Websites attacked. Have malicious code.

Discussion in 'Security' started by mmads, Nov 23, 2009.

  1. #1
    mmads, Nov 23, 2009 IP
  2. harishsyndrome

    harishsyndrome Peon

    Messages:
    128
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    First inform your service provider about this condition.

    Ask him to do a Scan and get back up of all your files.

    If you have lost your PR, dont worry google is much resposive. But be patient, it takes time.

    ONe of my friend's website has been recovered and his PR has been restrored after 23 days of struggle.

    Good Luck
     
    harishsyndrome, Nov 23, 2009 IP
    mmads likes this.
  3. WeWatch

    WeWatch Active Member

    Messages:
    75
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    50
    #3
    Without being able to see your sites, (must be some change made to the code) it's difficult to tell what kind of infection you have.

    However, I've seen many other sites getting hosed by hackers. It usually starts with a virus on a PC with FTP access to the hosed website. The virus steals the FTP login credentials and "hacks" the website using legit FTP logons.

    Then they remote control files that allow them to re-infect the website without using FTP.

    I typically find .php files, sometimes in the images folder. The file might be called gifimg.php or something else.

    If you have .php files on your site, then check them all for a string like this:

    eval(base64_decode

    Any files with that line in it "might" be bad and need further review.

    Post back here with any questions.
     
    WeWatch, Nov 24, 2009 IP
    mmads likes this.
  4. mmads

    mmads Well-Known Member

    Messages:
    225
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    130
    #4
    I will be looking into this more. Yhank you for the responses. Very helpful.
     
    mmads, Nov 24, 2009 IP