{"id":897,"date":"2009-06-09T09:42:40","date_gmt":"2009-06-09T09:42:40","guid":{"rendered":"http:\/\/blog.resellerclub.com\/?p=897"},"modified":"2016-10-17T18:44:29","modified_gmt":"2016-10-17T13:14:29","slug":"safeguarding-your-website-from-gumblar-attacks","status":"publish","type":"post","link":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/","title":{"rendered":"Safeguarding your website from Gumblar Attacks"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">Over the past few weeks, several websites hosted on our Linux Servers threw up virus alerts. Further investigation revealed that these alerts were triggered by an injection attack on packages hosted on our servers, commonly known as <em>Gumblar Attacks<\/em>. FTP logs of these infected packages indicated that machines of the customers who own those domains were compromised and had been used to upload malicious content to their respective Hosting Packages. A few pointers for your benefit:<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">What is a Gumblar Attack?<\/span><\/strong><\/p>\n<p><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">Gumblar appears to be a combination of exploit scripts and malware. The scripts are embedded in .html, .js and .php files using obfuscated Javascript. They load malware content from Third Party sites without the user&#8217;s knowledge, while also stealing FTP credentials from the victim&#8217;s computer, which then allows it to spread and infect additional sites. Therefore, when someone visits such an infected site they get infected; if they have FTP credentials for a website on their machine then those sites get infected too. This explains the exponential growth of the exploit in such a short space of time.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">What makes it different from other Malware exploits?<\/span><\/strong><br \/>\n<span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">There are a number of aspects to this exploit that not just help it spread, but also make it difficult to remove. Firstly, it infects users browsing legitimate websites; if these users are webmasters then it infects their websites by using their FTP credentials to inject the script into their site. The obfuscated malicious code being dynamically generated, makes it difficult to detect and difficult to automatically remove. Not only does the script vary from site to site, it can also vary from page to page on that the one site.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">For a more detailed read, you can check out the following news <a href=\"http:\/\/news.cnet.com\/8301-1009_3-10244529-83.html\" target=\"_blank\">article<\/a>.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\"><strong>What steps have we taken?<\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>As a precautionary measure, we have blocked FTP services on our Linux Hosting Servers. This will prevent infection of any other Hosting Package. We are in the process of removing malicious content from all those packages that was infected as a result of this. However if we re-establish FTP connections, your clients will re-infect their respective Hosting Packages since their machines are likely to be compromised.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>We will be shifting to a Secure FTP connection and resetting everyone&#8217;s FTP passwords across all Linux Hosting packages. You can modify these passwords from your respective Control Panel at a later date. We strongly urge you warn your Customers about this worm and ask them to scan their machines given its exponential spread so far.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Verdana,Arial,Helvetica,sans-serif; font-size: small;\">-ResellerClub Support Desk<\/span><\/p>\n<p>&nbsp;<\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground:  !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 100% !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>&nbsp; Over the past few weeks, several websites hosted on our Linux Servers threw up virus alerts. Further investigation revealed that these alerts were triggered by an injection attack on packages hosted on our servers, commonly known as Gumblar Attacks. FTP logs of these infected packages indicated that machines of the customers who own those<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1533],"tags":[126,174,175,124,40,135],"hashtags":[],"class_list":{"0":"post-897","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-tech","7":"tag-directi","8":"tag-ftp","9":"tag-gumblar-attacks","10":"tag-malware","11":"tag-resellerclub","12":"tag-security"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Safeguarding your website from Gumblar Attacks<\/title>\n<meta name=\"description\" content=\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Safeguarding your website from Gumblar Attacks\" \/>\n<meta property=\"og:description\" content=\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"ResellerClub Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100005889763273\" \/>\n<meta property=\"article:published_time\" content=\"2009-06-09T09:42:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-10-17T13:14:29+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Andrew Acker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/\",\"name\":\"ResellerClub Blog\",\"description\":\"Web Hosting &amp; Domains\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#webpage\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/\",\"name\":\"Safeguarding your website from Gumblar Attacks\",\"isPartOf\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\"},\"datePublished\":\"2009-06-09T09:42:40+00:00\",\"dateModified\":\"2016-10-17T13:14:29+00:00\",\"author\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/0a320715a2bdbf7796c3cb13539bdf92\"},\"description\":\"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.resellerclub.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Safeguarding your website from Gumblar Attacks\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/0a320715a2bdbf7796c3cb13539bdf92\",\"name\":\"Andrew Acker\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/eeb328c335741468b6caed4229de46c24ded4b5e47beef6b09c1889435e6e09d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/eeb328c335741468b6caed4229de46c24ded4b5e47beef6b09c1889435e6e09d?s=96&d=mm&r=g\",\"caption\":\"Andrew Acker\"},\"sameAs\":[\"http:\/\/www.resellerclub.com\"],\"url\":\"https:\/\/www.resellerclub.com\/blog\/author\/andrewa\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Safeguarding your website from Gumblar Attacks","description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Safeguarding your website from Gumblar Attacks","og_description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","og_url":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/","og_site_name":"ResellerClub Blog","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=100005889763273","article_published_time":"2009-06-09T09:42:40+00:00","article_modified_time":"2016-10-17T13:14:29+00:00","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Andrew Acker","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.resellerclub.com\/blog\/#website","url":"https:\/\/www.resellerclub.com\/blog\/","name":"ResellerClub Blog","description":"Web Hosting &amp; Domains","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#webpage","url":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/","name":"Safeguarding your website from Gumblar Attacks","isPartOf":{"@id":"https:\/\/www.resellerclub.com\/blog\/#website"},"datePublished":"2009-06-09T09:42:40+00:00","dateModified":"2016-10-17T13:14:29+00:00","author":{"@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/0a320715a2bdbf7796c3cb13539bdf92"},"description":"Subscribe to the official ResellerClub Blog for tips on your Web Design and Development business. Get updates on Digital Marketing, Doamins and Hosting offers!","breadcrumb":{"@id":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.resellerclub.com\/blog\/safeguarding-your-website-from-gumblar-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.resellerclub.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Safeguarding your website from Gumblar Attacks"}]},{"@type":"Person","@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/0a320715a2bdbf7796c3cb13539bdf92","name":"Andrew Acker","image":{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/eeb328c335741468b6caed4229de46c24ded4b5e47beef6b09c1889435e6e09d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/eeb328c335741468b6caed4229de46c24ded4b5e47beef6b09c1889435e6e09d?s=96&d=mm&r=g","caption":"Andrew Acker"},"sameAs":["http:\/\/www.resellerclub.com"],"url":"https:\/\/www.resellerclub.com\/blog\/author\/andrewa\/"}]}},"_links":{"self":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/comments?post=897"}],"version-history":[{"count":9,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/897\/revisions"}],"predecessor-version":[{"id":13579,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/897\/revisions\/13579"}],"wp:attachment":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/media?parent=897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/categories?post=897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/tags?post=897"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/hashtags?post=897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}