Y T Nuke  
Results 1 to 12 of 12
So after two days of wondering why my sites are lagging so much, I finally ...
  1. #1
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Exclamation Please Read - New Virus F'ing up Sites

    So after two days of wondering why my sites are lagging so much, I finally made it through my files via filezilla. I found some amazing s**t.

    There is a new file out there called inc.php, that is a particularly bad one. if you own a network like I do, it could be months before your able to actually find it an eliminate it.

    This came out of a wordpress installation, and we know those are vulnerable, but none the less, this is a nasty piece of work that everyone needs to know about.

    it uses a find .pwd parameter that allows the hacker to own your password. I am not sure of any other names that it is going around as at the moment, but I know that avira did give it a new ranking and name classification, meaning that it is something new.

    Hopefully that helps some of you to get it out there, and I know someone will be googling inc.php soon, and I hope they find this article, so they know they are infected.

    Bottom line, CHMOD, and check ur S**T!

    UPDATE: HERE IS WHAT VIRUSTOTAL HAD TO SAY ABOUT IT, 530AM est:

    ssdeep

    1536:EtzhQp55YgGJVJrpmxPpN4RMLCeDVgWBiu:EtzpmxPpSR kDZF TrID

    HyperText Markup Language (100.0%)
    First seen by VirusTotal

    2012-02-04 10:25:52 UTC ( 2 minutes ago ) Last seen by VirusTotal

    2012-02-04 10:25:52 UTC ( 2 minutes ago ) File names (max. 25)


    1. inc.php
    I think what it is trying to say is that it's pretty new and pretty mean. that was the comment section. Only a few of the antiviruses (Avira, Avast and Trend Micro) had any positive result. AND THAT'S BECAUSE I SENT IT TO THEM OVER 6 HOURS AGO!!!
    Last edited by oblivionembraced; 02-04-2012 at 08:32 AM.

  2. The Following User Says Thank You to oblivionembraced For This Useful Post:

    AdisLCS (02-03-2012)

  3. #2
    AdisLCS's Avatar
    AdisLCS is offline Jr. VIP
    Join Date
    May 2009
    Posts
    456
    Reputation
    62
    Thanks
    174
    Thanked 136 Times in 101 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    thank you for the heads up and giving me something to do Friday night :-)

  4. The Following User Says Thank You to AdisLCS For This Useful Post:

    oblivionembraced (02-04-2012)

  5. #3
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Yeah, it's my ideal friday. i am dumping my sql databases

  6. #4
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Also, please note, I am rather new to BHW, so if you can put this in a place where people with wordpress sites are going to see it, any help for others is greatly appreciated, and get's positive rep from me.

    I know some of you are going to try to make money off of this. I just hope the other half are going to try to save their S**t and rescue the internet. This is rather bad news for everyone.

  7. #5
    killakem's Avatar
    killakem is offline Jr. VIP
    Join Date
    Oct 2011
    Posts
    277
    Reputation
    80
    Thanks
    50
    Thanked 150 Times in 50 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Any more information on this anyone?? A link to the vulnerability report maybe??

  8. #6
    kvmcable's Avatar
    kvmcable is offline Regular Member
    Join Date
    Dec 2010
    Location
    NW Indiana
    Posts
    449
    Reputation
    112
    Thanks
    147
    Thanked 294 Times in 127 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Guys that run dedis should invest in good protection. Get mod security, keep pattern files up to date, spend a Benjamin with config server to lock your dedi down and install csx anti-virus, chkroot, lfd, enable flood protection and replace passwords with keys. If you can't do key files then use HAC to lock down your server root to only your IP addies. Make sure you use a couple proxy IPs as backup in case your local internet goes down or changes your IP without warning.

    I've been using dedis for many years. Once I found out about config server, csx, lfd and mod security I haven't come close to an infection and I run hundreds of sites.

    I get emails all day long about attempts to cross script inject, ddos, brute force attacks, FTP and mail hack attempts but they get 5-8 shots before lfd shuts their ass out and send me an email. CSX scans every day looking for viruses and quarantines on the fly. Chkroot scans the root files. All the protection updates daily and scans 24.7.

    Do it right and spend $100. It'll be the best $100 you ever spent. I run 12 dedis and haven't have an infection make it through in more than 2 years and many of my client sites are targets for hackers (osc, cre, wp, etc). I'm not affiliated with config servers but just like the service they do. They get you 80% there and with a little reading you can tweak the rest.

