Solved

Strange files in webroot

Posted on 2014-12-02
9
226 Views
Last Modified: 2016-02-24
My website is hosted on GoDaddy.  Some time ago they turned off server logs and said everyone should use Google Analytics.  Just recently I noticed the logs are back.  So I downloaded all that were there and ran them through a log analyzer.   I noticed a file in the root were being looked at that I did not put there.  On Nov. 18 there was 2 HEAD commands for the file zip.asp. The IP points to Europe. Then starting on the 19th there were multiple GETs from all sorts of IP addresses.  Any idea how the file got there?

I also saw references to scripts/umRusy7isT.asp.  It had 1 line of code that was a response.write

I have deleted both files and the script folder as it was now empty.

Should I be concerned?
0
Comment
Question by:IBMJunkman
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40476932
Looks like you may have been hacked.
What are you running - Wordpress or something similar?
0
 

Author Comment

by:IBMJunkman
ID: 40476941
Plain old ASP based site.  No Wordpress or any other canned apps.
0
 
LVL 53

Accepted Solution

by:
COBOLdinosaur earned 500 total points
ID: 40476982
It is possible that a relatively new exploit: HttpCombiner ASP.NET - Remote File Disclosure Vulnerability was used to steal files.  It has only been around for a month but it does not look like it does damage.

See: http://www.exploit-db.com/exploits/34920/
Not a great quality site, but it does cover a lot of minor annoyances.

You need to change all your pass words and make sure you have a high level of security.  Godaddy is not the best place for hosting if you need to have anything more than minimum secerity.

Cd&
0
 

Author Comment

by:IBMJunkman
ID: 40477197
Password changed.  I noticed my default.htm had a November update date.  Looked at it and saw some code inserted with HREFs to statsboston, santancrownrotaryclub, stjohnchurchnj, tailwheelbasics, etc.  Reloaded my default.htm.  All it does is a redirect to a specific page.

Also saw a default.asp that has tons of code with an include at the bottom that included default.htm.  It has been deleted.

Also just noticed the welcome.html supplied by GoDaddy had a whole DIV inserted with tons of URLs in it.

And the Google analytics HTML was modified with the same junk.  Deleted it. Now I think I need to get it back.  I believe it made my site Google registered.

I had 2 other HTML files in the root, also. They were modified.  Not needed so I deleted them.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:IBMJunkman
ID: 40477206
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 40477508
There's shell hacks to worry about too.  Unless you had a super-weak password or were in the habit of reusing your password on multiple sites, the odds are your account wasn't hacked at all and instead the server was hacked via a higher-level exploit or another user on the server was allowing anyone to execute scripts somewhere.  Once an attacker gets access to the whole server, they can run scripts that target common file names and inject code that way and then other people use the injected files as launching points for a variety of bad behavior.  

GoDaddy is sort of (in)famous for getting their shared servers hacked.  Move to a better host if you can.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40477528
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
Apart from the pink elephant in the room that Jason has commented on, also make sure your own pc is secured.

There are plenty of viruses out there that "steal" your information - usernames/passwords etc - from your home pc and sell this on
0
 

Author Closing Comment

by:IBMJunkman
ID: 40477618
While the suggestion may not be my actual problem it prompted me to check other files which is where I found more infection.
0
 
LVL 53

Expert Comment

by:COBOLdinosaur
ID: 40479147
Glad you got it tracked down.  Now you need to deal with the prevention side of things.  You will remain vulnerable as long as you use Godaddy.  Anytime you see a host spending millions of dollars on promotion, and offering bargain prices; beware.  Cheap hosting is overpriced because what they deliver is worth less than they charge.  If you see a host all good reviews; they are probably lies written by people paid to do it.  If the reviews are on a site specializing host reviews, then they are a probably a referrer and collect a commission for every sucker they hook.

Most big name hosting companies that offer bargain rates are just looking to take your money while delivering as little as possible.  I avoid the "bigs" and use smaller hosting services like http://asmallorange.com/hosting/shared/ where I have my personal site. In the 3 years I have used them, I have only had to open 3 tickets and all got a response in under 10 minutes and all were resolved within an hour.  I generally don't make recommendation for hosting, but I suggest you look at what you actually need and then look at host who offer what you need and use a host like ASO as a baseline.  If a host costs you a couple of extra bucks a month but gives you what you need including security then you are getting good value.

Cd&
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

This article describes how to use the timestamp of existing data in a database to allow Tableau to calculate the prior work day instead of relying on case statements or if statements to calculate the days of the week.
Although it can be difficult to imagine, someday your child will have a career of his or her own. He or she will likely start a family, buy a home and start having their own children. So, while being a kid is still extremely important, it’s also …
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to dynamically set the form action using jQuery.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now