"attack" site

Discussion in 'Security' started by americamba, Jan 28, 2009.

  1. #1
    What's up? I was advised that people were warned about my site as being an "attack" site. What can I do? Please help. I suspect that this is the reason that I have lost all Amazon sales. People are probably being scared away. Thanks for a good look at it and good advice as to what I should do.

    best wishes, Frank

    Following are the links that came up to my daughter who tipped me off.

    http://safebrowsing.clients.google.c...sEnEspanol.php

    http://www.google.com/interstitial?u...ingstyles.htm/
     
    americamba, Jan 28, 2009 IP
  2. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #2
    The links are broken. We can't help if we don't know your site address.
     
    UseShots, Jan 30, 2009 IP
  3. americamba

    americamba Member

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #3
    Sorry they got truncated in the post window. How do I prevent that? What I get in preview and what you receive is a broken form. Ses the ..... ? I sent:

    http://safebrowsing.clients.google....ttp://www.bookslibros.com/LibrosEnEspanol.php

    http://www.google.com/interstitial?url=http://www.bookslibros.com/learningstyles.htm/

    The latest report I get after deleting from my host and replacing with an older verion I thought was clean is:

    they still don't work...same thing.
    Your main site is the only site that works initially but when you click on external links the security warnings come up. all the pages that you wrote work- it's the links that take you to book purchases that are messed up.​
     
    americamba, Jan 30, 2009 IP
  4. ~kev~

    ~kev~ Well-Known Member

    Messages:
    2,866
    Likes Received:
    194
    Best Answers:
    0
    Trophy Points:
    110
    #4
    What can you do? You can remove the scripts that try to install spyware or malware on peoples computers. Run a clean site and you will not get flagged.
     
    ~kev~, Jan 30, 2009 IP
  5. americamba

    americamba Member

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #5
    how do I do that? is there a way to identify the problems?
     
    americamba, Jan 30, 2009 IP
  6. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I've found two obfuscated malicious scripts inside your homepage.

    The first is right after body tag. it starts with

    document.write(unescape('%3C%69%66%72%61...
    Code (markup):
    it creates a hidden iframe.

    The other is right before the closing </body> tag.

    It starts with

    function c71912231668n4937080c1e784(n4937080c1ef95){ 
    Code (markup):
    it creates a hidden iframe from bigsellstaff .cn

    You should remove the malicious scripts (or upload a clean copy from backup) and request a review via Google's Webmaster Tools.

    Most likely your own computer is infected. Scan it for viruses and spyware. Then change all passwords.

    Be sure to check your .php files. They may be vulnerable to hacker attacks.
     
    UseShots, Jan 31, 2009 IP
  7. americamba

    americamba Member

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #7
    Thanks for the help. What does "obfuscated" mean in this context of scripts. I know what it means in the context of mealy mouthed politicians. Also could you please tell me which URLs have the bad scripts. I have a few domains and pages. I am not sure what you meant by my "homepage" . thanks again, Frank
     
    americamba, Jan 31, 2009 IP
  8. koan

    koan Well-Known Member

    Messages:
    607
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    135
    #8
    No offense but if you don't know what a homepage is, maybe you should hire a professional to fix your sites, otherwise the problem will come back.
     
    koan, Jan 31, 2009 IP
  9. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Obfuscated means it is not clear what the script does when you look at it. It may lool like random chars and digits.

    I found the malicious code inside the homepage of the site you mentioned "bookslibros com"
     
    UseShots, Jan 31, 2009 IP
  10. kiran_n444

    kiran_n444 Active Member

    Messages:
    123
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #10
    Also if this occured earlier today, GOOGLE displayed "THIS IS AN ATTACK SITE" for all search results.
     
    kiran_n444, Jan 31, 2009 IP
  11. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #11
    No. This site is really infected and "may harm your computer". It contains real malware.
     
    UseShots, Jan 31, 2009 IP
  12. traffic.web

    traffic.web Guest

    Messages:
    43
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    remove obfuscated script from your site and check again...
     
    traffic.web, Feb 1, 2009 IP
  13. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #13
    If your site has security weakness, attackers will come back and do the malicious script insertion again.
    It won't finish for you just remove the script.
     
    justdoit1, Feb 2, 2009 IP
  14. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #14
    I've found out http://onlinelinkscan.com/ is unreliable.

    Now I'm coding a perl-based malware-link checker for web sites. PM me if you want it.
     
    justdoit1, Feb 4, 2009 IP