Is it possible to attack XSS on a static page (i.e. without PHP)?

The client I'm working on mysteriously ended up running some malicious scripts on their site. I am a little puzzled that the site is static and not dynamically generated - no PHP, Rails, etc. At the bottom of the page, someone opened a new tag and script. When I opened the file on the web server and deleted the malicious content and reloaded, it was still there. How is this possible? And more importantly, how can I deal with this?

EDIT: To make it weirder, I just noticed that the script only appears in the source if the page is accessed directly as "domain.com/index.html" but not as "domain.com".

EDIT2: Anyway, I found some php file (x76x09.php) sitting on a web server that must have been updating the html file, despite my attempts to split it into a script. I am currently up to date, but I need to do some work to make sure rogue files do not just appear again and cause problems. If anyone has any suggestions about this, feel free to leave a comment, otherwise thanks for helping everyone! It was very appreciated!

+3
source share
4 answers

No, this is not possible if someone does not have access to your files. Therefore, in your case, someone has access to your files.

Change It is best if you ask serverfault.com what to do if the server is hacked, but:

  • change your shell passwords
  • /var/log/messages .
  • .

, , http, , .

+3

, , , XSS - DOM. JavaScript, . WhiteHat Security XSS "" .

, , , , JS.

+3

, . , , , .

0
source

This happened to me before - it happens if they receive your ftp data. So, whoever did this, obviously somehow caught your ftp data.

The best thing is to change your password and contact your web hosting company to find the best solution.

Unfortunately FTP is not the most secure ...

0
source

Source: https://habr.com/ru/post/1753197/


All Articles