Announcement

Collapse
No announcement yet.

MiFbody.com Trojan/Worm Infection Warning

Collapse
X
Collapse
Who has read this thread:
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • MiFbody.com Trojan/Worm Infection Warning

    Guys,

    I regret to have to inform everyone that on 4/11 at 5:30pm, MiFbody.com was hacked and a trojan/worm code was injected into many of the .htm, .html, and .php files on the website. The person that actually hacked the site not only infected MiFbody.com but infected the other site on my server, Meissenation.com, too -- literally infecting hundreds of files with a possibly malicious code string.

    I'm slowly going through the very tedious process of manually removing the string from each individual file that was edited on April 11th. I'm not even close to being finished at this point, but I wanted to throw up a warning message sooner than later.

    At this point, I do not know the seriousness of the trojan/worm. BitDefender 2008 with up-to-date definitions, Symantec Antivirus corporate edition with up-to-date definitions, and McAfee Antivirus corporate edition on Vista with up-to-date definitions never picked up any viruses in their scans, nor did it ever warn me when going to the page.

    When my hard drive crashed after the M&G, I went back to using Windows XP and was using BitDefender 2008 for a period of time. It wasn't working as I wanted, so I decided to go back to the free route and went back to Avast! over the weekend. Today for the first time I actually allowed Meissenation.com to load (I normally go straight to MiFbody) which then popped up a warning message that the index.php file which loads first on Meissenation.com was infected.

    For the most part, those that go to http://www.mifbody.com/vbulletin/ directly should not be as concerned. Those that went to http://www.mifbody.com/ which then redirects to the vbulletin website are those that might be infected.

    Again, I do not know 100% the seriousness of the trojan/worm or whether it's even a trojan/worm at all. I've had a hard time even finding any information on the internet about the code that was added to all my files and it *seems* that Avast! is the only antivirus that's even picking it up.

    Regardless, I felt it was my responsibility to alert everyone. I'm currently in the process of editing and expunging all the virus code from the .htm, .html, and .php files and will update when MiFbody.com has been "cleaned."

    Sorry guys.

    - Brian
    Last edited by meissen; July 15th, 2008, 09:55 PM.
    - Brian Meissen
    Owner, MiFBody.com
    Administrator, LTxTech.com


    1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
    2022 Camaro LT1 - "Cherry Bomb 2"
    Michigan FBody Meet & Greet Car Show 2022
    June 4th, 2022 - 9am to 3pm!!!
    The HUB Stadium, Auburn Hills, MI

  • #2
    WORMSSS

    Comment


    • #3
      Damn hackers! Glad I go straight to the forums though.

      Comment


      • #4
        ouch...f'ing losers

        Comment


        • #5
          Update: Well, my eyes are burning and bloodshot, but I've gone through every single folder and edited every single .html, .htm, and .php file infected on 4/11 at 5:30pm in the /vbulletin/ directory so I can say the whole forum has been cleansed.

          ON A POSITIVE NOTE:
          I did a search of the website address that the code was trying to access and came up with this page:
          http://www.castlecops.com/p1093493-Funberry.html

          They list a file that was downloaded and a file that opens with internet explorer which allows the malware to run. I searched my computer for both files and found no traces of those files specifically. SO -- as long as it is using a static file name and not dynamically changing with each instance, I myself did not have the virus on my computer and I'm hoping it'd be the same for everyone else.
          - Brian Meissen
          Owner, MiFBody.com
          Administrator, LTxTech.com


          1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
          2022 Camaro LT1 - "Cherry Bomb 2"
          Michigan FBody Meet & Greet Car Show 2022
          June 4th, 2022 - 9am to 3pm!!!
          The HUB Stadium, Auburn Hills, MI

          Comment


          • #6
            My virus scan found nothing, but I just have AVG.

