Help please - Mysql Injection Attack

Discussion in 'Security' started by DavidBlaze, Sep 5, 2009.

  1. #1
    Hello,

    We have a Linux based oscommerce website. Since yesterday someone has been injecting encrypted code into every .php file on our website (example: <?php /**/eval(base64_decode('encrypted code here')); ?>).

    We have tried to figure out what back door the person is using with no luck.

    We are in need of help and if anyone can figure out how this is happening and a suitable prevention, we are willing to pay.

    Please PM me if you can help and I will send you the details.

    Thanks in advance.
     
    DavidBlaze, Sep 5, 2009 IP
  2. kailash

    kailash Well-Known Member

    Messages:
    1,248
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    190
    #2
    Do you own your server or your web site is hosted on shared server? If you are on shared server you have less option to investigate it from your end. You will need to update your host as soon as possible to find the root cause. Additionally, you can take following steps from your end:

    [1] Change your FTP users password. If possible use combination of special characters.
    [2] Upgrade all installed third party scripts in your web site.
    [3] If you are using third party template or module then make sure they are secure.
    [4] Scan the system to check possible virus/trojan/spyware infection from where you are uploading and managing your web site.

    Kailash
     
    kailash, Sep 5, 2009 IP
  3. user099

    user099 Active Member

    Messages:
    218
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #3
    you can try to contact the user SecureCP.
    I had a similar problem and he cleaned and protected my server.
     
    user099, Sep 7, 2009 IP
  4. jtpratt

    jtpratt Well-Known Member

    Messages:
    170
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    123
    #4
    Kailash had some great ideas to get you started - you need to get that bad code out of there. Your choices are to find and remove it yourself, or hire someone (like me) to find and remove it for you.

    Be sure once clean to have someone lockdown that site a bit more for you.
     
    jtpratt, Sep 9, 2009 IP
  5. bluearrow

    bluearrow Well-Known Member

    Messages:
    1,339
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #5
    like user099 said contact SecureCP. He will able to help you.
     
    bluearrow, Oct 4, 2009 IP