Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Iframe Malware in my website.

General questions about VestaCP
Post Reply
  • Print view
Advanced search
16 posts
  • Previous
  • 1
  • 2
mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: Iframe Malware in my website.
  • Quote

Post by mehargags » Thu Mar 05, 2015 3:09 pm

I can point you in some Directions, may be it can help you.

pls check attached some PHP/SH scripts that you can run to see your code's malicious detection. I don't remember whereall I got these from so posting the whole folder.

CodeScanner.zip
------------------------------
Also try try scanning with maldet https://www.rfxn.com/projects/linux-malware-detect/

The infected files with injected code should have a different modified date than the rest of the files of the website? so start spotting them by date modified, you may possibly be able to spot the injected files.

As Skurudo hinted... search all the files for "eval(" to detect anything suspicious.

Code: Select all

grep -R "eval(" .
the Last and absolute resort would be to get all files checked by a PHP Dev .

Good luck
Top

30874
Posts: 33
Joined: Tue Mar 03, 2015 1:22 am

Re: Iframe Malware in my website.
  • Quote

Post by 30874 » Fri Mar 06, 2015 2:48 am

mehargags wrote:I can point you in some Directions, may be it can help you.

pls check attached some PHP/SH scripts that you can run to see your code's malicious detection. I don't remember whereall I got these from so posting the whole folder.

CodeScanner.zip
------------------------------
Also try try scanning with maldet https://www.rfxn.com/projects/linux-malware-detect/

The infected files with injected code should have a different modified date than the rest of the files of the website? so start spotting them by date modified, you may possibly be able to spot the injected files.

As Skurudo hinted... search all the files for "eval(" to detect anything suspicious.

Code: Select all

grep -R "eval(" .
the Last and absolute resort would be to get all files checked by a PHP Dev .

Good luck
Thank you very much. Now I will do anything that let it solve.

Narong.
Top

30874
Posts: 33
Joined: Tue Mar 03, 2015 1:22 am

Re: Iframe Malware in my website.
  • Quote

Post by 30874 » Fri Mar 06, 2015 2:54 am

30874 wrote:
mehargags wrote:I can point you in some Directions, may be it can help you.

pls check attached some PHP/SH scripts that you can run to see your code's malicious detection. I don't remember whereall I got these from so posting the whole folder.

CodeScanner.zip
------------------------------
Also try try scanning with maldet https://www.rfxn.com/projects/linux-malware-detect/

The infected files with injected code should have a different modified date than the rest of the files of the website? so start spotting them by date modified, you may possibly be able to spot the injected files.

As Skurudo hinted... search all the files for "eval(" to detect anything suspicious.

Code: Select all

grep -R "eval(" .
the Last and absolute resort would be to get all files checked by a PHP Dev .

Good luck
Thank you very much. Now I will do anything that let it solve.

Narong.
How to use the PHP scripts scan file as your suggestion. I am new to all activities, but I am trying to do it
Top

30874
Posts: 33
Joined: Tue Mar 03, 2015 1:22 am

Re: Iframe Malware in my website.
  • Quote

Post by 30874 » Fri Mar 06, 2015 4:06 am

skurudo wrote:You need to delete or move those files from your site, but how it work after this - it's need to test
Now , I try to delete it from my site and acutally i need to delete all data from my site . I can do it again how to delete the problem site out of vesta (I mean format this site but still keep another site in vesta).

I hope you can help me for this.
Best regards,
Narong.
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: Iframe Malware in my website.
  • Quote

Post by mehargags » Fri Mar 06, 2015 9:45 am

Copy the PHP file inside your site root and call it from the browser, the SH script needs to be run from SSH.
Top

30874
Posts: 33
Joined: Tue Mar 03, 2015 1:22 am

Re: Iframe Malware in my website.
  • Quote

Post by 30874 » Sat Mar 07, 2015 3:20 pm

mehargags wrote:Copy the PHP file inside your site root and call it from the browser, the SH script needs to be run from SSH.
Thank you very much . I am trying and let you know about stauts.

Best regards,
Narong.
Top


Post Reply
  • Print view

16 posts
  • Previous
  • 1
  • 2

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password