Plusnet
Saturday 21st November 2009Login | Register | Help
Pages: 1 [2]

Badware on my forum

« Reply #16 on 13/11/2009, 10:23 »
From my experience this is more likely to be an SQL injection attack or similar, rather than a successful guess of your FTP password. I've not used plesk so don't know about raw apache logs but that's where you want to be looking. Check for long requests, especially ones with odd looking characters in.
Ben Brown
PlusNet Systems Engineer
Logged
« Reply #17 on 13/11/2009, 12:03 »
Hi Ben,

We're not talking about password guessing but password capture. The payload for this particular iframe includes an infected pdf file designed to do exactly that (and worse).

It could be a hybrid attack, using either password capture or SQL injection, depending on the host, but the xfer logs are likely to be much shorter than the access logs, so that's the quickest thing to eliminate or confirm.

At least safe mode is set on PAYH.

Gabe
Logged
  • Midnight Caller
  • Posts: 1506
  • Please remember that I am Dyslexic wen replying
  • View Profile WWW
« Reply #18 on 13/11/2009, 15:25 »
@Gabe, I will have a look at the xfer logs as soon as I can!
Kind Regards, Gary Lambert.      Force9 ID: dyslexia,
PlusNet ID: tdadyslexia,     PlusNet Since 6 Febuary 2001


DHEA Community Forum        Pleas Help Me To Save Lives
Logged
Pages: 1 [2]
Jump to:  

Related Sites

Community Apps

Here at Plusnet we're always trying to use clever open source things to make our lives easier. Sometimes we write our own and make other people's lives easier too!

View the Plusnet Open Source applications page

About Plusnet

We sell broadband, phone, VoIP and more to homes and businesses in the UK. Winner of 9 out of 11 Categories in the 2008 USwitch survey. Winner of "Best Consumer ISP" at 2008 ISPA awards. Voted number 1 in the Broadband Choices 2008 survey.

© Plusnet plc All Rights Reserved. E&OE

Powered by SMF | SMF © 2006-2008, Simple Machines LLC

Add to Technorati Favourites