Websites can be affected by viruses; however, these are not the same viruses that would affect a computer. They are specifically designed and intended to run on a website and exploit that environment.
How Do Viruses Gain Access? #
They usually gain access by exploiting a known security vulnerability. This method is the most common because it requires the least effort from the attacker. In these cases, a component of the website or server has been found to allow an unauthorized action through a specific series of operations, thus creating a security hole. Normally, these security issues are quickly resolved, but it is essential for the website and server to be maintained to apply these solutions. In such instances, attackers exploit unmaintained sites.
On other occasions, though less common, they gain access by discovering a password that provides access to areas from which a virus can be introduced. There are several ways they can discover a password:
- The password was too simple: Attackers use dictionaries of commonly used passwords to check if you are using one that many others also use. It is always advisable to use complex passwords.
- The attacker may have read your password: There are computer viruses that obtain passwords for everything you connect to. These passwords are then sold by attackers to each other “by weight,” and a specialized website attacker uses them for their purposes. To prevent this, it is important to use passwords only on secure devices.
- The attacker tried thousands of passwords until they found yours. This is commonly known as a brute-force attack. To counter this, we install a system on the website that prevents multiple password attempts, blocking those who try.
Why Do They Do It? #
Most likely, the attacker has nothing personal against you or your website. In fact, they often do not even know they have hacked your site, as these processes are automated. The main objective is to exploit your resources to, in some way, make money:
- Displaying advertisements to your visitors.
- Implementing SEO strategies that benefit other sites (usually to the detriment of yours).
- Sending unsolicited email (spam) to various email accounts.
- Mining cryptocurrencies and/or causing your visitors to mine cryptocurrencies for their benefit.
- Using your server to attack other websites.
- Obtaining user information from your website for illicit purposes (Should this occur, the Spanish Data Protection Agency must be notified).
- Using your server as hosting for their content.
And sometimes, they simply remain hidden, waiting for a better moment to attack in the future.
What Can Be Done Against These Attackers? #
These actions are classified as cybercrime in Spain and other European legislations. However, in practice, the ultimate perpetrator is usually not apprehended, as they make tracing difficult and take refuge in countries that will not act against them.
How Do These Viruses Affect Websites? #
The way these viruses affect websites is specific to each case:
- Some enter and operate silently without anyone noticing.
- Others are more brazen, suddenly displaying advertisements, making it obvious that something has happened.
- Some suddenly break the site, making their presence more obvious.
Regarding their technical impact on the site: Some are very easy to clean because they only affect a few files, while others, acting like a virus, spread and embed themselves in all possible files and data on the website, making their cleanup much more complicated.
Our Process #
At GIGA4, we have a defined protocol to: eliminate the virus, recover the site, update it, and secure it:
- We create an isolated copy of the site from the original.
- We analyze the site to understand the nature and scope of the infection.
- We attempt to recover an unaffected backup.
- If this is possible, we use the backup as a reference to clean the site, making the cleanup more efficient.
- If no backup exists, we perform a completely manual cleanup.
- At this point, the virus would be gone, but we know there is a security vulnerability through which it entered once and through which it could potentially re-enter. Therefore:
- We update the site by updating its components.
- We secure the site with various preventive strategies to avoid common attacks such as brute-force attacks, the use of known passwords, or the use of specific control scripts.
- We secure the server by changing its passwords.
- We delete all files from the server and upload our isolated copy as the new secure version of the site.
By doing this, the site is cleaned, cannot be re-infected with the same virus or through the same security hole, and is better protected for the future with preventive measures.
Priority Assistance #
We handle these cases with priority because it is important to prevent the situation from worsening.
It is common that when a known security vulnerability exists, more than one attacker will find it. Therefore, there may not only be one virus on the website, but several coexisting, and the time elapsed is crucial in this regard. Usually, the more time passes, the more viruses.
Although there are some curious cases where attackers, upon gaining entry, close the security hole behind them. This prevents other attackers from entering through the same point, aiming to avoid sharing it.