My page was attacked via xss, but on ftp all files are not changed?

Posted by Dobiatowski on Stack Overflow See other posts from Stack Overflow or by Dobiatowski
Published on 2010-06-11T11:51:56Z Indexed on 2010/06/11 12:02 UTC
Read the original article Hit count: 266

Filed under:
|
|
|
|

Hi, yesterday i noticed that sometimes on my webpage shows up javascript errors. when i went to source code, i found that one of .js files was totaly replaced with a ton of porn links.

i checked the ftp for this file, but there was just old javascript file without any changes. yet i go back to check source code via browser and indeed there was again original .js

today i visited my webpage again and the problem repeated.

  • first visit showed me ton of porn pages
  • cached .js file was hacked
  • but after clearing browser cache js go back to oryginal

i checked all files on my ftp against my offilne version, but all files are without any change.

in last few years i was attacked by xss few times but in every case it was easy to diagnose and fix. but now i spend 12h and didnt find infection.

do you have any idea how to find it? the webpage is: http://robert.frk.pl

© Stack Overflow or respective owner

Related posts about php

Related posts about JavaScript