Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Warning: Iframe based attacks using stolen FTP access info

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #161  
Old 10-28-2008, 12:25 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Good lord man, don't post the hack code or the link to your site here! You trying to infect the whole community? I have removed it. Contact your host, it is easiest for them to remove it. Change your FTP passwords ASAP as mentioned above. Read the threads above, they explain what you need to do, but it is much easier to have your host help with this.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #162  
Old 10-28-2008, 12:29 PM
 
TWS Accessories TWS Accessories is offline
 

eXpert
  
Join Date: Sep 2004
Posts: 236
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by balinor
Good lord man, don't post the hack code or the link to your site here! You trying to infect the whole community? I have removed it. Contact your host, it is easiest for them to remove it. Change your FTP passwords ASAP as mentioned above. Read the threads above, they explain what you need to do, but it is much easier to have your host help with this.

Oopse, sorry!

I am at softlayer dedicated support - do you think they can help if I create a ticket or this is something I should just call firetank or x-cart about?

any suggestion would help.
Reply With Quote
  #163  
Old 10-28-2008, 12:30 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

X-Cart and Firetank won't be able to help you quick enough - this is an emergency that needs to be addressed ASAP. Hopefully your host is a responsive one.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #164  
Old 10-28-2008, 12:33 PM
 
TWS Accessories TWS Accessories is offline
 

eXpert
  
Join Date: Sep 2004
Posts: 236
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by balinor
X-Cart and Firetank won't be able to help you quick enough - this is an emergency that needs to be addressed ASAP. Hopefully your host is a responsive one.

Well, I'm going to create a ticket now and have them look at it. Should I ask them to check anything specific?
Reply With Quote
  #165  
Old 10-28-2008, 12:34 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Yes, you need to have them go through your whole site and remove the hack. Read the threads above, there are some specific commands that have been supplied by other hosts.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #166  
Old 10-28-2008, 12:38 PM
 
gravel gravel is offline
 

Senior Member
  
Join Date: Mar 2004
Posts: 156
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Man I can't believe this. I absentmindedly clicked on the impostercity link in the email notification from this thread and it opened in Firefox. I closed it immediately but I wonder if my computer is now infected. How do I check?
__________________
X-Cart version 4.0.17
X-Cart version 4.0.18
Web servers = Apache
OS = Linux
Reply With Quote
  #167  
Old 10-28-2008, 12:39 PM
 
TWS Accessories TWS Accessories is offline
 

eXpert
  
Join Date: Sep 2004
Posts: 236
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by gravel
Man I can't believe this. I absentmindedly clicked on the impostercity link in the email notification from this thread and it opened in Firefox. I closed it immediately but I wonder if my computer is now infected. How do I check?

your computer won't be hacked. Just clear your cookies before you go to your x-cart sites.
Reply With Quote
  #168  
Old 10-28-2008, 12:40 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

That is what I was afraid would happen Are you running anti-virus software? If so, run a scan asap and DO NOT log on to your site via FTP until you know you are clean.

Impostercity, you have no idea what you have done. Clicking on your site while infected downloads a keylogger on to any computer that accesses it. It has nothing to do with cookies, it is a VIRUS!
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #169  
Old 10-28-2008, 12:41 PM
 
TWS Accessories TWS Accessories is offline
 

eXpert
  
Join Date: Sep 2004
Posts: 236
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by balinor
Yes, you need to have them go through your whole site and remove the hack. Read the threads above, there are some specific commands that have been supplied by other hosts.


OK so remove the hacks from all .PHP files and by hacks, you mean the hit-counter link and the other iframe link/code? That is all?

I will read the rest thank you.
Reply With Quote
  #170  
Old 10-28-2008, 12:44 PM
 
gravel gravel is offline
 

Senior Member
  
Join Date: Mar 2004
Posts: 156
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

How can I be sure? What about the quote below?
Quote:
Originally Posted by pauldodman
When someone visits that site, their browser is detected and attacked (browsers affected are IE, firefox and opera). The visitor is unaware that they may have a keylogger that sends the persons passwords ect to the hacker(s) and moves on. If the innocent visitor has an ftp or root password for any internet sites, the hackers use a program that goes to the persons site(s) and instantly adds the hidden iframe to every index type page. This is why there seems to be no indication that the site has been compromised, as the hackers already have the ftp or root passwords to login. And since they have at least your account ftp pass, whatever permissions your folders and files are set to make no differ ence.
After they put the iframe code into that person's pages, anyone visiting that site will be redirected to the hackers infection site, where the person's computer will be injected and infected.
__________________
X-Cart version 4.0.17
X-Cart version 4.0.18
Web servers = Apache
OS = Linux
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 09:32 PM.

   

 
X-Cart forums © 2001-2020