Author |
Message |
Daman
Joined: Fri Jan 26, 2007 3:22 am Posts: 1451
|
 Re: DataRealms Website Malware Warning
Did you actually find the breach? Did you grep -ri "base64_decode" . ? Check to see if it was done via SQL injection by grep -i the logs for "OUTFILE" / "DUMPFILE", alternatively "EXEC", alternatively http://code.google.com/p/apache-scalp/ , alternatively take the professional route and install an intrusion detection system
|
Wed Jun 27, 2012 11:06 am |
|
 |
scancode
The Licensing Guy
Joined: Sun Aug 24, 2008 2:00 am Posts: 64 Location: Buenos Aires, Argentina.
|
 Re: DataRealms Website Malware Warning
It was way less exciting than that. FTP password was compromised. All relevant passwords were changed and computers are being scanned for malware.
I did check the rest of the site for base64'd content, iframes, and external scripts. Everything seems to be clean.
I guess I *could* install an IPS, but that's up to the serverguys.
|
Wed Jun 27, 2012 4:58 pm |
|
 |
Data
DRL Developer
Joined: Tue Jul 27, 2004 8:02 pm Posts: 428 Location: AZ
|
 Re: DataRealms Website Malware Warning
yet again, scannie saves the day! thanks dude
|
Thu Jun 28, 2012 9:46 am |
|
 |
Azakan
Joined: Mon Jan 25, 2010 7:43 pm Posts: 572 Location: Joined: Thu Jun 11, 2009 8:28 pm
|
 Re: DataRealms Website Malware Warning
Scancode is indeed worthy of a imaginary statue for his heroic deeds.
Also I guess the extreme slowness of the forums are gone now?
|
Thu Jun 28, 2012 7:12 pm |
|
 |
Harzipan
Joined: Fri Aug 12, 2011 9:23 pm Posts: 1416 Location: North-Ish
|
 Re: DataRealms Website Malware Warning
It's been gone for awhile. At least for me.
|
Thu Jun 28, 2012 7:24 pm |
|
 |
Natti
Data Realms Elite
Joined: Fri Jul 03, 2009 11:05 am Posts: 3878
|
 Re: DataRealms Website Malware Warning
Harzipan wrote: It's been gone for awhile. At least for me.
|
Thu Jun 28, 2012 8:23 pm |
|
 |
Azakan
Joined: Mon Jan 25, 2010 7:43 pm Posts: 572 Location: Joined: Thu Jun 11, 2009 8:28 pm
|
 Re: DataRealms Website Malware Warning
I meant like, FOREVER! But yeah, I havent notised it either but it used to come and go.
|
Thu Jun 28, 2012 9:10 pm |
|
 |
|