Author Topic: Virus and Security problems with ListMailPRO?  (Read 4348 times)

BGSWebDesign

  • Posts: 625
    • View Profile
    • http://www.bgswebdesign.com
Virus and Security problems with ListMailPRO?
« on: December 16, 2014, 09:16:55 am »
Hi,

Have you seen anything like this before DW?

I just received a ticket from my host, the same host I've been using for the last 3+ years.  The ticket shows that there is a possible infection and security breach, here is the URL it shows (I've changed the domain name/IP for protection):
--
Quote
|date |id |virusname |ip |domain |Url|
+-----------------------------------------------------------------------------------------------
|2014-12-13 02:42:12 CET |50021665 |Adware.FakeDriverUpdate.gen |99.99.99.999 |mywebsite.com |http://mywebsite.com/mail/link.php?id=_zc0ienfrlovrs1
+-----------------------------------------------------------------------------------------------

Quote
Please preserve on any reply our Subject: [clean-mx-viruses-50021665](99.99.99.999)-->(security@mywebshost.com) viruses sites (1 so far) within your network, please close them! status: As of 2014-12-15 04:04:10 CET

Then there follows inside the message this:

Quote
Advice: The appearance of a Virus Site on a server means that
someone intruded into the system. The server's owner should
disconnect and not return the system into service until an
audit is performed to ensure no data was lost, that all OS and
internet software is up to date with the latest security fixes,
and that any backdoors and other exploits left by the intruders
are closed. Logs should be preserved and analyzed and, perhaps,
the appropriate law enforcement agencies notified.

DO NOT JUST DELETE THE FILES. IF YOU DO NOT FIX THE SECURITY
PROBLEM, THEY WILL BE BACK!

How can I assure the host that this is stopped, and all mailing is not happening from this possible virus?

Have you seen anything like this before DW?

I should also say that I signed-in to my ListMailPRO installation there just a minute ago and all seems fine, LMP is in the process of handling DailyMail and all looks to be fine? 

« Last Edit: December 16, 2014, 09:21:39 am by BGSWebDesign »
Thanks,
-Brett
http://www.bgswebdesign.com/Contact-Us.php

*** I do custom List Mail Pro installations ***
Contact me through my website (above)

DW

  • Administrator
  • Posts: 3787
    • View Profile
    • https://legacy.listmailpro.com
Re: Virus and Security problems with ListMailPRO?
« Reply #1 on: December 17, 2014, 04:17:09 am »
Hi Brett,

It looks like the content, domain or some part of the URL has been listed in an anti-virus system. If it were me I would email the host and assure them I am not hosting any viruses on my site and ask that they flag the link or content as safe.

It may also be worthwhile to find out what anti-virus system they use so it could further be determined if this is server-specific or a more widespread issue, and if the flag is based on content, domain, the structure of LMP links or something else.

This does not as yet appear to be a security problem at all.

Regards
« Last Edit: December 17, 2014, 04:20:28 am by DW »
Dean Wiebe
ListMailPRO Author & Developer - Help | Support | Hosting

BGSWebDesign

  • Posts: 625
    • View Profile
    • http://www.bgswebdesign.com
Re: Virus and Security problems with ListMailPRO?
« Reply #2 on: December 20, 2014, 07:22:56 pm »
Hi DW,

Please look at this as I'm not sure what it means, the Host replied with the following:
Quote
The complaint is not against the emails sent from the server. It's against the virus "Adware.FakeDriverUpdate.gen" which was included in the url http://myhost.com/mail/link.php?id=_zc0ienfrlovrs1. Please check it and remove the virus from the server.

I had a look to the link referenced and visited it directly, when I do, I see this:
Quote
link not found..

I'm not sure what is going on here, is this attempting to be a valid link, when it is not?  Is there some virus / software incorrectly identifying a virus in link.php?  Can you please fill me in exactly on how to track down where I could locate that link, or tie it to a specific user/signup in my list and how this could lead to a virus?

Does this look like some way that a virus is inserted in LMP, or that there is a virus located at that link?  I'm asking the host for confirmation as I don't find anything there, but can you tell me what this might mean, have you seen it before?

Thanks,
-Brett
http://www.bgswebdesign.com/Contact-Us.php

*** I do custom List Mail Pro installations ***
Contact me through my website (above)

BGSWebDesign

  • Posts: 625
    • View Profile
    • http://www.bgswebdesign.com
Re: Virus and Security problems with ListMailPRO?
« Reply #3 on: December 21, 2014, 02:27:51 am »
Hello DW,

It appears there is a website that runs around an has a history of reporting false positives. It is clean-mx.de, and you can find more about it at: http://bluetack.co.uk/forums/index.php?showtopic=20173

So, unfortunately the internet has other sites as well that go through content looking for things to report and reporting them automatically, without even having a human verify them.  The sad part is that
some hosts rely on this information causing great stress to webmasters and website owners.

Thank you for looking at the post, but it appears it's all related to false positive reports.

Thanks,
-Brett
http://www.bgswebdesign.com/Contact-Us.php

*** I do custom List Mail Pro installations ***
Contact me through my website (above)