Something Odd On My Site......

free web hosting
Free Web Hosting > Astahost > Hosted Members Support

Something Odd On My Site......

Chesso
I went to check out my site today and low and behold, some spyware try loading itself and some .wmv file tryed to run from the main page....

I was like "wtf mate lol", anyway I went into my cpanel file manager and checked out the index files source and someone has managed to add an iframe to the end of the source going to some advertising rubbish or some such.

Is there anyway people can do this without my login details? If not can I request a change of password somehow blink.gif

Reply

dhanesh
>> LINK <<

Check the above link, recently posted my m^e. A Similar problem had happend at asta, and its believed to be the advertiser who is at fault. Check the post and see if that helps.

Regards
Dhanesh.

Reply

Chesso
Mine wasn't that site but a similar problem that it is via an iframe, but it was many websites, about 8/10. None of them to my knowledge were the one listed in that main post.

It hasn't seem to have come back yet and it's the first time it has happened since I have been here, about 5+months.

Could it be to do with the google ads on my site or something? It's a bit weird because it was directly injected into the main index file itself.

Reply

Chesso
Sorry for the double post.

It has happened again, and some functions.php file keeps appearing in my main site folder that is 158kb's.

The site the iframe linked to this time is (http://www.brucemeisterman.com/) which I checked out and is just some photographer site or something.

I reset my password for cpanel and removed my mysql account but for some reason I cannot gain access to my cpanel now to re-setup user for the database (it wouldn't let me modify only delete so I had to delete and then try to re-create with new password).

Whew what a pain heh.

EDIT: Hmmm mysql from cpanel won't even let me create a new user now or database (it seems it completely removed the old one...... luckily I keep this stuff backed up heh heh tongue.gif).

EDIT: Ok I have managed to re-setup the database user with new password, got no idea why it wasn't working before but it's mysteriously started working *shrugs*. I have also went and password protected all my folders so they can't be viewable and will fail unless an index file is present in them heh heh oh and all the password resetting of course.

If it happens again than I have no idea how they managed it lol.

 

 

 


Reply

vujsa
Be sure to set the permissions on your template directory correctly.

I had a problem in Mambo once where I used the built in editor to edit my templates which required that I set the permissions on the folder and files to 777. I stopped using the internal editor and left my files read only and haven't had any problems since.

That is the only way I can think of to directly edit your file to insert an iframe into a file.

Hope you don't have any more problems with this.

vujsa

Reply

Chesso
I don't use any of that mambo and template stuff. It's call done from scratch tongue.gif.

But I think I know what you mean, I don't really need write permissions of any files except besides from the cpanel file manager, that wouldn't be affected?

Reply

CaptainRon
OMG, this has triggered some serious thoughts with myself. I had given 777 permissions to certain folders since a php scripts requires it to be that way....

I will write away change it back to 755 smile.gif

Reply

nightfox
QUOTE(CaptainRon @ Aug 30 2006, 02:59 AM) *

OMG, this has triggered some serious thoughts with myself. I had given 777 permissions to certain folders since a php scripts requires it to be that way....

I will write away change it back to 755 smile.gif

Don't do it unless you're positive you can. Some scripts will not function unless the files and/or folders are CHMODed to 777. Configuration scripts should NEVER be set to 777 unless they're blank and the installer needs to right to them but after that you should set the permissions back.

But like you said, "I had given 777 permissions to certain folders since a php script requires it to be that way...."
Keywords in bold. It must require it, so don't change the permissions. The script probably needs to write, read and execute to files inside those folders. The script will probably have limited functionality if you did this.

Upload folders MUST have 777 permission or else no one could upload stuff. The server would reject all uploads through the browser.

Just consult the manual (or installation guide) about file permissions.

NEVER give your public_html directory full permissions either.

[N]F

Reply

cyborgxxi
So, are you having any more problems lately? Hehe, always keep your watch over those security holes!! It's always easy to overlook them and wow... it must suck when you have those huge files 158kbps in your storage. Haha, I've had odd things happen to my site too.

Actually, my SQL files and databases we're messed up and I couldn't access the software!! Not even the panel... and doh! I had to uninstall (more like reformat) the software... well by deleting everything from my Astahost account drive and reinstalling the webboard software.

So, I have to say KUDOS FOR YOU!!! Backups are always great to have and more the merrier... and better if you have 'em every week or so smile.gif

Reply

Chesso
Well I test everything locally and use a somewhat identical content database, plus I wrote everything from scratch and it's pretty lean.

So if something got bunged that bad, I can just nuke and re-upload (re-run sql) in a couple of minutes and I'm back up again *shrugs* heh heh smile.gif.

