分享

写回答

发帖

[提问] Godaddy 回信了,晕,说无法帮我们清除

GoDaddy GoDaddy 4419 人阅读 | 12 人回复

发表于 2010-5-12 19:56:49 | 显示全部楼层 |阅读模式

Unfortunately it does not appear that we have received the malicious code you intended to include with your inquiry. Please resend this information in plain text format. You may also wish to attach your response to this email as a text document. This will ensure that we are able to view your response and assist you further.

Generally, staying current with 3rd party application patches and having a strong server password are your best defenses against malware. When checking for the presence of malware, be sure to check the code residing on your server and not your backup files. Always use a virtual machine for verification to avoid infecting your own computer.

Malware can be anything from unexplained links on your web pages to executables that infect your site visitors' computers. There are three major steps to keep your hosting server and web pages free of malware. Make sure you address each of these to keep your hosting account clean and uninfected.

NOTE: Once your hosting server becomes infected with malware, we cannot assist you with its cleanup. You need to be proactive in preventing malware and in identifying/removing it if your server account becomes infected.

Identifying Malware

Perhaps Google contacted you indicating your site was infected or maybe it was one of your site visitors that alerted you. Possibly you noticed something yourself. If you think you're having an issue with malware, here are steps to identify the problem.

NOTE: Always use a virtual machine to test for malware to prevent infecting your own computer. Remember to test the code that resides on your hosting server — not your backup files.

Software downloads offered from your site may contain malware. Test any offered software posted on your site to avoid unintentionally passing along malware.

Links from your site to malware sites. Be sure to test all links on your site.

Search for unknown links — especially links to executables that you do not recognize: .exe, .bat, .cmd, .scr, or .pif.

You can purchase or download free software that scans for malicious links in your code.

Be sure to check online malware clearing houses such as http://www.stopbadware.org/ to learn of known issues.

Malware can be distributed through ads on your site. These can be identified the same way you identify malware links but you can also research problems via the Internet to see if others have had problems with your ad partner(s).

Malware links can be lurking in user-posted areas of your site. These can be identified in the same manner as links in other portions of your site.

Be alert for hacking attacks. Injection (inserting code or executables onto your web pages) is a common method of hacking that exploits a security vulnerability to introduce harmful code to one or more of your web pages.

Invisible frames: These tags set up tiny frames on a web page. They are virtually invisible because of their size. To find these, search for iframe tags with height=“0” width=“0”. These are usually placed at the very top or bottom of the source code for the page.

Obfuscated code: This type of attack is designed to be hidden and to be difficult to identify. Most common ways code is obfuscated are encoding and encrypting.

Encoding can be spotted as using hex or unicode/wide characters.

For hex, you'll see strings of percent signs ('%' ) followed by two characters (e.g. %ww%xx%yy). Unicode can be identified as "\u" followed by 4 characters and these blocks can take up several paragraphs. Example: \u9900\u1212\u8879.

Encrypted code is harder to find because there are no set patterns. Since even Javascript syntax is based on English words, most of your code should be readable. If you find entire sections of your code that are completely unintelligible blocks of letters, numbers, and symbols, you are probably looking at encrypted code.

Often the easiest method to identify malware is to download all of your source code to a virtual machine and scan it using anti-virus and anti-spyware programs.

NOTE: Most hacking focuses on HTML code but it is also possible for malware including executables, javascript files, or even images to be uploaded to your site if the hacker gains access to your hosting server.

Removing Malware

The method required to remove the malware you find on your hosting server will differ depending upon what you have found. Here are some methods to rid your hosting server of malware that has infected it.

If you find malware in software that you offer for download, remove the infected software from your site and do not offer it again until you are sure that it is not infected. If you created the software, you can use malware prevention sites to understand guidelines for software compliance.

If you find links to malware sites on your site, remove them from your code.

If ads on your site are linking to malware, remove the infected ads. If you use an ad network, this may mean removing all of the network's ads from your site until you can insure that the network is clean. You may also wish to contact your ad provider and let them know.

If malware is found in user-generated areas of your site, remove the malware links you've found. This may involve editing user posts or deleting entire user posts.

