vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 Programming Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=15)
-   -   XSS Attack (https://vborg.vbsupport.ru/showthread.php?t=162736)

Awjvail 11-15-2007 12:08 AM

XSS Attack
 
Hi there,

recently, my website has been the victim of an (apparent) xss attack.

However, from what I gather about XSS, you need to have either PHP or Javascript on a page in order to execute an attack on it.

There has been some javascript appearing on my pages which redirects to other pages; some being spyware websites. However, on my index.html, which I use to redirect to my forums, the only code in the whole page is this:

PHP Code:

<meta http-equiv="refresh"content="0;URL=/forums/index.php"

Is it possible to execute an XSS Attack on this? Some how they are sticking javascript onto that page.. the page has no exploitable things on it.. it is just a meta refresh bringing you to my forums homepage.

I have password protected my index.html with .htaccess, however the attacks keep coming and malicious javascript keeps getting injected into index.html.

Is this an XSS attack or something different? If so, what would it be?

The same code has also been injected into virtually every index.php and index.html I have on my server, mostly in directories which nobody even knows about - something I thought was only achievable by having server access.

Marco van Herwaarden 11-15-2007 05:05 AM

If all your index.* files are affected, then it is most likely done by a script installed on your server. If you are on a ahsred server, it might even be running from a different account on the same server if the security is not setup correct for the server.

Please contact your host.

Awjvail 11-15-2007 03:17 PM

That is exactly what it was. After some fighting and them telling me it was an XSS attack multiple times, they finally (apparently) have fixed it. Ironic, because their support website was also affected by this issue.

This is what they told me (They said "Dear Blair".. I've got no clue who Blair is.):

Quote:

Dear Blair,

We have investigated the root cause of the issue and it is a type of iframe hacking from an Serbian IP which got into one of the customised php scripts of one of the clients and then got FTP access of domains and modified the pages.

We have removed that script and the banned the IP and process of removing that hacked script from the domains in under process.

We have also added some strong mod_security and firewall rules to prevent this .


Please feel free to contact us back in case of any other information.


Please feel free to contact us back in case of any other information.


Regards,

Alan

Analogpoint 11-15-2007 04:49 PM

Quote:

Originally Posted by Awjvail (Post 1383085)
their support website was also affected by this issue.

Look for a new host.

Awjvail 11-15-2007 05:42 PM

I was thinking about that.. however, what put me off was the great deals that this host has. I get 500gb of diskspace, unmetered bandwidth, etc, all for a very, very, reasonable price. My site uses about 35gb of bandwidth per month, however we expect our traffic to rise somewhat in the next few weeks when we partner with a large company.

Do you know of anything comparable to what we have now?

Zachery 11-15-2007 05:44 PM

lol, you're not paying enough to get that much.

I pay for a dedicated server and don't even get 500gb of storage.

Awjvail 11-15-2007 05:48 PM

How do you know how much we pay? :\

Zachery 11-15-2007 05:59 PM

Are you paying more than 300 dollars a month for that shared hosting account?

Awjvail 11-15-2007 06:03 PM

Nope; we're not, and I agree - their plans are unrealistic.

We don't use 500gb of disk space anyway and I highly doubt we ever will - we only use about 400mb, if that.

Can anyone recommend me a better host? Our website is not nearly large enough for a dedicated server; perhaps a VPS? I'm not even sure we're big enough for that :P

Princeton 11-16-2007 12:23 PM

as the saying goes ...
"You get what you pay for."

next attack - you will loose everything ...
protect yourself and get a new host now

Awjvail 11-16-2007 12:39 PM

I'm in the process of looking for a new host as we speak.

Please see this thread: https://vborg.vbsupport.ru/showthread.php?t=162819

The host is www.3ix.org in case anybody cares.

Ever since this incident their support has been very pissy towards me whenever I use support.


All times are GMT. The time now is 08:42 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01027 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (11)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete