Hello , Can anybody help me with my problem ?
I have one week new website hosted on dreamhost , yesterday my website has been hacked by TrojanDownloader.Pegel.BN , I immediately deleted all the website from the server , because the website is new (Nucleus CMS and forum in subfolder punBBB) I'm almost sure that i was the only user using it at the moment , I got via firefox browser and NOD32 antivirus warning that I have a virus( TrojanDownloader.Pegel.BN), immediately after adding new Nucleus CMS plugin - email form . This virus started to spread all over all index.php etc files javascript code on the bottom of each file , it started after I submitted first email from my website to my another email account , so I'm sure that it is with this email form sender plugin related , I deleted all the website , changed all my ftp passwords (was very strong before) , I cleaned and reinstalled comp and uploaded clean files to the server without this email plugin and now for assure myself I used Free Acunetix Web Vurnelability scanner and it says:
This script is possibly vulnerable to Cross Site Scripting (XSS) attacks
This vulnerability affects /index.php.
Attack details :
The POST variable memberid has been set to 1>"><ScRiPt%20%0d%0a>alert(41350)%3B</ScRiPt>.
When i opened the index.php in my root there's no javascript , there's nothing similar , scanner also shows me that it is connected with email:
<div class="content">
<div class="contenttitle">
<h2>Send message</h2>
</div>
<a id="nucleus_mf"></a>
<form method="post" action="#nucleus_mf">
<div class="mailform">
<input type="hidden" name="memberid" value="1>"><ScRiPt
>alert(43545);</ScRiPt>" />
<input type="hidden" name="action" value="sendmessage" />
<input type="hidden" name="url" value="http://worldwidedancers.net/xml-rss2.php?memberid=1>"><ScRiPt
>alert(43545);</ScRiPt>" />
Can you help me please ? where can I find this code ? This must the problem from the past which infected mostly all the index files with malicious javascript , pls. help me to find this code , as Im a laik I suppose that this code is a starter which will immdeiately after spread the code around the site , please help me I think that this is the best forum to ask ,
thank you Daniel .
www.worldwidedancers.com
www.worldwidedancers.net - my hacked website - reuploaded but there is somewhere this malicicious code -dont know where
www.dancersrecruit.com
www.nightclubsworld.net
www.vallerica.com


