homepage Welcome to WebmasterWorld Guest from 54.161.166.171
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Pubcon Platinum Sponsor 2014
Visit PubCon.com
Home / Forums Index / WebmasterWorld / Webmaster General
Forum Library, Charter, Moderators: phranque & physics

Webmaster General Forum

    
Web Site has been hacked
Junk files added after </html> on Home page
Senmar50




msg:3866696
 9:40 pm on Mar 9, 2009 (gmt 0)

Hi,

The home page of my web site has been hacked. At the end of the page, after the </html>, all kinds of links are listed. The home page has at least 500-600 of the junk links. When you open my web page, windows ask if you would accept an "Add-On" script. I just said no, because I didn't add anything. I downloaded the home page to my computer, and removed the bad files. What can I do to make sure, it will not happen again.
Thanks,
Senmar

[edited by: phranque at 9:57 pm (utc) on Mar. 9, 2009]
[edit reason] No urls, please. See TOS [webmasterworld.com] [/edit]

 

Demaestro




msg:3866763
 10:58 pm on Mar 9, 2009 (gmt 0)

Go through your raw access files and search for PUT or webdav

Chances are however they changed the file they used a PUT or some webdav vulnerability.

Once you find how they did it you will be able to answer how to stop it from happening again.

dreamcatcher




msg:3866779
 11:42 pm on Mar 9, 2009 (gmt 0)

Is it a shared server attack from another site? Moving to a dedicated server or another host is probably your best bet.

dc

Senmar50




msg:3866808
 12:45 am on Mar 10, 2009 (gmt 0)

I just found in my root directory a "php" file listing all the links that appeared at the end of my web pages:

<?
phpinfo()
?>
<u style=display:none</a>LOTS OF LINKS</u>..

I also found out that all the "html and php" files in the root directory were hacked. The bottom of all these pages listed the links that were in the "php" file.

I cleared the links from all the hacked pages; and deleted the php file. Everything seems to be alright for now. How do I secure my root directory? This is the first time I've been hacked, after six years.

Thanks for your help...
Senmar

phranque




msg:3866896
 3:26 am on Mar 10, 2009 (gmt 0)

you might find useful information in the following WebmasterWorld threads.

Hacker gets access to server. How?:
[webmasterworld.com...]
How Hacked Servers Can Hurt Your Traffic:
[webmasterworld.com...]
Securing A Linux Web Server:
[webmasterworld.com...]

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / WebmasterWorld / Webmaster General
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved