| 
		
			
			
				
			
			
				 
			
			
				
			
		 | 
		
			
			
				 
			
				
			
		 | 
	||||
| 
				Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.  You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us.  | 
		
		 
		![]()  | 
	
		
			
  | 	
	
	
		
		|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
| 
		 | 
	Thread Tools | 
| 
			
			 | 
		#1 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
			
			 Hi u all! 
		
	
		
		
		
		
			I'm having this issue at programs url. When I try to access to a promo tool, the link leads me to an URL that gives me access to admin page 'r57Shell'. This is a little weird! I get this URL from their NATs program. Anyone trying to access that tool will also see it and my try to cause some troubles i guess... ![]() I havent received any email confirming my subscription to their nats system. I have sent a support ticket warning them. Best regards 
				__________________ 
		
		
		
		
		
			
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#2 | 
| 
			
			
			
			 Too lazy to set a custom title 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Sep 2005 
				Location: Springfield 
				
				
					Posts: 13,826
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 webair.com.... 
		
	
		
		
		
		
			why am I not supprised... 
				__________________ 
		
		
		
		
	
	Make a bank with Chaturbate - the best selling webcam program        Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!! PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#3 | 
| 
			
			
			
			 Too lazy to set a custom title 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2002 
				Location: Montreal, Quebec 
				
				
					Posts: 29,764
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 That shell script gives root acess to your server : 
		
	
		
		
		
		
			http://www.nullamatix.com/find-r57-a...and-txt-files/ Do a rootkit scan and address this urgently ![]() 
				__________________ 
		
		
		
		
	
	I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time ....  | 
| 
		
 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#4 | 
| 
			
			
			
			 there's no $$$ in porn 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jul 2005 
				Location: icq: 195./568.-230 (btw: not getting offline msgs) 
				
				
					Posts: 33,063
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I guess someone needs to reinstall his server.... 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#5 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I have sent a support mail ... 
		
	
		
		
		
		
			i will try to talk with the owner here... 
				__________________ 
		
		
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#6 | |
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Jun 2007 
				
				
				
					Posts: 160
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 
				__________________ 
		
		
		
		
	
	dlXer - web design, developing, managed hosting, website optimizations  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#7 | |
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Join Date: Nov 2005 
				
				
				
					Posts: 2,167
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 
				__________________ 
		
		
		
		
	
	agentGFY *at* gmail.com  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#8 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Industry Role:  
				Join Date: Sep 2006 
				
				
				
					Posts: 43
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 looks like that NATS install is on a virtual plan? 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#9 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Oct 2002 
				Location: netherlands 
				
				
					Posts: 248
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 check your installed scripts for exploits and updates asap. 
		
	
		
		
		
		
		
		
			
		
		
	
	but probably there are more scripts like that on your server or their server if its a dedicated and you are the owner. turn on safe mode... or turn it on temp. before the get deeper  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#10 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Its not mine. 
		
	
		
		
		
		
			I'm just an affiliated. I'm sent an email to the programs support, added the owner to ICQ and I have sent a message to him here in GFY... cant get in contact with him. How does NATs handels with password? I guess that is saved on a database and not encoded by md5 or something :S 
				__________________ 
		
		
		
		
		
			
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#11 | 
| 
			
			
			
			 there's no $$$ in porn 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jul 2005 
				Location: icq: 195./568.-230 (btw: not getting offline msgs) 
				
				
					Posts: 33,063
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 The attacker was able to install that r57shell script. That does tell you one thing: the server has been compromised. It doesn't tell you how they got in, what they did or what level of access they eventually acquired.  
		
	
		
		
		
		
		
	
	Once you've determined that the server has been compromised, there is one thing you absolutely need to do: wipe and reinstall the server. While going through your logs, scanning for rootkits, auditing your scripts etc is recommended to find out more information about how they got in. Information you can use to prevent future compromises, but it does not change the fact that the server needs to be reinstalled. A system that has been compromised is a system that can no longer be trusted.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#12 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 The server is not mine. 
		
	
		
		
		
		
			I'm just a lousy webmaster that registered on the server's owner NATs program, and that the RSS links send me to the r57shell script... i'm afraid that my password may have been stolen.. 
				__________________ 
		
		
		
		
		
			
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#13 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Oct 2002 
				Location: netherlands 
				
				
					Posts: 248
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 once you got a c99 or r57 shell on the box , you can get all data , logs , databases etc. everything on that box 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#14 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Nov 2009 
				Location: Heaven 
				
				
					Posts: 4,306
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 u r screwed 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#15 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I'm going to warn that webair guy that uses GFY!... 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#16 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		
		
	
		
		
		
		
			 
				__________________ 
		
		
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#17 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Feb 2002 
				Location: NYC, NY 
				
				
					Posts: 8,531
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 dick =)  
		
	
		
		
		
		
			![]() ------------------------ Looks like they got in via a vulnerable script. Thanks for the report MrGusMuller and for contacting me. I got my guys on it now. 
				__________________ 
		
		
		
		
		
			
		
		
	
	![]() ~ Webair Dedicated Cloud Servers™ ~ WEBAIR VSYS™ Virtual Hosting Platform ~ Superior CDN Network ~ ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~ ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected]  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#18 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I have warned the webair, and few minutes later the problem was corrected. 
		
	
		
		
		
		
			Now, to anyone who might me interested, the affiliated program was HYPEDOUGH.COM. I was able to read the wp-config.php and see the username/password for the database. ![]() 
				__________________ 
		
		
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#19 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Oct 2002 
				Location: netherlands 
				
				
					Posts: 248
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 it probably was wordpress which was exploited, last version had vulnerabilities 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#20 | 
| 
			
			
			
			 Damn Right I Kiss Ass! 
			
		
			
			
			Industry Role:  
				Join Date: Dec 2003 
				Location: Cowtown, USA 
				
				
					Posts: 32,422
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Usually it is a forum or a support form coded in 1998. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#21 | 
| 
			
			
			
			 Too lazy to set a custom title 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2002 
				Location: Montreal, Quebec 
				
				
					Posts: 29,764
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 or a pirated " nulled " script or addon in which the exploit was integrated and became active at the install . 
		
	
		
		
		
		
			As U-Bob stated, once a box is compromised , it is better to reinstall OS. Accounts could always be moved to another box, but must be clean of the shell script. 
				__________________ 
		
		
		
		
	
	I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time ....  | 
| 
		
 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#22 | ||
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Oct 2010 
				Location: Portugal 
				
				
					Posts: 1,262
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 The wp-config.php that I have read had STRANGE embebed code! I'v warned webair guys 'cause no one from HYPE has said anything to me. Are they on vacations? Quote: 
	
 
				__________________ 
		
		
		
		
	
	StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113  
			 | 
||
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#23 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Nov 2009 
				Location: Heaven 
				
				
					Posts: 4,306
				 
				
				
				
				 | 
	
	|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 |