If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
These forums remain online primarily for archival purposes. While posting is still possible, it should not be considered a means for support. Please login to our portal and submit a ticket if you require assistance and we'll be more than happy to assist you.
Regular updates are posted to our blog and we will continue to post important notices to the Script Security forum section here. You can subscribe to that forum to automatically receive notifications.
A site I host (clawhon.com) keeps getting hacked. They are not using any PHP scripts from what they say. In the root level (www) "a.exe" and "i.html" keeps popping up even though they delete them daily. The files look like they are spyware and their unique visitors that are accessing these files are 200,000+.
If you have a recent copy of your site, I'd say delete EVERYTHING,
reset the password in WHM, and then upload each file after you've checked it manually.
Make sure no hidden backdoors. Besides that, thats only thing I can think of.
"How can someone be so distracted yet so focused?"
- C
Looks like your site was flash based? Your flash site didn't need any backend access to database or anything? If you don't think it was a script exploit then the other possibilities are (in order of likelihood):
Some else you gave access too?
Home computer compromised?
Server compromised?
First start at home make sure your computer isn't compromised and then change your account passwords. Revoking all other user access in the process. If the server was compromised you wouldn't be the only one effected ... so check WHT.
"Whatcha mean I shouldn't be rude to my clients?! If you want polite then there will be a substantial fee increase." - Buddha
Send trouble ticket to support and ask them to investigate who and when accessed site in period you know it was hacked. That info could lead to attacker and means he used to attack you.
Send trouble ticket to support and ask them to investigate who and when accessed site in period you know it was hacked. That info could lead to attacker and means he used to attack you.
Wow, support does that? Is it free/paid? Dathorn keeps getting better and better.
"How can someone be so distracted yet so focused?"
- C
Once I had suspiction that account was compromised I asked them for help and they did help. They looked for me what IP's were used to access that account. Noone mentioned payment.
Comment