CruelKind Posted June 20, 2014 Posted June 20, 2014 (edited) Today the website I manage was hacked and our title result and homepage image shows f***ed by 7sign. It also managed to dump 200,000+ files into our folders Anyone have an immediate understanding and/or solution? Edited June 23, 2014 by CruelKind Quote
TwstR Posted June 20, 2014 Posted June 20, 2014 probably some script kiddie, few guild websites i used got "hacked" in this way, just putting some porn and stuff on there.. Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 Thanks, but I know what the problem is.. I need a solution Quote
Heretic121 Posted June 20, 2014 Posted June 20, 2014 Well... after a quick google search, it would appear they've hit a few websites. What's the website you manage? and do you know how they got in? Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 it's usarplus.com (I've turned it off for now so you wont see it) I know I've been hit because it replaces homepage.asp with a separate file, causing it to show the msg I indicated above. It appears to be returning that file even after I restore or delete it. Quote
Heretic121 Posted June 20, 2014 Posted June 20, 2014 Google Cache is a wonderful thing, looks like a custom built website. Could you contact the developer, unless you are, and ask for some help? It's quite likely they got in through something they/he/she made Also, do you have any backups of the website? Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 right - The developer is me/us here on location. yes we have backups, but when I restore the asp page in question it reverts back to the hacked file. This tells me there's a program running somewhere checking and restoring the corrupted files whenever they are deleted. I suspect the solution is to remove the offending program directly from the registry, though so far my searches haven't turned up the culprit. Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 Someone shoot me in the face and end this nightmare Quote
Matt_14 Posted June 20, 2014 Posted June 20, 2014 (edited) Who is your website host? They could maybe reset your account? and then you could install the back up files back up? Edited June 20, 2014 by Matt_14 Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 (edited) We host our own websites, servers on site We have backups, but until I remove the virus itself, it repopulates the infected files immediately after. Edited June 20, 2014 by CruelKind Quote
Heretic121 Posted June 20, 2014 Posted June 20, 2014 (edited) See normally I would have plenty of things for you to check, but then I found out you're using some version of Windows and decided against it. Not because it's Windows, but because I don't have a clue where to even begin lol Don't even get me started on ASP! Edited June 20, 2014 by Heretic121 Quote
CruelKind Posted June 20, 2014 Author Posted June 20, 2014 well the problem is fixed, and I'm not entirely sure how. I ended up deleting all the added trash files and AVG discovered a few Trojans after an upgrade of their service and the issue seems resolved. sigh... I must have lost a minimum of $500 today. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.