Community Forums
Connect with us on LinkedIn
  
+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 16 to 18 of 18
  1. #16
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Default

    Quote Originally Posted by ramzex
    Crap!

    This is not the iframe method!
    We had exact same issues our our customers webservers.
    We have investigated this issue and found the following:
    ramzex:

    I saw your original post a couple days ago and briefly contacted you
    but I have also been very busy this week helping a lot of users deal with
    the current hacking attacks going around, helping people secure their
    servers, and have not had much free time available. I would very much
    like to take a look at your server and sit down and go over with you all
    that you have done to try to clean it out and update the security as
    there is likely a great many areas you missed (based on your comments
    in each of your posts) that I may be able to help you address.

    You are already off to a good start in the things you list in your post
    above but I also see a great number of critical areas to address where
    you did not mention doing anything to secure your server in those areas.
    When you are available, try to contact me and if I have a few free moments,
    I'll try to make room to talk to you and help you with your server.

    -Spiral

  2. #17
    Registered User
    Join Date
    Jul 2009
    Posts
    1

    Default

    Hi Everybody.

    This is my first post.
    First of all please be careful everyone who uses FILEZILLA.

    The reason? Very Simple
    Look in your machine for a file called "sitemanager.xml".
    You can open it with a notepad.
    It holds all the information of your accounts.
    In plain text.
    User.
    Password (not encrypted!!).

    Once you have a trojan/virus (like Malicious.PDF.Gen, etc), is a piece of cake to it to get that information. It only have to read the xml and send that information to the attacker.


    Now i am using another free ftp client. EFTP.
    It encrypts everything. I will try it now.

    Good Luck (and sorry for my odd english)

  3. #18
    Member konrath's Avatar
    Join Date
    May 2005
    Location
    Brasil
    Posts
    314

    Default

    [QUOTE=ramzex;541109]Crap!

    This is not the iframe method!
    We had exact same issues our our customers webservers.
    We have investigated this issue and found the following:

    Hello

    I do not agree with you.

    ------------------------------
    3. Script has modified the passwords of the accounts located in /etc/passwd
    ------------------------------

    The passwords of the customers are not modified.


    What I see in this log (sent by sallen812) is exactly what happens to my clients infected with iframe hack.



    Thank you
    Konrath
    Last edited by konrath; 07-13-2009 at 10:49 PM.

Similar Threads & Tags
Similar threads

  1. FTP Hacker
    By sallen812 in forum cPanel and WHM Discussions
    Replies: 17
    Last Post: 07-13-2009, 10:46 PM
  2. Hacker?? Need help
    By ChipW in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-12-2007, 02:42 AM
  3. is this a hacker ?
    By gordypordy in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 02-01-2006, 12:07 PM
  4. Crazy hacker.......
    By amal in forum cPanel and WHM Discussions
    Replies: 14
    Last Post: 05-09-2005, 10:58 PM
  5. Is this a hacker??
    By hjnet in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-31-2002, 06:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube