Malware Found on my site plz help

Discussion in 'Security' started by sweta.singh.98, Nov 28, 2009.

  1. #1
    hi ..


    I have a website ...but from last few day i m facing malware problem that malware changing my index.php file ... went i saw that i have deleted all files and uploaded again ...then after 4 days i found same prob and same code ..i m using Awast but awast is not able to deduct that malware it is found by AVG ..

    Code added by malware is


    Can any buddy help me out (I have changed my all passwords)

    Plz help me
     
    sweta.singh.98, Nov 28, 2009 IP
  2. kbduvall

    kbduvall Peon

    Messages:
    71
    Likes Received:
    3
    Best Answers:
    4
    Trophy Points:
    0
    #2
    Delete that code and restore your pages. I would suggest restoring your entire site from backups if you can as there's no telling how many pages they edited.

    You've already changed your passwords ... good. Make sure they're strong passwords though. Weak passwords can be cracked in minutes. Something like n8$sG1@q would be a good example.

    Also go through all your 3rd party scripts and make sure you're using all the current versions. Remove any 3rd party scripts that are no longer being maintained by the creator.

    Hope this helps.
     
    kbduvall, Nov 28, 2009 IP
  3. sweta.singh.98

    sweta.singh.98 Guest

    Messages:
    628
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #3


    They add only index.php page .....

    And After checking ftp logs i found a ip 216.97.235.70 which is of lunarpages.com's (web hosting company) .....

    Can u help me out how i can fix this problem ....i have blocked this IP. Now they still access my FTP ?

    Thanks in advance
     
    sweta.singh.98, Nov 29, 2009 IP
  4. kbduvall

    kbduvall Peon

    Messages:
    71
    Likes Received:
    3
    Best Answers:
    4
    Trophy Points:
    0
    #4
    Also make sure there are no suspicious FTP accounts set up on your server.
     
    kbduvall, Nov 29, 2009 IP
  5. sweta.singh.98

    sweta.singh.98 Guest

    Messages:
    628
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    ok thanks for your suggestion
     
    sweta.singh.98, Nov 30, 2009 IP
  6. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #6
    check the file permission of index.php. see if its 755.
     
    olddocks, Dec 3, 2009 IP
  7. sweta.singh.98

    sweta.singh.98 Guest

    Messages:
    628
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    its 755 .........
     
    sweta.singh.98, Dec 4, 2009 IP
  8. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Why don't you change that out to 644
     
    SecureCP, Dec 4, 2009 IP
  9. sweta.singh.98

    sweta.singh.98 Guest

    Messages:
    628
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #9
    ok i have done this .... after 5 days i will see it ...
     
    sweta.singh.98, Dec 7, 2009 IP