Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 297
  • Last Modified:

Strange files in webroot

My website is hosted on GoDaddy.  Some time ago they turned off server logs and said everyone should use Google Analytics.  Just recently I noticed the logs are back.  So I downloaded all that were there and ran them through a log analyzer.   I noticed a file in the root were being looked at that I did not put there.  On Nov. 18 there was 2 HEAD commands for the file zip.asp. The IP points to Europe. Then starting on the 19th there were multiple GETs from all sorts of IP addresses.  Any idea how the file got there?

I also saw references to scripts/umRusy7isT.asp.  It had 1 line of code that was a response.write

I have deleted both files and the script folder as it was now empty.

Should I be concerned?
0
IBMJunkman
Asked:
IBMJunkman
  • 4
  • 2
  • 2
  • +1
1 Solution
 
GaryCommented:
Looks like you may have been hacked.
What are you running - Wordpress or something similar?
0
 
IBMJunkmanAuthor Commented:
Plain old ASP based site.  No Wordpress or any other canned apps.
0
 
COBOLdinosaurCommented:
It is possible that a relatively new exploit: HttpCombiner ASP.NET - Remote File Disclosure Vulnerability was used to steal files.  It has only been around for a month but it does not look like it does damage.

See: http://www.exploit-db.com/exploits/34920/
Not a great quality site, but it does cover a lot of minor annoyances.

You need to change all your pass words and make sure you have a high level of security.  Godaddy is not the best place for hosting if you need to have anything more than minimum secerity.

Cd&
0
Free recovery tool for Microsoft Active Directory

Veeam Explorer for Microsoft Active Directory provides fast and reliable object-level recovery for Active Directory from a single-pass, agentless backup or storage snapshot — without the need to restore an entire virtual machine or use third-party tools.

 
IBMJunkmanAuthor Commented:
Password changed.  I noticed my default.htm had a November update date.  Looked at it and saw some code inserted with HREFs to statsboston, santancrownrotaryclub, stjohnchurchnj, tailwheelbasics, etc.  Reloaded my default.htm.  All it does is a redirect to a specific page.

Also saw a default.asp that has tons of code with an include at the bottom that included default.htm.  It has been deleted.

Also just noticed the welcome.html supplied by GoDaddy had a whole DIV inserted with tons of URLs in it.

And the Google analytics HTML was modified with the same junk.  Deleted it. Now I think I need to get it back.  I believe it made my site Google registered.

I had 2 other HTML files in the root, also. They were modified.  Not needed so I deleted them.
0
 
IBMJunkmanAuthor Commented:
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
0
 
Jason C. LevineNo oneCommented:
There's shell hacks to worry about too.  Unless you had a super-weak password or were in the habit of reusing your password on multiple sites, the odds are your account wasn't hacked at all and instead the server was hacked via a higher-level exploit or another user on the server was allowing anyone to execute scripts somewhere.  Once an attacker gets access to the whole server, they can run scripts that target common file names and inject code that way and then other people use the injected files as launching points for a variety of bad behavior.  

GoDaddy is sort of (in)famous for getting their shared servers hacked.  Move to a better host if you can.
0
 
GaryCommented:
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
Apart from the pink elephant in the room that Jason has commented on, also make sure your own pc is secured.

There are plenty of viruses out there that "steal" your information - usernames/passwords etc - from your home pc and sell this on
0
 
IBMJunkmanAuthor Commented:
While the suggestion may not be my actual problem it prompted me to check other files which is where I found more infection.
0
 
COBOLdinosaurCommented:
Glad you got it tracked down.  Now you need to deal with the prevention side of things.  You will remain vulnerable as long as you use Godaddy.  Anytime you see a host spending millions of dollars on promotion, and offering bargain prices; beware.  Cheap hosting is overpriced because what they deliver is worth less than they charge.  If you see a host all good reviews; they are probably lies written by people paid to do it.  If the reviews are on a site specializing host reviews, then they are a probably a referrer and collect a commission for every sucker they hook.

Most big name hosting companies that offer bargain rates are just looking to take your money while delivering as little as possible.  I avoid the "bigs" and use smaller hosting services like http://asmallorange.com/hosting/shared/ where I have my personal site. In the 3 years I have used them, I have only had to open 3 tickets and all got a response in under 10 minutes and all were resolved within an hour.  I generally don't make recommendation for hosting, but I suggest you look at what you actually need and then look at host who offer what you need and use a host like ASO as a baseline.  If a host costs you a couple of extra bucks a month but gives you what you need including security then you are getting good value.

Cd&
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

  • 4
  • 2
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now