Help - Hackers have taken over my site!

Discussion in 'Security' started by kinkarso, Sep 11, 2010.

  1. #1
    Well, kind of. I was notified by Google that there has been phishing pages uploaded on my website that, of course, I did not initiate. I went through the access logs and saw when and how they were uploaded - through a shell script!

    I was able to trace and delete 3 different shell scripts located at various locations on my site, but as I keep looking, it seems they are everywhere. Is there any way I can do a site-wide malware scan that would pinpoint these buggers so I can get rid of them?

    Thanks,
    Donny
     
    kinkarso, Sep 11, 2010 IP
  2. st1905

    st1905 Well-Known Member

    Messages:
    573
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    135
    #2
    An easy way is to scan your /home with clamscan , also check your server for rootkits and backdoors with rkhunter, if you are rooted then you`ll need someone to clear your server (Its not that easy to do but possible).
     
    st1905, Sep 12, 2010 IP
  3. ŦʂĞɧ ųŞøƝ

    ŦʂĞɧ ųŞøƝ Peon

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    It's actually pretty simple, I'll help you just PM me/respond on here and ill help with what i can.
     
    ŦʂĞɧ ųŞøƝ, Sep 12, 2010 IP
  4. kinkarso

    kinkarso Well-Known Member

    Messages:
    358
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    120
    #4
    Thanks st1905, just did a clamscan of my public_html directory and it showed 0 infected. It looks like I may have gotten to all of the infected files.

    ŦʂĞɧ ųŞøƝ, sure, if you have another idea, please let me know :).

    Thanks!
    Donny
     
    kinkarso, Sep 12, 2010 IP
  5. !!DomainsMaster!!

    !!DomainsMaster!! Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    aww sad :((
     
    !!DomainsMaster!!, Sep 20, 2010 IP
  6. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Makes me wonder how they got the shell script onto your server in the first place.
     
    phpSiteMinder, Sep 20, 2010 IP
  7. semoweb

    semoweb Peon

    Messages:
    26
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Do you have some type of uploading script that allows php files to be uploaded?
     
    semoweb, Sep 20, 2010 IP