Where’d Arbu go? A Tale of Corrupt Directories
Tuesday, May 5th, 2009At around midnight last night the Arbu.biz server went down. No, let’s be accurate here, the providers Bluehost.com took the Arbu server down. Why? Well, someone or somegroup has hacked into our ftp accounts and uploaded a little bitty .exe file along with some supporting images and such. And what was it’s function this ickle bitty file? Hmm? To insert trojans onto unsuspecting PC users’ computers.
The next question is “How did they do that?” A neat piece of software which exploits the fact that (a) cpanel webservers (like Arbu’s) have anonymous ftp accounts set up (b) that sysadmins use three letter abbreviations for their subdomains and (c) that cpanel has reached such a level of ubiquity that firing a specific request at servers to upload to ‘images’ folders works often enough for the effort to be worth it.
So the effect? Well aside from costing several of my sites and my clients’ sites 12 hours of downtime, impugning my reputation with Bluehost and stressing me to the eyeballs? It has shown me how easy it is for the black hats to take advantage of everyone else, especially those who don’t protect their pcs and don’t update their browsers. Here’s a shocking grab of the referrers to the hacked directory:
The top entries are most revealing and show how the South Americans have used the directory to attack anyone with a live.com email. Evidently, a spam email referring to the .exe file. And how did we rid ourselves of this lurgi? We deleted it, and every other exe file on our server, all the images associated with it, and finally we discontinued our anonymous ftp service (sorry to those that use it) its too much trouble.
If you have had a similar experience let us know, or if we should be doing something more to protect ourselves and our server, let us know.
Related articles by Zemanta
- How to use file manager in cPanel (5min.com)
- Vicomsoft FTP Client gains QuickLook, Growl support (macworld.com)
- How to back up your site in cPanel (5min.com)
- How to use Index Manager in cPanel (5min.com)
- Home FTP Server (ghacks.net)
- MSI or EXE Setup (ghacks.net)




















