Copy link to clipboard
Copied
Our servers have been hacked and we're having trouble finding the point of entry for the trojan.
What we're seeing is essentially every web file (.htm(l),.cfm,.php,.js, etc) being appended with a script code trying to load a swf from "chanm.3322.org/flash/".
We've cleaned it up once and then restarted the server and it got infected again.
Is this familiar to anybody else here yet? Any tips on cleaning this up??
Ugh, headache!
Thanks
Paul
Copy link to clipboard
Copied
Hi,
Have you checked your server logs?.
Copy link to clipboard
Copied
Please search the forums, this problem has been answered before
(basically one of the computers with FTP access is infected with
Gumblar or some other FTP-stealing-trojan).
Mack
Copy link to clipboard
Copied
Looks like it may be an image upload form:
http://badwarebusters.org/main/itemview/5298
http://www.cfexecute.com/post.cfm/spoofing-mime-types-with-coldfusion-and-cfhttp
This should tell you how to secure the form:
http://www.petefreitag.com/item/701.cfm
Ken Ford
Adobe Community Expert - Dreamweaver/ColdFusion
Adobe Certified Expert - Dreamweaver CS4
Adobe Certified Expert - ColdFusion 8
Fordwebs, LLC
http://www.fordwebs.com
http://www.cfnoob.com
Copy link to clipboard
Copied
If you are getting this kind of problem, then obviously your server-side security is insufficient:
If an image-upload succeeded in making such a file replacement, then there are any number of points at which such an action should have been rendered impossible ... and so, if they succeeded, "shame on you."
How do I say this delicately... if this happened, then the person(s) responsible should be fighting to keep their jobs in the face of "gross negligence" and "dereliction of duty." 😕
They should, as my grandma would say, at least "have some 'splainin to do..."