default userpic

Trojan Horse Files

Vote 0 Votes

I have been having a problem with someone exploiting a security hole in MT to upload trojan horse files to my MT blog folder. I've deleted the offending file, but my site's been tagged as an "attack site" by Firefox, and I need to know how to stop this.

I'm using MT 4.21-en. Is there some configuration setting I can change to keep this from happening?

Reported on Movable Type 4.2

3 Replies

| Add a Reply
  • Hi jsharf,

    Not good. I would do the following:

    Get a backup of all entries, comments and templates in your blog. Be sure not to include any of the stuff uploaded by that hacker.

    Second, delete everything and reset your server for security (new install, passwords, etc.)

    Start with a new install of MT 4.261 (or whatever is the newest version) for security.

    Import the backup of your templates and entries and comments.

    Now about the "attack site" warning: do you get this warning by the Google Safe Browsing feature of firefox? Is your website listed as harmful/malware site if you search for your site on google?

    Then you should contact stopbadware.org to get your site delisted from being flagged a malware site.

    If your site is flagged by a anti-virus suite and not by Google Safe Browsing, you should contact the company behind that anti-virus suite to get delisted as an attack site.

    Sorry, it surely sounds like a lot of work but I deem this is the only true safe way to bring up your site as a safe site for your users again. :-(

    Chris

  • It would be useful if you have additional information on how this attack was done. Do you know the attack vector? Maybe raise it as a bug if you don't want to give the info out here.

  • I only know what the results were.

    In the main folder for the blog - not the mt folder, but the root folder for each specific blog - there were new or edited css files. The correct css files is styles.css; the new ones are styles-site.css, and styles-site-default.css.

    I have downloaded the entire blog archives, and don't see any .htaccess files that have been updated recently, so I don't think that's the problem.

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

1773 6162

Last Topic: Excluding categories from blog by kholechek on Feb 9, 2012

86 302

Last Topic: website entries by masoud on Oct 26, 2011

1429 5077

Last Topic: What apocalypse hit this community in the middle of 2011? by 75th on Feb 10, 2012

695 2910

Last Topic: Insert Image / File Fails by Russ Miller on Feb 10, 2012

84 291

Last Topic: How to have some other characters in entry basename automatically written by Afshin Haghighatnia on Dec 22, 2011

173 737

Last Topic: About the MT version stated in HTML source by Alex E. Schneider on Feb 7, 2012

190 567

Last Topic: Analytics Reporting by michael webster on Feb 5, 2012

48 210

Last Topic: An idea and also a request by Afshin Haghighatnia on Jun 29, 2011

64 246

Last Topic: jQuery in MT 5.1 still at 1.4 - why? by perlmonkey on May 25, 2011

code.sixapart.com

137 478

Last Topic: Getting a thumbnail with xpath by Peter on Mar 13, 2011

222 720

Last Topic: Custom Field for Asset Not Appearing by android on Feb 9, 2012