Topic: My Site Being Attack

Hello All,

This is the second time my sites had been attacked.. Im not so sure if it was done via SQL injection or what.
All the indexes on my hosting have script viruses.

Can some one please recommend me steps to further the security of my sites.

I barely have knowledge regarding this but I thought fluxBB was secure and away from SQL injection attacks.. So what other ways can the attacker get thru?

Thanks for the inputs, whatever it is it would be valuable to me right now.. sad

Im not really sure what is causing this problem, but I definetly want to put a stop on it asap.

Re: My Site Being Attack

If they're altering the scripts themselves, you probably have either a shonky host or other insecure services/scripts running on the server.

Screw the chavs and God save the Queen!

Re: My Site Being Attack

the only php site running that time.. a while ago.. was fluxbb..
How can I know if they are altering the scripts themselves? so transfering host will solve the problem?

too bad.. i like that host it's cheap and really faster than expensive known ones..

Thanks for the help mattF..

Re: My Site Being Attack

I never said PHP scripts. I merely said scripts. There will be a damned sight more running on that server than merely your forum.

As to what, specifically, they are altering, that is for you to tell us. It's your host and we ain't psychic, hence only you know the answer to that. Are they altering the DB itself? Are they altering the flatfiles? What is in your server logs? There are no known exploits in Flux, so you would most likely be better off discussing this matter directly with your host and seeing what they say.

Last edited by MattF (2009-06-02 10:45:44)

Screw the chavs and God save the Queen!

Re: My Site Being Attack

Well they said it only happened to my sites.
and I dont know how to look at the server logs they are mostly bots. not much traffic still cause havent launched the sites yet..

Is it possible for me to infect my sites? or my sites infected me? my computer has trojan in it right now. dont know if its the site.

Last edited by joe.banana (2009-06-02 11:52:10)

Re: My Site Being Attack

Again, which part of your site, exactly, is being altered?

Last edited by MattF (2009-06-02 12:02:08)

Screw the chavs and God save the Queen!

Re: My Site Being Attack

index.html and index.php scripts are being inserted all over the index files..

Re: My Site Being Attack

Are you on a shared host?

Re: My Site Being Attack

Yes im on a shared host.. but how come the virus was only on my site and all the index files even those hidden index files..

and i use password managers so even i cant remember my passwords.

Re: My Site Being Attack

How do you know the "virus" was only on your site? My assumption on a shared host would be that it was part of a mass defacement of index files (plenty of backdoor scripts have that functionality)

If you're convinced the problem was FluxBB, look for files that shouldn't be there (especially PHP files). If the problem is with FluxBB, you'll find a backdoor script somewhere that allowed someone to do this.

Re: My Site Being Attack

nope there is no other files only indexes were modified.. Also while googling I found this..

http://www.bluehostforum.com/showthread.php?t=16810

I think its this one.. but how do i prevent such things from further happening? Ive been hit twice..

Re: My Site Being Attack

Well, that page suggests that the issue is a virus on your computer which is using the passwords you save and modifying your website. So, if that's the case, the solution is to change your passwords and remove the virus from your computer. wink

However, defacement of only index files suggests that it was not a virus, which would instead target any files it could. It's much more likely to be something with your host. You still haven't told me how you know that no other sites on your shared server were compromised.

Re: My Site Being Attack

Contacted the hosting company..
im not 100% sure if that's the case but I did got hit with a virus AFTER my site was hacked.


However, defacement of only index files suggests that it was not a virus, which would instead target any files it could. It's much more likely to be something with your host. You still haven't told me how you know that no other sites on your shared server were compromised.

So what was it if it wasnt a virus? someone is hacking and fooling around with me?

Re: My Site Being Attack

joe.banana wrote:

nope there is no other files only indexes were modified.. Also while googling I found this..

http://www.bluehostforum.com/showthread.php?t=16810

I think its this one.. but how do i prevent such things from further happening? Ive been hit twice..

Some things the BlueHost post didn't mention:

(1) Don't use Adobe Acrobat as your default program to read PDF's - use something less common like Foxit Reader instead.
(2) If you must use Adobe Acrobat, go into the options and ensure Javascript within PDF's is disabled.
(3) Use another default browser - eg Opera or Firefox to browse the web.
(4) Change the passwords you use on the server for FTP access to your site immediately if you think you are under attack, and do so regularly (eg once per month) in future.
(5) Check to see if any new and unauthorised users have been created within your account that may have access to FTP for example, and delete them.
(6) Do not - repeat do not - store your passwords for FTP, SSH etc on your computer anywhere.
(7) If you can do so (depends on your host) only allow access to FTP, SSH, or your web-based site control panel etc from IP address ranges that match yours (eg the IP range of your ISP).

etc etc.

Re: My Site Being Attack

sirena wrote:

etc etc.

(8) As you type your password, do not whisper or think of it wink

Bert Garcia - When all you have is a keyboard

Re: My Site Being Attack

Just out of curiosity. Are you actually infected with the Trojan mentioned in that link you posted?

Screw the chavs and God save the Queen!

Re: My Site Being Attack

thanks for the inputs guys so far its quite now.. but the slow cs response made me switch to another hosting, that was an eyeopener for me..

i was infected with trojan win32.arsm i think its a diff one, google search yielded very little info regarding this.. my proquota.exe was infected which wasnt seen by avira but caught by kaspersky online scanner. deleted the file and took a new exe from different computer, i guess this will work for now until i do a clean format.

Also microsoft malicous removal tool didnt saw it.

Re: My Site Being Attack

hcgtv wrote:
sirena wrote:

etc etc.

(8) As you type your password, do not whisper or think of it wink


....even if you are wearing your tin-foil hat ;^)

TwoHawks
Love is the Function.
No Form is the Tool.