I have been working on a client's site and it seems they have been affected by some kind of hack. The index.php and bootstrap.inc files are filled with spam links and text relating to a Japanese shopping site. The links don't seem to show anywhere on the front end but they do affect the site's description on Google, filling it with Japanese text etc.

When this first occurred, there were hundreds of pages also added to the site which I removed and they haven't come back but every time I clean up the index.php and bootstrap.inc files, within a day or two the spam content has been added back in somehow.

So far I have tried changing the FTP passwords, completely reinstalling Drupal (the latest version) and changing the file permissions (they're currently at 755) and nothing has made any difference.

Any tips on where to look or how to prevent this occurring would be much appreciated as it so far seems impossible to shift!

Comments

pobster’s picture

That these files have been altered suggests the security issue is with your hosting and nothing directly to do with Drupal itself. Most Drupal exploits only allow writing to the database (which is the main source of access on a Drupal site). FTP is notoriously insecure and it's probable that this access is the cause of your hack, there's also "sideways" hacking if you're on shared hosting, where an individual can write to other account filesystems in certain circumstances (i.e. they're not fully sandboxed in).

Anyways, you really need to work with your hosting provider to prevent this from reoccurring.

Thanks,

Pobster

a-mulgrew’s picture

Hi pobster, thanks for your reply.

I've spoken to the hosting company about it and they assure me it's nothing on their end and that the only IP address that has edited any files has been my own, so it seems to be some kind of automated thing affecting the site.

I'm really not sure what I should be looking for, either in the files or the database. I've searched the database for the content that's being added and related terms and come up with nothing, while Drupal core has been completely updated and reinstalled manually so the files should be clean.

The client is at the point where they want to move hosting provider but I'm slightly apprehensive to recommend that if it's something that will just be transferred over with the files or database.

pobster’s picture

The hack isn't in the database from what you've written above, it's just added onto the end of the index.php and bootstrap.inc files. The chances are extremely high that it's a shared-host hack - my advice, change your hosting provider. The alternative is that the attacker is gaining access to the site through your FTP (as in, there's a trojan on your machine), run a virus scan. FTP is the worst way to put files on a server...