<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techno m'lounge - Where technology meets human senses.&#187; Site Attacked</title>
	<atom:link href="http://sumitghosh.co.in/tag/site-attacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://sumitghosh.co.in</link>
	<description>Technology, if not handled with care becomes disruptive, Iam a live example...</description>
	<lastBuildDate>Fri, 06 Jan 2012 13:53:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hola!- One of my sites got attacked by a worm.</title>
		<link>http://sumitghosh.co.in/hola-one-of-my-sites-got-attacked-by-a-worm/</link>
		<comments>http://sumitghosh.co.in/hola-one-of-my-sites-got-attacked-by-a-worm/#comments</comments>
		<pubDate>Sun, 27 Sep 2009 21:17:30 +0000</pubDate>
		<dc:creator>Sumit Ghosh</dc:creator>
				<category><![CDATA[Hacking n Cracking]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Site Attacked]]></category>

		<guid isPermaLink="false">http://sumitghosh.co.in/?p=252</guid>
		<description><![CDATA[One fine morning as I was browsing some sites we did using Mozilla 3.5 and I clicked on on link to our demo servers, one of my sites started showing this message. I got shocked what the f**k is this? Its like our demo server got attacked.. I was in panic , called the server [...]]]></description>
			<content:encoded><![CDATA[<p>
<!-- Begin Google Adsense code -->
<script type="text/javascript"><!--
google_ad_client = "pub-2400903147192847";
/* 300x250, created 9/27/09 - bysumit */
google_ad_slot = "3492758136";
google_ad_width = 300;
google_ad_height = 250;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
<!-- End Google Adsense code -->
<br />
One fine morning as I was browsing some sites we did using Mozilla 3.5 and I clicked on on link to our demo servers, one of my sites started showing this message. I got shocked what the f**k is this? Its like our demo server got attacked..</p>
<p>I was in panic , called the server support, raised a critical support ticket, did all that is possible.</p>
<div id="attachment_253" class="wp-caption alignleft" style="width: 454px"><a href="http://sumitghosh.co.in/wp-content/uploads/2009/09/Capture.PNG"><img class="size-large wp-image-253  " title="Mozilla's Alert Message for any attacked site reported by Google." src="http://sumitghosh.co.in/wp-content/uploads/2009/09/Capture-1024x638.PNG" alt="Mozilla's Alert Message for any attacked site reported by Google." width="444" height="345" /></a><p class="wp-caption-text">Mozilla&#39;s Alert Message for any attacked site reported by Google.</p></div>
<p>Thanks a lot to my server company IXwebhosting, they checked my sites and were able to tell me it was an ftp stolen password issue.</p>
<p>They cleaned by sites and told me that some system in my network has a trojan which used to send passwords to some remote server and it used to automatically login using my password and change files in the ftp.</p>
<p>We cleaned all PCs in our network and got everything setup. However to remove the error message from Mozilla, I had to use my google account and personally go to Google&#8217;s web master tools and get my site reviewed by Google.</p>
<div id="attachment_254" class="wp-caption alignleft" style="width: 483px"><a href="http://sumitghosh.co.in/wp-content/uploads/2009/09/capture2.png"><img class="size-full wp-image-254 " title="Request Review by Google." src="http://sumitghosh.co.in/wp-content/uploads/2009/09/capture2.png" alt="Request Review by Google." width="473" height="305" /></a><p class="wp-caption-text">Request Review by Google.</p></div>
<p>The very day I got my site restored back.</p>
<p>But wait!!!!</p>
<p>This attack took place again and I was shocked&#8230; We went back to the hosting company, they said again the ftp passwords have gotten stolen.</p>
<p>Lol!! We were like, what can be done now!<br />

<!-- Begin Google Adsense code -->
<script type="text/javascript"><!--
google_ad_client = "pub-2400903147192847";
/* 300x250, created 9/27/09 - bysumit */
google_ad_slot = "3492758136";
google_ad_width = 300;
google_ad_height = 250;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
<!-- End Google Adsense code -->
</p>
<p>The hosting company was a real savior, they have a special ftp firewall software installed with them , using which we can allow or deny a particular IP range to access our ftp.</p>
<p>Voila!, we got the solution, I limited the ftp access to a IP subnet within our Airtel network here.</p>
<p><strong>There are two files ftp.allow and ftp.deny. The format depends from firewall to firewall which your server company deploys.</strong></p>
<p>So finally I can sit and have coffee in peace, with the attacker thinking what went wrong <img src='http://sumitghosh.co.in/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  lolz</p>
<img src="http://sumitghosh.co.in/?ak_action=api_record_view&id=252&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://sumitghosh.co.in/hola-one-of-my-sites-got-attacked-by-a-worm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

