Project Detail

website hacked - need urgent help (Adobe Acrobat issue)  

website hacked - need urgent help (Adobe Acrobat issue) is project number 418065
posted at Freelancer.com. Click here to post your own project.

 

| More Free Trial For New Buyers
 

Status:

Selected Providers: Azoth

Budget: $30-250

Created: 04/13/2009 at 21:04 EDT

Bid Count: 5

Average Bid:
$ 226

04/14/2009 at 21:04 EDT

Project Creator: givememyleg
Employer Rating: 10/1010/1010/1010/1010/1010/1010/1010/1010/1010/10 (23 reviews)

Bid On This Project
 

Description

Our website has been reported to have been hacked and one of our user's computers effected. Please see their report:

Your website has been hacked.

Here's some of the code which I've been able to pull off my infected computer (Please see attached txt file).
(Don't worry, it's been put into Notepad so it isn't code anymore.)

I got this when I clicked on to do the bWin room review (http://www.flopturnriver.com/reviews/Online-Poker-BwinPoker.php - PLEASE BE CAREFUL WHEN VISITING THIS LINK AS IT MAY EFFECT YOUR SYSTEM). It is still causing my main computer to crash but I've been able to isolate what it is.

This bug is using a vulnerability to Adobe Acrobat, detailed on their website and warning people to install a patch.
Read about it here: http://www.adobe.com/support/security/bulletins/apsb09-04.html

As you can see from the above code, the exploit causes a pop-up window to search for installs of Adobe and run a snippet to create a PDF which then hooks into the registry and calls the 'Reboot-AH' worm to crash the computer and reboot it so as to install the virus keys into the registry. If you have Adobe Acrobat Reader on the machine you're screwed.

We need someone who is an expert in virus removal and website security who can fix this issue ASAP. This is very urgent and you should not bid if you can not start immediately. Escrow will be used.


Additional files submitted:
code-hack.txt

Messages Posted:0 View project clarification board Post message on project clarification board

Bid On This Project
 

If you are the project creator or one of the bidders Log In for more options

 

200

0 days

04-13-2009 22:45 EDT

Hi Good day, Web Hacker Bid. Please cehck PM for more Details. Regards C.Rajesh B.E

help

 

180

1 day

04-14-2009 15:10 EDT

I have experience as sysadmin and blackhat, please see PM

help

 

250

5 days

04-13-2009 22:34 EDT

I`ll Do it..

help

 

250

3 days

04-13-2009 21:23 EDT

(No Feedback Yet)

Hey, I am a security-expert from Germany. I am a founder of www.ose.at. I am specialized in finding and fixing security-vulns in webapps: SQL-Injection XSS CRFS RFI&LFI Human Stupidy Our last references are: mozilla.com, comunio.de To see more of us and to get more information look at my portfolio: www.ose.at If you really need security-advice contact me, I will help you. Friendly greetings from germany. Damian

help

 

250

7 days

04-14-2009 11:45 EDT

(No Feedback Yet)

Hi, we are a professional hacker (Ethical) from India . we have done security testing for more than 50+ applications (200+ IP Addresses) including Firewalls, Routers and other Network devices. we can offer a considerable amount of relevant experience, including: A Master Degree, which has included several courses related to Information & Network Security, certificate from EC-Council in Ethical Hacking and our extensive experience in Information & IT Security including Penetration Testing/ Vulnerability Assessment, Security Policy Review and Compliance Testing and Ethical Hacking. we have worked on various projects of Penetration Testing, Vulnerability Assessment and Ethical Hacking using Manual Methods, Commercial and Open Source Tools. Penetration tests included latest exploits, Information Gathering, Vulnerability Scanning using tools like Nessus, Acunetix Web Vulnerability Scanner, and Paros Web Proxy; manually exploit known and unknown vulnerabilities in the web application through SQL Injection, Cross Site Scripting and other attacks. we also contribute actively in OWASP on number of Information Security related topics and write Technical Papers for other Information Security Forums. Below is our professional's synopsis: Ø Post Graduate Degree in Computer Systems Security from University of Glamorgan, UK. Ø Around 6 Years experience in IT including 3 Years experience in IT Security and Ethical Hacking. Ø Experience in Web Application Penetration Testing and Vulnerability Assessment. Ø Contributing actively in OWASP and preparing Technical Papers for other Information Security Forums. Ø Conducting Security Assessment and Penetration Testing using Manual Methods, Commercial and Open Source Tools. Providing suggestions to improve Network and Web Application Security. Ø Experience in reviewing and Modification/ Creation of Information Security Policies, Procedures and Guidelines. Thorough understanding of various Information Security Standards like BS7799/ ISO 17799. Ø Thorough understanding of SQL Injection, XSS Attacks & Web Vulnerability Assessment. Ø Understanding of Security Protocols likes SSL, SSH. we hope you will find the above information useful and we are look forward to get this poject as we can provided you best solution . Thanks.

help


    Bid on this Project