ProductCart E-Commerce Solutions Homepage
Forum Home Forum Home > ProductCart > Customizing ProductCart
  New Posts New Posts RSS Feed - Virus infected
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Virus infected

 Post Reply Post Reply
Author
Message
matle View Drop Down
Newbie
Newbie


Joined: 19-November-2009
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote matle Quote  Post ReplyReply Direct Link To This Post Topic: Virus infected
    Posted: 18-January-2010 at 8:53pm
Hi all,
I have successful installed and customized our website with ProductCart more than month ago. Unfortunately, last week, we got infected with virus named Trojan.Malscript B, another noted with Trojan-Downloader.JS.Agent.ewo (Kaspersky AVP) & (ZoneAlarm)

I Checked our sourrces and saw that all of our .js, .asp and .html were infected. Those files were modified at the same time and date. Does any body know how our site was infected? Is it because the hacker inserted a script in one of our input fields and this script was executed by our ProductCart software? or the hosting was infected? Our code produced something that were noted as virus?, any possibilities and how to protect our site for the second time?

Thanks,



Edited by matle - 18-January-2010 at 8:59pm
Back to Top
netprofits View Drop Down
Certified ProductCart Developers
Certified ProductCart Developers


Joined: 05-January-2006
Location: United States
Status: Offline
Points: 22
Post Options Post Options   Thanks (0) Thanks(0)   Quote netprofits Quote  Post ReplyReply Direct Link To This Post Posted: 18-January-2010 at 9:00pm
Hi Matle,
 
Most likely your site was hacked by someone who "sniffed" your FTP credentials when you connected to your web site to either upload files or make additional updates to the web site. We have heard of this happening more often over the past several months.
 
The best solution is to ask your web hosting service to restore a backup from before the date the files were hacked.
 
Additionally you should contact you web host to see if there is a way to either access your site with Secure FTP or to restrict FTP access to your computer's IP address.
 
Hope this helps!
 
Dan
NetProfits Internet Consulting

Certified ProductCart Developer

Our Site
Back to Top
Greg Dinger View Drop Down
Certified ProductCart Developers
Certified ProductCart Developers
Avatar

Joined: 23-September-2006
Location: United States
Status: Offline
Points: 238
Post Options Post Options   Thanks (0) Thanks(0)   Quote Greg Dinger Quote  Post ReplyReply Direct Link To This Post Posted: 18-January-2010 at 9:04pm
I second the suggestion at locking FTP to known IPs, perhaps that from both your home and office.
 
There was an attack last year where servers were being compromised by FTP, and regardless of changing the FTP password one day, the site was successfully attached the next day.  The hackers would insert IFRAME code into pages.  Locking FTP to known IPs will help limit your exposure to such a re-occurrance.
 
Good luck.
Back to Top
Hamish View Drop Down
Admin Group
Admin Group


Joined: 12-October-2006
Location: United Kingdom
Status: Offline
Points: 56
Post Options Post Options   Thanks (0) Thanks(0)   Quote Hamish Quote  Post ReplyReply Direct Link To This Post Posted: 18-January-2010 at 9:05pm
Hi Matle,
   My suspicion is that the problem is server related, or another app on the same server.
Either that or an FTP account with sufficient privileges has been cracked.
  
Our own site and that of many customers are scanned regularly for vulnerabilities and there are no known vulnerabilities in the code.

The hosting company should be able to examine the server logs to help ID the source/route of infection.
Back to Top
matle View Drop Down
Newbie
Newbie


Joined: 19-November-2009
Status: Offline
Points: 0
Post Options Post Options   Thanks (0) Thanks(0)   Quote matle Quote  Post ReplyReply Direct Link To This Post Posted: 18-January-2010 at 9:18pm
Thanks all for prompt reply. Smile
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.031 seconds.