Solved

Strange files in webroot

Posted on 2014-12-02
9
261 Views
Last Modified: 2016-02-24
My website is hosted on GoDaddy.  Some time ago they turned off server logs and said everyone should use Google Analytics.  Just recently I noticed the logs are back.  So I downloaded all that were there and ran them through a log analyzer.   I noticed a file in the root were being looked at that I did not put there.  On Nov. 18 there was 2 HEAD commands for the file zip.asp. The IP points to Europe. Then starting on the 19th there were multiple GETs from all sorts of IP addresses.  Any idea how the file got there?

I also saw references to scripts/umRusy7isT.asp.  It had 1 line of code that was a response.write

I have deleted both files and the script folder as it was now empty.

Should I be concerned?
0
Comment
Question by:IBMJunkman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40476932
Looks like you may have been hacked.
What are you running - Wordpress or something similar?
0
 

Author Comment

by:IBMJunkman
ID: 40476941
Plain old ASP based site.  No Wordpress or any other canned apps.
0
 
LVL 53

Accepted Solution

by:
COBOLdinosaur earned 500 total points
ID: 40476982
It is possible that a relatively new exploit: HttpCombiner ASP.NET - Remote File Disclosure Vulnerability was used to steal files.  It has only been around for a month but it does not look like it does damage.

See: http://www.exploit-db.com/exploits/34920/
Not a great quality site, but it does cover a lot of minor annoyances.

You need to change all your pass words and make sure you have a high level of security.  Godaddy is not the best place for hosting if you need to have anything more than minimum secerity.

Cd&
0
Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

 

Author Comment

by:IBMJunkman
ID: 40477197
Password changed.  I noticed my default.htm had a November update date.  Looked at it and saw some code inserted with HREFs to statsboston, santancrownrotaryclub, stjohnchurchnj, tailwheelbasics, etc.  Reloaded my default.htm.  All it does is a redirect to a specific page.

Also saw a default.asp that has tons of code with an include at the bottom that included default.htm.  It has been deleted.

Also just noticed the welcome.html supplied by GoDaddy had a whole DIV inserted with tons of URLs in it.

And the Google analytics HTML was modified with the same junk.  Deleted it. Now I think I need to get it back.  I believe it made my site Google registered.

I had 2 other HTML files in the root, also. They were modified.  Not needed so I deleted them.
0
 

Author Comment

by:IBMJunkman
ID: 40477206
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 40477508
There's shell hacks to worry about too.  Unless you had a super-weak password or were in the habit of reusing your password on multiple sites, the odds are your account wasn't hacked at all and instead the server was hacked via a higher-level exploit or another user on the server was allowing anyone to execute scripts somewhere.  Once an attacker gets access to the whole server, they can run scripts that target common file names and inject code that way and then other people use the injected files as launching points for a variety of bad behavior.  

GoDaddy is sort of (in)famous for getting their shared servers hacked.  Move to a better host if you can.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40477528
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
Apart from the pink elephant in the room that Jason has commented on, also make sure your own pc is secured.

There are plenty of viruses out there that "steal" your information - usernames/passwords etc - from your home pc and sell this on
0
 

Author Closing Comment

by:IBMJunkman
ID: 40477618
While the suggestion may not be my actual problem it prompted me to check other files which is where I found more infection.
0
 
LVL 53

Expert Comment

by:COBOLdinosaur
ID: 40479147
Glad you got it tracked down.  Now you need to deal with the prevention side of things.  You will remain vulnerable as long as you use Godaddy.  Anytime you see a host spending millions of dollars on promotion, and offering bargain prices; beware.  Cheap hosting is overpriced because what they deliver is worth less than they charge.  If you see a host all good reviews; they are probably lies written by people paid to do it.  If the reviews are on a site specializing host reviews, then they are a probably a referrer and collect a commission for every sucker they hook.

Most big name hosting companies that offer bargain rates are just looking to take your money while delivering as little as possible.  I avoid the "bigs" and use smaller hosting services like http://asmallorange.com/hosting/shared/ where I have my personal site. In the 3 years I have used them, I have only had to open 3 tickets and all got a response in under 10 minutes and all were resolved within an hour.  I generally don't make recommendation for hosting, but I suggest you look at what you actually need and then look at host who offer what you need and use a host like ASO as a baseline.  If a host costs you a couple of extra bucks a month but gives you what you need including security then you are getting good value.

Cd&
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
One event, two days, a great line-up of speakers, and 48% female presence. Still have no idea what I’m talking about?
Any person in technology especially those working for big companies should at least know about the basics of web accessibility. Believe it or not there are even laws in place that require businesses to provide such means for the disabled and aging p…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question