Solved

Strange files in webroot

Posted on 2014-12-02
9
250 Views
Last Modified: 2016-02-24
My website is hosted on GoDaddy.  Some time ago they turned off server logs and said everyone should use Google Analytics.  Just recently I noticed the logs are back.  So I downloaded all that were there and ran them through a log analyzer.   I noticed a file in the root were being looked at that I did not put there.  On Nov. 18 there was 2 HEAD commands for the file zip.asp. The IP points to Europe. Then starting on the 19th there were multiple GETs from all sorts of IP addresses.  Any idea how the file got there?

I also saw references to scripts/umRusy7isT.asp.  It had 1 line of code that was a response.write

I have deleted both files and the script folder as it was now empty.

Should I be concerned?
0
Comment
Question by:IBMJunkman
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 58

Expert Comment

by:Gary
ID: 40476932
Looks like you may have been hacked.
What are you running - Wordpress or something similar?
0
 

Author Comment

by:IBMJunkman
ID: 40476941
Plain old ASP based site.  No Wordpress or any other canned apps.
0
 
LVL 53

Accepted Solution

by:
COBOLdinosaur earned 500 total points
ID: 40476982
It is possible that a relatively new exploit: HttpCombiner ASP.NET - Remote File Disclosure Vulnerability was used to steal files.  It has only been around for a month but it does not look like it does damage.

See: http://www.exploit-db.com/exploits/34920/
Not a great quality site, but it does cover a lot of minor annoyances.

You need to change all your pass words and make sure you have a high level of security.  Godaddy is not the best place for hosting if you need to have anything more than minimum secerity.

Cd&
0
Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

 

Author Comment

by:IBMJunkman
ID: 40477197
Password changed.  I noticed my default.htm had a November update date.  Looked at it and saw some code inserted with HREFs to statsboston, santancrownrotaryclub, stjohnchurchnj, tailwheelbasics, etc.  Reloaded my default.htm.  All it does is a redirect to a specific page.

Also saw a default.asp that has tons of code with an include at the bottom that included default.htm.  It has been deleted.

Also just noticed the welcome.html supplied by GoDaddy had a whole DIV inserted with tons of URLs in it.

And the Google analytics HTML was modified with the same junk.  Deleted it. Now I think I need to get it back.  I believe it made my site Google registered.

I had 2 other HTML files in the root, also. They were modified.  Not needed so I deleted them.
0
 

Author Comment

by:IBMJunkman
ID: 40477206
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 40477508
There's shell hacks to worry about too.  Unless you had a super-weak password or were in the habit of reusing your password on multiple sites, the odds are your account wasn't hacked at all and instead the server was hacked via a higher-level exploit or another user on the server was allowing anyone to execute scripts somewhere.  Once an attacker gets access to the whole server, they can run scripts that target common file names and inject code that way and then other people use the injected files as launching points for a variety of bad behavior.  

GoDaddy is sort of (in)famous for getting their shared servers hacked.  Move to a better host if you can.
0
 
LVL 58

Expert Comment

by:Gary
ID: 40477528
What other security is there on a website besides an account user ID and password and a FTP user ID and password?
Apart from the pink elephant in the room that Jason has commented on, also make sure your own pc is secured.

There are plenty of viruses out there that "steal" your information - usernames/passwords etc - from your home pc and sell this on
0
 

Author Closing Comment

by:IBMJunkman
ID: 40477618
While the suggestion may not be my actual problem it prompted me to check other files which is where I found more infection.
0
 
LVL 53

Expert Comment

by:COBOLdinosaur
ID: 40479147
Glad you got it tracked down.  Now you need to deal with the prevention side of things.  You will remain vulnerable as long as you use Godaddy.  Anytime you see a host spending millions of dollars on promotion, and offering bargain prices; beware.  Cheap hosting is overpriced because what they deliver is worth less than they charge.  If you see a host all good reviews; they are probably lies written by people paid to do it.  If the reviews are on a site specializing host reviews, then they are a probably a referrer and collect a commission for every sucker they hook.

Most big name hosting companies that offer bargain rates are just looking to take your money while delivering as little as possible.  I avoid the "bigs" and use smaller hosting services like http://asmallorange.com/hosting/shared/ where I have my personal site. In the 3 years I have used them, I have only had to open 3 tickets and all got a response in under 10 minutes and all were resolved within an hour.  I generally don't make recommendation for hosting, but I suggest you look at what you actually need and then look at host who offer what you need and use a host like ASO as a baseline.  If a host costs you a couple of extra bucks a month but gives you what you need including security then you are getting good value.

Cd&
0

Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Changing Web Hosts: Need Your Expert Opinion & Ideas 6 48
window close link 7 35
Application.cfm not found issue 2 36
Prevent certain words from being typed in a form 6 30
When it comes to write a Context Sensitive Help (an online help that is obtained from a specific point in state of software to provide help with that state) ,  first we need to make the file that contains all topics, which are given exclusive IDs. …
Color can increase conversions, create feelings of warmth or even incite people to get behind a cause. If you want your website to really impact site visitors, then it is vital to consider the impact color has on them.
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will get a basic understanding of what section 508 compliance can entail, learn about skip navigation links, alt text, transcripts, and font size controls.

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question