1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Is my website Hacked?

Discussion in 'Security' started by Napoleon, Jan 28, 2008.

  1. #1
    I asked my friend to view a page on my site http://www.secretipaddress.com/tools.php
    He got a warning like[​IMG]

    I tried to view another page of my site using IE6 and my antivirus alerted me about a trojan called TR/agent.cyt.107

    Is my website hacked? Is there a code injection? The friend who warned me told me he will ignore the warning and see what happens and he is not online again.:(

    What should I do? I checked all the code and there is no suspicious files or text.
     
    Napoleon, Jan 28, 2008 IP
    wisdomtool likes this.
  2. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Anybody? Its still there.:(
     
    Napoleon, Jan 28, 2008 IP
  3. SticKer

    SticKer Well-Known Member

    Messages:
    2,393
    Likes Received:
    78
    Best Answers:
    0
    Trophy Points:
    115
    #3
    i checked the page but didn't receive any warning.
     
    SticKer, Jan 28, 2008 IP
  4. Dondon2d

    Dondon2d Peon

    Messages:
    3,193
    Likes Received:
    146
    Best Answers:
    0
    Trophy Points:
    0
    #4
    SticKer, did you use IE7 to view the page? As far as I know, IE7 pops up this message when the site is using old active controls. Careful though as your site may be injected, inspect all files and look for suspicious codes (Javascript).
     
    Dondon2d, Jan 28, 2008 IP
  5. SticKer

    SticKer Well-Known Member

    Messages:
    2,393
    Likes Received:
    78
    Best Answers:
    0
    Trophy Points:
    115
    #5
    i had checked with firefox and didn't get errors.

    Now i checked with ie7 and got an error to run an addon: remote data service data control.
     
    SticKer, Jan 28, 2008 IP
  6. Dondon2d

    Dondon2d Peon

    Messages:
    3,193
    Likes Received:
    146
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Exactly my point SticKer.
     
    Dondon2d, Jan 28, 2008 IP
  7. SticKer

    SticKer Well-Known Member

    Messages:
    2,393
    Likes Received:
    78
    Best Answers:
    0
    Trophy Points:
    115
    #7
    i was wondering what do you guys do in such cases. how can the site owner fix the problem. is it some problem with the code or somewhere else?
     
    SticKer, Jan 28, 2008 IP
  8. Dondon2d

    Dondon2d Peon

    Messages:
    3,193
    Likes Received:
    146
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Yeah, as far as I know it has something to do with the code, especially the ones using active controls, or the server perhaps.
     
    Dondon2d, Jan 28, 2008 IP
  9. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,825
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #9
    I check, it prompt me for a username and password. I am using Firefox
     
    wisdomtool, Jan 28, 2008 IP
  10. SticKer

    SticKer Well-Known Member

    Messages:
    2,393
    Likes Received:
    78
    Best Answers:
    0
    Trophy Points:
    115
    #10
    so is this error a hack attempt or just a code error?
     
    SticKer, Jan 28, 2008 IP
  11. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I disabled the access to my site temporarily so that nobody will be infected. I took the risk and ignored the antivirus warnings and looked at the source in IE.
    This line is added just after <body>
    <script language='JavaScript' type='text/javascript' src='lstbj.js'></script>
    Code (markup):
    Now, I looked at the code of that file from FTP and nothing is there. Is this some kind of code injection? What should I do?
     
    Napoleon, Jan 28, 2008 IP
  12. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,825
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #12
    It would be great if every webmaster is as considerate as you are. Hopefully some members here who are experts would be able to help you with it. I am too stupid to be of much help when it comes to programming. Can only wish you the best.

     
    wisdomtool, Jan 28, 2008 IP
  13. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Thanks wisdomtool, I hope some experienced DPer will look into this thread.:(
     
    Napoleon, Jan 28, 2008 IP
  14. mann3r

    mann3r Peon

    Messages:
    1,416
    Likes Received:
    100
    Best Answers:
    0
    Trophy Points:
    0
    #14
    have you checked if the file is hidden? also try to contact your host admin and address this issue. they will help and remove this file. and try to remove that line and check if pop-up again and inject the code again to index.
     
    mann3r, Jan 28, 2008 IP
  15. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #15
    I'll check with my host. The problem is that the extra piece of code is appearing only if I view through IE. I dowloaded all the files and there is no such javascript. Is there some way to hide the code in HTML? Using the chinese font or something like that?
     
    Napoleon, Jan 28, 2008 IP
  16. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #16
    I found a XML file with the name dwsync.xml. Can this be the problem?
     
    Napoleon, Jan 28, 2008 IP
  17. Dondon2d

    Dondon2d Peon

    Messages:
    3,193
    Likes Received:
    146
    Best Answers:
    0
    Trophy Points:
    0
    #17
    What is inside the XML file? Try deleting it but make a backup just in case it's not the file that's causing the problem.
     
    Dondon2d, Jan 28, 2008 IP
  18. konradbraun

    konradbraun Peon

    Messages:
    842
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #18
    I have had that problem... usually an <iframe ...> code somewhere on the page... usually header. I won't take a risk looking at the page as I lack proper protection on my PC.
     
    konradbraun, Jan 29, 2008 IP
  19. Napoleon

    Napoleon Peon

    Messages:
    732
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    0
    #19
    The file is found in the images folder. I'm pretty sure I didn't create it
     
    Napoleon, Jan 29, 2008 IP
  20. Dondon2d

    Dondon2d Peon

    Messages:
    3,193
    Likes Received:
    146
    Best Answers:
    0
    Trophy Points:
    0
    #20
    Hmm, it doesn't look suspicious. Try deleting it (make a backup though) and see if it messes up your site in some way.
     
    Dondon2d, Jan 29, 2008 IP