Go Back   HostGator Peer Support Forums > HostGator Announcements > Network Status

Notices

Reply
 
Thread Tools
  #1  
Old 04-22-2008, 10:13 PM
Sonikempire Sonikempire is offline
Hatchling Croc
 
Join Date: Jan 2007
Posts: 20
Default iframe issue [edited]

Is anyone else experiencing issues with their sites on gator109. All of my pages have a suspect iframe code in it and they all redirect to a site.

security is working on it, hopefully they can restore it.

This sucks.
Reply With Quote
  #2  
Old 04-23-2008, 12:11 AM
Sonikempire Sonikempire is offline
Hatchling Croc
 
Join Date: Jan 2007
Posts: 20
Default Re: gator109 hacked

Talked to security@hostgator.com, and they can't save the files. They scanned and cleaned like 11,000 files but the site still redirects to a malicious site.

They can't restore it to a previous backup because of some large inode.
What am i left here with?

1. Move to another host and start fresh?
2. Stay here and start fresh?
3. Kill myself and not deal with this headache?

Whoever can help, the existing ticket number is FFM-2596687.

You guys had harder problems in the past, please try to restore my site. I put years of work into it, please!
Reply With Quote
  #3  
Old 04-23-2008, 12:36 AM
jimbug's Avatar
jimbug jimbug is offline
Baby Croc
 
Join Date: Jan 2008
Location: California, USA
Posts: 83
Default Re: gator109 hacked

1. Could you describe the problem exactly.
____a. One or more lines added to your files.
____b. The hacker has overwritten lines or just added to the file?
2. Give an example, something that shows the hack.
3. What file types affected (php, html, etc.).
4. Do you have shell access?
__________________
Jim
http://www.jimbug.org/
Reply With Quote
  #4  
Old 04-23-2008, 02:51 AM
striddy's Avatar
striddy striddy is offline
Veteran Croc
 
Join Date: Mar 2008
Location: /home/australia/earth
Posts: 4,093
Default Re: gator109 hacked

Quote:
Originally Posted by Sonikempire View Post
They can't restore it to a previous backup
Do you not have current backups (plural) of your own?

__________________
- David
Reply With Quote
  #5  
Old 04-23-2008, 03:22 AM
GatorFord's Avatar
GatorFord GatorFord is offline
HostGator Staff
 
Join Date: Jan 2007
Location: Houston, TX
Posts: 1,548
Default Re: gator109 hacked

This appears to be just one particular account that was defaced. Not the whole server. Our security department is working with you at this time.

This is almost always due to :

1. Out of date scripts.
2. Insecure passwords.
3. Improper storage of passwords.
4. Trojans/keyloggers on your machine.
5. Sharing passwords with a "webmaster" or other developer who may want to use your account for rogue purposes.

Regardless, our Security department will get this handled for you. Please just update the ticket if you have any further questions or concerns and your peers here in the forums can also help you.

Keep in mind that if you need to fully roll back to NAS backups you can fill out the form at http://hostgator.com/restore.php

Although, if it is restored, and they were able to deface it originally, it will likely happen again unless you take some proactive steps to prevent it.
__________________
Ford M.

Folding@Home Stats :
Reply With Quote
  #6  
Old 04-23-2008, 07:23 AM
Sonikempire Sonikempire is offline
Hatchling Croc
 
Join Date: Jan 2007
Posts: 20
Default Re: gator109 hacked

Every file (html, php) other than images, videos, etc are have an iframe script in them. The site currently is still redirecting to the malicious site, and possibly trying to install malware.

I'm thinking that the problem was the /gallery because cpanel didn't let me update it, and manual update would always give me errors.

As for the backup, the $15 is not a problem, but to what date will it be restored? Right before the problem happened? or weeks/months earlier?

Thanks

Last edited by Sonikempire; 04-23-2008 at 10:09 AM.
Reply With Quote
  #7  
Old 04-23-2008, 08:15 AM
jacci's Avatar
jacci jacci is offline
Hatchling Croc
 
Join Date: Mar 2008
Location: Sydney
Posts: 18
Default Re: gator109 hacked

I got done too and i am on gator418. Moving host is not the answer i beleive, as i got done with the same kind of iframe insertion on my old host as well.

My old host told me bad luck boo hooo. Hostgator helped me clean files i missed as well as showed me how to increase security so that seomthing like this is harder to happen again. They had been really wonderful, and about 100 times more helpful than my last host.

Hacking is part of life on the net (sad reality that that is) and it is always a nightmare. Lucky i am a backup demon so it was just a matter of reupload for me.

