<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MarketingbyAnn Blog&#187; iframe</title>
	<atom:link href="http://www.marketingbyann.com/tag/iframe/feed" rel="self" type="application/rss+xml" />
	<link>http://www.marketingbyann.com</link>
	<description>Ann Liu Shares Money-Making Online Tips</description>
	<lastBuildDate>Mon, 06 Feb 2012 06:16:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A Must Read: iFrame Attack the Sites</title>
		<link>http://www.marketingbyann.com/2009/11/13/a-must-read-iframe-attack-the-sites</link>
		<comments>http://www.marketingbyann.com/2009/11/13/a-must-read-iframe-attack-the-sites#comments</comments>
		<pubDate>Thu, 12 Nov 2009 18:45:10 +0000</pubDate>
		<dc:creator>Ann Liu</dc:creator>
				<category><![CDATA[Alert & Opinion & News]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[ftp]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[iframe attack]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.marketingbyann.com/?p=5078</guid>
		<description><![CDATA[What will you feel after you come back from a wonderful birthday dinner and find out your sites are gone? Sure, you&#8217;ll not feel good. Guess what &#8211; it just happened to me! Fortunately, I send an emergency email immediately to my Hosting Support Desk, within less than 10 minutes, the issues got fixed and [...]]]></description>
			<content:encoded><![CDATA[<p>What will you feel after you come back from a wonderful birthday dinner and find out your sites are gone? Sure, you&#8217;ll not feel good. Guess what &#8211; it just happened to me! Fortunately, I send an emergency email immediately to my <a href="http://www.marketingbyann.com/recommends/kioskhosting.html"><u>Hosting Support Desk</u></a>, within less than 10 minutes, the issues got fixed and problems solved. </p>
<p>Below is the reply I got from the hosting help angle, which I would like to share with you, a MUST read!  </p>
<blockquote><p>Hello Ann,</p>
<p>I&#8217;m very sorry for the situation that you have encountered on your sites. The issue you have experienced is what is called an &#8216;iframe attack.&#8217; This attack works by placing an undesired page within your website&#8217;s root directory, which then overtakes your existing homepage. This can cause both a &#8220;500 Internal Server Error&#8221; or just simply a blank page. <span id="more-5078"></span></p>
<p>This issue is perpetrated through an unusual vector that many times is overlooked when it comes to compromised websites. The primary vector is through the client&#8217;s computer, or your computer. How this works, is you may have, unexpectedly or unknowingly, visited a site that was infected by malware &#8211; spyware, viruses, adware or otherwise. This malicious software is then installed without your permission, and then proceeds to collect information regarding certain things. In this particular instance the filtered information is your FTP details, user name and password. Using this stolen information they then upload the file directly to your site, causing this issue. This is why sometime when you delete that file, it simply comes back.</p>
<p>To resolve this issue, you must do the following:</p>
<p>Immediately install and scan with virus and spyware removal software.</p>
<p>Change ALL passwords, including email and database passwords.</p>
<p>Remove the file.</p>
<p>To prevent this in the future, unfortunately the best way is to sport best practices on the internet. Do not open emails with attachments that you do not recognize. Keep updated security software &#8211; virus and spyware removal tools, at all times. Make sure your operating system is up to date at all times. Be careful of the links that you click from friends and family. Doing this, you will save yourself from many issues, beyond simply the problem above.</p>
<p>There is another form of iframe attack, that has been circling the internet as well, that is not so easily fixed. This attack will modify files found within your web directory directly using exploits that do not require any issues to exist on your personal computer at home. These exploits are also not caused by insecurities in the server.</p>
<p>In these cases, the situation is caused by insecurity on running scripts such as Joomla or WordPress. These scripts can be exploited to create or edit index pages or .htaccess files creating this issue. Most of the time, these exploits are found in external, user created content like Themes and Plugins that are not developed according to the standards found by the primary developers and community of those applications. When this is the case, it is best to disable all plugins, and either upgrade or restore your script installation from backup.</p>
<p>While we understand this is frustrating, we appreciate your patience while we work to help you through this issue. If you need assistance in removing files or need advice or recommendations on this issue, please let us know and we will be more than happy to assist you in the future.</p>
<p>Thank   you,<br />
GVO &#8211; Abhilash,<br />
Server Administrator,<br />
GVO Support.
