Not had alot to post here recently so thought I would post about Gumblar!
Earlier this week a friend of mine who operates a gaming website with me was infected with a variant of the Gumblar virus.
Basically this virus stole ftp details from his computer, then used these to login to our FTP and add a small piece of code to the end of all pages which started with the word index, ended with .js, and additionally select WordPress and phpBB files. This code then advised some users visiting the website that they had a virus and needed to purchase the anti virus solution offered, others caught the site trying to download trojans on their anti virus.
Whilst fortunately this particular site is on a different web server and account to the site in question it did mean a sizeable cleanup operation which disrupted our website significantly and wasted about 6 hours of my life!
I figured I would post up the offending code incase anyone did want to have a look through it.
Code Samples are in .txt documents contained within this .rar file:
Right click and save file, do not open in browser
So there we have it! It pays to have a good antivirus, and if you don’t need to store your ftp password, don’t! For me it was alot of work sorting out my site, for my friend it was twice as much as all his other sites have been edited too!