I would have to commend the hostgator support for their help when this same thing happened to me, the iframe was inserted into every php and html file on the site
Reply With Quote
  #8  
Old 04-23-2008, 10:09 AM
Sonikempire Sonikempire is offline
Hatchling Croc
 
Join Date: Jan 2007
Posts: 20
Default Re: gator109 hacked

They are working on it. Hopefully they will be able to restore it.
Reply With Quote
  #9  
Old 04-23-2008, 10:54 AM
GatorFord's Avatar
GatorFord GatorFord is offline
HostGator Staff
 
Join Date: Jan 2007
Location: Houston, TX
Posts: 1,548
Default Re: gator109 hacked

In the case of a hacked or defaced page the restoration process from our NAS server will be free (the 15$ fee) will be waived.

I'm notifying our upper tier security admins on this to further assist you guys. Thanks again for your patience.
__________________
Ford M.

Folding@Home Stats :
Reply With Quote
  #10  
Old 04-23-2008, 10:58 AM
jonel's Avatar
jonel jonel is offline
Junior Croc
 
Join Date: Mar 2008
Posts: 131
Default Re: gator109 hacked

Quote:
Originally Posted by jacci View Post
Lucky i am a backup demon so it was just a matter of reupload for me.
I also wanted to create some backups, but I don't know how to do it. I have my site running in database. I try one time to backup my entire site, I think I made a success on it but to restore the site in database is another thing. My question is, how to create backups that are easy to restore?
Reply With Quote
  #11  
Old 04-23-2008, 11:07 AM
jacci's Avatar
jacci jacci is offline
Hatchling Croc
 
Join Date: Mar 2008
Location: Sydney
Posts: 18
Default Re: gator109 hacked

I use phpmyadmin and export my databases, saving them on my hardrive. I usually do this every 2 days or so, (every day when I am being good).

To restore them, i just drop whatever is my corrupted database, leaving it empty and then run the import command to upload the backup. It is easy as. Got abuout 10 databases for forums, guestbooks, efiction, galleries and wikis and never have any trouble restoring them using that procedure.

I also do a site dump every month or so using the backup home directory in the cpanel.

I am new to hostgator and i notice that that backup aslo has a facility to do the databases too, although i am still doing manually as i know the restore procedure through myphpadmin works without me having to modify anything. don't know about the other one yet
__________________
pretendercentre
Reply With Quote
  #12  
Old 04-23-2008, 01:38 PM
GatorJamyn
HostGator Guest
 
Posts: n/a
Default Re: gator109 hacked

I've taken a look at/cleaned both accounts. If you see outstanding issues, let me know and I'll take care of it. Thanks.
Reply With Quote
  #13  
Old 04-23-2008, 09:59 PM
Sonikempire Sonikempire is offline
Hatchling Croc
 
Join Date: Jan 2007
Posts: 20
Default Re: iframe issue [edited]

Great job on restoring the site.

There were a few things that i messed up, while cleaning the the code by myself.

So i had to request a NAS restore. I was told that the site will be restored to 4-20-2008.

Thanks to all Hostgator staff, especially Ford and Jamyn.

Hostgator rocks!
Reply With Quote
  #14  
Old 04-23-2008, 10:17 PM
striddy's Avatar
striddy striddy is offline
Veteran Croc
 
Join Date: Mar 2008
Location: /home/australia/earth
Posts: 4,093
Default Re: gator109 hacked

Quote:
Originally Posted by jonel View Post
I have my site running in database. I try one time to backup my entire site, I think I made a success on it but to restore the site in database is another thing. My question is, how to create backups that are easy to restore?
What system or CMS, etc is the site running under? e.g. wordpress, drupal, joomla, etc?

If you provide some info on that I'm sure someone here will provide you with an answer.
__________________
- David
Reply With Quote
  #15  
Old 04-25-2008, 05:45 PM
Tsunami Tsunami is offline
Hatchling Croc
 
Join Date: Sep 2006
Posts: 1
Default Re: iframe issue [edited]

Same issue here on gator378. This is the second time in 2 days. It affected my root domain & subdomains, injecting the code into the main index files (index.php, default.html etc) but doesn't seem to go any deeper in the directory structure, i.e. it doesn't hit the index file in a Wordpress theme.

@ jimbug - It adds adds the line of code to the page and downloads the JS/Psyme.QM virus.

I also have another account on Hostgator, which at this time, has not been infected but that maybe because it is on a different server and / or is still on PHP 4.4.4 (not 5.2.5 as the other account is running).

Thankfully, I have the files locally so its just a case of overwriting the server versions. It is an annoyance we could all do without... bad for visitor confidence. However, it isnt just Hostgator hit by this, I have seen others suffer the same issue.

Be great to find a solution...

Last edited by Tsunami; 04-25-2008 at 06:03 PM.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 07:29 AM.