</p></blockquote>
<div id="crp_related"><h3>You might also like:</h3><ul><li><a href="http://www.marketingbyann.com/2011/05/16/protect-your-wp-blog-from-sql-injection-attact" rel="bookmark" class="crp_title">Protect Your WP Blog From SQL Injection Attact</a></li><li><a href="http://www.marketingbyann.com/2011/02/25/permalinks-are-not-working-after-upgrade-to-wp-3-1" rel="bookmark" class="crp_title">Permalinks are Not Working After Upgrade to WP 3.1</a></li><li><a href="http://www.marketingbyann.com/2010/05/10/how-to-create-your-mini-ebook-in-24-hours-or-less" rel="bookmark" class="crp_title">How To Create Your Mini Ebook In 24 Hours Or Less</a></li><li><a href="http://www.marketingbyann.com/2010/05/29/the-top-10-free-software-internet-marketers-must-have" rel="bookmark" class="crp_title">The Top 10 FREE Software Internet Marketers Must Have</a></li><li><a href="http://www.marketingbyann.com/2010/02/05/your-first-genesis-to-success-make-money-site-guide-p6_2" rel="bookmark" class="crp_title">Your First Genesis to Success Make Money Site Guide P6_2</a></li></ul></div><form action="http://www.aweber.com/scripts/addlead.pl" method="post" onsubmit="return sbmgValidateFormPostPg2('name','from')"><input type="hidden" name="meta_web_form_id" value="2062350524" /><input type="hidden" name="meta_split_id" value="" /><input type="hidden" name="listname" value="annliu" /><input type="hidden" name="redirect" value="http://www.marketingbyann.com/thankyou.html" id="redirect_ac1ccf601ad85f11b07fc6d3aecebf2d" /><input type="hidden" name="meta_adtracking" value="subscribers_magnet"><input type="hidden" name="meta_message" value="1" /><input type="hidden" name="meta_required" value="email" /><input type="hidden" name="meta_tooltip" value="" /><div align="center" style="padding:6px;;"><div align="left" style="width:300px; height:auto; border:1px solid #E3E3E3; background-color:#FFFFFF; ;  padding:10px 15px 10px 15px; ">
						<div style="padding-bottom:5px;font-family:Trebuchet MS, sans-serif;font-size:14px;"><span style="font-size: medium;"><strong>Join my blog tips newsletter and get a free copy of powerful promotion through video marketing ebook</strong></span></div>
						<div style="padding-bottom:7px;font-family:Trebuchet MS, sans-serif;font-size:12px;">Receive up-to-date ecourses, promotiional tips and all the goodies - Free</div><div align="right" style="font-family:Trebuchet MS, sans-serif;font-size:14px; padding-bottom:5px; margin:0px 10px 0px 5px; padding-right:15px; width:45; color:#000000;font-family:;font-weight:bold  "> 
							<div align="center" style="float:left; margin:0px 5px 0px 10px;">Name:&nbsp;</div>	
								<input type="text" name="name" value="" id="sbmgValidateFormPostPg2_name" style="font-family:Trebuchet MS, sans-serif;font-size:11px;width:300px;border:1px solid #BABABA; background-color:#FFFFFF" />
						</div><div align="right" style="font-family:Trebuchet MS, sans-serif;font-size:14px; padding-bottom:5px;  margin:0px 10px 0px 5px; padding-right:15px; width:45; color:#000000;font-family:;font-weight:bold " >
							<div align="center" style="float:left; margin:0px 5px 0px 10px;">Email:&nbsp;</div>
								<input type="text" name="from" value="" id="sbmgValidateFormPostPg2_from" style="font-family:Trebuchet MS, sans-serif;font-size:11px;width:300px;border:1px solid #BABABA;  background-color:#FFFFFF" />
						</div>
						
						<div align="left" style="padding-bottom:8px;  padding-right:15px; padding-left:45px; margin:0px 10px 0px 5px;">
							<div style="float:left; margin:0px 5px 0px 10px;">&nbsp;</div>
								<input name="submit" type="submit" style="font-family:Trebuchet MS, sans-serif;font-size:13px;font-weight:bold;border:1px solid #990000; border-right-width:2px; border-bottom-width:2px; background-color:#000000; color:#FFFFFF; font-weight:normal" value="Subscribe Me!" />
						</div>	
						<div style="line-height:13px;padding-bottom:5px;font-family:Trebuchet MS, sans-serif;font-size:12px;">We respect your privacy and your information will not be shared with any third party.</div><div align="center" ><a rel="nofollow" target="_blank" href="http://www.maxblogpress.com/go.php?offer=ann888&pid=35" target="_blank" style="font-size:x-small;color:#000000;text-decoration:underline"></a></div></div></div></form>]]></content:encoded>
			<wfw:commentRss>http://www.marketingbyann.com/2009/11/13/a-must-read-iframe-attack-the-sites/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

