![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Jul 2004
Posts: 1,207
|
Malware removal service
There must be some vulnerability in the server I use or I don't know what's the cause, but my sites are being flagged with google malware warning. I also see some nasty .php files being randomly added to some of my websites. Both wordpress and plain html.
Any of you guys know of a reliable service that'll clean this shit for me and patch the vulnerabilty so it won't happen in the future ?
__________________
Like X-ART !! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Yellowplum / 247mg
Industry Role:
Join Date: Feb 2008
Location: Nicosia, CY
Posts: 2,161
|
Tpl files in wp ate mostly infected with this which finally effect html files or php files...you need to contact host to clear this for you... Its called injection....
__________________
247mg.com - Indian Affiliate Program - Over 50+ Sites To Promote - Monetize Your INDIAN Traffic Today! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Jul 2004
Posts: 1,207
|
This makes sense, unfortunately my host , I won't name it here, is not so good at doing anything more complicated. You think I should push them to get this done ?
__________________
Like X-ART !! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
fgfdftre6
Industry Role:
Join Date: Oct 2012
Location: In the closet with your dad!
Posts: 6,690
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Raise Your Weapon
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,601
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,606
|
Maybe your ftp password got stolen (in case you had stored it in Total Commander or similar) via a malware?
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
It's 42
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
|
Sloppy PHP coding -- use PDO
Inputing user submitted data the right way: PHP: PDO - Manual This is probably beyond the scope of your abilities but the developers creating the code for your API should know better. This is a nice blog article in more layman terms: a2z notes: Introduction to PDO Here is a long read on the SQL injection vulnerabilities in PHP query language. mysql - How can I prevent SQL-injection in PHP? - Stack Overflow |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
ProntoAdmin | On Demand Server Administration
Hosts aren't really responsible for your content. Some might be willing to help but when there is a recurring problem, most of them are going to tell you to get it figured out or they are going to shut you down.
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
I’m still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
Tom
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Quote:
If there were malicious files found somewhere, deleting them isn't going to make much difference. They will just keep returning until whatever allowed them to be uploaded is fixed. Most of the time it's a vulnerable WP theme or plugin and in that case, it's absolutely not something the host should be messing with. A lot of fledgling hosting companies will do this but those are typically the ones who haven't had a lesson in liability yet.
__________________
I like pie. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Yellowplum / 247mg
Industry Role:
Join Date: Feb 2008
Location: Nicosia, CY
Posts: 2,161
|
We face the same issue and host tech created script to remove all injection in tpl file codes and it works.... Our host - Amerinoc 😎
__________________
247mg.com - Indian Affiliate Program - Over 50+ Sites To Promote - Monetize Your INDIAN Traffic Today! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Industry Role:
Join Date: Jun 2010
Location: Tokyo Red Light District
Posts: 2,145
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Oct 2013
Location: Canada
Posts: 890
|
I could check it for you. Email me or contact me on ICQ.
I could do it live with you on TeamViewer or a similar tool. Don't trust anybody requesting ssh, ftp or admin access to your server without you monitoring their actions and them giving you a full report... It'll probably get you in more trouble than you're in. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Industry Role:
Join Date: Oct 2013
Location: Canada
Posts: 890
|
Quote:
They may change hardware, monitor system updates, install scripts, but I would never expect them to work on client code without compensation. If they do, you're probably paying too much for hosting monthly. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Jun 2012
Location: Canada
Posts: 1,338
|
It usually comes all from a single php file that reupload the bad files you see when you delete them and reinsert nasty codes into your html files.
Open one of your site and look at the source code of the page, check it without javascript enabled if your afraid of getting a virus, find an include which don't belong there, if it's encoded with eval (most of the time), decode it here HTML & JavaScript Encoder/Decoder. Then look at the path of the php include file inside that code. Find that file and delete it (its the main file). Then run ComboFix on your computer to make sure you don't have any backdoor virus. That you got while watching porn ![]() Then change your FTP, Cpanel (whatever), root password for your server. Got those a few times and this is how i got ride of them... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Industry Role:
Join Date: Jun 2012
Posts: 457
|
I had lots of malware problems years ago on shared hosting, always WordPress. I spent many hours fixing it only to have them back in via a back door, but as a quick and dirty fix most (WP) problems disappear if you disable the php eval function.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
I’m still alive barley.
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
|
Quote:
__________________
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |