Simple Machines Community Forum

SMF Support => SMF 1.1.x Support => Aiheen aloitti: yankeedoodle02 - syyskuu 08, 2011, 01:41:03 IP

Otsikko: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 01:41:03 IP
hi all

im new here, so be nice  :)

in the last couple of days, the forum that I own has been infected with some sort of malicious virus or scripting. when a user visits the site, the web browser warns them that the site is dangerous and should not be visited. for this reason, we have put the forum into maintenance mode while we try and solve the problem.

im no expert in these matters, and have no way of knowing how to fix the problem. My partner has changed the permissions and also the password, to prevent a brute force attack.

Can anyone make any suggestions? I have no idea how to even access the scripting for the site, let alone what to look for and how to change it

I hope someone has some patience to humour me

thanks
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 01:47:13 IP
what version of smf are you running? what file is causing the warning?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 02:09:32 IP
running 1.1.14

I have no idea what the file is, how it got in, or even where to find it  :(
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:10:46 IP
can you post a link to your forum?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 02:16:13 IP
sure, the site is

www.banditforum.co.uk
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:19:06 IP
you would have to take it up with google

http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&hl=en-US&site=http://www.banditforum.co.uk/forum/
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 02:20:46 IP
thanks I have done this by installing some DNS coding to the site. waiting for a reply from them at the moment
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:22:10 IP
also check your files to make sure none have been modified without your knowledge. that warning showed in firefox but not in opera, so not all users would get the warning.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 02:24:43 IP
thanks. I've had the warning in firefox but not in IE. google also states that the site has not hosted any malware in the last 90 days. would this suggest that the site is in a stable enough state to allow users to continue using it?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:25:35 IP
that i cant say without checking all the files and the posts etc.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 02:32:10 IP
thanks. namesco host our server

I have checked through the files, and 2 directories listed as being recently modified I cant access.

When I try to view the directory it says "System error 13: Permission denied"
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:34:35 IP
ask your host to look into why.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Omniverse - syyskuu 08, 2011, 02:44:40 IP
I would look at these 2 threads, betting it's the same attack.

http://www.simplemachines.org/community/index.php?topic=451702.0
http://www.simplemachines.org/community/index.php?topic=451581.0

Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:46:40 IP
i dont think so on this one, i dont get any messages from my anti-virus software like i have before on that other site.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 02:56:50 IP
also who is your host?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 03:03:26 IP
our server is with namesco. i think they are our host?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 03:05:25 IP
they look like a decent host, not oversold. has your host replied with any information about how this could have happened?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 03:08:14 IP
yes, their reply was as follows:

Thank you for your enquiry,

You will need to ensure the scripts are cleaned of all malicious code and update the software to the latest stable release to ensure all known security holes are patched.

I would also suggest a developer manually check the code for any security holes for maximum security.


they also recommended we changed the permissions for more secure ones, which we have done.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 03:14:47 IP
sounds like a host that does not track these things, i would suggest you find a host that would track these things, without it if you did have a security breach from within smf we would have a harder time finding out what happened.
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 08, 2011, 03:52:47 IP
thanks for your advice

ive just looked at the ftp index for the site.

when I click on the directories that I couldnt open within the server, this ftp index tells me that these directories do not exist, despite being right there in front of my eyes  :-\
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Illori - syyskuu 08, 2011, 03:54:15 IP
have your host check your file/folder ownership
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: yankeedoodle02 - syyskuu 12, 2011, 03:40:56 IP
thanks for all your help so far

got google webmaster tools up and running. it detected a suspicious script in a .js file in the javascript directory. I have removed the script from the file but the forum continues to give me the same warning message about malicious files.

got a guy looking over the coding for me soon hopefully

in the meantime, anyone got anymore suggestions?
Otsikko: Re: scripting issues, malicious site warning
Kirjoitti: Angelina Belle - syyskuu 23, 2011, 10:17:37 AP
Back everything up (including all of your files), uninstall all mods,

GET RID OF any executable files in your website. Maybe there is a malicious non-SMF file there to re-infect your files, and all it takes is a bot to come along and run it to cause you a problem again?

Do not delete your attachments. They have funny names on purpose. If you delete them, you'll only have to restore them from your backup.
Do a fresh install of all of your files, and re-install all of your mods.

That would get rid of EVERY executable file on your website, and give you all fresh new files.  You would not need to track down the infected files, because they would be G O N E.