If your site has been hacked:

Take the site offline to avoid putting site visitors and customers at risk.

Remove all offending code. This is only effective long-term in conjunction prevention.

Fix underlying security vulnerabilities to prevent future attacks.

Check for and remove any 'back doors' left by the hacker. A back door allows the hacker future access even after you secure the site.

Check user forums for the software you are using on your site to determine if other users have been affected and to see if your site is missing security updates.

Preventing Malware

Long term, this is the most important tool against malware. Following these guidelines can save you time, effort, and trouble in the future.

Insure software offered for download is malware-free before making it available.

Before adding a link to your site, check it for malware.

Use only reputable ad providers and monitor them regularly.

Insure that your ad providers are currently clean and that they scan regularly for malware from advertisers.

Before choosing and implementing a new ad partner, use Internet searches to check them out for previous or current problems.

Monitor user-generated areas of your site.

Post terms of use for additions to your forums or blogs to explicitly forbid posting links to malware. Actively monitor these areas for suspicious links or executables.

Use a strong password. For guidelines on creating a password see Generating a Strong Password.

Use FTP-SSL, if available. To check your hosting server for FTP-SSL availability and to connect using FTP-SSL, see Connecting to Your Shared Hosting Account with FTP-SSL.

Scan your site for security vulnerabilities. There are both free and commercial auditing scanners you can use.

Make sure to install the latest available version and all available patches for 3rd party software you're using on your site. This is very important. If the 3rd party software you are using has a security vulnerability, your site will be vulnerable. Staying current with provider releases and security patches will lessen those vulnerabilities.

If you require the server FTP logs, please specify the 7-day-date-range you would like the logs for, and we will be happy to provide this information.

Please let us know if we can assist you in any other way.

Regards,
Will P.
Online Support Technician

大概意思就是说他们不确定这恶意代码是在他们服务器上,他们认为是我们自己的程序安全,他们无法帮我们清楚

我杯具啊,这情况怎么搞?又不是只有我自己,你们再写信去吧,我不知道怎么办了

你们再帮忙翻译下,可能我翻译会有出错

回答|共 12 个

doff

发表于 2010-5-12 20:19:36 | 显示全部楼层

这么多中招,不是他们的问题难道是我们的问题??而且配置文件gdform.php也被感染要怎么说???


转了一下你的回信
http://www.doff.com.cn/blog/articles/godaddy-kongjian-guama

joun98

发表于 2010-5-12 20:23:58 | 显示全部楼层

希望被挂上恶意代码的朋友积极联系下godaddy官方,他们现在是不认为问题是出自他们那

大家携手合作解决这件事吧

wuyinggoal

发表于 2010-5-12 20:51:13 | 显示全部楼层

真郁闷,也差不多这样回复我的

andol

发表于 2010-5-12 21:15:47 | 显示全部楼层

让你附上含有恶意代码的文件供他们参考
RAKSmart

yihongge

发表于 2010-5-12 22:00:52 | 显示全部楼层

楼主怎么写的信啊?我也要写,大家都写,看godaddy怎么处理

yt7260

发表于 2010-5-12 22:04:36 | 显示全部楼层

我也被挂了,谁英文好点的联系下GOD把eval函数给禁用了吧
RAKSmart

lieser

发表于 2010-5-12 22:24:34 | 显示全部楼层

我靠,正准备买GD呢,看来还是不买的好

kedabbs

发表于 2010-5-12 22:25:33 | 显示全部楼层

谁会写英语的 帮我也写一个 我也发一下  中了这个 <script src="http://holasionweb.com/oo.php"></script>.

yilot

发表于 2010-5-12 22:38:48 | 显示全部楼层

刚转到GD,怎么看了大家说的,还不如IX客服。
我前不久在IX的asp程序也被批量加入代码。修改回来就加入。
后来联系ix客服,他们客服帮我全站批量清楚了代码,然后让我把ftp访问ip限制打开。就是一个文件定义的。
我每天只要修改这个文件,增加我的ip,我就能ftp连接。
您需要登录后才可以回帖 登录 | 注册

本版积分规则