Solved

Strange files in webroot

Posted on 2014-12-02
9
240 Views
Last Modified: 2016-02-24
My website is hosted on GoDaddy.  Some time ago they turned off server logs and said everyone should use Google Analytics.  Just recently I noticed the logs are back.  So I downloaded all that were there and ran them through a log analyzer.   I noticed a file in the root were being looked at that I did not put there.  On Nov. 18 there was 2 HEAD commands for the file zip.asp. The IP points to Europe. Then starting on the 19th there were multiple GETs from all sorts of IP addresses.  Any idea how the file got there?

I also saw references to scripts/umRusy7isT.asp.  It had 1 line of code that was a response.write

I have deleted both files and the script folder as it was now empty.

Should I be concerned?
0
Comment
Question by:IBMJunkman
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40476932
Looks like you may have been hacked.
What are you running - Wordpress or something similar?
0
 

Author Comment

by:IBMJunkman
ID: 40476941
Plain old ASP based site.  No Wordpress or any other canned apps.
0
 
LVL 53

Accepted Solution

by:
COBOLdinosaur earned 500 total points
ID: 40476982
It is possible that a relatively new exploit: HttpCombiner ASP.NET - Remote File Disclosure Vulnerability was used to steal files.  It has only been around for a month but it does not look like it does damage.

See: http://www.exploit-db.com/exploits/34920/
Not a great quality site, but it does cover a lot of minor annoyances.

You need to change all your pass words and make sure you have a high level of security.  Godaddy is not the best place for hosting if you need to have anything more than minimum secerity.

Cd&
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 

Author Comment

by:IBMJunkman
ID: 40477197
Password changed.  I noticed my default.htm had a November update date.  Looked at it and saw some code inserted with HREFs to statsboston, santancrownrotaryclub, stjohnchurchnj, tailwheelbasics, etc.  Reloaded my default.htm.  All it does is a redirect to a specific page.

Also saw a default.asp that has tons of code with an include at the bottom that included default.htm.  It has been deleted.

Also just noticed the welcome.html supplied by GoDaddy had a whole DIV inserted with tons of URLs in it.

And the Google analytics HTML was modified with the same junk.  Deleted it. Now I think I need to get it back.  I believe it made my site Google registered.

I had 2 other HTML files in the root, also. They were modified.  Not needed so I deleted them.
0
 

Author Comment

by:IBMJunkman
ID: 40477206
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 40477508
There's shell hacks to worry about too.  Unless you had a super-weak password or were in the habit of reusing your password on multiple sites, the odds are your account wasn't hacked at all and instead the server was hacked via a higher-level exploit or another user on the server was allowing anyone to execute scripts somewhere.  Once an attacker gets access to the whole server, they can run scripts that target common file names and inject code that way and then other people use the injected files as launching points for a variety of bad behavior.  

GoDaddy is sort of (in)famous for getting their shared servers hacked.  Move to a better host if you can.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40477528
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
Apart from the pink elephant in the room that Jason has commented on, also make sure your own pc is secured.

There are plenty of viruses out there that "steal" your information - usernames/passwords etc - from your home pc and sell this on
0
 

Author Closing Comment

by:IBMJunkman
ID: 40477618
While the suggestion may not be my actual problem it prompted me to check other files which is where I found more infection.
0
 
LVL 53

Expert Comment

by:COBOLdinosaur
ID: 40479147
Glad you got it tracked down.  Now you need to deal with the prevention side of things.  You will remain vulnerable as long as you use Godaddy.  Anytime you see a host spending millions of dollars on promotion, and offering bargain prices; beware.  Cheap hosting is overpriced because what they deliver is worth less than they charge.  If you see a host all good reviews; they are probably lies written by people paid to do it.  If the reviews are on a site specializing host reviews, then they are a probably a referrer and collect a commission for every sucker they hook.

Most big name hosting companies that offer bargain rates are just looking to take your money while delivering as little as possible.  I avoid the "bigs" and use smaller hosting services like http://asmallorange.com/hosting/shared/ where I have my personal site. In the 3 years I have used them, I have only had to open 3 tickets and all got a response in under 10 minutes and all were resolved within an hour.  I generally don't make recommendation for hosting, but I suggest you look at what you actually need and then look at host who offer what you need and use a host like ASO as a baseline.  If a host costs you a couple of extra bucks a month but gives you what you need including security then you are getting good value.

Cd&
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
app server have enough resources... 2 40
Easy responsive table out of existing table 28 55
Grunt Copy file to another destination. 1 33
hosting images 4 27
Boost your ability to deliver ambitious and competitive web apps by choosing the right JavaScript framework to best suit your project’s needs.
Because your company can’t afford for you to make SEO mistakes, you’ll want to ensure you’re taking the right steps each and every time you post a new piece of content. This list of optimization do’s and don’ts can help you become an SEO wizard.
The viewer will get a basic understanding of what section 508 compliance can entail, learn about skip navigation links, alt text, transcripts, and font size controls.
The is a quite short video tutorial. In this video, I'm going to show you how to create self-host WordPress blog with free hosting service.

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question