查看完整版本: [-- 發現有2個網頁檔案被插入程式碼問題已修復,用戶請即採取下列措施 --]

【好友論壇】- 以足球會好友 -> 【論壇政務總處】 -> 發現有2個網頁檔案被插入程式碼問題已修復,用戶請即採取下列措施 [打印本頁] 登錄 -> 注冊 -> 回復主題 -> 發表主題

垃圾桶 2013-03-18 19:00

發現有2個網頁檔案被插入程式碼問題已修復,用戶請即採取下列措施

各位會員,

在會員通知及在定期檔案完整性檢查中,發現2個網頁檔案(index.html及index.php)被插入程式碼,該等程式碼為一個Web Bot counter,風險為中度。我已即時把該等程式碼移除,並已修改該等檔案寫入權限,避免問題再次發生。用戶在現階段請即進行下列步驟以保障電腦安全。

1) 請即清理網頁緩存
(Step by Step Guide: http://www.wikihow.com/Clear-Your-Browser%27s-Cache)
2) 請更新防毒程式及反間諜程式之資料庫並進行掃瞄

如發現於進入好友時出現奇怪情況,例如被轉址或部份網頁突然下載緩慢,請即通知我或ecko以便檢查,謝謝

垃圾桶,技術支援版版主
二零一三年三月十八日晚上七時



freezefox 2013-03-18 22:37
簡單D,我地管理人員改左個PW 咪重實際。

Ar敬 2013-03-19 00:35
會唔會比人偷取資料

freezefox 2013-03-19 11:17
Ar敬:會唔會比人偷取資料[表情] [表情]  (2013-03-19 00:35) 

應該唔會既。好似話最差既情況都係比人入到黎,撞到個PW,攪亂我地既版面者。

Gabriel 2013-03-19 12:05
scan左無事....改改密碼啦我

freezefox 2013-03-19 12:34
Gabriel:scan左無事....改改密碼啦我[表情] [表情]  (2013-03-19 12:05) 

你唔駛啦。主要係可以進入SERVER 個幾個者。即係總版、我同技支。一改就全部一齊改的。

Gabriel 2013-03-19 12:36
freezefox:你唔駛啦。主要係可以進入SERVER 個幾個者。即係總版、我同技支。一改就全部一齊改的。 (2013-03-19 12:34) 

okay!

Ar敬 2013-03-19 23:38
freezefox:你唔駛啦。主要係可以進入SERVER 個幾個者。即係總版、我同技支。一改就全部一齊改的。 (2013-03-19 12:34) 

我掃過無事

文仔 2013-03-20 23:35
但係會係咩途徑比人插左d碼入黎?

freezefox 2013-03-21 15:07
文仔:但係會係咩途徑比人插左d碼入黎? (2013-03-20 23:35) 

呢個問題要桶少回覆了。

ecko 2013-03-27 23:13
freezefox:呢個問題要桶少回覆了。 (2013-03-21 15:07) 

有機會係因為其中一隻account 比人盜用左.
呢隻account 既password 已經改左.
而家monitor 住先.

freezefox 2013-03-28 00:31
ecko:有機會係因為其中一隻account 比人盜用左.
呢隻account 既password 已經改左.
而家monitor 住先. (2013-03-27 23:13) 

好耐無見!

文仔 2013-03-28 00:59
ecko:有機會係因為其中一隻account 比人盜用左.
呢隻account 既password 已經改左.
而家monitor 住先. (2013-03-27 23:13) 

有無log 記住d修改??

ecko 2013-04-04 20:47
文仔:有無log 記住d修改?? (2013-03-28 00:59) 

其實有access log 既~
不過經左proxy, check 唔到source

ecko 2013-04-04 21:00
freezefox:好耐無見![表情] (2013-03-28 00:31) 

我間唔中都有入黎睇下有冇突別事既~
有野就 whatsapp / line / facebook la~

freezefox 2013-04-05 10:16
ecko:我間唔中都有入黎睇下有冇突別事既~
有野就 whatsapp / line / facebook la~ (2013-04-04 21:00) 

