[BlueOnyx:03352] Re: Gumblar

Colin Jack colin at mainline.co.uk
Sat Jan 16 09:12:18 -05 2010




On 16/01/2010 12:11, "Dudi Goldenberg" <dudi at kolcore.com> wrote:

Avast identified the zip content as:

JS:Illredir-A [Trj]

Suspected to be a Trojan.

D.

Yup - infects PCs and then harvests FTP passwords.
Bad lads then FTP into your site and modify it.

We have had two sites compromised so far.

I would like to search the entire server /home/.sites for signature code but could do with a little help writing a script.

Colin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.blueonyx.it/pipermail/blueonyx/attachments/20100116/a48307c7/attachment.html>


More information about the Blueonyx mailing list