|
|
已经快一年没做了,空间上的网站都是死的,不知道哪个黑客这么无聊。这是DH给我的信,大家说说要怎么解决。我已经把空间上的站全清空了,反正都被DH限制,无法打开了
Hello,
During a recent security scan we have identified that one or more of your hosted sites show signs of being compromised as they are hosting known, malicious web-based backdoors. Specifically, the following file(s) have been accessed by intruders and have been associated with unsolicited bulk email, denial of service or other abusive activity:
We have identified the following known backdoors under your account:
/home/chemin10/c*****d.com/w33595930n.php
/home/chemin10/c****d.com/w66377039n.php
/home/chemin10/1***ys.com/w78317278n.php
/home/chemin10/us**l.info/w35661341n.php
/home/chemin10/yo***ll.com/lmdex.php
/home/chemin10/y****l.com/land/lmdex.php
We have disabled the page(s) in question (via adjusting permissions on the files, e.g.. chmod, or backing up the file first renaming it to "filename.INFECTED" and cleaning up the injected code) until you are able to address this matter.
The existence of these pages on your website(s) is likely a sign you have been compromised. We completely empathize with your problem -- having a site hacked can be a frustrating and stressful experience but we hope that this notification helps prevent this matter from being a serious one. We're here to help but we need your assistance first as there are some actions we're not able to take on your behalf as they involve changes to software versions and files under your account. To that end, we highly recommend that you take the following steps:
- Update any 3rd party software under the account, including content management systems, gallery software, weblogging tools, etc. Be sure to use current, secure versions and keep them up-to-date.
- Update any plugins and/or themes on your sites (Recent attacks against websites have targeted vulnerable software such as timthumb.php which is included in some wordpress themes, separate from the core files)
- Check your website(s) files for any signs of tampering (file timestamps show recent editing) or files you did not upload yourself and remove them. Looking at the reported files above should give you a good starting point.
- Check your website(s) files for any 777 directories, (e.g.. a directory that allows anyone on the server to write or edit the files in the directory; these permissions will look like rwxrwxrwx via the command line)
- Change your FTP password(s). Be sure they are at least 8 characters in length and do not contain English words. Random numbers and letters work best.
If you have any questions, please feel free to reply to this email and we will be more than happy to assist you with securing your sites.
Sincerely,
The DreamHost security team
|
|