    A good host will run daily virus scans and find a virus before you or Google does. ;-)

  9. The Following User Says Thank You to kvmcable For This Useful Post:

    bigeazy (02-04-2012)

  10. #7
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Ok, so here's the latest update.

    I got the virus submitted to avira and viruslab. Avira responded first. They used their program to correctly deduce that it is a new virus, and are updating their software to find it. PLEASE take note, they named is something completely new that I have never heard of, but if you know something about this particular threat, please do share. It's a rather evil virus, and it almost runs silent, so detecting it is a bit of a problem. the only reason that I caught it was my server ping jumped from 100millisecond to around 300millisecond overnight, and my traffic level hadn't increased. Page views were the same, and I hadn't added anything crazier than I already did to my sites. they were pretty much stationary, except for a quote form that I was updating periodically. I will post the avira response:
    Dear Sir or Madam,

    Thank you for your email to Avira's virus lab.
    Tracking number: INC00975929.

    A listing of files alongside their results can be found below:
    File ID Filename Size (Byte) Result 26554620 inc.php 64.38 KB MALWARE
    Please find a detailed report concerning each individual sample below:
    Filename Result inc.php MALWARE
    The file 'inc.php' has been determined to be 'MALWARE'. Our analysts named the threat PHP/Shell.G.2. The term "PHP/" denotes a PHP scriptvirus. Detection is added to our virus definition file (VDF) starting with version 7.11.22.23.
    Alternatively you can see the analysis result here:
    http://analysis.avira.com/samples/de...identid=975929

    An overview of all your submissions can be found here:
    http://analysis.avira.com/samples/de...HwpGn6dNpvtkrC


    Please note: If you have specific questions please address them to support@avira.com
    Kind regards
    Avira Virus Lab
    I placed as much information about this virus around the internet as I could whilst working with my database last night, and I am back at it again at 5am. It's that nasty. Here's some tricks and tips to help out, also the same path that I am following to deal with it:
    I am moding all of my htaccess to require a htpasswd for all admin areas. I am changing table prefixes for the entire database, wiping and regenerating cookies, removing login meta and finally I have disabled new users to any of my wordpress installations that haven't received that treatment yet.

    here is a good place to look for the required files and plugins to make this all possible:
    http://www.htaccesstools.com/htpasswd-generator/
    and
    http://www.websitedefender.com/wordp...y-scan-plugin/

    These two sites and plugins make it possible to beat this thing after you have cleaned it out. You should be able to find it in the root directory (or if you have multiple installations under a main url, it will be burried in a root directory of another site inside the main.
    Once the inc.php file is irradicated, you need to go through your images folders. make sure that you have a good backup that's not corrupted (or at least remember the file names that you use), and make a backup of your database using the security scan plugin. Then when in the images folders, you should be looking for files that carry almost similar naming to the images that you have. It likes to hide there, and in the database. I am working on isolating the strings, so that you can use a simple "find and replace" command.

    Thanks all who are keeping this going, and I appreciate everyone helping out to wipe this out before it becomes a nightmare for us all. finally, if you think your infected, I will be helping as many people as I can. Send me a raw export of your DB (use security scan) and I will do it as fast as I can.

    Thanks
    Last edited by oblivionembraced; 02-04-2012 at 08:17 AM.

  11. #8
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Quote Originally Posted by kvmcable View Post
    Guys that run dedis should invest in good protection. Get mod security, keep pattern files up to date, spend a Benjamin with config server to lock your dedi down and install csx anti-virus, chkroot, lfd, enable flood protection and replace passwords with keys. If you can't do key files then use HAC to lock down your server root to only your IP addies. Make sure you use a couple proxy IPs as backup in case your local internet goes down or changes your IP without warning.

    I've been using dedis for many years. Once I found out about config server, csx, lfd and mod security I haven't come close to an infection and I run hundreds of sites.

    I get emails all day long about attempts to cross script inject, ddos, brute force attacks, FTP and mail hack attempts but they get 5-8 shots before lfd shuts their ass out and send me an email. CSX scans every day looking for viruses and quarantines on the fly. Chkroot scans the root files. All the protection updates daily and scans 24.7.

