<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: RoundStorm FTP Hack &#8211; Solution</title>
	<atom:link href="http://www.everythingilike.com/roundstorm-ftp-hack-solution/feed" rel="self" type="application/rss+xml" />
	<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution</link>
	<description>You Can&#039;t Kill Happy</description>
	<lastBuildDate>Tue, 20 Dec 2011 08:19:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Snype</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-355</link>
		<dc:creator>Snype</dc:creator>
		<pubDate>Tue, 03 Aug 2010 16:14:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-355</guid>
		<description>@David the passwords are encrypted locally but can be easily decrypted depending on the app. Check to see if your FTP client has a setting for a &quot;Master Password.&quot; This should increase the security of your passwords, also if you save passwords in your browser you might want to setup a &quot;Master Password&quot; there too.

@Ivan I had to download and run Avast free anti-virus in Boot mode. This found several *.sys, *.tmp files that were infected. Mainly in temp and system32 folders. NoScript is really helping and uninstalling Java also didn&#039;t hurt.</description>
		<content:encoded><![CDATA[<p>@David the passwords are encrypted locally but can be easily decrypted depending on the app. Check to see if your FTP client has a setting for a &#8220;Master Password.&#8221; This should increase the security of your passwords, also if you save passwords in your browser you might want to setup a &#8220;Master Password&#8221; there too.</p>
<p>@Ivan I had to download and run Avast free anti-virus in Boot mode. This found several *.sys, *.tmp files that were infected. Mainly in temp and system32 folders. NoScript is really helping and uninstalling Java also didn&#8217;t hurt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ivan haentjens</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-341</link>
		<dc:creator>ivan haentjens</dc:creator>
		<pubDate>Sat, 31 Jul 2010 20:27:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-341</guid>
		<description>forget the cpanel option, I&#039;ve had sites hacked on hosting servers not offering cpanel or plesk. In my opinion the malware resides on the pc of the webmaster.</description>
		<content:encoded><![CDATA[<p>forget the cpanel option, I&#8217;ve had sites hacked on hosting servers not offering cpanel or plesk. In my opinion the malware resides on the pc of the webmaster.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ivan haentjens</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-340</link>
		<dc:creator>ivan haentjens</dc:creator>
		<pubDate>Sat, 31 Jul 2010 20:18:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-340</guid>
		<description>Some thoughts...

Does anyone of you use phpmaker?
Does anyone has / had mywebsearch plugin installed?

regards,
Ivan</description>
		<content:encoded><![CDATA[<p>Some thoughts&#8230;</p>
<p>Does anyone of you use phpmaker?<br />
Does anyone has / had mywebsearch plugin installed?</p>
<p>regards,<br />
Ivan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-337</link>
		<dc:creator>David</dc:creator>
		<pubDate>Fri, 30 Jul 2010 22:46:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-337</guid>
		<description>Thanks for the great advice.

I just helped to restore a clients site that was infected. It&#039;s a nasty one and as you said was in every file and directory.  We did a full site restore to fix.

But I&#039;m curious about the details of your comment. &quot;Delete all FTP Passwords and do not save any on your client&quot;. Is the virus somehow grabbing passwords from the FTP Client?

I&#039;m a Mac guy which (normally) gives me a certain level of security, and I&#039;m using Transmit for Mac, which  is a pretty decent FTP client. However my passwords are saved within Transmit. (Although they are encrypted). 

I&#039;m just wondering what kinds of hoops need to be jumped?

Thanks again!</description>
		<content:encoded><![CDATA[<p>Thanks for the great advice.</p>
<p>I just helped to restore a clients site that was infected. It&#8217;s a nasty one and as you said was in every file and directory.  We did a full site restore to fix.</p>
<p>But I&#8217;m curious about the details of your comment. &#8220;Delete all FTP Passwords and do not save any on your client&#8221;. Is the virus somehow grabbing passwords from the FTP Client?</p>
<p>I&#8217;m a Mac guy which (normally) gives me a certain level of security, and I&#8217;m using Transmit for Mac, which  is a pretty decent FTP client. However my passwords are saved within Transmit. (Although they are encrypted). </p>
<p>I&#8217;m just wondering what kinds of hoops need to be jumped?</p>
<p>Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-312</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 21 Jul 2010 14:28:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-312</guid>
		<description>@Nick, I thought about that too but found it easier to use shell since we have access to our servers. The only flaw I see in using a PHP script is that you&#039;ll need to properly CHMOD all the files before running the script and maybe on shared hosts the script will not be able to run for long periods of time. 

Other solutions: 
- restore a backup of the site. If you have cPanel or Plesk this should be easy.
- If your site is in a version control system you can simply revert all changed files.

I can probably whip up a PHP script if enough requests come in.</description>
		<content:encoded><![CDATA[<p>@Nick, I thought about that too but found it easier to use shell since we have access to our servers. The only flaw I see in using a PHP script is that you&#8217;ll need to properly CHMOD all the files before running the script and maybe on shared hosts the script will not be able to run for long periods of time. </p>
<p>Other solutions:<br />
- restore a backup of the site. If you have cPanel or Plesk this should be easy.<br />
- If your site is in a version control system you can simply revert all changed files.</p>
<p>I can probably whip up a PHP script if enough requests come in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-311</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Wed, 21 Jul 2010 00:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-311</guid>
		<description>Back... 

As one who &#039;dabbles&#039; in php, the thought came to me that as the AV big boys haven&#039;t yet taken this problem under their wings. Perhaps a small group of talented indiviuals could write a php/asp/etc script that would run though all the files and a person&#039;s site automatically editing out the offending code. 

I know the concept is valid, however, I do not feel I am sufficiently skilled to write it. Correcting via the shell may be a bit too daunting for the average site owner. Whereas, running a simple script is some thing easily done by even a novice.

Just a thought.

Nick</description>
		<content:encoded><![CDATA[<p>Back&#8230; </p>
<p>As one who &#8216;dabbles&#8217; in php, the thought came to me that as the AV big boys haven&#8217;t yet taken this problem under their wings. Perhaps a small group of talented indiviuals could write a php/asp/etc script that would run though all the files and a person&#8217;s site automatically editing out the offending code. </p>
<p>I know the concept is valid, however, I do not feel I am sufficiently skilled to write it. Correcting via the shell may be a bit too daunting for the average site owner. Whereas, running a simple script is some thing easily done by even a novice.</p>
<p>Just a thought.</p>
<p>Nick</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-310</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Tue, 20 Jul 2010 12:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-310</guid>
		<description>Also have been &#039;infected&#039;. It added to all my index, js files as well as many html and php files with &#039;main&#039; as the prefix.

Still very limited information on the web about it</description>
		<content:encoded><![CDATA[<p>Also have been &#8216;infected&#8217;. It added to all my index, js files as well as many html and php files with &#8216;main&#8217; as the prefix.</p>
<p>Still very limited information on the web about it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-309</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Mon, 19 Jul 2010 07:01:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-309</guid>
		<description>Did the virus get from your computer to your website or your website to your computer? The virus never got onto my computer thanks to Eset&#039;s AV, it was on the website first. 

I would love to know how it worked because if it got in once then it can sure as heck do it again and I doubt just changing my passwords will work. 

But I have a lot of different systems so knowing which is vulnerable requires knowing how the script works. I have tried to contact various AV firms but they are all useless.</description>
		<content:encoded><![CDATA[<p>Did the virus get from your computer to your website or your website to your computer? The virus never got onto my computer thanks to Eset&#8217;s AV, it was on the website first. </p>
<p>I would love to know how it worked because if it got in once then it can sure as heck do it again and I doubt just changing my passwords will work. </p>
<p>But I have a lot of different systems so knowing which is vulnerable requires knowing how the script works. I have tried to contact various AV firms but they are all useless.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-306</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 15 Jul 2010 18:23:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-306</guid>
		<description>Thanks for the info Mark. I also recently found that getting rid of this virus on the my PC is tricky. I have installed NoScript (Firefox Plugin) and completely uninstalled Java6 my computer... The sites I visit hardly used Java anyway.</description>
		<content:encoded><![CDATA[<p>Thanks for the info Mark. I also recently found that getting rid of this virus on the my PC is tricky. I have installed NoScript (Firefox Plugin) and completely uninstalled Java6 my computer&#8230; The sites I visit hardly used Java anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.everythingilike.com/roundstorm-ftp-hack-solution#comment-305</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 15 Jul 2010 16:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.everythingilike.com/?p=791#comment-305</guid>
		<description>I had the same thing on my website, it infected various different scripts and somehow even got in to replace and infect well protected files. It even got to some scripts that are not public. To me this suggests some kind of root level access.

I don&#039;t know how this virus works or anything about its method or how to protect against it, but I have managed to check through 20,000 odd files and replace them with fresh copies from my backups. Mostly index.php&#039;s, .js files and .html stuff.</description>
		<content:encoded><![CDATA[<p>I had the same thing on my website, it infected various different scripts and somehow even got in to replace and infect well protected files. It even got to some scripts that are not public. To me this suggests some kind of root level access.</p>
<p>I don&#8217;t know how this virus works or anything about its method or how to protect against it, but I have managed to check through 20,000 odd files and replace them with fresh copies from my backups. Mostly index.php&#8217;s, .js files and .html stuff.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 4/7 queries in 0.005 seconds using memcached
Object Caching 964/970 objects using memcached
Content Delivery Network via static.everythingilike.com

Served from: www.everythingilike.com @ 2012-02-06 14:10:09 -->
