Jump to content

Recommended Posts

Posted (edited)

DISCLAIMER

DO NOT CLICK LINKS IN THIS THREAD UNLESS YOU'RE SURE YOU'RE TESTING IN A 100% SAFE ENVIRONMENT!

 

With that over...

 

Here is a pure funky issue we've come across and we would like your assistance please (although please be careful!)

 

We had a report that our students were going to a legitimate school resource website and were instead being redirected to that nasty XP-Antivirus 2009 virus website.

 

So off we go and dutifully investigate.

 

The website we were going to is:

(DISABLED TO PREVENT CLICK)

www(DOT)sense-lang(DOT)org/typing/

 

If we enter the URL in the web browser directly, it goes through to the site just fine. However, if we go to google.com and search for "sense lang" and click the link there we get redirected to the antivirus-virus site.

 

It redirects to antivirusonlivescan.com DANGER! - Browsing to this page may infect!

 

Now, we were thinking at first it was a DNS attack, but no! If it was, it would surely go to the wrong site if we typed the url straight.

 

So it must be something with the link. Google itself actually links straight to the site, and the site seems clean when directly going there. The URL in the bar actually changes which indicates it's not a DNS attack. It's very odd.

 

Even more strange is that if we go unfiltered, we don't suffer this problem.

 

This made us think it was a problem with one of our proxies/filters.

 

There are two proxies/filters in our path:

 

{ Internet } -> SWGfL Proxies (staffproxy.swgfl.org.uk / proxy.swgfl.org.uk) -> Smoothwall -> { Us }

 

We connected via both the staffproxy and the standard proxy and eliminated Smoothwall from the equation (as we were still having the problem if we were on the SWGfL proxies).

 

To me, it seems like something has hijacked the SWGfL proxy. We tried a few other search engines, and made our own web-page which linked to sense-lang and some of these were safe.

 

Our own link was clean, as was live.com and a few minor search engines. But using yahoo, altavista or ask.com returned virii infected links.

 

If anyones brave enough to set themselves up a virtual machine session and test with proxies (even better if you're on the SWGfL) to see if you also suffer the same conditions to get erroneously linked off to said virus site.

 

I for one am totally baffled as to how the redirect is happening.

 

As for our machines, they're clean and have nod32 installed. We also deny exe files from being downloaded from every proxy in the pipeline. We are certain there isn't another virus sitting at our end.

 

I'll be interested in peoples results, and please be careful!

 

Thanks!

Edited by ZeroHour
borking the link to prevent accidents - ZH
  • Thanks 1
Posted

Good finds, still confused as to how the search engines are linking the hi-jacked connection/virus but totally displaying info regarding the genuine site right down to the url you link to instead... Plus now we get inconsistent results with being through a proxy or not, so I'm not convinced the proxy has any bearing on it at all.

 

Sometimes we get through to the proper website via clicking a google link, but we ALWAYS get through to the proper site by putting it into the web-address bar.

 

What's more funky is to view the google cache, looks like executable code!

Posted (edited)

I'm using an unproxied direct link here on what I believe(!) is a clean machine. If I use your query of "Sense lang" and click the result link in Google, I get the redirect - however what is odd is that if I right click the link and copy/paste to the URL bar, I get http://sense-lang.org/typing/ - which is correct. If I then hit enter, it works and displays the correct website.

 

It seems like the "Sense lang" website has been compromised in some way - look at the following wget. First one uses no referrer - same as typing into the URL bar or copying and pasting the link.

 

>wget "http://sense-lang.org/typing/"
--12:24:37--  http://sense-lang.org/typing/
Resolving sense-lang.org... 71.18.63.16
Connecting to sense-lang.org|71.18.63.16|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 31718 (31K) [text/html]
Saving to: `index.html'

100%[=======================================>] 31,718      36.1K/s   in 0.9s

12:24:39 (36.1 KB/s) - `index.html' saved [31718/31718]

 

>wget --referer=http://www.google.com http://sense-lang.org/typing/
--12:25:35--  http://sense-lang.org/typing/
Resolving sense-lang.org... 71.18.63.16
Connecting to sense-lang.org|71.18.63.16|:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: http://89.28.13.202/in.html?s=ix [following]
--12:25:35--  http://89.28.13.202/in.html?s=ix
Connecting to 89.28.13.202:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: http://viewallclicks.com/soft.php?aid=0147&d=6&product=XPA&refer=bb1f0
c2b3 [following]
--12:25:36--  http://viewallclicks.com/soft.php?aid=0147&d=6&product=XPA&refer=b
b1f0c2b3
Resolving viewallclicks.com... 89.149.227.232
Connecting to viewallclicks.com|89.149.227.232|:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: http://proffesional-scan.com/2009/1/freescan.php?nu=880147 [following]

--12:25:36--  http://proffesional-scan.com/2009/1/freescan.php?nu=880147
Resolving proffesional-scan.com... 89.149.253.215, 78.159.118.217
Connecting to proffesional-scan.com|89.149.253.215|:80... connected.
HTTP request sent, awaiting response... 302 Found
Location: en/freescan.php?id=880147 [following]
--12:25:36--  http://proffesional-scan.com/2009/1/en/freescan.php?id=880147
Reusing existing connection to proffesional-scan.com:80.
HTTP request sent, awaiting response... 200 OK
Length: 1386 (1.4K) [text/html]
Saving to: `freescan.php@id=880147'

100%[=======================================>] 1,386       --.-K/s   in 0s

12:25:36 (46.8 MB/s) - `freescan.php@id=880147' saved [1386/1386]

 

That result is consistent/repeatable.

 

Trying to grab the 89.28.13.202/in.html file without a parameter gets you a 302 back to Google. Clever.

