store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 11:41 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 14 posts ] 
Author Message
 Post subject: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Tue Feb 17, 2009 8:54 pm 
Offline
Forum User
Forum User

Joined: Tue Jan 15, 2008 9:01 am
Posts: 26
Hello,

I'm running a server with Plesk 8.3, Centos 5.2, ASL (kernel 2.6.26.6-1.art.i686, mod_security mod_security-2.5.7-1, etc) and PHP 5.2.6

I have one site hacked, and I can't out find how it was done.

All index.* files now have a iframe injected after the body tag.

The files are not world writeable, and the owner is the site user (plesk default)

The iframe contains this src: "http://bestlotron.cn/in.cgi?cocacola60"

I have looked at every log file I could remember, but I didn't find any clue (no FTP, no file injection in PHP pages, etc).

There are no mod_security log entries that could be possible related to this issue either.

I'm wondering if the problem is related to the PHP version, or any PHP setting, plus some flaw in the code's PHP pages.

Any help will be welcome.

Thank you.
Alexandre


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Tue Feb 17, 2009 9:25 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
First thing to do is look at the time stamps on the files and then look at who logged in at those times. Every iframe case we have dealt with was a straight login to the system through FTP or SSH where the attacker simply stole a password via a keylogger on a desktop.

Let us know what you found, and if you need our team to login to your box please let us know. If you prefer to do this via email please send an email to support@atomicorp.com.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Sat Feb 21, 2009 5:28 am 
Offline
Forum User
Forum User

Joined: Fri Feb 06, 2009 9:19 am
Posts: 38
which site is it? and what have you on it?


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Sat Feb 21, 2009 10:45 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
As an aside, so far 100% of the cases we've seen with this happening have been straight logins by the badguys. If you find an iframe at the bottom of a file thats the MO for that kind of login - they steal a username/password from a users desktop with a keylogger, then hit the users sites (because again the keylogger told them what they logged into) and they just feed all these site+username/password combos into a script and put their junk on the bottom of all the index.php and index.html files. In short, its not really a hack - that is to say its not a vulnerability in the technical sense - its a very simple attack on the users site by just logging with the users legitimate account. Not much you can do about that without getting into setting up rules to limit what IPs that user can come from, rules on the time they login, etc.

We're working on a one time password addon for ASL that can help to protect your users from password theft. No timeline on when that will be available, we'll post more when we have sometime to share.

In the mean time, if you see this for only ONE of your vhost sites - you can be pretty sure its that someone just logged into that site and changed its files and not the box was hacked or otherwise broken into.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Sun Feb 22, 2009 10:30 am 
Offline
Forum User
Forum User

Joined: Tue Jan 15, 2008 9:01 am
Posts: 26
Hello,

Thank you all for your updates.

In fact I already had another case a couple of months ago.

At this time I have made a similar search and I didn't found anything too.

I have assumed that the problem was related to the user's computer (files changed locally in this computer) or some password compromised.

I have asked the client to changed this password and check his computer for virus.

But now I have another case with the same pattern (but with different "virus"): some pages within a site with some added content, that shows a virus message in my computer everytime it is loaded (I'm using Avast AV).

That's why I'm concerned about this issue, since I couldn't determine for sure what really happened in both cases.

Thank you.
Alexandre


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Mon Mar 02, 2009 7:48 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Would you like us to take a look at your logs?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Tue Mar 03, 2009 9:56 am 
Offline
Forum User
Forum User

Joined: Tue Jan 15, 2008 9:01 am
Posts: 26
Hello Michael,

Yes, it would be very nice.

I have already granted access (installed your ssh keys) and sent the server information to our support email a couple of weeks ago.

If you don't have this information anymore I can send it again.

Thank you.
Alexandre


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60
Unread postPosted: Tue Mar 03, 2009 7:31 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Yes, please send a heads up to support@atomicorp.com and we can take a look at it tomorrow.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Thu Mar 05, 2009 10:29 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
As a followup for anyone else interested in this one it was a simple case of the users password having been stolen and the bad guys just logged into the account and added the iframes to the end of the php files. No vulnerability in the system.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Thu Mar 05, 2009 11:35 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Thanks, that's good to know.

I'm sure zooming is relieved about that too!

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Thu Mar 05, 2009 12:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Other followup on this, some of my counterparts in the Cpanel community told me that there is a botnet that is automating this. They've had over 1000 separate domains get caught by this same exact attack. Looks to me like malware is owning desktops, and looking for people who store ftp credentials for hosting environments specifically.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Thu Mar 05, 2009 1:09 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 10, 2006 12:55 pm
Posts: 656
scott wrote:
Other followup on this, some of my counterparts in the Cpanel community told me that there is a botnet that is automating this. They've had over 1000 separate domains get caught by this same exact attack. Looks to me like malware is owning desktops, and looking for people who store ftp credentials for hosting environments specifically.


Sounds very similar to what happened to auctiva.com a couple of weeks ago. The Chinese are getting some nasty hacks in.


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Fri Mar 06, 2009 9:20 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Yeah. A large proportion of the attacks that I look into (as opposed to the ordinary ones that happen every few mins) are from China at the moment. We are considering blocking China completely, having already done so for certain other hotspots (though those are mostly skiddie hostpots rather than the real blackhat crowd)

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Site Hacked - PHP Iframe Exploit - cocacola60 [SOLVED]
Unread postPosted: Fri Apr 03, 2009 1:27 pm 
Offline
Forum User
Forum User

Joined: Tue Jan 15, 2008 9:01 am
Posts: 26
Just for the record, the client has changed his password and I haven't any other incident since.

Thank you!
Alexandre


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 14 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group