Archived posting to the Leica Users Group, 2004/02/13

[Author Prev] [Author Next] [Thread Prev] [Thread Next] [Author Index] [Topic Index] [Home] [Search]

Subject: Re: [Leica] OT: Help, my web site has been hijacked!
From: Brian Reid <reid@mejac.palo-alto.ca.us>
Date: Fri, 13 Feb 2004 09:43:46 -0800
References: <402C5CAA.4DB7B59F@chello.nl> <2147483647.1076657567@cambric.reid.org> <402D06F7.A079DC4F@chello.nl>

> Don Cardish did look at the
> source code and found two added lines at the bottom which loaded the
> offending site.

This is often the signature of a transparent proxy meddling with the data stream.
If it happens again, what you need to do is to *download* a copy of your index.htm file from your website (reversing the normal process that you would use to upload it). Make sure you save a copy of the real file somewhere else before you do this.

Then, when you download, compare the downloaded file with your master copy. If they are identical, this means that the damage is probably being done by a transparent proxy somewhere in the data path between your hosting company and its victims. If they are not identical, this means that your hosting company has been compromised.

- --
To unsubscribe, see http://mejac.palo-alto.ca.us/leica-users/unsub.html

In reply to: Message from Nathan Wajsman <n.wajsman@chello.nl> ([Leica] OT: Help, my web site has been hijacked!)
Message from Brian Reid <reid@mejac.palo-alto.ca.us> (Re: [Leica] OT: Help, my web site has been hijacked!)
Message from Nathan Wajsman <n.wajsman@chello.nl> (Re: [Leica] OT: Help, my web site has been hijacked!)