Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 1 of 9 1 2 3 ... LastLast
Results 1 to 15 of 124
  1. #1
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default SOLUTION for Gumblar/IFRAME/JS hacks with stolen FTP Passwords...

    I wrote a script for Cpanel + Pure FTP + Clamav installed servers.

    Anti-Gumblar Protection Documentation

  2. #2
    Member
    Join Date
    Sep 2004
    Posts
    887

    Default

    Looks nice, but does clamscan really do any good detecting javascript/iframe inserts? Probably not. They can change by the minute. I'm even doubtful that clamscan is very good at catching rogue php shellcode pages.

    I'd be interested in hearing what others think about clamAV's abilities to discover these things.

    Mike

  3. #3
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    I'm using over 1 week and no negative point about clamav. Catched every infection...

  4. #4
    Member
    Join Date
    Aug 2003
    Posts
    77

    Default

    Does it catch up .cgi scripts (dark mailer etc.), who are a able to send out spam?

  5. #5
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    System scanning all files while upload.

    Pls send me sample files. I cant test and write here..

    hidonet@gmail.com
    Last edited by hidonet; 08-08-2009 at 07:40 AM.

  6. #6
    Member
    Join Date
    Jan 2006
    Location
    Assen, The Netherlands
    Posts
    18

    Default

    Doesn't this solution cause the server to have a high load and is there a chance normal ftp uploads will fail/corrupt?

    Thanks
    Arjan Menger
    http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting
    http://www.joomlablog.nl - Nederlands Weblog Over Joomla!

  7. #7
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    A little bit slows down ftp uploads. Waits 1 or 2 second after all uploaded files.
    I have ~500 sites in one server and there is no complaint from customers.

  8. #8
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default Anti Gumblar Script UPDATED

    http://www.oxio.net/anti_gumblar/ftp_clamscan.phps

    Script is much more clever.

    1 ) Moves infected file to the quarantine directory
    2 ) If antivirus answers as NOT INFECTED for file, scans it with word scanner and scans file for gumblar like addresses ( .cn:808x/tx.cgi... etc.). Yo can add your patterns.
    3 ) Changes account's password with random password
    4 ) Sends you a mail about all that actions and new password
    5 ) Blocks Attacker ip with firewall ( CSF, APF etc )
    6 ) Kills live FTP connection of attacker


  9. #9
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    Quote Originally Posted by headout View Post
    Does it catch up .cgi scripts (dark mailer etc.), who are a able to send out spam?
    I've added a new wordscan function on last release.

    Scans cgi, pl files too. Add your patterns you want to catch.. Pattern must be unique. If you add #!/usr/bin/perl as pattern, script blocks every perl, cgi file.

    Be careful

  10. #10
    Member isputra's Avatar
    Join Date
    May 2003
    Location
    Mbelitar
    Posts
    593

    Default

    Anyone using this Gumblar Script beside the maker ? Please give us a review here.
    It's me ...... It's me ......

  11. #11
    Member isputra's Avatar
    Join Date
    May 2003
    Location
    Mbelitar
    Posts
    593

    Default

    Code:
    $GLOBALS["whmhash"]        ="511e....2c";                // whm remote access key for root user
    What is this mean ?

    Can I install this script under /usr folder not /root folder ? I know that some configuration on ftp_clamscan.php has to be change to /usr. But is there any downside not using root folder ?
    It's me ...... It's me ......

  12. #12
    Member
    Join Date
    Jan 2008
    Posts
    11

    Default

    Tried on 64-bit OS, not working.

  13. #13
    Member
    Join Date
    Jun 2003
    Location
    Bharat
    Posts
    230

    Default

    Well working fine on my cPanel 11.24.5-R37946 - WHM 11.24.2 - X 3.9, CENTOS 5.3 x86_64 standard as far as catching the attack, it quarantines the files and sends the mail, but no other actions, does not log IP, IP blocking, password change is not working.

    I am running it at a different location than /root and edited the script a bit to save log at /var/log/ftp_clamscan.log

    This script need PHP function shell_exec to be enabled.

    Though I must say its a good job and can be made better.
    Vinayak Sharma
    Vinsar.Net - Quality WebHosting Services at Economical Price USA & UK Servers
    Book Your Domain with Confidence Reliable Domain Reseller Account

  14. #14
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    Quote Originally Posted by Vinsar View Post
    Well working fine on my cPanel 11.24.5-R37946 - WHM 11.24.2 - X 3.9, CENTOS 5.3 x86_64 standard as far as catching the attack, it quarantines the files and sends the mail, but no other actions, does not log IP, IP blocking, password change is not working.

    I am running it at a different location than /root and edited the script a bit to save log at /var/log/ftp_clamscan.log

    This script need PHP function shell_exec to be enabled.

    Though I must say its a good job and can be made better.
    Thanks...

    If you want another function please do not hesitate to contact me

  15. #15
    Member
    Join Date
    Apr 2005
    Location
    Istanbul / Turkey
    Posts
    57

    Default

    Quote Originally Posted by Bartuc View Post
    Tried on 64-bit OS, not working.
    There is no special function about 32bit or 64 bit. If php, clamav, cpanel, pure-ftpd, CSF ( or APF, or similar Firewall ) is working on your server this script works too.

+ Reply to Thread
Page 1 of 9 1 2 3 ... LastLast
Similar Threads & Tags
Similar threads

  1. Effective iframe/gumblar hack prevention?
    By Wallaby in forum Security
    Replies: 5
    Last Post: 04-30-2010, 12:36 PM
  2. SOLUTION for Gumblar/IFRAME/JS hacks with stolen FTP Passwords...
    By hidonet in forum cPanel and WHM Discussions
    Replies: 98
    Last Post: 12-22-2009, 11:44 PM
  3. iframe / javascript hacks?
    By jack01 in forum Security
    Replies: 612
    Last Post: 11-20-2009, 10:14 PM
  4. iframe / javascript hacks?
    By jack01 in forum cPanel and WHM Discussions
    Replies: 612
    Last Post: 11-20-2009, 10:14 PM
  5. IP addresses from IFrame Hacks
    By noimad1 in forum cPanel and WHM Discussions
    Replies: 22
    Last Post: 01-29-2008, 05:41 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube