BugTraq
what is this? Jan 13 2008 04:01PM
crazy frog crazy frog (i m crazy frog gmail com) (5 replies)
Re: what is this? Jan 16 2008 08:57AM
Yousef Syed (yousef syed gmail com)
Re: what is this? Jan 15 2008 05:16AM
Denis (sp23 internode on net) (3 replies)
RE: what is this? Jan 15 2008 04:33PM
Memisyazici, Aras (arasm vt edu) (1 replies)
Re[2]: what is this? Jan 15 2008 04:41PM
Denis (sp23 internode on net)
Re: what is this? Jan 15 2008 04:28PM
Jamie Riden (jamie riden gmail com)
Re: what is this? Jan 15 2008 06:12AM
crazy frog crazy frog (i m crazy frog gmail com) (2 replies)
Re[2]: what is this? Jan 15 2008 05:26PM
none (updates digitalis com au)
Re: [Full-disclosure] what is this? Jan 15 2008 06:45AM
Nick FitzGerald (nick virus-l demon co uk) (1 replies)
Re: [Full-disclosure] what is this? Jan 15 2008 08:26AM
crazy frog crazy frog (i m crazy frog gmail com) (1 replies)
Re: [Full-disclosure] what is this? Jan 15 2008 05:22PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: [Full-disclosure] what is this? Jan 15 2008 05:24PM
crazy frog crazy frog (i m crazy frog gmail com)
Re: what is this? Jan 14 2008 09:46PM
Gadi Evron (ge linuxbox org)
Re: what is this? Jan 14 2008 03:44PM
Jose Nazario (jose monkey org) (3 replies)
Re[2]: [Full-disclosure] what is this? Jan 14 2008 09:39PM
3APA3A (3APA3A SECURITY NNOV RU)
RE: what is this? Jan 14 2008 07:09PM
Mario Contestabile (marioc computer org)
Re: what is this? Jan 14 2008 03:56PM
crazy frog crazy frog (i m crazy frog gmail com)
Re: [Full-disclosure] what is this? Jan 14 2008 09:34AM
3APA3A (3APA3A SECURITY NNOV RU) (1 replies)
Re: [Full-disclosure] what is this? Jan 14 2008 11:52AM
Nick FitzGerald (nick virus-l demon co uk) (1 replies)
Re: [Full-disclosure] what is this? Jan 14 2008 01:56PM
crazy frog crazy frog (i m crazy frog gmail com)
hmm.thanks everyone for the suggestions.

On Jan 14, 2008 5:22 PM, Nick FitzGerald <nick (at) virus-l.demon.co (dot) uk [email concealed]> wrote:
> 3APA3A wrote:
>
> > Dear crazy frog crazy frog,
> >
> > Clear your computer from trojan, change FTP password for you site
> > hosting access, because it's stolen, access your hosting account via
> > FTP and remove additional text (usually at the end of the file, after
> > </html>) from all HTML/PHP pages.
>
> Ummmm -- the only part of that likely to be relevant here is the last.
>
> These kinds of web page "compromises" are typically achieved through
> bad/ill-configured/non-updated server-side web applications (or their
> underlying script engines) and are typically achieved without requiring
> any more special or privileged access to the victim sites than the
> ability to run a clever Google search or your own brute-force spidering
> via a bot-net, etc.
>
> Of course, simply removing the undesired iframe/script/etc tags from
> your compromised pages is not enough. Although doing so does not mean
> that this attacker will come back, it equally does nothing to close the
> hole they used in the first place, and the next attacker searching for
> that hole will hit you just as easily and indiscriminately...
>
>
> Regards,
>
> Nick FitzGerald
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

--
advertise on secgeeks?
http://secgeeks.com/Advertising_on_Secgeeks.com
http://newskicks.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus