Malware - How Can it be Avoided?
I was just the victim of a malware attack on one of my sites. I have been able to get rid of most of it, except for in the blog, which I am still trying to clean up. I am nearly at the point of deleting it and starting fresh on the blog.
I am not sure how it got there in the first place. Can you tell me how I can prevent this from happening again?
Are there any good tools you can recommend for pinpointing all the infections so I can clean up the site.
Also, where can I report this issue to so that it can be dealt with? I do not want to say the domain name that caused the issue for 2 reasons. First is that it is a porn site and the domain name make reference to a woman's genitals and an action that goes with that. Second is that I do not want to advertise for them...
Any help you can offer would be appreciated.
Thanks
Wade
Wade
decibel.places posted this at 03:08 — 18th April 2009.
He has: 1,494 posts
Joined: Jun 2008
haha, like nuns?
ohhh, you mean genitals
decibel.places posted this at 03:16 — 18th April 2009.
He has: 1,494 posts
Joined: Jun 2008
Wade,
sorry, couldn't resist.
hmmm, I am not an expert on malware attacks on web sites
have you searched on the name of the bug?
I can see two ways for it to get into your code
1. You put it there by using some pre-written code that has the baddie in it waiting to be activated.
2. It was injected by insecure PHP forms that allowed it to be "added" to your files.
Given the nature of the site, there is a lot of shady sh*t going on, also cutthroat competition.
Again, a search on the bug's name can help you decide how to deal with it.
Restoring your site to a backup will fix scenario #2, but you will need to evaluate your security before you are infected again. It will do nothing if you are placing the malware there yourself.
err - what does this have to do with your financial site? if you want to promote it, a link in your sig is appropriate, you may not just add a project to an unrelated post...
greg posted this at 03:24 — 18th April 2009.
He has: 1,581 posts
Joined: Nov 2005
Also, the website the from the project you have attached in your post has malware.
I clicked the blog link on your site and was confronted with the "Attack Report Site".
So it seems more than one of your sites has been attacked. Are you using the same scripts on all sites? Perhaps a plugin in Wordpress? Or are all your sites being attacked for a reason?
Sometimes if you rub someone up the wrong way in a forum they can be vindictive and seek revenge, spamming or DOSing your site.
Wade Henderson posted this at 03:41 — 18th April 2009.
He has: 29 posts
Joined: Mar 2009
The site that is posted was the one that was attacked...this is the only one that that has had a problem.
It was originally on my index page, but that has been clean up, but I can not seem to get it off the blog. Like I was saying I am about to delete the blog and start fresh if I can not find a solution...
That is why I referenced this site, not as a ad, just as a reference to the site that I am having an issue with.
The plugin for word press is not the same as the other sites I have as they were done at different times.
I have changed all FTP and passwords but I would really like to know how to prevent this in the future.
Really makes me mad all the work that goes into our sites and then people do this kind of thing...
Wade
greg posted this at 04:20 — 18th April 2009.
He has: 1,581 posts
Joined: Nov 2005
I didn't realise the site in question was the attached project.
You don't need to attach a project to reference a site, a link in the thread is fine. Also, perhaps it's worth removing the project from TWF until you get the malware issue resolved, as Google claims it has 10 malicious software exploits downloaded and installed without user consent.
Not sure why you cannot get it off the blog.
If it's not just text in articles that need deleting then it might be in a script.
But it's somewhere in the code or article or database, and looking at your scripts should allow you to delete it and find the cause.
If it's directly in the blog files (page.php, archive.php etc) then it sounds like they have managed to write to your files.
If it's in the DB somewhere then they have gained access to that. Otherwise it might just be articles.
Prevention will come when you find out where the code is, and how they did it.
Brutal posted this at 08:40 — 22nd April 2009.
They have: 134 posts
Joined: Feb 2009
You should only be able - advise you hire a good php programmer, I think it will eliminate and prevent attacks in the future, because you will pay him money for this.
malwareremovals... posted this at 21:57 — 26th March 2012.
They have: 3 posts
Joined: Mar 2012
There's no way to be 100% secure, but if you follow the simple guidelines for Hardening Wordpress here: http://codex.wordpress.org/Hardening_WordPress, they will help, all though they are the very VERY minimum/basics. There are many tools you can use to secure your sites.
CJ Chamberland
Website Malware Removal Services
Mae Rose posted this at 05:51 — 4th April 2012.
They have: 31 posts
Joined: Feb 2012
It can be avoided by not surfing the Internet and not opening any unknown file executables.
Want to join the discussion? Create an account or log in if you already have one. Joining is fast, free and painless! We’ll even whisk you back here when you’ve finished.