Hi,
We have tried many ways to temporary and manually fix the now famous hack too.
Below is the info and fixes:
Fixes we have made:1. Follow steps in
http://blog.sucuri.net/2010/10/oscommer ... ky-ru.htmla. Ask hosting IT support to help clean up .htaccess file.
This is what the .htaccess looks like:
RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.* [OR]
RewriteCond %{HTTP_REFERER} .*ask.* [OR]
RewriteCond %{HTTP_REFERER} .*yahoo.* [OR]
…
RewriteRule ^(.*)$
http://devisionnetwork.ru/suomi/index.php [R=301,L]
b. A backdoor is created inside /js/conf.php and another one at /flops.php. Make sure to remove these and search for other PHP files that are not part of the official osCommerce distribution.
c. Blackhat SEO SPAM is added to includes/application_bottom.php.
2. Securing the Admin folder
a. Rename Admin folder.
b. After renamed Admin folder, make changes in renamed_admin_directory/includes/configure.php
define('DIR_WS_HTTP_ADMIN', '/shop/admin-gbh-group/');
define('DIR_WS_HTTPS_ADMIN', 'admin-gbh-group/');
define('DIR_FS_ADMIN', '/home/gbhgroup/public_html/shop/admin-gbh-group/');
There is also issue with hack, read Jan's thread here (
http://forums.oscommerce.com/index.php?showtopic=340995).
c. Password protect the renamed Admin folder with hosting control panel.
3. Remove filemanger (it is vulnerable). Search and delete all “file_manager.php”.
Example:
admin\includes\languages\english
admin\includes\languages\espanol
admin\includes\languages\french
admin\includes\languages\german
4. Remove all “define_language.php” (it is vulnerable).
Example:
admin\
admin\includes\languages\english
admin\includes\languages\espanol
admin\includes\languages\french
admin\includes\languages\german
5. Is your site really yours?
http://www.unmaskparasites.com/6. Practical Guide to Dealing With Google's Malware Warnings
http://www.unmaskparasites.com/malware- ... upshop.comInfo
•
http://blog.sucuri.net/2010/11/oscommer ... n-etc.html•
http://blog.sucuri.net/2010/11/continui ... sites.html•
http://blog.sucuri.net/2010/11/malware- ... merce.html•
http://blog.sucuri.net/2010/10/oscommer ... ky-ru.htmlHow to Scan Website1. Use
http://www.unmaskparasites.com and check. It will mainly list if google things the site is malicous, but can also show bad strings.
2. Use
http://www.web-sniffer.net and view the site as google. Ensure that your page loads.
3. Check at
http://www.URLVoid.com for the domain. Use the virus scan section afterward.
4.
http://blog.sucuri.net – This blog has large amounts of useful data regarding these recent attacks on osCommerce (and variants).
5. Search all source code and look for something like:
a. <script src="http://nt07.in/3`></script>
b. <script src="http://nt06.in/3`></script>
c. <script src="http://nt04.in/3`></script>
d. <script src="http://nt02.co.in/3`></script>
e. <script src="http://nt002.cn/E/J.JS`></script>
f. ar-kirm.ru<br />
g. arkirm.ru<br />
h. camentrueopt.ru<br />
i. ccmilkwq.ru<br />
j. class-woods.ru<br />
k. classwoods.ru<br />
l. devisionnetwork.ru<br />
m. devisionpanel.ru<br />
n. drevingjp.tk<br />
o. drivegup.tk<br />
p. enterteiment-wizrd.ru<br />
q. enterteimentwizrd.ru<br />
r. everywoods.ru<br />
s. interwumedi.ru<br />
t. jaobsofterty.ru<br />
u. kirm-ar.ru<br />
v. kirmar.ru<br />
w. kirm-sky.ru<br />
x. kirmsky.ru<br />
y. networkdevision.ru<br />
z. relax-july.ru<br />
aa. sensationworld.ru<br />
bb. sky-ar.ru<br />
cc. sky-kirm.ru<br />
dd. taeliterup.ru<br />
ee. tecros.ru<br />
ff. traypro.ru<br />
gg. tutaanti.ru<br />
hh. zandecluf.ru
ii. eval
jj. base64_decode