Forums suffering virus/trojan infection

Fast Guy

Moderators
Staff member
Just found this on another website I use.

PC Advisor web site said:
Google results poisoned with malicious links

Security threat found on legitimate websites

Robert McMillan
A new attack that peppers Google search results with malicious links is spreading quickly, the US Computer Emergence Response Team has warned.

The attack, which has intensified in recent days, can be found on several thousand legitimate websites, according to security experts. It targets known flaws in Adobe's software and uses them to install a malicious program on victims' machines, CERT said.

The program then steals FTP login credentials from victims and uses that information to spread further. It also hijacks the victim's browser, replacing Google search results with links chosen by the attackers.

Security experts started tracking the attack in March, when it had infected several hundred websites, but in recent weeks the number of infected sites has jumped dramatically. The attack has been called Gumblar because at one point it used the Gumblar.cn domain, though on Monday it had switched to a different one.

Security vendor ScanSafe has counted more than 3,000 infected websites, up from around 800 just over a week ago.

That kind of continued growth is unusual, according to Mary Landesman, a senior security researcher with ScanSafe. Attackers have launched many widespread web attacks over the past few years, but after a few months the total number of infected sites usually drops as webmasters clean up their servers.

With Gumblar, more and more sites are now being infected. Landesman believes it's because Gumblar's creators have been good at obfuscating their attack code and making it harder to spot on infected sites. And because they've been stealing FTP login credentials, they've been able to use a few new tricks to get their software onto the sites. "They're doing things like changing folder permissions … and leaving behind multiple ways that they can get back into the server," she said.

Still, web attacks have become so widespread that Gumblar remains a relatively small-scale phenomenon, according to Symantec Security Response Product Manager John Harrison. Last year, Symantec counted 18 million online attacks against its customers. With Gumblar, it has counted 10,000. "It's really just another day with drive-by downloads," he said. "There really are so many of these."

Security experts say that if you're using a fully-patched system with up-to-date security software, you should be protected from these attacks. To date, they've worked by hitting the victim with malicious PDF or Flash files.
another website said:
Gumblar: A Botnet of Compromised Websites

As we mentioned last week:
...site owners who have had their sites compromised by Gumblar should keep in mind that while stolen FTP credentials appear to be the initial means of access, once that access is gained it appears the attackers are 'backdooring' the sites. This means that simply changing the FTP password won't be enough. Site owners will want to check their logs carefully for changes that may have been made post-intrusion. This includes checking things like htaccess, php_includes, and other configuration settings, as well as ensuring directory permissions are set appropriately.
Thanks to these 'backdoors', what we're really looking at here can only be described as a botnet of compromised websites. And a growing one at that. Even with the dip in traffic that occurs over the weekend, Gumblar compromised sites still grew another 10% since last Friday, now up a total of 246% from when we first began tracking the increase just over a week ago.
 
Last edited:

GTiR-Aholic

New Member
this is an interesting read and it makes sense, they wouldn't rely on just using the ftp details that were found/stolen.. once they gain access they are able to create new ftp accounts.. anonymous ftp accounts so that even when you change the root password for your root ftp account, their access will still be live.

I had 1 of my servers attacked once where a client's site was hacked, the user didn't do much just put a splash page infront of the website ... bit of a rep thing going on, didn't erase any data from my clients site just a simple splash page saying it's been hacked blah blah blah.. after deleting the page I noticed that there was a random ftp account created looking like this: sfah49yaskj3r0u7a9s8@clients-domain.com and after confirming with the client, it wasn't one he created.

This site is loading a lot quicker now though.. before it was taking ages for me whilst it was trying to load data from gumblar.. it's much quicker now but the warnings still appear.
 

paz

Active Member
The apple macs at work will only just let me on now, they give me a virus message every time I load a page. Very annoying - can't even log in.
 

antgtir

New Member
Ive given up going on the site at home until i know its sorted. Im quite happy to use the work comps though :lol:

There seems to be plenty of info about the virus but nothing on how to deal / eliminate it, does anyone know anything on this?

Ant.
 

GTiR-Aholic

New Member
Ive given up going on the site at home until i know its sorted. Im quite happy to use the work comps though :lol:

There seems to be plenty of info about the virus but nothing on how to deal / eliminate it, does anyone know anything on this?

Ant.

I did put a post up on how to successfully remove the virus from the site.. i think it's on page 2-3.
 

antgtir

New Member
People will have to manually switch the attack warning system off in Firefox as the site will still be tagged as having a problem.

Ant.
 

stevepudney

GTiROC CHAIRMAN
Staff member
People will have to manually switch the attack warning system off in Firefox as the site will still be tagged as having a problem.

Ant.
didn't have to do anything with mine, just clicked on a link in my email and it opened in ffox first time
 

MORF114

Active Member
If i log out of the site and return to main front page logged out of site and my profile, i get the std main portal screen in white/grey but as soon as i enter any other page from here it automatically logs me in without asking or giving me any prompts, surely thats not normal ??
 
Top