Reply


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

Similar Topics

Keywords : Odd Site

  1. Time Travel? - Site activity showing up from the past (4)
  2. Site Down Again, Help Or Suggestions? - (6)
    I’m starting to get a complex because my site, ycoderscookbook.com is down again. I hate to SPAM
    the forums like this but I have a support ticket submitted and have not head anything in three days.
    From what I am seeing, the Gamma server is up but for some reason the DNS is not resolving to the
    domain. Ycoderscokbook.com has been down since Friday. Perhaps one of the admins can look into
    this for me /wink.gif" style="vertical-align:middle" emoid=";)" border="0" alt="wink.gif" /> I
    know that BuffloHELP was very nice after the server migration and pulled a few string...
  3. Can't Access Any Site Hosted On The Server - (4)
    Ever since yesterday, I wasn't able to access my site http://maxotek.net , so I tried
    others' sites like http://www.handyphp.com , none of which opened. I've tried PINGing the
    sites and have received no response as yet. I've heard that there were some changes to the IP
    addresses for the shared IPs. Just a while ago, I heard from a friend of mine that he was able to
    access the sites. Another one reported of a Gateway Timeout error. Do I need to make some changes
    in the CPanel or will this be solved automatically?...
  4. Site Not Working - Can access cpanel, but site will not load (5)
    Alright, well my website is http://www.sourcedevelop.com I can access cpanel by going to
    https://gamma.xisto.com:2083/frontend/rvblue/index.html and entering my username and password.
    However, when i try and load my website....it says that it cannot find the server. Anybody else
    experiencing this?...
  5. Site / Account Not Working - (10)
    I currently have over 10 credits, but my account isn't working as if my account had been
    depleted below zero. Help please?...
  6. Site Not Opeing ( Phpbb Forum) :: Can't Connect To Local Mysql - (3)
    Hi all, Please help me! My site was working fine! ( www.fun.niranvv.com ) But now, its showing
    one error message as: Warning: mysql_connect() : Can't connect to local MySQL server
    through socket '/var/lib/mysql/mysql.sock' (2) in
    /home/niranvv/public_html/fun/db/mysql4.php on line 48 Warning: mysql_error(): supplied argument is
    not a valid MySQL-Link resource in /home/niranvv/public_html/fun/db/mysql4.php on line 330 Warning:
    mysql_errno(): supplied argument is not a valid MySQL-Link resource in
    /home/niranvv/public_html/fun/db/mysql4.php on line...
  7. My Site Is Suspended - xtremewarez.uni.cc (8)
    My site is just currently suspended and it says contact your billing/support of astahost but i have
    seen the support and all i se is oyu have ICQ and i do not have ICQ can i talk through here in the
    forum? Also, maybe you can get a live chat system and talk through there. Maybe we can talk through
    email/MSN if you have it. Thanks -Lewis P.S if i cannot keep my current site can you delete it
    and ill make another different one....
  8. Mysql Error Never Seen On My Site Before (too Many Connections). - (13)
    I just tried to visit my site to see if anything had changed on my forums and such and I got this
    message: Warning: mysql_connect(): Too many connections in /xxxx/xxxxx/xxxxxx_xxxxx/xxx/xx_xxxx.php
    on line 7 Error! Could not connect: Too many connections. I have never recieved this error before,
    does this mean someone is mucking with my site somehow??? The particular php file it mentions is
    the one that defines variables like db username etc and connection to the site's database that I
    include wherever it is needed in various file for the site. EDIT: I managed t...
  9. Site Unavailable! - Server Timeout error! (7)
    My Astahost Website seems to be unavailable currently. The Time is : 4:15 PM IST (GMT+5:30hrs)
    The browser gives a "Server Timeout Error". Is this a temporary server downtime, or do I have to
    re-configure my site or something? I also have enough credits to go on with - 17 at this time...
    My site is : www.omkarshub.astahost.com ...
  10. Problems With PHP/Joomla On Hosted Site - PHP sevred pages are blank in Firefox, network error in Safari (7)
    I am having some odd problems with my hosted site. They started sometime yesterday. I have not made
    any changes for about two weeks. In Firefox, the index page (index.php) for Joomla comes up blank.
    I can access my Control Panel and can check that the files are there and look correct. No favorites
    icon is displayed either and the page source is empty. In Safari, I get the favorites icon but then
    get a network error and a blank page ("Safari can’t open the page “http://mistymanor.astahost.com/”.
    The error was: “lost network connection” (NSURLErrorDomain:-1005) Please cho...
  11. Google Sitemaps Not Verifying My Site... - Tells me to configure server (4)
    This is the error that Google gives me while i try to verify my site. NOT VERIFIED We've
    detected that your 404 (file not found) error page returns a status of 200 (OK) in the header. The
    explanation for this error at google is: This configuration presents a security risk for site
    verification and therefore, we can't verify your site. If your web server is configured to
    return a status of 200 in the header of 404 pages, and we enabled you to verify your site with this
    configuration, others would be able to take advantage of this and verify your site as well....
  12. Adsense Ad - Is it ok to put on Astahost hosted site? (1)
