Author Topic: Malicious script (cgi35.plala.or.jp/BTO/) is constantly being injected in site  (Read 5108 times)

0 Members and 1 Guest are viewing this topic.

alenavesna

  • Guest
<script src=hxxp://cgi35.plala.or.jp/BTO/data/entry/css.js></script>

The script above is constantly being injected in my website. I am still puzzled how, but seems to be an SQL Injection.

http://google.com/safebrowsing/diagnostic?site=cgi35.plala.or.jp/bto/&hl=en-us - you can check here Google confirmation about this script and how many site it infected!

Some is injecting this script into my database tables. That person also installs (still no sure how, but probably through vulnerability) phpSPY, although then deletes it after script installation.

- Please - any recommenations?
- Any ideas about what the script does?
- Can Avast find it and "cure" it?
- Any knowledge about phpSPY?

Many thanks.

 ???

Jtaylor83

  • Guest
Can you remove the script?

alenavesna

  • Guest
Every time I manually remove it from my database tables - I am getting an attack again. This is happening since February 14 (when Symantec also had SQL injection attack). Someone is doing it to my site on a daily basis.  >:(

I would really like to get more help on this issue.

Thanks!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
You need to speak to your site HOST as php or sql injection is something that they should be aware of and taking steps to prevent it. As far as PHP goes older versions of the software have vulnerabilities which are being exploited.

Change your site passwords to something a little stronger to see if that helps and seek help from your HOST provider, ensuring they have the latest versions of PHP/SQL, etc...

Obviously once exploited your site would become a soft target, so at the very least you need strong passwords and change the chmod permissions for pages so they aren't able to modified by other than the owner.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security