Vulnerable software detected on your account

Job ID: 34023779

Budget: $10 – $30 USD

Dear John,

While conducting our regular server security audit, we detected that the application hosted on your site has become vulnerable to exploits and creates a serious threat to the integrity of the shared server.

We have compiled a list with the suspicious files and it is stored in your account's home folder in a file called suspicious_files.txt:

/home/customer/www/examplesite.com/suspicious_files.txt

It can be downloaded either through Site Tools File Manager or using your local FTP client.

If you are unable to edit or download any of the suspicious files from the provided list, our system has most likely revoked the read, write and execute permissions from those files automatically during the malware scan. In such case you should modify the permissions of these files from either the File Manager tool in Site Tools or over SSH before you can edit/download the files and clean them up.

https://www.siteground.com/kb/files-folders-permissions/

Alternatively you can delete the infected files and reupload their clean version from a backup. Note that regardless of whether you choose to restore the files from our system backups or a backup of your own, the chosen backup should be created before the site got compromised, because otherwise the restored files may still contain malicious code.

You also have the option to manually scan your website URLs and files and fetch a list with suspicious files through our recently enhanced SG Site Scanner service:

https://www.siteground.com/blog/new-and-improved-sitescanner-security-service/

To ensure the overall security of the server and all websites hosted on it, we had to temporarily disable access to this application.

We are very much aware of the inconvenience this issue may cause you, so we would like to take a moment and explain the reasons for our actions: as you know, your account is hosted on a shared hosting server and thus sharing the resources of the server with other customers' accounts. If one account and even one application is hacked, this will endanger the integrity of the whole shared server and all other accounts on it. This is why the above-explained precaution is absolutely necessary.

Very often sites are compromised because of outdated software or stolen login details. Please check the following article for more information:

https://www.siteground.com/kb/why-was-my-website-compromised/

In your case we can offer you 2 solutions:

1. Clean and secure the site by yourself.

2. Security audit performed by our partners from Sucuri. We recommend the website security company Sucuri for malware detection, malware cleanup and malware prevention. Their 2-in-1 Website AntiVirus Website Firewall (WAF) solution supports and protects all websites built on any platform.

https://my.siteground.com/sucuri

Regardless of which way you choose to approach the problem, make sure to upgrade any applications you are using and their extensions to the latest available release. In addition, you should change the passwords of your FTP accounts, which you can do from Site Tools as explained in the following article:

https://www.siteground.com/kb/how_to_change_the_ftp_password/

When ready make sure to reopen the ticket about this case so that we can confirm the issue is resolved.

Last but not least, we recommend you to scan your local computer with an anti-virus software of your choice, in order to confirm that the same is not infected in any way.

Thank you for your understanding and cooperation.

This messsage is an example of the message i got from siteground where i host my website from
basically my website is down and i need it up and running as quick as possible please let me know how soon you can get these melicious files from my site please and thank you
Related categories: PHP Linux Web Security WordPress Web Hosting