Recent Site Problems
June 25th, 2009
I’ve been having some problems with the site recently. The security of my site has been compromised several times over the last few weeks. The site has been the subject of repeated injection attacks that have injected malicious code into various pages. If you visited the site over the last day or two and saw a warning from Google, that’s why that came up. Each time I have removed the malicious code, and done everything I can to better secure the site.
At this point I have decided that my current web host can’t provide me with the level of security that I want and so I’m going to be moving the site over the next day or two. I’m going to do everything I can to make sure there’s as little downtime as possible. However, it is possible that the site may go down for an hour or two at some point. If that’s the case, I apologise in advance.
I did promise a post about WWDC this week, but the site being repeatedly hacked has taken up most of my time over the last 3 or 4 days. Once I’ve moved the site and determined that it’s stable, I’ll get back to my regular postings.
Owen






Hi Owen,
My company hosts a few hundred sites for customers and we’ve recently had this same problem with two different customers. In both cases, I am fairly sure a virus on the client computers got the customer’s FTP credentials and used them to upload malicious code (hidden iframe based browser exploit) to the site’s main index.html file.
In both cases, the customer had tried to remove the code one or more times before contacting me. I changed the FTP password and started seeing a lot of failed logins from different IP addresses. Since changing the password and cleaning the files, the malicious code has not come back again.
In one of the cases, I know for sure the customer had a virus and had to have their PC reformatted. Otherwise, I would have suspected a server problem from the beginning. In the other case, my customer had used a 3rd party to work on their web site, so it’s hard to know if the 3rd party (or one of their contractors) could have been infected (though with the high number of FTP login attempts at all hours, at this point I have to assume something weird was going on).
I’m not saying you have (or somebody you gave the FTP login to has) a virus. But, this all just happened a couple of weeks ago. I’m just getting the information out there with the hope that somebody can benefit.
PJ