<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bleuken.com &#187; PHP Hacks</title>
	<atom:link href="http://www.bleuken.com/tag/php-hacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bleuken.com</link>
	<description>SEO, Programming, Gadgets, Boxing, Etc.</description>
	<lastBuildDate>Sun, 15 Jan 2012 12:16:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Removal and Prevention of Gumblar.cn Infections</title>
		<link>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/</link>
		<comments>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/#comments</comments>
		<pubDate>Wed, 06 May 2009 02:27:03 +0000</pubDate>
		<dc:creator>bleuken</dc:creator>
				<category><![CDATA[Some Tips]]></category>
		<category><![CDATA[Gumblar.cn]]></category>
		<category><![CDATA[PHP Exploits]]></category>
		<category><![CDATA[PHP Hacks]]></category>

		<guid isPermaLink="false">http://www.bleuken.com/?p=854</guid>
		<description><![CDATA[Gumblar.cn is a website is listed to be suspicious and contains several exploit scripts and trojans that might harm and infect computers. Google marked it as not safe for browsing. I first encountered on a website that I am working on and seen how and where it infects the website. What the trojan did on [...]<p><a href="http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/">Removal and Prevention of Gumblar.cn Infections</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>



No related posts.]]></description>
			<content:encoded><![CDATA[<p>Gumblar.cn is a website is listed to be suspicious and contains several exploit scripts and <a href="http://www.bleuken.com/search/trojans">trojans</a> that might harm and infect computers. Google marked it as not safe for browsing. I first encountered on a website that I am working on and seen how and where it infects the website. What the trojan did on the site is it embeds its encrypted scripts on .HTML, .JS and .PHP files. You can find the Javascript of the trojan on .HTML files prior to the &lt;body&gt; tag while it embeds itself on .JS files at the bottom most of the said script file. On .PHP files, it usually infects INDEX.PHP files and embeds itself either at the top or bottom of the file. I also found some infections on common .PHP files that are usually INCLUDEd as a constant file of the site. The current anti-virus that detects the said virus was AVAST Home Edition with Web Shield and Networking Shield ON.</p>
<p>Here&#8217;s what you will see if you will try to surf a site on Google Chrome that is infected by the trojan coming from the said site:</p>
<p><img class="aligncenter size-full wp-image-855" title="gumblar-cn-googlechrome" src="http://www.bleuken.com/wp-content/uploads/2009/05/gumblar-cn-googlechrome.jpg" alt="gumblar-cn-googlechrome" width="479" height="183" /></p>
<p><span id="more-854"></span>Now, how to remove it from your website? Well I found no reference on the net to remove it instantly so what I did is I removed the trojan scripts on each file (.JS, .HTML, INDEX.PHP) that I suspected for infection using Filezilla (FTP client program). For the WordPress infection, what I only did was I re-updated / upgraded the site to the latest version which causes the process to override existing files then remove the script from the WP-CONFIG.PHP file. This is the only file that is not overwritten by the said process that&#8217;s why I need to remove the trojan scripts manually.</p>
<p>As always, prevention is better than cure to avoid the pain of fixing the problems it cause to the site and to the owner. Here are some of my suggestions and recommendations I found from different web hosting sites regarding avoidance of <a href="http://www.bleuken.com/search/hacking">hacking</a> and malware infections on your site:</p>
<ol>
<li>Change the file attributes of the files that doesn&#8217;t require writing permissions. I usually set my files to 755 attributes (MOD 755)</li>
<li>Update your antivirus virus database and enable or use network + web shield features at all times. Usually infection of websites starts from the local PC that uses to upload new files.</li>
<li>Read this PHP Security fixes recommended by a web hosting company. It contains comprehensive tips on how to avoid PHP exploits and hacks. Read it carefully and apply it if it is possible.</li>
</ol>
<p>If you have any better solutions out there or any recommendations on dealing on this kind of exploits/hacks, feel free to leave it here. I am sure that a lot of people will really highly appreciated the help that you can provide.</p>
<p><a href="http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/">Removal and Prevention of Gumblar.cn Infections</a> is a post from: <a href="http://www.bleuken.com">Bleuken.com</a></p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.bleuken.com/removal-and-prevention-of-gumblarcn-infection-20090506/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced (User agent is rejected)
Object Caching 520/563 objects using disk: basic

Served from: www.bleuken.com @ 2012-02-10 22:59:03 -->
