Spam Being Inserted Into My HTML

Discussion in 'Security' started by Zibblu, Jan 26, 2010.

  1. #1
    I have a website on travel and I started to notice people finding my site for porn related keywords in StatCounter. So I checked out the "text only" version of my site in Google and I found that somehow lots of porn related words (and links to porn websites) were hidden on some of my html pages (but not all.)

    I have StatCounter, Google Analytics, AdSense, & some CJ.com javascript ads on these pages.

    The site is being hosted on ANHosting, BTW.

    Any clues on what I can do to stop this from happening?
     
    Zibblu, Jan 26, 2010 IP
  2. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #2
    no precise clue but one precise own experience that might help
    a year or so ago I had ONE link exchange with a french SE
    the back-link to that french SE however called / created sometimes a POPUP/POPunder on my site ..

    hence among other sources look at all your backlinks you have installed on your site
    and look at all the uploaded files to see if you have any files NOT from you on your server

    also check ALL possible comment data if you have such - and check all uploaded graphic files ( png, gif, jpeg, etc ) for included malware - with other words check ALL your server files with a good virus SW and root kit detector

    any XXS or mysql iinjection, etc may be blocked either by properly using mod_security and/or snort if you run your own server for your site

    see where you have your doors open and then learn how to close/secure all and then remove existing wrong data from your server

    a website name might be useful for more detailed help
     
    hans, Jan 28, 2010 IP
  3. Zibblu

    Zibblu Guest

    Messages:
    3,770
    Likes Received:
    98
    Best Answers:
    0
    Trophy Points:
    0
    #3
    hans, I think you are right... I think came from a link exchange thing I did a long time ago... I have deleted all of those files (as I stopped participating some time ago) and I've noticed that the html injection only happened on older html files, it hasn't happened on any newer files I've put up... so hopefully the problem is solved.
     
    Zibblu, Jan 28, 2010 IP