Phishing Attack on Gnome
Today, the Data Center has shut down the Gnome server (72.232.186.26) for several hours after discovering two accounts from our clients hosting a phishing website for Bank of America and Wells Fargo.
We coordinated with the DC engineers to get the server back online so we could investigate and remove the phishing sites.
It turns out that the two accounts by clients have folders that were open and allowed culprits to upload a zipped file of the fake website and extract them. We have deleted the files and secured the folders. We’re still looking into other client accounts that may have similar cases.
We request all clients to regularly and actively check their accounts for open folders (CHMOD them to 644) and update any add-on scripts or web apps they have installed so to avoid similar incidents in the future.
April 5th, 2009
