Portal Home > Knowledgebase > Industry Announcements > Web Hosting Main Forums > Providers and Network Outages and Updates > ddoshostingsolutions.com hacked?


ddoshostingsolutions.com hacked?




Posted by SC-Martin, 07-10-2012, 10:57 AM
I'm visiting their site and I get redirected to some .ru site that probably is a virus. My kaspersky shows that. Anyone have same issue?

Posted by KMyers, 07-10-2012, 11:18 AM
Quote:
Originally Posted by SC-Martin
I'm visiting their site and I get redirected to some .ru site that probably is a virus. My kaspersky shows that. Anyone have same issue?
Is it still happening? I just visited it and it seemed to be ok

Posted by morrisonhosting, 07-10-2012, 12:18 PM
Quote:
Originally Posted by KMyers
Is it still happening? I just visited it and it seemed to be ok
Actually it is still happening. It's javascript that is redirecting to that site on 404 errors.

See: http://labs.sucuri.net/db/malware/malware-entry-mwht291

Malware scan of the site through sucuri through off alarms: http://sitecheck.sucuri.net/results/...gsolutions.com

-Tyler Morrison

Posted by DDHS Bob, 07-10-2012, 03:32 PM
Quote:
Originally Posted by SC-Martin
I'm visiting their site and I get redirected to some .ru site that probably is a virus. My kaspersky shows that. Anyone have same issue?
A hidden iframe was injected in to our main site a day ago after one of our staff members was infected with malware through another website injected with a hidden iframe. The hidden iframe was promptly removed, but a malicious rewrite rule still managed to stay hidden. It turns out that FileZilla stores usernames/hosts/passwords in plaintext, and this piece of malware automatically reads them, connects to the victim site via FTP, and automatically injects a hidden iframe in all .php & .html files, while also creating a sneaky .htaccess rewrite rule.

You were redirected by an .htaccess rule which was left behind. It is only triggered by specific referrers, so not all visitors were affected.

Our client area is hosted on a different server than our main site. The client area was not affected by this incident.

If you haven't done so already, run a full scan on your computer with your anti-virus software.



Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read
FDC Denver Outage (Views: 1085)
IPS Down? (Views: 1005)
SLHost down? (Views: 951)


Language: