Login Contact Us 24/7 Support Desk Home: nettigritty.com Web Hosting India Web Hosting India
FAQ » Mail

Archive for the 'Mail' Category

Website infected with an IFRAME or malware script

Monday, May 25th, 2009

Websites infected with an IFRAME or malware script

IFRAME and java script based malware infections are growingly common these days. These infections normally occur either through leaked FTP passwords or machines infected with virus / malware that adds these lines of code on files uploaded. Most of the time, it is through a leaked FTP password obtained from an insecure system.

Hackers setup normal looking websites (or use a previously hacked website where the owner is unaware of the malware) and setup expensive keylogging and hacking tools like Mpack. When a user vists the site, it scans the browser for history, passwords and other such critical information. The visitor who is unaware of the keylogger inadvertantly sends passwords and other details to the hacker who then has access to the vistors FTP details. Once the hacker obtains the FTP login details, an automated program or script is then used access the persons website and add hidden iframe or javascript code to the compromised website. Since this gets done through FTP, the user remains unaware of the hack or compromise and no matter what permissions are set, the hacker is able to write to the users website files.

This hacked website is then used to further spread the attack when a visitor opens it and accesses the hidden iframe content. This is a growing issue and thousands of websites are infected almost on a daily basis through this method.

Prevention:
1. Keep your computer operating system up to date at all times. Always download available OS security updates at the earliest.
2. Do not use Internet Explorer to FTP your website. Use a seperate FTP program like Core FTP or WS_FTP
3. Avoid saving passwords in the browser, specially FTP passwords. Do not FTP from a public or insecure connection.
4. Change passwords frequently and set a strong alphanumeric password.
5. Install an antivirus and keep it updated. Avast is a good free antivirus program for home / personal use and can be downloaded from www.avast.com
6. Avoid suspicious websites
7. If you receive an email from an unknown person with an attachment do not open it.

Cleaning up after an infection:
1. Take your site offline and put up a maintenance page on your website to avoid getting it blacklisted by search engines.
2. Format and secure your machine with a reliable install disk or use a fresh installed, OS updated computer with an updated antivirus.
3. Change FTP and other related passwords.
4. Delete all files and upload clean content - verify that the files you are uploading are not infected by checking for unknown Java script or iframe code normally found near the body tag in the code and at the end of the file. If a backup copy is unavailable, check code of files on the server for the same and delete the malware lines of code.
5. Take steps listed in prevention above to avoid repetition of such issues.

Site is black-listed by google / firefox / chrome
1. Follow steps in Cleaning up after infection
2. Follow steps in Prevention
3. Verify that no malware is present in your website
4. Follow http://googlewebmastercentral.blogspot.com/2008/04/my-sites-been-hacked-now-what.html

Other related links
http://googlewebmastercentral.blogspot.com/2007/09/quick-security-checklist-for-webmasters.html
http://googlewebmastercentral.blogspot.com/2008/08/hey-google-i-no-longer-have-badware.html

Where is Neomail?

Tuesday, May 30th, 2006

Neomail support has been discontued in cpanel as the script will soon be obsolete and support discontinued by cpanel developers on the script.

Emails will remain unaffected and can be accessed using the other interfaces.

To view the same folders in Squirrelmail, login, select Squirrelmail, click folders and subscribe to the folders you used previously in Neomail. Refresh folder list or the page to see the folders listed in the left column.

Mails are bouncing with the error “retry timeout exceeded”

Saturday, March 11th, 2006

This error on Linux/Cpanel servers normally indicates that the disk quota of that account is full. Upgrade the account or reduce usage and retry.

Error Number: 0×800CCC0F

Saturday, March 11th, 2006

“Your server has unexpectedly terminated the connection. Possible causes for this include server problems, network problems, or a long period of inactivity. Error Number: 0×800CCC0F”

This error is often modem or firewall related. First, try reconfiguring as per the tutorials at http://www.nettigritty.com/support/hosting/tutorials/emailtutorial.php

If the issue persists, please see:
http://support.microsoft.com/?kbid=813514

How do i configure Outlook Express to download my mail?

Friday, November 25th, 2005

You can configure your email ID in Outlook Express by following this video

An unknown error has occurred. Error Number: 0×800CCC0B

Friday, November 25th, 2005

An unknown error has occurred. Subject ‘Test Sending 18 Mar 2004′, Account: ‘mail.yourdomain.com’, Server: ‘mail.yourdomain.com’, Protocol: SMTP, Port: 25, Secure(SSL): No, Error Number: 0×800CCC0B

I am getting this error message. What can I do ?

This is most often a problem with your email client, not cpanel, you need to turn on “My Server Requires Authentication” if you are using outlook you can find this option here:

tools > accounts > [choose account] > properties > servers

You can also follow the tutorial here to enable outgoing SMTP authentication.

Another common reason for this error is that the recepient ID is invalid. Delete the mail in your outbox, create a new mail and check the recepient ID.

The connection to the server has failed. Error Number: 0×800CCC0E.

Friday, November 25th, 2005

The connection to the server has failed. Account ‘mail.yourdomain.com’, Server: ‘mail.yourdomain.com’, Protocol: SMTP, Port: 25, Secure(SSL): No, Socket Error: 10051, Error Number: 0×800CCC0E. I am getting this error message. What can I do ?

If you have not changed anything since the last time you checked / sent mail, do not adjust your settings simply close Outlook Express, reopen it and try again later.

In windows XP try resetting the TCP/IP stack, by:

* Clicking on Start then Run then type in cmd
* On the screen which opens, type in netsh int ip reset c:\resetlog.txt

If this has not resolved your problem you need to check your Outlook Express settings, making sure that the POP3 and SMTP servers are correct.

Next, ensure port 25 for SMTP is not blocked by your LAN, proxy, firewall or Internet Service provider. This is a very common scenario where an ISP blocks outgoing port 25 access to third party SMTP server for their customers.

You can workaround that by changing to port 26 by following the third demo video set at
http://www.nettigritty.com/support/hosting/tutorials/emailtutorial.php

If you are still unable to send, ensure outgoing SMTP authentication is enabled. If that also fails, you would need to check with your ISP if they are blocking third party SMTP servers and ask them for the SMTP server you should use.

You can configure by following tutorial 3 at http://www.nettigritty.com/support/hosting/tutorials/cpaneltutorials.php

If you’re still having problems, it could be that Outlook Express is itself corrupt. You may need to uninstall and reinstall it.

© Copyright Nettigritty Private Limited | Terms of Service (AUP) | Privacy Policy | Network Details


Domains
Register Domain
Transfer Domain
Domain Pricing
Email
eProMail for Business
Hosted Exchange
Mail on Linux
Free 2GB Email Address
Hosting
Linux Hosting
Windows Hosting
Virtual Private Servers

Online Backup
Dedicated
Celeron Servers
Pentium Servers
Core 2 Duo Servers
Core 2 Quad Servers
See all Servers
 
Ecommerce
SSL Certificates
Payment Gateway
Resellers
Domain Reseller
Linux Reseller Plans
Windows Reseller Plans