做咩淨係上黎睇下有冇事,而唔入去吹下水。

ecko 2013-04-18 21:48
freezefox:
做咩淨係上黎睇下有冇事,而唔入去吹下水。[表情]


  有時間就覆我facebook message la~ @freezefox  

freezefox 2013-04-19 00:25
見到

freezefox 2013-04-27 14:47
ECKO,供應商完全無理我個電郵喎!

ecko 2013-04-28 20:52
freezefox:ECKO,供應商完全無理我個電郵喎! (2013-04-27 14:47)

你有冇ticket system 個email 同 password 呀?

http://home.geeks.hk/supporttickets.php

email 唔覆係好正常~ 因為人地真係用ticket system~

freezefox 2013-04-28 21:29
ecko:你有冇ticket system 個email 同 password 呀?
http://home.geeks.hk/supporttickets.php
....... (2013-04-28 20:52) 

我呢兩日打比佢。


PW 我要CHECK 一CHECK先知。

ecko 2013-04-28 22:25
freezefox:我呢兩日打比佢。
PW 我要CHECK 一CHECK先知。 (2013-04-28 21:29) 

好的~ 急都急唔黎~
btw~ 你返左香港未?

freezefox 2013-04-28 22:30
ecko:好的~ 急都急唔黎~
btw~ 你返左香港未? (2013-04-28 22:25) 

返左兩日。

ecko 2013-04-28 22:51
咁就好啦~ 可以吹下你搞啦~

freezefox 2013-04-28 23:20
ecko:咁就好啦~ 可以吹下你搞啦~ [表情]  (2013-04-28 22:51) 

聽日第一日返工,會忙少少。不過後日要見客,更忙,所以盡量聽日下午攪掂佢。

freezefox 2013-05-02 18:03
Hi Jacob,

Can you SMS your root password to 9017XXXX. We will access your server and diagnose the issue. We will also put in some security measure and update the firewall system to drop the brute force. In regarding to the webpages being hacked over and over again, you will also need ot go through folders to see if there is any file doesnt seem to be yours, you can see it easily by the folder's last changes (date). There must be a PHP file that acting as a "web upload" that can send commands. I will access PHP file to disable common executive commands such as exec() and shell_exec() but this will cause some program to fail, do alert us if you experience issue.

Thanks

Alistair Lam



freezefox 2013-05-02 18:04
佢今日話原來之前收唔到我地既電郵。所以我RESEND 多次比佢。然後佢回左呢段野比我地。

ecko 2013-05-02 20:52
比root account~ 我有少少concern~
我會問埋桶少~ 我地都agree 就比啦~

freezefox 2013-05-02 21:37
ecko:比root account~ 我有少少concern~
我會問埋桶少~ 我地都agree 就比啦~ (2013-05-02 20:52) 

定係我地自己都可以攪得掂。

ecko 2013-05-02 22:05
Latest email from support

Dear Daniel,
We have already secured your server. Please note several changes have been made in DirectAdmin Control Panel
1) Brute Force Monitor - This is to monitor the past 4 days of Brute Force. Only monitors, it won't do anymore than this
2) ConfigServer Firewall&Security - This is a firewall and login failure daemon, what it does it will monitor any brute force and send to the firewall for blocking. You can also key in IP address and click "Block" in a very convenience way.

Additionally, we have made some further security
1) PHP - disable some basic dangerous function - shell_exec(), dl() and etc...
2) Port Change - From 22 into
xxxx to minimize brute force into SSH
3) Renamed /home/admin/public_html/index.php into virus.index.php. This is because it is scanned to have virus linkage by Norton.

The new Directadmin password is sent to you, please change accordingly.


ecko 2013-05-02 22:06
freezefox:定係我地自己都可以攪得掂。 (2013-05-02 21:37) 

呢D 野, 唔想自己搞~ 始終人地先係專家~

ecko 2013-05-02 22:07
ecko:呢D 野, 唔想自己搞~ 始終人地先係專家~ (2013-05-02 22:06) 

重有~ 有D 野唔係我地自己可以做到~

freezefox 2013-05-02 22:22
ecko:重有~ 有D 野唔係我地自己可以做到~ (2013-05-02 22:07) 

但頭先你又話你有COCERN?