    Is it OK or against the TOS to put an Adsense ad (or anyother content based Ads) on the website I am
    hosting at Astahost? Ooops! I am extremly sorry. I should I looked properly during my search on
    Adsense. It seems like I can put Google Adsense on my Astahost hosted website. Forum moderators,
    please excuse my blunder - you may close this thread....
  13. Astahost Banner Or Icons? - Something to display on my site? (2)
    As I am setting up my site, I am looking for two things, one is a set of icons to display in the
    footer with links to the various technologies and vendors I use, the other is a set of rotating
    banner ads for sites or services I think really deserve more attention (I am not collecting money
    for the ads). Does Astahost have a recommended click-through icon for footers and/or a banner or us
    to display on our sites? Where can I find it? ...
  14. My Site - error accessing my site hosted here (5)
    Today at local time GMT+1 --> 15:12 I could not access my site http://www.final-design.net hosted
    here at Astahost. error looks as follows: QUOTE The page cannot be displayed The page you are
    looking for is currently unavailable. The Web site might be experiencing technical difficulties, or
    you may need to adjust your browser settings. I hope you'll fix that soon. Thanks to
    admins in advance....
  15. Php Parsing Error On Smf On My Site - Parse error: parse error, unexpected T_C (16)
    QUOTE Parse error: parse error, unexpected T_CONSTANT_ENCAPSED_STRING in
    /home/jeremy1/public_html/guild_forum/Sources/Subs.php on line 272 thats the error I get when
    people try to access the forums I run on my website. I've been through the code but can't
    figure out exactly whats wrong. I'm still quite new to PHP and still have a very limited
    understanding of it. All I can say for certin is that up untill around 2 p.m. PST the forums were
    working then around that time they seem to have stopped and started outputing that error message.
    If anyone c...
  16. >30 = ~2 ; Credits Don't Compute; Site Down - Credit system appears horribly broken (6)
    First let me say that I am upset at the moment, so if this comes across that way, do not take it
    personally. This may be a simple mistake somewhere, but I am very confused and frustrated. I found
    this site, built up about 20 credits, and applied for a basic site (cost, 10 credits). Over the
    couple days it took the site to be approved, I continued posting and got up to somewhere over 30.
    The account was approved, I spent the weekend at a local festival (what I do for a living) which
    tied me up for 48 hours. I get back, and my new site, which I have printed on the busines...
  17. Switching From Fp To Dreamweaver - Easiest way to switch a FP site to DW? (6)
    Ok heres my problem, I would like to switch my site from being a Frontpage site to a more flexable
    Dreamweaver site. I'm ready to give up my training wheels and move on to the real deal but my
    problem is that I don't know how to go about it without trashing all the work I've put into
    my site. I'm willing to trash it and start from the ground up, though I'll do it grudingly,
    but if anyone knows how I can do it with the least amount of loss of functionality and rework
    I'd be greatly appreciate it....
  18. Web Site Still Not Accessible - www.relspace.astahost.com (4)
    I received an email that everything was back up and running but my website is still not there and it
    is not accessible by ftp either. www.relspace.astahost.com ...
  19. Backing Up My Whole Site For Transfering ? - (1)
    I am currently using a MySQL/PHP site. How would I go about transfering my whole site without losing
    any information or files? Do I just make a backup and upload it to the new server? I also need to
    transfer the php files, so would I just download them and upload them again? Would I have to install
    my portal again ? Need help! /blink.gif' border='0' style='vertical-align:middle'
    alt='blink.gif' /> /blink.gif' border='0' style='vertical-align:middle' alt='blink.gif' /> ...
  20. How Long Until My Site Is Back Up? - glitch101 (1)
    My account was suspended today, but I am almost up to 10 days worth of credits and it still does not
    work. How long does the unsuspended process take? I feel as if I am wasting time. Will someone
    please help?? here's my account info. http://glitch101.astahost.com /unsure.gif'
    border='0' style='vertical-align:middle' alt='unsure.gif' /> /unsure.gif' border='0'
    style='vertical-align:middle' alt='unsure.gif' /> ...
  21. Hosted By Astahost Button - A link back button to place on your site (2)
    This is a nice little button to place on your site to show your appreciation to astahost for hosting
    your site. It’s a modification to the one on your cpanel.
    http://www.caribcirc.astahost.com/images/astahost.gif ...
  22. Site Down... - (10)
    My website is down. /mellow.gif' border='0' style='vertical-align:middle' alt='mellow.gif' /> Is
    there a server problem or something? Is anyone else's site down?...
  23. Un-suspend My Site - UN-SUSPEND MY SITE (1)
    Hi, B'coz of some un avoidable situation i was offline for some days, and my site
    http://arunzunlimited.astahost.com was SUSPENDED due to lack of posts, but now I HAVE ENOUGH NUMBER
    OF POSTS, so Please UN-SUSPEND MY WEBSITE My website URL is : http://arunzunlimited.astahost.com
    Hoping for Quick Reply. Regards Arunkumar.H.G...



Looking for odd, site






*SIMILAR VIDEOS*
Searching Video's for odd, site
advertisement




Something Odd On My Site......