|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
SOLUTION for Gumblar/IFRAME/JS hacks with stolen FTP Passwords...
I wrote a script for Cpanel + Pure FTP + Clamav installed servers.
Anti-Gumblar Protection Documentation |
|
|||
|
Looks nice, but does clamscan really do any good detecting javascript/iframe inserts? Probably not. They can change by the minute. I'm even doubtful that clamscan is very good at catching rogue php shellcode pages.
I'd be interested in hearing what others think about clamAV's abilities to discover these things. Mike |
|
|||
|
System scanning all files while upload.
Pls send me sample files. I cant test and write here.. hidonet@gmail.com Last edited by hidonet; 08-08-2009 at 07:40 AM. |
|
|||
|
Doesn't this solution cause the server to have a high load and is there a chance normal ftp uploads will fail/corrupt?
Thanks
__________________
Arjan Menger http://www.welldotcom.nl - Professionele Joomla! Design, Ontwikkeling en Hosting http://www.joomlablog.nl - Nederlands Weblog Over Joomla! |
|
|||
|
Anti Gumblar Script UPDATED
http://www.oxio.net/anti_gumblar/ftp_clamscan.phps
Script is much more clever. 1 ) Moves infected file to the quarantine directory 2 ) If antivirus answers as NOT INFECTED for file, scans it with word scanner and scans file for gumblar like addresses ( .cn:808x/tx.cgi... etc.). Yo can add your patterns. 3 ) Changes account's password with random password 4 ) Sends you a mail about all that actions and new password 5 ) Blocks Attacker ip with firewall ( CSF, APF etc ) 6 ) Kills live FTP connection of attacker
|
|
|||
|
Quote:
Scans cgi, pl files too. Add your patterns you want to catch.. Pattern must be unique. If you add #!/usr/bin/perl as pattern, script blocks every perl, cgi file. Be careful
|
|
|||
|
Well working fine on my cPanel 11.24.5-R37946 - WHM 11.24.2 - X 3.9, CENTOS 5.3 x86_64 standard as far as catching the attack, it quarantines the files and sends the mail, but no other actions, does not log IP, IP blocking, password change is not working.
I am running it at a different location than /root and edited the script a bit to save log at /var/log/ftp_clamscan.log This script need PHP function shell_exec to be enabled. Though I must say its a good job and can be made better. |
|
|||
|
Quote:
If you want another function please do not hesitate to contact me
|
|
|||
|
There is no special function about 32bit or 64 bit. If php, clamav, cpanel, pure-ftpd, CSF ( or APF, or similar Firewall ) is working on your server this script works too.
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| iframe / javascript hacks? | jack01 | cPanel and WHM Discussions | 612 | Yesterday 10:14 PM |
| Solution For Iframe Java Script Hack | apscinsspl | cPanel and WHM Discussions | 17 | 10-02-2009 05:02 PM |
| iframe solution | nileshparmar | cPanel and WHM Discussions | 2 | 04-16-2009 08:58 AM |
| IP addresses from IFrame Hacks | noimad1 | cPanel and WHM Discussions | 22 | 01-29-2008 05:41 AM |
| JavaScript & IFRAME Insert Hacks Through xfercpanel | dynaweb | cPanel and WHM Discussions | 3 | 09-15-2007 02:46 PM |