Author Topic: Very Frustrated...Websites Compromised  (Read 67016 times)

0 Members and 1 Guest are viewing this topic.

July 12, 2009, 06:17:44 pm
Reply #15

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 13, 2009, 01:15:37 am
Reply #16

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

I also read you can do something with the .HTACCESS file?

Is this true?

I deleted the entire websites that were affected and will be running ALL the scans you suggested tonight.

Once I get the OK from that site you suggested (that my computer is ok), I will re-load the sites with the new passwords.

Derek

MyseryFCM - I send you a private email question (sorry, meant to post here).

July 13, 2009, 01:17:43 am
Reply #17

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
I also read you can do something with the .HTACCESS file?

Is this true?

This is indeed true, yes. This file has been known to be modified to redirect to malicious sites, so should also be replaced with a backup if possible.

MyseryFCM - I send you a private email question (sorry, meant to post here).

No problem :)
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 13, 2009, 01:30:13 am
Reply #18

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

By the way, I checked my serve and I do not have a .HTACCESS file.

Is this a problem?

DN

July 13, 2009, 01:33:52 am
Reply #19

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 14, 2009, 08:26:56 pm
Reply #20

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

Ok, my Hijack This log was checked and clean.

They also made me do three other scans, all of which were clean.

I am not sure I understand the tutorials for the htaccess.

Do I need one for it to work?

Thanks,

DN

July 14, 2009, 08:30:33 pm
Reply #21

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
You don't need a .htaccess, no. It is generally recommended however.

Now your machine has the all clear, you can delete the files on the server, and replace them with the clean backups :) (assuming your FTP password has been changed now?)
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 15, 2009, 11:46:26 am
Reply #22

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

Before I started the malware check on my computer, I went on all three servers that I deal with and deleted the files.

I checked my files on my computer and they are clean.

The company I deal with changes the passwords and emails to me so I should get them today.

I have done everthing you suggestion.

I hope this ends the problem.

Thanks,

Derek

July 15, 2009, 05:52:35 pm
Reply #23

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 16, 2009, 11:44:58 pm
Reply #24

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

I see this line in one my pages:

<!-- saved from url=(0022)http://internet.e-mail -->

Does it mean anything?

DN

July 16, 2009, 11:53:50 pm
Reply #25

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
That means the page was saved from somewhere else.

Is the file one of yours? (can you post a copy of it? (zipped please))
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 20, 2009, 12:18:44 am
Reply #26

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

They are the files from my computer.

They appear to be on all my files.

Thanks,

DN

July 20, 2009, 02:23:34 am
Reply #27

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Where the files obtained from? (i.e. did you use a crawler or such, to backup an online copy of your site).

My reason for asking is that the line in question, is only ever seen, when a downloader of some description, has been used to create an offline copy of a website. It is highly unusual for files to contain this otherwise.
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 20, 2009, 02:44:09 am
Reply #28

#41baby

  • Jr. Member

  • Offline
  • **

  • 14
Hello,

I have no idea.  I create the site on my computer and upload it to the server.  I never had a back-up.

What should I do with that line?

Can I delete it?

DN

July 20, 2009, 04:01:55 am
Reply #29

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
You can delete that line, yes :)
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net