Tak se mi stalo u běžného českého hostingu (Kapusta.cz), že se mi na subdoménu nainstaloval nějaký phishing script který imitoval internetovou stránku jedné anglické banky s cílem samozřejmě natěžit data lidí kteří budou takto oklamáni.
Dostal jsem email od FraudWatch International, která se zabývá odstraňováním a likvidací phising stránek.
Dear Web Site Administrator
The FraudWatch International Security Operations Centre (
www.fraudwatchinternational.com) has received a report of a fraudulent financial web page (illegal phishing content) hosted on a website you administer.
URL:
http://xxx.xxx.cz/thumbs/home/index1.phpAdditional URL's:
Brand Phished: Mashreqbank
IP Address: XXX.XXX.XXX.XXX
*************************
On behalf of our client, we would greatly appreciate your assistance in:
a) Urgently Cleaning, closing or disallowing access to the site listed above as appropriate.
b) obtaining and providing to us additional information regarding this incident, for example relevant logs or file from the host,
*************************
If you are not the correct person to be dealing with this incident, please forward this request to the relevant person.
If you are already aware of this matter, we apologise for any inconvenience. If possible, we would still appreciate a copy of any relevant files from the host, including logs and any php files relevant to the phishing site, which may indicate where the stolen login credentials are being sent.
The Anti-Phishing Working Group has published a document that will assist in securing this website and preventing future occurences of this problem. You can find this document here:
http://www.apwg.com/reports/APWG_WTD_HackedWebsite.pdfThis incident has been assigned an Incident Number, found in the subject line. We will be monitoring this incident, and tracking its progress to closure. Please use this incident code in the subject line of all correspondence relating to this Incident.
Please contact us should you require any clarification or assistance. We thank you for your urgent consideration of this request.
Regards,
Security Operations
FraudWatch International
Tel USA: +1-(415) 200 0621
Tel AUS: +613 9887 6777
Fax: +613 8660 2688
Email:
security@fraudwatchinternational.comhttp://www.fraudwatchinternational.comPíší abych neprodleně odstranil ten phishing skript. To ale bohužel nešlo přes FTP. Soubory i složka byly jakoby chráněny proti zápisu. Tak jsem kontaktoval Hosting providera, ten mi psal odpověď ale ta mi samozřejmě nedošla jak zákonem schválnosti.
No a FraudWatch International kontaktoval všechny zůčastněné, i datacentrum kde má Kapusta servery. Datacentrum prý chtělo Kapustě zablokovat všechny servery. No tak nakonec Kapusta zablokovala celý můj web asi na 3 dny než jsme se zkontaktovali a Kapusta mi smazala závadnou subdoménu.
Pozor neinstalujte si skript: "Bits Video Script 2.04 » SCRiPTMAFiA.ORG" ten to mohl celé zavinit.