Urgent Help !!! Somebody is hacking into my sites and injecting iframes

Discussion in 'PHP' started by james.alex, Oct 15, 2009.

  1. #1
    I am not that much into programming , but somebody is hacking to my site and injecting some kind of iframes ... it happened to another site , but that wasn't that important for me, but now it has happened to one of my major site not sure what is going on. Need some immediate help

    I see this code

    This is the infected index home page file now
    This was the original index


    when I try to replace it agin gives some error it happened a day before , when I replace the index from backup it worked , but today its not working, need some help immediatly .. thanks
     
    james.alex, Oct 15, 2009 IP
  2. facebook

    facebook Well-Known Member

    Messages:
    390
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    140
    Digital Goods:
    1
    #2
    There must be some vulnerability in ur script. Please post the other files for us here. May be I can have a look and see what the problem is... :)
     
    facebook, Oct 16, 2009 IP
  3. lmao

    lmao Guest

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    ftp client u r using is injected with the virus .Change your ftp client
     
    lmao, Oct 16, 2009 IP
  4. jestep

    jestep Prominent Member

    Messages:
    3,659
    Likes Received:
    215
    Best Answers:
    19
    Trophy Points:
    330
    #4
    Change all user and SSH password on your server. This isn't an injection, somebody has write access to your server which is really bad. The iframe is the least of your problem. Your entire server could be compromised. You should investigate beyond the homepage.

    Also, are you on a shared server? It's possible another account on the server was compromised, and there isn't proper internal protection.
     
    jestep, Oct 16, 2009 IP
  5. AdnanAhsan

    AdnanAhsan Well-Known Member

    Messages:
    601
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    110
    #5
    i think "lmao" is right, you may have virus in your ftp client, some time ftp clients put additional codes into pages if they are using as illegal copy or virus etc .. So scan your pc first.
     
    AdnanAhsan, Oct 17, 2009 IP