Dwayne Coots

Renaissance Biological Organism

  • Home
  • News Channel
  • About
  • TechnoVision
You are here : Dwayne Coots » Tech Channel » FTP Exploit – Back Door to Your Website

FTP Exploit – Back Door to Your Website

Published On 04 Oct 2009 By Dwayne. Under: Tech Channel. Tags: free information, malware, malware prevention, security, webmaster resources, webmaster security  

Recently a client reported the heder.php exploit had infected their website. They needed help with the cleanup, so we got them back online, but they had questions like, “How did these files get onto my site?”

First understand that heder.php is just one type of site trojan. There are many flavors of this type of site exploit and they have some things in common, so it might be worth a blog post to cover them.

These kinds of exploits compromise your hosting account. Then they install malicious code into your html pages. They also add some entries to your htaccess file to redirect incoming traffic to the payload. Usually the payload is a version of the same exploit so the code can spread to the next victim.

So now we know how you get it… Basically, this exploit is usually dropped onto your machine when you visit an infected website. It will overwrite a Microsoft ActiveX file on your machine — which is how it hides from your antivirus. (Yes as usual it’s a Micro$oft exploit).

So what does it do?

In the background it scans for usernames and passwords. If it finds them it steals then and uploads them to the hackers. If it finds FTP credentials it uses those to upload itself to your websites and inject some code into your home page and write some backdoor ssh access files into your server space.  This is how it spreads – once it is on your website, anyone who lands on it gets the new code and the process starts attacking their machine.

I have anti-virus software so I’m safe right?

Nyet! Most Antivirus software cannot find it because it is more like spyware. Also it hits your machine via php and javascript code and those are functions your web browser uses all the time — so a firewall is useless to prevent this. Since it hacks an activex helper it hides really well from scanners.

Okay so why do people do this crap? Why me? What do they get out of it?

The hackers make money by retrieving your other credentials (usernames and passwords to banking sites, credit cards etc…) as well as personal info (your SSN, address, phone numbers, etc) and then it uploads them to a public board in encrypted form that only the original programmers have the decrypt key to. So all your data is uploaded to a public forum and the hackers pull these files daily and decrypt them. Then they:

  • Sell your email address to spammers
  • Sell your personal info to identity thieves
  • Sell your credit card details to fraudsters
  • Share your exploited ftp details with partners who now have write-privilege to install other payloads to your website…
  • Then they post teaser code to boards to help other hackers develop better code.

As a webmaster you should always keep a close eye on your security — particularly ftp credentials. FileZilla is one popular ftp client that is taking a big hit because it stores your credentials in unencrypted format. So if you manage 10 websites for clients and use FileZilla for FTP – you could be at real risk. FilaZilla is an excellent Windows FTP client, but please do not store your passwords in it. (Uncheck the “Save Password” box in the FTP profiles and keep a separate encrypted list of site credentials.)

Hope this helps…

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  

Trackbacks/Pingbacks

  1. » FTP Exploit – Back Door to Your Website » Free Software
  2. FTP Exploit – Back Door to Your Website Webmaster World
« Got Docs? Use Scribd to Convert and Post Them
Then They Came for the Bloggers… »
Related Articles From This Category
Video Conferencing Solutions

Video Conferencing Solutions

Published On 18 Feb 2010  

Video Conferencing Solutions Guest Post By: Sean W. Do you need to train your employees ...

Still Stuck with Stone Age Dialup?

Still Stuck with Stone Age Dialup?

Published On 05 Feb 2010  

Recently I've been having to deal with a client who lives in a remote area ...

Then They Came for the Bloggers…

Then They Came for the Bloggers…

Published On 06 Oct 2009  

Another death blow to free speech came on the morning of October 5th, 2009 as ...

Thick or Thin Affiliate? Work vs Worry

Thick or Thin Affiliate? Work vs Worry

Published On 13 Jan 2009  

The thick and thin of affiliate marketing often comes down to a trade-off between work ...

Install a Custom WordPress Theme

Install a Custom WordPress Theme

Published On 27 Aug 2008  

So you have your own blog using WordPress and want to install a custom theme. ...

  • Links
    • At Your Servers
    • Free Classifieds
    • Human Consciousness 2.0
    • Mama Coots Blog
    • Mobile Business Services
    • My Google Buzz
    • My Posterous
    • My Twitter
    • Permanent Backlinks
    • Power Site Promotion
    • Rovin Net
  • dwaynecoots @ Twitter
  • Categories
    • Answers
    • Commentary
    • Mailbag
    • Marketing
    • News
    • Resources
    • SEO
    • Tech Channel
    • Uncategorized
    • Website Design Tips
  • Tags
    affiliate marketing article marketing articles blue dial Coldwell Banker custom blog theme dermatechrx documents First Time Home Buyer Tax Credit freedom free information globalism google SEO tools healthcare INFO internet marketing malware malware prevention Marketing News pdf PPP real estate referrer spam research scribd search engine secrets search metrics search trends security SEO SEO and search marketing SEO marketing SEO search marketing server stats skincare solutions skin problems social media marketing theme tutorial thin affiliate web design tips webmaster resources webmaster security webspam wordpress theme
DarkGloss WordPress Theme By MagPress
Thanks To Free MMO Games | VPS Hosting | Video Hosting
Copyright © 2010 Dwayne Coots All Rights Reserved.