How can someone add a malicious script to my website main page?

Discussion in 'Site & Server Administration' started by iowadawg, May 14, 2006.

  1. #1
    I just checked one of my sites and it would not load, got hung up and stayed there for ages.
    Could not use task manager to shut the page down.
    Had to finally shut down computer to get rid of the page not loading.
    Once I was back up, went to my cpanel and into my index page.

    Someone had added a script between <header></header> code plus
    the same script after the </body> and before the </html> codes.

    How can someone add a script like this?

    What should I do to prevent this in the future?
     
    iowadawg, May 14, 2006 IP
  2. FeelLikeANut

    FeelLikeANut Peon

    Messages:
    330
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #2
    If you have a server-side program running, there may be a flaw there; they may have discovered your password for FTP access; they may have cracked the server itself.
     
    FeelLikeANut, May 14, 2006 IP
  3. iowadawg

    iowadawg Prominent Member

    Messages:
    10,918
    Likes Received:
    811
    Best Answers:
    0
    Trophy Points:
    380
    #3
    What is a server side program.
    Yeah, change user and password for the site.
    If they hacked into the server, they have not touched any of my other sites.

    Thank you.
     
    iowadawg, May 14, 2006 IP
  4. -Abhishek-

    -Abhishek- Regaining my Momentum!

    Messages:
    2,109
    Likes Received:
    302
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Ok Listen, are you using a dynamic webpage ??
    One which imports data from your database ??
    Then I guess you are a victim of an sql injection ...
    Can you please quote the malicious code here ?? I'd like to see it :) if you don't mind!
    Abhishek
     
    -Abhishek-, May 15, 2006 IP
  5. iowadawg

    iowadawg Prominent Member

    Messages:
    10,918
    Likes Received:
    811
    Best Answers:
    0
    Trophy Points:
    380
    #5
    No database on this site.
    Pure static web pages.

    Can't send the script as I deleted it upon finding it.

    If it shows up again, will copy and paste it here for you.

    Thank you.
     
    iowadawg, May 15, 2006 IP
  6. jestep

    jestep Prominent Member

    Messages:
    3,659
    Likes Received:
    215
    Best Answers:
    19
    Trophy Points:
    330
    #6
    Just for safety, I would immediately change the FTP user and passwords for the site.

    Also, if you have access to logs look in your transfer and access logs and see if there is anything in there that may explain it.
     
    jestep, May 15, 2006 IP
  7. iowadawg

    iowadawg Prominent Member

    Messages:
    10,918
    Likes Received:
    811
    Best Answers:
    0
    Trophy Points:
    380
    #7
    Log in password, etc.
    Can't see the logs...simply because I had never activated that part!
    Now it is active...so if it happens in the future, I can hunt them down and stick a hot poker up the butts.
     
    iowadawg, May 15, 2006 IP