            Comment


            • #7
              Whenever I clicked the "Photo Gallery" I got a warning about a trojan. It doesn't do that anymore! Good work Brian!!!
              Last edited by Chicklet; July 16th, 2008, 07:30 AM.
              Bingo Bangle Jewelry Design
              http://bingobangle.synthasite.com/



              sigpic

              Comment


              • #8
                Good work bud



                VicePresident of West Michigan Firebird Club
                A.K.A The Maverick
                http://www.cardomain.com/ride/660128/1
                93 TA Currently Under Construction AGAIN
                2007 2500 Chevy Silverado Crew Cab w/ 6.0L & 3.73's

                Comment


                • #9
                  I set up an access control list so my home IP address is the -ONLY- IP address allowed to access the server via SSH (which is how the hacker got in) so that should stop it from happening again.
                  - Brian Meissen
                  Owner, MiFBody.com
                  Administrator, LTxTech.com


                  1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                  2022 Camaro LT1 - "Cherry Bomb 2"
                  Michigan FBody Meet & Greet Car Show 2022
                  June 4th, 2022 - 9am to 3pm!!!
                  The HUB Stadium, Auburn Hills, MI

                  Comment


                  • #10
                    Sweet.

                    Comment


                    • #11
                      Damnit Todd, why do you do these things???

                      Secret hacker life, Brian worship... What's next?!?












                      Thanks for the heads up B, but it's not your fault at all, this is just some hopeless loser ****ing with all that's good. Great work on cleaning it up, though.
                      Gone but not forgotten: 1986 Chevrolet Camaro IROC-Z

                      "You shall ride eternal. Shiny and chrome."

                      Comment


                      • #12
                        Originally posted by meissen View Post
                        I set up an access control list so my home IP address is the -ONLY- IP address allowed to access the server via SSH (which is how the hacker got in) so that should stop it from happening again.
                        overflow attack? or did he hack the root or some other priviledge account?

                        Comment


                        • #13
                          Originally posted by bmwmcars View Post
                          overflow attack? or did he hack the root or some other priviledge account?
                          Hacked root some how or another. Root password was the default password that my host gave me. It was a randomized "complex" 8-digit password and used alphanumeric characters (not a word disguised with numbers, totally random), so I just never changed it after the host gave it to me as I figured it was 'secure enough.' As soon as I realized the intrusion into root, I changed the password for the root account to a more complex 16 digit password.

                          I have it set up so that any time root level access is granted I get an e-mail with the IP address and host name. I went through my e-mail folder and found I did have the e-mail from the time the hacker got root access, but surprisingly the IP and hostname were blank. I don't quite know what that means. I tested logging into SSH using a different username that was not root and then using the su command it and it still e-mailed me with my IP and hostname filled in, so not sure. I'm not linux guy, so I don't quite understand it all.

                          Go figure though... set up the security to e-mail me when root is granted, yet I didn't investigate when I received the e-mail back on April 11th and I disregarded it.
                          - Brian Meissen
                          Owner, MiFBody.com
                          Administrator, LTxTech.com


                          1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                          2022 Camaro LT1 - "Cherry Bomb 2"
                          Michigan FBody Meet & Greet Car Show 2022
                          June 4th, 2022 - 9am to 3pm!!!
                          The HUB Stadium, Auburn Hills, MI

                          Comment


                          • #14
                            So Brian, for us old geezers that are not all that good at computers, how do we know if we are infected. I use Norton, which you said did not find the virus. Is there anything unusual we might notice on our computer that would possibly tip us off that we have this virus?
                            RIP Doug,You will always be remembered
                            3/3/53 ~ 12/22/10

                            Western Michigan Camaro Club - President
                            2002 Hot Rod Magazine Ltd. Ed. by Berger
                            1985 Camaro IROC-Z
                            1974 Camaro Type LT / Z28
                            2002 Trail Blazer LTZ
                            2003 Honda VFR 800i Interceptor

                            1996 Camaro SS (Sold )

                            www.wmcamaro.org

                            Comment


                            • #15
                              Let me try to find more information. The link I posted to CastleCops mentions two files -- a KB######.exe file and a .DLL file. Do a search of your computer for either of those files. I didn't have them on my comp but maybe my antivirus at the time caught it and never told me.

                              Comment

                              Working...
                              X