice from seasoned website vets or security. OR a link to an ebook or even a good ebook title would be sufficient. TIA
__________________
7 Billion people on the planet. They aint ALL gonna astronauts. Some will get hit by trains...

Need GOOD SS pins to clean your brass? Try the new and improved model...



And remember- 99.9% of the lawyers ruin it for the other .1%...
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -8. The time now is 10:41 AM.




Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Proudly hosted by GeoVario the Premier 2A host.
Calguns.net, the 'Calguns' name and all associated variants and logos are ® Trademark and © Copyright 2002-2021, Calguns.net an Incorporated Company All Rights Reserved.
All opinions, statements and remarks made by Calguns.net on this web site and elsewhere are solely attributable to Calguns.net.



Seams2SewBySusy