Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-21-2011, 08:39 AM   #1
boneprone
Hall Of Fame
 
boneprone's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: Portland Oregon USA
Posts: 34,415
:mad HACKED: How to Remove ATX2 Tradescript Hack? 2nd click out goes to HACK.

People using ATX 2. This seems to be common among not just ATX but other trade scripts as well. There is a hack that a hacker puts into out.cgi in trade script that when the surfer clicks twice it goes to the hackers desired site..

Ive dealt with this before with old trade scripts and removed them without problem. Normally you can see a file installed that doesnt look right in the trade script folder.

This time its a little more complex.

What's strange is we've even changed out the versions of the script.
__________________

Industry Hall Of Fame Legend Mike Jones
Bow to the Power - Still BP4L
http://gfyawards.com/hall-of-fame
Learn about it kids.
boneprone is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 08:40 AM   #2
boneprone
Hall Of Fame
 
boneprone's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: Portland Oregon USA
Posts: 34,415
and anyone know how they get in to do this in the first place?
I always run the latest version.

Are they getting in via an old version with a hole in php? Apache? OS??
__________________

Industry Hall Of Fame Legend Mike Jones
Bow to the Power - Still BP4L
http://gfyawards.com/hall-of-fame
Learn about it kids.
boneprone is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 08:47 AM   #3
Juicy D. Links
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: N.Y. -Long Island --
Posts: 122,992
bump bump
Juicy D. Links is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 09:49 AM   #4
Just Alex
Liv Benson to You, Bitch
 
Just Alex's Avatar
 
Industry Role:
Join Date: Aug 2007
Location: Maryland and WV
Posts: 6,060
Anal Probe is fucking with your script again?
Bustard.
__________________
Just Alex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 09:52 AM   #5
cybermike
Confirmed User
 
Join Date: Jan 2002
Location: Ny
Posts: 4,109
Lots of scripts getting hacked :\
__________________
Hey surfers how about some The Best Porn Sites
cybermike is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 09:52 AM   #6
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 09:52 AM   #7
u-Bob
there's no $$$ in porn
 
u-Bob's Avatar
 
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
wipe the server and reinstall everything.
u-Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:03 AM   #8
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
Quote:
Originally Posted by u-Bob View Post
wipe the server and reinstall everything.
what he said if nothing helpes, who knows where is vulnerability on
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:06 AM   #9
Phoenix
BACON BACON BACON
 
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
wipe it if you cant block it
__________________
Skype Phoenixskype1
Telegram PhoenixBrad
https://quantads.io
Phoenix is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:07 AM   #10
Qbert
Confirmed User
 
Qbert's Avatar
 
Industry Role:
Join Date: Jun 2004
Location: Dark Side of the Moon
Posts: 813
If the peeps at Arrow Scripts don't have the answers on how to fix and prevent this problem than I'd be changing to a different trade script.
Qbert is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:16 AM   #11
ThatOtherGuy - BANNED FOR LIFE
So Fucking Banned
 
Industry Role:
Join Date: Apr 2011
Posts: 1,241
My only advice would be...

Stop using software that gets hacked and has no support to fix it
ThatOtherGuy - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:21 AM   #12
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 77,055
have your host clean it. i had two sites hacked with arrow scripts
__________________
TRUMP 2025 KEKAW!!! - The Laken Riley Act Is Law!
DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com
brassmonkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:21 AM   #13
Agent 488
Registered User
 
Industry Role:
Join Date: Feb 2006
Posts: 22,511
dynamite the server. start over.
Agent 488 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 10:50 AM   #14
KillerK
Confirmed User
 
Join Date: May 2008
Posts: 3,406
time for a new trade script
KillerK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 11:30 AM   #15
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by cybermike View Post
Lots of scripts getting hacked :\
Not mine since i applied simple security trick
Klen is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 02:36 PM   #16
critical
Confirmed User
 
Join Date: Aug 2009
Posts: 478
You should host your box with Critical.net. We would, as your host, have tracked that down and locked down the box for you.

Just sayin' - Your host should be checking that out for you.
critical is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 02:38 PM   #17
96ukssob
So Fucking Banananananas
 
96ukssob's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: If I was in your ass you'd know it
Posts: 12,991
Quote:
Originally Posted by KlenTelaris View Post
Not mine since i applied simple security trick
what is that?
__________________
Email: Clicky on Me
96ukssob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 06:22 PM   #18
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by Qbert View Post
If the peeps at Arrow Scripts don't have the answers on how to fix and prevent this problem than I'd be changing to a different trade script.
I wouldn't be jumping up and down about ATX just yet. You don't know for sure whether the trade script itself is vulnerable, or the hacker is getting in some other way and simply using the trade script as a redirect point (which is common, since that's where all clicks go...)
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-21-2011, 07:50 PM   #19
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
Ask Vince Russo or Anal Hobbitt.
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-22-2011, 02:28 PM   #20
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by bossku69 View Post
what is that?
You simply need to disable tmp folder to execute.
Klen is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.