We help IT Professionals succeed at work.

Check out our new AWS podcast with Certified Expert, Phil Phillips! Listen to "How to Execute a Seamless AWS Migration" on EE or on your favorite podcast platform. Listen Now

x

My php webpage got hacked ! please help

Styleminds
Styleminds asked
on
Medium Priority
391 Views
Last Modified: 2013-12-09
Hello i have my main webpage consist of a index.php and a main.php included that have additional information to display and the permission of these files 0644 i was suprised when i found that my website didn't display correctly i open these files and i saw a strange hidden iframe inserted and it have a suspicious link think it is a spam !

So how can i prevert from such hacking ! and how these get to my file , however now i changed my cpanel password but i think they got from another hole !

So please help me and advice about your experience in such hack and how can i secure myself

www.audiominds.net 
Comment
Watch Question

Unlock this solution with a free trial preview.
(No credit card required)
Get Preview

Author

Commented:
Well i am using helpinghandhost.com hosting.! can anyone explain why they did this ! is this an bot spamming or a human spaming and how it get to my file !
There was a recent mass hack originating from china called the Gumblar Hack. They got their link inserted on as many sites as possible to increase their search rankings and drive large amounts of traffic onto their pages. In so doing they are able to collect tiny payments from advertisers millions more times than usual and make some money.

The below threads contains links to a script that can be used to clean up after this infection, and also a more in-depth analysis of the attack

http://www.danielansari.com/wordpress/2009/05/automatic-removal-of-gumblarmartuz-trojan/

http://www.webpayments.ie/blog/Gumblar-What-is-it-How-to-I-remove-it-.html

Author

Commented:
Thanks MKlefasStennett for the info but how technically they got into my file thru my ftp connection !
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview
Commented:
Unlock this solution with a free trial preview.
(No credit card required)
Get Preview

Author

Commented:
So how can we prevent this hack and how can we check if we are safe!

Commented:
Your hosting provider is going to have to prevent this - it doesn't sound like you have much control over the system.  If you really want to have control over access to your system, you should look into a VPS server and configure it yourself.  I like slicehost - of course you have to learn how to install and configure all of the systems you want to use, but I think that's valuable information anyways.

Of course, this is all based on the assumption that they got in through your cpanel.

Author

Commented:
well i don't want to get into this headache so what i want is a secured shared system i don't have that deep access and even i don't have a SSH access , so what you suggest me to do to check if there still other spamms in my webpage or in my whole hosting ?
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a free trial preview!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.