The hacker added a code in .htaccess file to redirect all search engine traffic to a malware website. I am now investigating this incident and trying to find out security loop holes. My situation is almost similar to this person's - .htaccess being hacked repeatedly
Here's a sample of intrustion attempt from FTP logs -
Aug 6 02:43:31 sg2nlftpg002 [30887]: ([email protected]) [INFO] FTPUSER is now logged in
Aug 6 09:43:33 sg2nlftpg002 [30887]: ([email protected]) [NOTICE] /home/content/81/7838581/html//.htaccess downloaded (846 bytes, 106.37KB/sec)
Aug 6 09:43:35 sg2nlftpg002 [30887]: ([email protected]) [NOTICE] /home/content/81/7838581/html//.htaccess uploaded (1435 bytes, 3.32KB/sec)
Aug 6 09:43:35 sg2nlftpg002 [30887]: ([email protected]) [INFO] Logout.
This is significantly different from my regular login attemps -
Aug 7 10:57:53 sg2nlftpg002 [11713]: session opened for local user FTPUSER from [my.ip.address]
Aug 7 10:58:28 sg2nlftpg002 [11713]: [FTPUSER] close "/home/content/81/7838581/html/.htaccess" bytes read 1435 written 0
Aug 7 11:14:29 sg2nlftpg002 [11713]: [FTPUSER] close "/home/content/81/7838581/html/.htaccess" bytes read 0 written 846
Aug 7 11:14:55 sg2nlftpg002 [11713]: [FTPUSER] close "/home/content/81/7838581/html/.htaccess" bytes read 846 written 0
Aug 7 12:08:03 sg2nlftpg002 [11713]: session closed for local user FTPUSER from [my.ip.address]
I have gone through HTTP traffic logs but couldn't find anything suspicious over there.
Other information that might be useful:
- I am on a shared host and the website runs on WordPress, BuddyPress and other popular plugins.
- To my knowledge all software under my control uses latest versions and is updated regularly.
- I use strong passwords and update them regularly. Only access website with SFTP and SSH using PUTTY.
- My local machine is free from viruses.
My question is how to prevent such attacks in future?
UPDATE
- Please see report from Google - http://www.google.com/safebrowsing/diagnostic?site=ask-oracle.com
- Another report related to network I am hosted on - http://www.google.com/safebrowsing/diagnostic?site=AS:26496