Trojan Horse

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • nsglazer
    New Member
    • Jan 2002
    • 22

    [CMS] Trojan Horse

    My forum (www.studentpilot.com) is getting security warning messages from Norton that it's infected with a trojan. Any clue what caused this and what I can do about it? It seems to be sporadic. I cant get it to load every time I visit the site.

    Neil
    Attached Files
  • SuperJuice
    New Member
    • Jul 2010
    • 14
    • 4.0.x

    #2
    Have you read the error?

    It refers to /a/tmp/des.jar on the 'attacking computer'

    Check if that file is available on your webserver, if it is.. get the mop out.

    Not sure how this has any real relevance to the CMS unless there is proof that the CMS was the attack vector.

    Comment

    • nsglazer
      New Member
      • Jan 2002
      • 22

      #3
      No such file is on my computer. I beleive this is being caused by something in the vbulletin CMS because we only see this warning on CMS pages of vbulletin. Thoughts?

      Neil

      Comment

      • djbaxter
        Senior Member
        • Aug 2006
        • 1418
        • 4.2.5

        #4
        Dump Norton.
        Psychlinks Web Services Affordable Web Design & Site Management
        Specializing in Small Businesses and vBulletin/Xenforo Forums

        Comment

        • SuperJuice
          New Member
          • Jul 2010
          • 14
          • 4.0.x

          #5
          Originally posted by nsglazer
          No such file is on my computer. I beleive this is being caused by something in the vbulletin CMS because we only see this warning on CMS pages of vbulletin. Thoughts?

          Neil
          I'm not talking about your computer, read the error.

          It specifies the host and the file, first thing to do is check if that exists.. if you own the host / IP find out how it got there.

          Are you on a shared host?

          If you go to http://79.135.152.196/ Firefox reports it as a Reported Attack Page.

          Comment

          • setishock
            Senior Member
            • Jun 2005
            • 1334
            • 4.2.x

            #6
            I hang out at a forum that was having an issue similar to that. The owner had switched ad companies and as it turned out getting some ads laced with some nasty s**t.
            I run nod32 on all my rigs and it was flipping out when I visited the forum. The other members running free and pay AV reported the same alerts. When the owner switched them off it stopped. I must also note he went back to the one he didn't have problems with before and it's been quiet since.
            The intermittent showing up may be not all of the ads are bad. Just certain ones.
            This might or might not be the case here but most certainly worth looking in to.
            ...

            Comment

            widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
            Working...