    Do it right and spend $100. It'll be the best $100 you ever spent. I run 12 dedis and haven't have an infection make it through in more than 2 years and many of my client sites are targets for hackers (osc, cre, wp, etc). I'm not affiliated with config servers but just like the service they do. They get you 80% there and with a little reading you can tweak the rest.

    A good host will run daily virus scans and find a virus before you or Google does. ;-)
    Actually, none of the search engines found this, and they crawl my sites quite often. When I did a virustotal BEFORE extraction, results came back clean. It's an interesting one, or I wouldn't be posting about it here!!

    None the less, thank you for your post, and the useful info. I will check out config tomorrow during business hours. I am also working at securing scripts to handle things like this and scan. When I do, I will share them in downloads area.

  12. #9
    sumit2531's Avatar
    sumit2531 is offline Newbies
    Join Date
    Jan 2012
    Location
    PARADISE
    Posts
    34
    Reputation
    21
    Thanks
    12
    Thanked 13 Times in 12 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Thanks for sharing such a nice information...it really looks interesting.....

  13. The Following User Says Thank You to sumit2531 For This Useful Post:

    oblivionembraced (02-04-2012)

  14. #10
    Bisturi is offline Newbies
    Join Date
    Nov 2011
    Posts
    48
    Reputation
    7
    Thanks
    16
    Thanked 24 Times in 12 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Quote Originally Posted by oblivionembraced View Post
    Actually, none of the search engines found this, and they crawl my sites quite often. When I did a virustotal BEFORE extraction, results came back clean. It's an interesting one, or I wouldn't be posting about it here!!

    None the less, thank you for your post, and the useful info. I will check out config tomorrow during business hours. I am also working at securing scripts to handle things like this and scan. When I do, I will share them in downloads area.
    Any idea as to how you got it or what security flaws it exploits? Can we webmasters do anything to avoid it?

  15. The Following User Says Thank You to Bisturi For This Useful Post:

    oblivionembraced (02-04-2012)

  16. #11
    Join Date
    Mar 2011
    Location
    PALM BEACH :)
    Posts
    25
    Reputation
    15
    Thanks
    3
    Thanked 20 Times in 8 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    Quote Originally Posted by Bisturi View Post
    Any idea as to how you got it or what security flaws it exploits? Can we webmasters do anything to avoid it?
    yes there are ways it can be avoided. It has a problem getting past .htaccess and .htpasswd that I mentioned at the top. If you comment .htaccess with the required lines:
    Code:
    AuthUserFile /etc/httpd/.htpasswd
    AuthType Basic
    AuthName “restricted”
    Order Deny,Allow
    Deny from all
    Require valid-user
    Satisfy any

    Then generate the .htpasswd file to keep access to that area low. I shared the generator up top, but again it is:
    http://www.htaccesstools.com/htpasswd-generator/


    It allows you build a / encrypted .htpasswd file, and it stops most scripts almost immediately. If they can't get to the admin areas to run, they're rather harmless (unless they make it onto your wamp server machine).

  17. The Following 2 Users Say Thank You to oblivionembraced For This Useful Post:

    Bisturi (02-04-2012), xzzxpimpxzzx (02-04-2012)

  18. #12
    xzzxpimpxzzx's Avatar
    xzzxpimpxzzx is offline Social King
    Join Date
    May 2007
    Location
    Costa Rica
    Posts
    357
    Reputation
    87
    Thanks
    82
    Thanked 247 Times in 83 Posts

    Default Re: Please Read - New Virus F'ing up Sites

    good job mate
    THE BEST, GREATEST, & MOST RELIABLE SOURCE
    FOR PINTEREST - ACCOUNTS, BOTS, & PROXIES CLICK HERE

Natural Slow Link Building


SEO Blasts - High quality link building service

Similar Threads

  1. Replies: 395
    Last Post: Today, 10:55 AM
  2. Google Changes Algo to Penalize Sites w/too Many Ads
    By teeniegenie in forum White Hat SEO
    Replies: 16
    Last Post: 02-04-2012, 12:58 PM
  3. Easy and Priceless Traffic Tactic For Fresh Sites
    By ulijonroth in forum Black Hat SEO
    Replies: 8
    Last Post: 06-02-2011, 04:19 PM
  4. Replies: 4
    Last Post: 02-13-2011, 07:05 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
  SEnukeX SEO Software
Proudly Powered by Hostwinds.com Web Hosting Click Here For Exclusive BHW Discounts!

Cheap Web Hosting


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76