Hundreds of DreamHost websites abused by spammers
Zsclaer identified rogue PHP redirect scripts uploaded on hundreds of websites hosted at DreamHost
IDG News Service - Rogue PHP pages that redirect users to work-at-home scams have been added to hundreds of websites hosted at DreamHost following a security breach suffered by the company in January, researchers from cloud security vendor Zscaler said.
DreamHost decided to reset the FTP and shell access passwords for all of its customers after discovering that hackers compromised one of its database servers on Jan. 20.
The company said at the time that no malicious activity had been immediately detected on its customers' accounts, but the situation might have changed in the meantime, according to Zsclaer.
Following the Dreamhost hack many websites hosted by the company have been hijacked to redirect users to a Russian scam page, said Zscaler senior security researcher Julien Sobrier in a blog post on Friday. "I've identified hundreds of websites hosted by DreamHost that contained a PHP page redirecting to hxxp://www.otvetvam.com/."
The landing website promoted a work-at-home scam in Russian. These kind of scams have been around for many years and they usually trick users into buying a so-called starter kit that is supposed to help them earn money on the Internet.
"I'm sure this is just the beginning of massive abuses on websites hosted by DreamHost," Sobrier said. However, other Web security researchers are not convinced that these attacks are necessarily connected to the DreamHost breach.
Website integrity monitoring firm Sucuri Security has been tracking these attacks and similar ones for a while now and it can't say whether they started after the DreamHost security breach or that they affect only websites hosted there, said David Dede, a security researcher with the company.
According to Dede, most of the compromised websites analyzed by Sucuri had outdated software and other security issues.
Independent security researcher Denis Sinegubko, who created the Unmask Parasites Web scanner, looked at some of the compromised websites given as examples by Zscaler and determined that they all had a backdoor PHP script installed on Dec. 26, long before the DreamHost breach. It might still be an infrastructure-wide compromise though, he said.
Sinegubko was also able to tell who was behind this attack campaign because he'd seen some of the spam domains before. "It's the gang that promotes one of the largest scam campaigns in Russian," the researcher said. "They target themes such as genealogy, horoscopes, medical devices, diets, free downloads, and all other sorts of snake oil."
Regardless of whether these sites were compromised as a result of stolen credentials, vulnerabilities in outdated software or a misconfiguration, webmasters should follow security best practices. These include regularly reviewing the access logs for suspicious activity, checking their Web directory trees for any newly created files that look out of place, changing their administrative passwords regularly and keeping their software up to date. Scanning their websites with free services like Zulu, Sucuri or Unmask Parasites, is also recommended.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts