Infected by code in index.php / index.html

General Discussion of atomic repo and development projects.

Ask for help here with anything else not covered by other forums.
DerFalk
Forum User
Forum User
Posts: 35
Joined: Wed Jun 25, 2008 5:15 am
Location: Good old Germany

Infected by code in index.php / index.html

Unread post by DerFalk »

Today my Sites were hacked :evil:

the infected all index.php / index.htm / index.html files with this crap:

Same as here: http://pastebin.com/E2NqcC0w

Someone seen this or can help what app this can cause?
Joomla? WP? proftp?
Thanx to all :)

DerFalk
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4155
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Infected by code in index.php / index.html

Unread post by mikeshinn »

Generally what you describe occurs via a compromised users password, which the badguys then use to upload the appended code via either FTP or SSH (usually FTP) via that stolen password. You may want to read this article:

https://www.atomicorp.com/wiki/index.ph ... ystem:_FTP

Appended code to index files is always an upload attack using a stolen password.
DerFalk
Forum User
Forum User
Posts: 35
Joined: Wed Jun 25, 2008 5:15 am
Location: Good old Germany

Re: Infected by code in index.php / index.html

Unread post by DerFalk »

Ok, after restore a backup, i will change all my passwords... :cry:
:evil:
Thanx to all :)

DerFalk
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4155
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Infected by code in index.php / index.html

Unread post by mikeshinn »

Check your desktops for malware too, if they stole your password 99.99999% of the time it from your desktop/laptop/etc. via a trojan. Also, if you use any tools that save your passwords make sure you dont save them anymore unless you rebuild your desktops from known trusted sources (and even then, dont save your passwords).
Post Reply