Jutros videh u Inboxu da sam dobio šest istovetnih poruka od noreply@google.com sa naslovom “Malware notification regarding avramovic.info”. Sve su stigle u 02:08. Prvo sam pomislio da je neki spam/scam, međutim, kad sam proverio – nije.

Evo sadržaja mejla:

Dear site owner or webmaster of avramovic.info,

We recently discovered that some of your pages can cause users to be infected with malicious software. We have begun showing a warning page to users who visit these pages by clicking a search result on Google.com.

Below are some example URLs on your site which can cause users to be infected (space inserted to prevent accidental clicking in case your mail client auto-links URLs):

http://www.avramovic .info/cv.pdf
http://www.avramovic .info/contact

Here is a link to a sample warning page:

http://www.google.com/interstitial?url=http%3A//www.avramovic.info/cv.pdf

We strongly encourage you to investigate this immediately to protect your visitors. Although some sites intentionally distribute malicious software, in many cases the webmaster is unaware because:

1) the site was compromised
2) the site doesn’t monitor for malicious user-contributed content
3) the site displays content from an ad network that has a malicious advertiser

If your site was compromised, it’s important to not only remove the malicious (and usually hidden) content from your pages, but to also identify and fix the vulnerability. We suggest contacting your hosting provider if you are unsure of how to proceed. StopBadware also has a resource page for securing compromised sites:

http://www.stopbadware.org/home/security

Once you’ve secured your site, you can request that the warning be removed by visiting

http://www.google.com/support/webmasters/bin/answer.py?answer=45432

and requesting a review. If your site is no longer harmful to users, we will remove the warning.

Sincerely,
Google Search Quality Team

Kada sam na Google-u otkucao “avramovic.info” imao sam šta i da vidim – “This site may harm your computer.” Kada kliknem na rezultat, Google pokazuje upozorenje i ne dozvoljava klijentu da ode na moj sajt.

google-result

Kada probam direktno da odem na sajt – Firefox izbacuje slično upozorenje:

firefox-warning

Pogledao sam source kod (iz browsera) glavne stranice svog sajta i našao kriptovani JavaScript kod na samom početku stranice, pre <HTML> taga. Zatim sam pogledao fajlove na serveru, prvo header i footer WordPress teme koju koristim na sajtu i nisam našао ništa, da bih u index.php fajlu samog WordPress-a naišao na php kod koji generiše gore linkovani JS kod i ubacuje ga na stranicu. Odmah sam ga, naravno, uklonio, i zatražio ponovni review sajta iz Google Webmaster Tools-a, kako je i savetovano. Sada čekam na izbacivanje sajta sa blackliste.

Nemam pojma otkud taj kod u index.php fajlu. Proverio sam neke foldere i fajlove koji su ranjivi i preko kojih je ranije upao backdoor na ovaj blog, ali nigde nisam našao ništa sumnjivo. .htaccess fajlovi nisu menjani, nema novih/sumnjivih/izmenjenih php fajlova, osim ovog index.php fajla koji je ubacivao maliciozni JS na sve stranice sajta. Ostaje jedino mogućnost da je malware na nekom drugom sajtu koji se hostuje na istom serveru i da je on uspeo da izmeni index.php fajl na mom sajtu. Zato sam sad stavio chmod 444 na index.php, što bi trebalo da svim korisnicima na serveru dozvoli samo čitanje ovog fajla, ne i pisanje u njega.