Edited by OutToLunch
  • Thanks 2
Posted
That's very interesting indeed! And it must be picking up specific referrers too, as we've clicked through on some other search engines and it's a-ok.
Posted

If you own a site you don't Google it. Therefore when you type in the address http://www.website.com (of your site) you get through to it fine.

 

When other users want to find it they Google it and get a virus.

 

It's a very clever ploy that can hand a virus to lots of users but when the admin gets reports and types in his web address he doesnt see anything wrong.

  • Thanks 1
Posted
Thanks for the research, quite a sneaky one too. Definitely one to look out for, especially with the number of students/teachers that can't follow instruction and put URL's straight into google.
Posted

I discovered earlier this morning that the same thing was happening with my web site. Viewing any of my URLs directly worked fine, but any referrals to my site from Google were instead getting sent to http://89[DOT]28[DOT]13[DOT]202/in.html?s=ix

 

I checked a number of complex possibilities, searching for an answer, without success. Then I decided to check a simple answer -- I checked my web site's root directory to see if someone had planted a rogue file in there.

 

I immediately discovered that my .htaccess file had been modified -- by someone other than me -- and replaced with code that sent any referrals from the major search engines to the URL above.

 

I'm not sure how someone was able to replace my .htaccess file with their own code, but that's what happened. Naturally I've now removed their "pirate code" and put my own .htaccess file back in place. Now Google referrals are working properly.

Posted
that nasty XP-Antivirus 2009 virus website.

 

There's an article about this in this month's PC Pro, with quite a detailed explanation of how it works. One phrase mentioned was "drive-by download". I assume this shouldn't be a problem with a decent, recently patched web browser, but could it be that Internet Explorer still has some vulnerabilities?

 

--

David Hicks

Posted
I discovered earlier this morning that the same thing was happening with my web site. Viewing any of my URLs directly worked fine, but any referrals to my site from Google were instead getting sent to http://89[DOT]28[DOT]13[DOT]202/in.html?s=ix

 

I checked a number of complex possibilities, searching for an answer, without success. Then I decided to check a simple answer -- I checked my web site's root directory to see if someone had planted a rogue file in there.

 

I immediately discovered that my .htaccess file had been modified -- by someone other than me -- and replaced with code that sent any referrals from the major search engines to the URL above.

 

I'm not sure how someone was able to replace my .htaccess file with their own code, but that's what happened. Naturally I've now removed their "pirate code" and put my own .htaccess file back in place. Now Google referrals are working properly.

 

What version of apache are you running and on what os?

It would be good to know why you were hacked to warn others. Thanks for the post and welcome to EduGeek as well :)

Posted

My site is hosted at IXwebhosting.com. I've seen posts from other IX clients that their sites are being attacked the same way. The rogue .htaccess file is being uploaded via FTP. I've changed my FTP password.

 

I'm on a Linux server with Apache - 1.3.31

  • Thanks 1
Posted

Hi ,

I am the owner of sense-lang.org.

I just want to let you know that the problem has been solved by deleting the htaccess file that had been rewrited by malicious program.

Anyway thanks for your help

Asaf

  • Thanks 1
Posted
Cheers for the responses guys, welcome to EduGeek and I hope IX sort the whole out soon. I would look for compensation tbh as your reputation is directly affected by this.
  • 3 weeks later...
Posted
My site is hosted at IXwebhosting.com. I've seen posts from other IX clients that their sites are being attacked the same way. The rogue .htaccess file is being uploaded via FTP. I've changed my FTP password.

 

I'm on a Linux server with Apache - 1.3.31

 

 

I see you are at IXwebhosting.com.

So am I.

I see you have experienced this problem November 11th.

I was made conscious of it only by November 20th.

 

I would like to know if you contacted the IXwebhosting.com administrators about this security matter.

 

If you rather make your answer private let me know how we can do that.

Thank you.

 

-Roger

in Québec City.

Posted
Cheers for the responses guys, welcome to EduGeek and I hope IX sort the whole out soon. I would look for compensation tbh as your reputation is directly affected by this.

 

How can we unite our efforts to look for compensation ?

Posted
I see you are at IXwebhosting.com.

So am I.

I see you have experienced this problem November 11th.

I was made conscious of it only by November 20th.

 

I would like to know if you contacted the IXwebhosting.com administrators about this security matter.

 

If you rather make your answer private let me know how we can do that.

Thank you.

 

-Roger

in Québec City.

 

No, I did not alert IX Webhosting. They should be alerting me (and you) about it.

Posted

I'd be interested in a full run down of what version of Apache, PHP, and what modules were installed as this sort of thing really is something to keep on top of.

 

If you don't maintain the server though I would push for compensation (even if it's a free month or two) or better yet, get a much better managed service.

Posted (edited)
Can you confirm the date and time the .htaccess file(s) was updated?

 

Thank you

 

Yes. My .htaccess file was hacked and replaced by the hacker's .htaccess file on Nov 7, 2008, at 7:58 pm, according to the IX server timestamp.

 

And, I know of one other IX account whose .htaccess file was hacked on Nov 29, 2008, at 5:06 pm, according to the IX server timestamp.

Edited by WavMaker
additional info
Posted
Yes. My .htaccess file was hacked and replaced by the hacker's .htaccess file on Nov 7, 2008, at 7:58 pm, according to the IX server timestamp.

 

And, I know of one other IX account whose .htaccess file was hacked on Nov 29, 2008, at 5:06 pm, according to the IX server timestamp.

 

Mine were hacked twice :

 

November 20th (no time provided) and November 27th 8:47 am

 

I suppose the hacker's cron will hit again sooner or later.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...