|
|
#1 (permalink) | ||
|
Registered User
Fresh Surpasser
Joined in Nov 2004
19 posts
Gave thanks: 0
Thanked 0 times
|
Just received 3 e-mails with viruses from surpass
I'm assuming that they are not from surpass administrators, but if they are not, I have a major security hole in my website, as the headers show the email originating from a surpass server. I receieved the following:
Subject: Account Alert Body: We attached some important information regarding your account. Headers: Quote:
Subject: *WARNING* Your e-mail account will be closed. Body: We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached. Headers: Quote:
I got two more sent with the same style.. When I first saw that a virus was attached, I expected to see something else in the headers, but it appears as if I sent it to myself, or someone got into my account and sent it to me. I understand that this probably wasn't the administration who sent this to me, but I am seeking better ways of protecting my site from and intruders, or any explanation as to how this may have occured! Thanks! |
||
|
|
|
|
|
#2 (permalink) |
|
after g, before i
Resident.
Joined in Jul 2004
Lives in N,BC,CA
8,058 posts
Gave thanks: 48
Thanked 129 times
|
What scripts are you running on your site? Have you checked various folders for any unrecognized files or even folders you don't remember putting there?
I'm pretty sure e-mail from Surpass would be going through the main Surpass Hosting server. Also, note the e-mail adresses in the "From:" part. They're "service" and "admin" at your domain. I think that gives a pretty good clue someone else is sending these e-mails. Also remember that it could potentially be another account on your server sending the e-mails. |
|
|
|
|
|
#3 (permalink) | |
|
Registered User
Fresh Surpasser
Joined in Nov 2004
19 posts
Gave thanks: 0
Thanked 0 times
|
Quote:
All the folders look the same.. I am the only one with an e-mail address on my account.. I'm assuming someone got my password somehow.. |
|
|
|
|
|
|
#4 (permalink) |
|
after g, before i
Resident.
Joined in Jul 2004
Lives in N,BC,CA
8,058 posts
Gave thanks: 48
Thanked 129 times
|
If you're running any PHP scripts like phpNuke, phpBB, etc... Something like that, they could have found an exploit to send e-mails from your server, or perhaps buried a script somewhere to do it.
You might want to e-mail support or abuse about it and have them check it out. You can do that at http://desk.surpasshosting.com/ |
|
|
|
|
|
#5 (permalink) | |
|
Registered User
Comfy Contributor
Joined in Mar 2004
Lives in Herts, UK
Hosted on Webdev & SH108
111 posts
Gave thanks: 0
Thanked 0 times
|
Quote:
Last edited by zogger; June 7th, 2005 at 4:27 PM. |
|
|
|
|
|
|
#6 (permalink) | |
|
after g, before i
Resident.
Joined in Jul 2004
Lives in N,BC,CA
8,058 posts
Gave thanks: 48
Thanked 129 times
|
Actually, that makes sense Zogger. I just checked some headers in my e-mail and it's very similar. I recieved an e-mail from buddhapuss.
Quote:
|
|
|
|
|
|
|
#8 (permalink) |
|
Registered User
Fresh Surpasser
Joined in Oct 2004
5 posts
Gave thanks: 0
Thanked 0 times
|
You've been hacked just like me. Fooled into opening a zip? You've installed a trojan that is downloading all your hard drive info to the perpetrator. Your virus scanner will not see it because it is custom made to target only Surpass email accounts and not a part of general virus attacks. Demand that Surpass supply you with a utility to remove the virus that has been installed on your computer and for godsake, unplug your computer from the internet until you're clean.
|
|
|
|
|
|
#9 (permalink) | |
|
Surpass Abuse Admin
Super #1
Joined in Mar 2005
Lives in Houston, TX
Hosted on NONE
7,794 posts
Gave thanks: 10
Thanked 277 times
|
Quote:
Chances are it's just this. I've seen hundreds of these over the last month: http://securityresponse.symantec.com...ober.o@mm.html
__________________
Unofficial IRC Channel: #surpass EFNetUnofficial = No official support. Support requests can be submitted to our helpdesk. |
|
|
|
|