ecko 2013-05-02 22:24
freezefox:但頭先你又話你有COCERN? (2013-05-02 22:22) 

係有少少concern~
不過佢出到 reset a/c 黎搞我地d server, 咁我不如比佢啦~

freezefox 2013-05-02 22:25
ecko:係有少少concern~
不過佢出到 reset a/c 黎搞我地d server, 咁我不如比佢啦~
[表情] (2013-05-02 22:24) 

RESET 左啦?定係建議咋?

ecko 2013-05-02 22:26
Dear Daniel,
We have already secured your server. Please note several changes have been made in DirectAdmin Control Panel
1) Brute Force Monitor - This is to monitor the past 4 days of Brute Force. Only monitors, it won't do anymore than this
2) ConfigServer Firewall&Security - This is a firewall and login failure daemon, what it does it will monitor any brute force and send to the firewall for blocking. You can also key in IP address and click "Block" in a very convenience way.
Additionally, we have made some further security
1) PHP - disable some basic dangerous function - shell_exec(), dl() and etc...
2) Port Change - From 22 into xxxx to minimize brute force into SSH
3) Renamed /home/admin/public_html/index.php into virus.index.php. This is because it is scanned to have virus linkage by Norton.
The new Directadmin password is sent to you, please change accordingly.

ecko 2013-05-02 22:41
For 大家 information

最初 send 比support 既 email:

Dear Geeks Concepts's Support,

We currently using Geeks Concepts Dedicated Server Service. However, we found there is "brute force ssh attack" to our server. There are hugh number of failed SSH login attempts to our server and they are trying to "guess" our account and password. Please find the access log in the attachment (Access Log.png).

Unfortunately, unauthorized access from anonymous has been done and some of our webpage has been changed by hacker.
We had removed the webpage and password had been changed to prevent their access. However, the hacker can access our server again and change webpage again.

I am sure that you must be the expert to solve the similar problem in other server. Would you please help to suggest if there is any tool (block the ip from accessing the server after several failed login attempts) from your side to implement in our server to prevent unauthorized access?

I have some idea to prevent the unauthorized access but I am sure that your solutions will be better. Please help to check if the following can be implemented to our server.

1. Change SSH port from port 22 to another port
2. Configure CentOS to drop packets from anyone but some trusted ip address

freezefox 2013-05-03 00:52
原來佢已經reset左

freezefox 2013-05-06 17:10
跟進一下,供應商個邊己經作出數個改動。如果問題仍然得唔到改善,請通知。

垃圾桶 2013-05-06 20:55
我地會keep mon住個情況

freezefox 2013-05-06 21:13
另外有封咁既電郵,關於供應商改名事宜。

Dear Customer

Regarding to Company Name Change

In order to our company to move forward and to offering a lot more services, we would like to announce starting 1st May 2013, we will change our company name as follow:

GEEKS CONCEPTS LIMITED >>>> GEEKS

Apart from our company name changed, our bank account will also be changed. We will notify you by another email and will be posted by letter for verification of our identity. Our new bank account will begin active on 1st May 2013 and we hope all customers to transfer to our new account accordingly. If you accidentally paid to our old account, it is fine, we will stop receiving payment of our old account on 14th May 2013.

您好

有關轉公司名稱事宜

讓我們繼續提供更多服務,我們將會在五月一日起使用以下新的公司名稱
GEEKS CONCEPTS LIMITED >>>>> GEEKS
除了轉公司名字外,我們也會更改銀行帳戶號碼。新的帳戶號碼將會以另一電郵及郵件寄給客戶。
請閣下從五月一日起使用我們新的銀行帳戶號碼支付服務費用。如客戶將費用支付到舊的銀行帳戶,我們會繼續收集直至五月十四日。


Thanks
Geeks Concepts Limited

ecko 2013-05-09 22:03
2013-05-09 Update

暫時冇再發現可疑既access log


freezefox 2013-05-09 23:06


查看完整版本: [-- 發現有2個網頁檔案被插入程式碼問題已修復,用戶請即採取下列措施 --] [-- top --]


Powered by phpwind v8.7 Code ©2003-2011 phpwind
Time 0.117456 second(s),query:3 Gzip disabled