Jets-News — Detecting and Removing a Website Compromise
The Challenge
Jets-News contacted us with a serious website security issue: visitors were occasionally redirected to websites containing adult content when clicking links on the site.
These unexpected redirects were damaging both the user experience and the company's reputation.
What We Discovered
We investigated the website and reviewed recent user activity and traffic patterns.
Our analysis showed that, several weeks before contacting us, an old administrator account had been used to access the website. The account had not been disabled after the administrator left the company.
Several backdoors had subsequently been placed on the website, allowing unauthorized actions to be performed.
What We Did
We analyzed the site's recent traffic and activity, identified the source of the unwanted redirects and located the malicious code.
We then:
- removed the malicious code and backdoors;
- disabled the compromised user account;
- checked the parts of the system associated with the attack;
- documented the findings of our technical investigation;
- prepared technical documentation and evidence for the client's further communication with the former employee and potential legal proceedings.
The Result
The source of the compromise was removed and the old account could no longer be used to access the system.
The unwanted redirects stopped and the website's reputation was restored.
The client did not need to rebuild or migrate the website. After the security issue was resolved, the existing system continued operating normally.