The mother of all viruses indeed. This one has been killing me for 3 days now.
If ANYONE has ANY help on this kind of thing let me know....we're stumped.
We have a server with a rather large reputable hosting company. It has about 50-60 ASP, database driven sites on it. The wheels are in motion for a migration next week but I need a fix for this if possible. I'm having to do a 'clean upload' every 3 hours on 4 infected sites.
Basically, on Wednesday one of the sites reported unusual activity. When you go to the homepage it starts refreshing your browser at an incredible rate (an attack on you the client). This occured because something had gained access to a folder in the site and dropped a javascript include / iframe tag into the code in a couple of places!
This, as far as I know is down to an XSS or SQL Injection attack.
Now, we've cleaned the code and tightened up the Db, removed the offending code and even locked the permissions to read only on the folder being hacked on each site but it keeps coming back!!!
Our Virus checker finds zip.
I believe this is a Rootkit Virus (basically hidden to the OS) but several Rootkit scanners have revealed nowt either.
All ports are locked out by a Cisco firewall and the only access to anything that isn't on port 80 is via a VPN with key.
I'm lost now!!
I just wanna know if we can stop it re-spawning for a few days!
Any help will be met with fee beer for the person that helps me solve it all.
If ANYONE has ANY help on this kind of thing let me know....we're stumped.
We have a server with a rather large reputable hosting company. It has about 50-60 ASP, database driven sites on it. The wheels are in motion for a migration next week but I need a fix for this if possible. I'm having to do a 'clean upload' every 3 hours on 4 infected sites.
Basically, on Wednesday one of the sites reported unusual activity. When you go to the homepage it starts refreshing your browser at an incredible rate (an attack on you the client). This occured because something had gained access to a folder in the site and dropped a javascript include / iframe tag into the code in a couple of places!
This, as far as I know is down to an XSS or SQL Injection attack.
Now, we've cleaned the code and tightened up the Db, removed the offending code and even locked the permissions to read only on the folder being hacked on each site but it keeps coming back!!!
Our Virus checker finds zip.
I believe this is a Rootkit Virus (basically hidden to the OS) but several Rootkit scanners have revealed nowt either.
All ports are locked out by a Cisco firewall and the only access to anything that isn't on port 80 is via a VPN with key.
I'm lost now!!

I just wanna know if we can stop it re-spawning for a few days!
Any help will be met with fee beer for the person that helps me solve it all.