JSRedir-R / Gumblar.cn – Preventing Re-infection

In the comments and in other places, I’ve seen a lot of folks breathe a sigh of relief that they finished cleaning out the JSRedir-R / Gumblar.cn infection, only to shortly thereafter find they got reinfected. It looks like reinfection is happening through compromised desktop computers that seek out FTP username and password information [...]

Fighting The JSRedir-R / Gumblar.cn Trojan

I spent the evening fighting an infection on a  client’s web server hosted by a third party. It was a bloody nightmare. I’m posting here to help any other wayward travelers who run into this issue as I think this is going to be the next big security storm. I also want to point [...]