1
gzekovic
Virus is blocking a page! Help needed
  • 2006/2/4 16:21

  • gzekovic

  • Just popping in

  • Posts: 3

  • Since: 2005/1/23


I am administering a XOOPS 1.3.10 page on the address www.legalis.hr

Problems started couple of days ago when page refused to load and every time blocked an Internet Explorer.

First I thought that there are some problems with hosting firm. I conntacted tech support and they notified me that I have a virus in httpdocs folder that is overwriting a index.php file of a page and is spreading to the visitors computers that way. I have checked there and found several new files there: help.zip (probably the source of virus), new Index.php (80 kb instead of 3kb), and files named: a.php, a.pl and a.asp. Same thing happend in the httpdocs => class folder with the small difference that here an Index.html file was changed same way.

Page works again after I delete those files and overwrite index.php with the original file, but within couple of hours same thing happens again. Last time (fifth time) couple of other folders and all their subfolders become infected too.

Tech support notified me that that way I am spreading virus to all the visitors of the page that do not posses an adequate antivirus protection.

I tried to search more information about that type of virus and infection on the web but found nothing useful.


Please help.

2
Herko
Re: Virus is blocking a page! Help needed
  • 2006/2/4 16:25

  • Herko

  • XOOPS is my life!

  • Posts: 4238

  • Since: 2002/2/4 1


Are you on a shared server? Are there other accounts on that server? Then it's a big possibility that the whole server is compromised. The malicious script is probably infecting other websites on that server too.

Have your tech support look into this! They need to find the point of entry, where the malicious script resides and how it got there.

Herko

3
gzekovic
Re: Virus is blocking a page! Help needed
  • 2006/2/4 16:44

  • gzekovic

  • Just popping in

  • Posts: 3

  • Since: 2005/1/23


Thanks Herko,

that is a shared server. See what tech support says:

Message 1:
The file /home/httpd/vhosts/legalis.hr/httpdocs/index.php contains or is trying to load a virus. Our anti-virus system picked it up immediately when trying to load your site. A few files and folders on your site were modified on 01/02/2006 and I see old files from 2003. I believe you are using an old version of xoops. If so, it probably has security vulnerabilities which someone exploited to gain access and modify files on your domain. Please always keep your scripts up to date to avoid situations like this.

Any visitors to your site over the past couple of days, who are not running any anti-virus software, will have been infected with the virus.


Message 2:

Unfortunately we cannot trace how the script was exploited. I suggest either upgrading the XOOPS installation or stop using it as it will more than likely occur again now that hackers are aware of your vulnerable installation.


I do not know what to think anymore. Originally that was 1.3.8 instalation upgraded to 1.3.9. When that happend I patched it to 1.3.10 but same thing is happening again.

Site is Hosted with a preety high tech US hosting company and I beleive that they posess quite good virus protection.

Thanks for any suggestion.

4
Poslanik
Re: Virus is blocking a page! Help needed
  • 2006/2/5 10:03

  • Poslanik

  • Just popping in

  • Posts: 95

  • Since: 2005/2/11


Why aren't you using XOOPS 2.0.x at least?

5
gzekovic
Re: Virus is blocking a page! Help needed
  • 2006/2/5 17:15

  • gzekovic

  • Just popping in

  • Posts: 3

  • Since: 2005/1/23


Quite simple reason. Site was built at 1.3.
And worked fine for couple of years.

Login

Who's Online

163 user(s) are online (129 user(s) are browsing Support Forums)


Members: 0


Guests: 163


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits