My Domain Is Hacked And Sends SPAM!

Discussion in 'Security' started by Macavi, Jan 25, 2010.

  1. #1
    I have noticed that my websites say "Hosting Account Suspended". Then i asked BlueHost technician what is wrong. He told me that one of my domains was SPAMMING. He told me that there may be scripts to do this, but how to know. How to find infected files? What to do?
     
    Macavi, Jan 25, 2010 IP
  2. D@rkLord

    D@rkLord Peon

    Messages:
    226
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Can't bluehost technician find the wrong scripts and delete it?
    I advise you to delete all the scripts you have installed or added lately.
     
    D@rkLord, Jan 25, 2010 IP
  3. Macavi

    Macavi Active Member

    Messages:
    97
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    65
    #3
    I didn't install any new scripts recently. I just want to know - was it code injection or some spammer wanted to put me out of business and just used my email address to send spam.
     
    Macavi, Jan 26, 2010 IP
  4. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #4
    use SEARCH function in THIS forum
    we had extensive threads covering that topic in earlier years - ALL is still valid

    if you did NOT secure your own site, then you most likely may have hackers using your site as phishing site
    hence you are a liability to our global community and thus the account is correctly closed by your host until you have secured your site.

    deletion of hacker files - if found - is NO solution!
    true solution is in finding HOW your site gets hacked/abused for spam and solving that issue!

    study ALL scripts you have ( blog and whatever, in perl or php or any other script EVER installed )
    search google for security issues with EVERY script you have
    even if you have NO scripts at all - may be you have easy passwords that got cracked ?

    research ALL access_log files
    compare all files ever requested with all files installed BY YOU

    do all a.m. research yourself UNTIL you FIND the exact cause of your spam being sent
    then fix and secure your site
    then request your host to reopen your account after having detailed him all security action you implemented

    one possible hint you may ask from your host is the exact time of last spam being sent - usually you may even find mail-log files for your site and do all that research yourself.
    knowing the exact time ( date, hr, minute, seconds ) gives you an idea WHEN exactly to look in your access_log files
     
    hans, Jan 26, 2010 IP