icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » All Things Techy » Site Maintenance » Website infected. Running malicious js file.

Site Maintenance Program updates, securing your website, creating backups.

Reply
 
LinkBack Thread Tools Search this Thread
Old January 9th, 2008, 4:25 AM   #1 (permalink)
Registered User
Fresh Surpasser
 
Joined in Mar 2006
2 posts
Gave thanks: 0
Thanked 0 times
Website infected. Running malicious js file.

If I clear all of my temporary internet files and go to my website, IE pops up a bar saying "The website wants to run the following add-on: 'Remote Data Services Data Control' from 'Microsoft Corporation'." And if I view the source, it shows that a ".js" file has been included after the "<body>" tag. The file name is made of random letters different each time and is only temporarily created. I've also checked that it occurs from multiple computers so it is not a problem with my local machine.

Has anyone seen this before? When I search online, I find acounts of it happening to other websites, but I can't find any information on the cause or a fix. My site that is getting the error is running Xoops 2.0 if that helps track down the cause. If anyone has any ideas about how to get thing under control, it would be appreciated.
theJuckett is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 9th, 2008, 2:49 PM   #2 (permalink)
Registered User
Comfy Contributor
 
schupp's Avatar
 
Joined in Oct 2004
Lives in Reykjavík/Toronto
Hosted on Pass16/18
168 posts
Gave thanks: 0
Thanked 0 times
I'll guess it is the init_basic.php exploit. My sites are getting hit 24/7 for it for several days now. I'm not vulnerable but they keep looking. Your site has been compromised and the crackers might now have shell access and can walk all over other people's sites (like mine).

You'll probably find all kinds of root kits, phishing scam files, etc. Suggest you shut down the site right away and hunt down all the problems you now have. If you have xoopsgallery then you should move or rename the directory right away as that is how they can get in.

You now have a lot of cleanup to do.
__________________
Pass16
Pass39
schupp is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 9th, 2008, 3:17 PM   #3 (permalink)
Operations
Super #1
 
Joined in Jun 2005
Lives in surpass headquarters
1,028 posts
Gave thanks: 67
Thanked 127 times
please contact our abuse team about this
https://desk.surpasshosting.com/inde...kets&_a=submit
__________________
Mike
Surpass Special Operations
Mike is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 9th, 2008, 4:40 PM   #4 (permalink)
Registered User
Fresh Surpasser
 
Joined in Mar 2006
2 posts
Gave thanks: 0
Thanked 0 times
Quote:
Originally Posted by schupp View Post
I'll guess it is the init_basic.php exploit. My sites are getting hit 24/7 for it for several days now. I'm not vulnerable but they keep looking. Your site has been compromised and the crackers might now have shell access and can walk all over other people's sites (like mine).

You'll probably find all kinds of root kits, phishing scam files, etc. Suggest you shut down the site right away and hunt down all the problems you now have. If you have xoopsgallery then you should move or rename the directory right away as that is how they can get in.

You now have a lot of cleanup to do.
I saw a bunch of logs trying to access a xoopsgallery module, but as far as I can tell I don't have that module installed. I'll report the abuse to surpass as suggested. Thanks.
theJuckett is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On