|
-
January 18th, 2012, 07:09 PM
#5
Junior Member
Some additional notes.
I looked up DNS poisoning, and it's certainly possible, but it's not clear how I'd diagnose it or fix it. I don't even know how to find out what DNS server would be involved. The hosting service is large, and may well operate its own DNS server, which would explain why I'm having problems with two different domains on the same host. Again, though, it's not clear to me how DNS poisoning could lead to modified files in my address space.
I couldn't find any clear references to "back shell," but there were references to "connect-back shell." I gather that's a shell that automatically connects to a user when it's started. I don't think there is such a thing on our server; we're not supposed to have shell access at all, so I'm quite sure there isn't supposed to be!
All of these break-ins look automated to me: a little code was appended or prepended to index.php or .htaccess. There's no indication that a human hacker has ever looked at one of our sites. That's consistent with my belief that nothing like a call-back shell is involved.
Up until now I thought the host simply did not support secure FTP. I just discovered that they do, but it's disabled by default -- you have to request them to turn it on. We'll be doing that, if we stay with the host long enough for it to matter!
Last edited by Orthoducks; January 19th, 2012 at 03:03 PM.
Similar Threads
-
By intmon in forum Security News
Replies: 1
Last Post: July 15th, 2005, 06:52 PM
-
By SwordFish_13 in forum AntiOnline's General Chit Chat
Replies: 19
Last Post: April 5th, 2004, 04:40 AM
-
By SDK in forum AntiOnline's General Chit Chat
Replies: 0
Last Post: February 27th, 2004, 03:56 PM
-
By gore in forum Newbie Security Questions
Replies: 11
Last Post: December 29th, 2003, 08:01 AM
-
By DigitalSyntax in forum Web Security
Replies: 0
Last Post: March 27th, 2003, 08:25 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|