Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

website malware threat alert

Options
  • 21-09-2010 1:40pm
    #1
    Registered Users Posts: 8,070 ✭✭✭


    Calls to some script on almost all sites hosted on one of our servers.
    Now sites show malware warning

    -Scanning the pc, updated flash, will see if acrobat needs update too
    -changed all ftp passwords
    -downloading everything

    whats the best way to get rid of the calls?
    notepad++ find in all open docs? [there could be up to 1OO legitimate infected files, rest is probably archive]

    most calls are at the end of the page, what if theres ones using iframes?


    Also do i just use google webmaster tools and submit the website back?
    any idea how long it will take to get off the blacklist?


    Thanks

    P.S: could i point a domains DNS to a different server? is it the IP that gets black listed?


Comments

  • Registered Users Posts: 16,413 ✭✭✭✭Trojan


    1. Plug the exploit (what was the attack vector?).
    2. Remove all the malware script calls.
    3. Re-upload the sites.
    4. Submit in Google Webmaster Tools for review, then wait...
    5. Done.


  • Registered Users Posts: 9,579 ✭✭✭Webmonkey


    Google are quite quick actually, I got off blacklist before within about a week or 2.

    But I also told them i took all measures etc, to protect the site etc etc. Just show you made an effort and found the actual problem that caused it in first place.


  • Registered Users Posts: 16,413 ✭✭✭✭Trojan


    Webmonkey wrote: »
    Google are quite quick actually, I got off blacklist before within about a week or 2.

    But I also told them i took all measures etc, to protect the site etc etc. Just show you made an effort and found the actual problem that caused it in first place.

    We had a client's site removed in *3 hours* after we moved hosting and ported it to a new CMS. Very quick turnaround from Google after submitting it in GWT.


  • Registered Users Posts: 9,579 ✭✭✭Webmonkey


    Trojan wrote: »
    We had a client's site removed in *3 hours* after we moved hosting and ported it to a new CMS. Very quick turnaround from Google after submitting it in GWT.
    Impressive. Maybe they prioritize sites based on page rank or something.


  • Registered Users Posts: 16,413 ✭✭✭✭Trojan


    Webmonkey wrote: »
    Impressive. Maybe they prioritize sites based on page rank or something.

    I don't think so, this was a PR2 or PR3 site, nothing fancypants :)

    I was well impressed with the speed though!


  • Advertisement
  • Registered Users Posts: 9,579 ✭✭✭Webmonkey


    Trojan wrote: »
    I don't think so, this was a PR2 or PR3 site, nothing fancypants :)

    I was well impressed with the speed though!
    Yeah PR3 myself. Ah well, depends how they feeling I guess!


  • Registered Users Posts: 7,739 ✭✭✭mneylon


    Placebo wrote: »
    P.S: could i point a domains DNS to a different server? is it the IP that gets black listed?
    It's the domain that's listed not the IP.

    Unless you clean the site moving it is pointless

    The two most common attack vectors are:

    - desktop > server - usually an infected PC somewhere which compromises the FTP account

    - serverside - usually an out of date script or plugin for CMS such as Joomla


  • Registered Users Posts: 8,070 ✭✭✭Placebo


    Thanks guys,
    google are taking less than 24hrs which is good.


Advertisement