Arkadaşlar sitenin kapanma sebebini öğrendim bir mail gelmiş burada paylaşıyorum. İngilizce olarak uyarı gelmiş. Trojen saptandı acilen kapatın falan diyor. Geçen gün sitemin footer kısmında iki tane ****ografik siteye link çıkışı gördüm kurcalarken temayı. Görsel olarak görünmeyecek şekilde yapmışlar. Ama wp-adminden kurcalarken tesadüfen gördüm. NAsıl yaptılar hiçbir fikrim yok. Sebebi o diye tahmin ediyorum. Şimdi de sitem kapalı. Ve bunların hiçbirinden ben sorumlu değil. Ne yapmam gerekiyor şimdi?
Gelen mail:
To whom it may concern:
RSA, The Security Division of EMC (“RSA”), an information security company, has detected and verified that a Malware (as defined below) program is being propagated from a server which is associated with the following URL:
http://yazinak.com (the “Designated Site”)
From our review, it is our understanding that you operate the Designated Site and that it is, therefore, under your control.
For the purposes of this letter, “Malware” means any software applications or executables that perform actions unanticipated by and without the consent of the person running the software. Malware is distributed via many mechanisms including, but not limited to: email attachments; content injection such as cross site scripting; exploiting security vulnerabilities in operating systems and other software; and/or insertion into downloadable software. Malware is designed, among other things, to misappropriate personal data in order to engage in fraudulent transactions using that data, and/or to compromise and co-opt an end-user’s networked computer; all for the purpose of performing illegal or improper acts such as misappropriating funds; carrying out denial of service attacks; and sending unsolicited mass emails.
For your information, we have analyzed the specific Malware and enclose a file, which includes:
Malware name: Brazilian Banker
Description: The Trojan uses HTML Injection in order to create fake login fields on several banks online login pages. In this way the Trojan is able to steal the user's login data /
credentials. All stolen data is sent to the Trojan's drop point.
Source of infection/distribution:
http://yazinak.com/email/email/sincronizar.php This file also details the method by which it appears that the Malware is downloaded to a victim’s computer.
In this instance, it is our belief that the specific purpose of the Malware is to misappropriate account credentials and identity information from the customers of one or more financial institutions in order to access their bank accounts fraudulently.
Therefore, we request that you immediately take all actions necessary to disable and remove this Malware from the Designated Site.
We would appreciate your email confirmation that the source of the Malware infection has been disabled.
We understand that you may not be aware of the above described improper use of the Designated Site and we thank you for your cooperation in the prevention of fraudulent online activity.
The foregoing is without prejudice to any and all rights and remedies of any financial institution impacted by the improper use of the Designated Site, which rights and remedies are hereby expressly reserved.
If you need further information, please do not hesitate to contact RSA at the numbers below.
Sincerely,
RSA SECURITY INC.