Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-11-2004, 04:29 AM   #1
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
FUCK ME@#$#@$ Maybe hacked can somone look at this code for me please?

This seems to be on a lot of my web pages on my server
<.....script language...="ja.vascript">
window.open ("http://vb-aus.com/traff/index.php","","toolbar=1,location=1,status=1,men ubar=1,scrollbars=1");
window.focus ();
</sc.rip.t>
\
I put in . so it wont work here. Has anyone seen this before?
TOM
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:31 AM   #2
nastyking
 
Join Date: Nov 2002
Posts: 2,174
yes, it's the infamous "test popup" virus. very dangerous in the wild.
__________________
nastyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:32 AM   #3
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by nastyking
yes, it's the infamous "test popup" virus. very dangerous in the wild.
Ok its even on webpages that I havent even touched in months, is there a fix I need all info to show my host. How the hell grrrrr
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:34 AM   #4
nastyking
 
Join Date: Nov 2002
Posts: 2,174
Quote:
Originally posted by va2k
Ok its even on webpages that I havent even touched in months, is there a fix I need all info to show my host. How the hell grrrrr
there is no way to fix it. you are doomed.
__________________
nastyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:35 AM   #5
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
it seems to be only on index.html pages
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:36 AM   #6
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by nastyking
there is no way to fix it. you are doomed.
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:50 AM   #7
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:55 AM   #8
justsexxx
Too lazy to set a custom title
 
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
Kaspersky blocked access to that page. So I guess it's full of shit code. How it could be on your page? No idea..Ask your host. Who is it?
__________________
Questions?

ICQ: 125184542
justsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 04:58 AM   #9
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by justsexxx
Kaspersky blocked access to that page. So I guess it's full of shit code. How it could be on your page? No idea..Ask your host. Who is it?
yea its weird HAVE NO idea how it got on my pages I put in a request to the host and knowing my host they will have it taken care of asap. At least ya tried to help, Thanks bro

I have no clue on these types of things... IM doing another scan on my home pc to see if it is something on my end that caused this doubt it though.. There are static webpages on my server that has this code in it. If it aint one person trying to fuck you its a whole network
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 05:11 AM   #10
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
For one of the biggest boards I am very supprised to see no one knows of this

TOM
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 08:09 AM   #11
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 08:32 AM   #12
inabon
Good Old Fat Webmaster
 
inabon's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Boquete, Panamá
Posts: 970
what operating system is your webs server running?
__________________
Whoever dies with most toys wins.
inabon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 09:22 AM   #13
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by inabon
what operating system is your webs server running?
LINUX
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 09:25 AM   #14
candyflip
Carpe Visio
 
candyflip's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,064
Quote:
Originally posted by va2k
LINUX
A bit more specific perhaps? There are many variations.
__________________

Spend you some brain.
Email Me
candyflip is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 09:28 AM   #15
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by candyflip
A bit more specific perhaps? There are many variations.
Linux version 2.4.20-28.7
([email protected]) (gcc version 2.96 20000731 (Red Hat Linux 7.3 2.96-126))
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:05 AM   #16
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
not hacked , but you have a virus on the server that re-wrote your html files.

dont just delete them.

notify your host that they have been hacked and make them fix it.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:07 AM   #17
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
ps. dont let them try to convince you this was your fault ( unless its your own server then it is your fault kind of )
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:18 AM   #18
cfU
Confirmed User
 
Join Date: Jan 2003
Posts: 933
delete everything and throw your server away.
cfU is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:49 AM   #19
justsexxx
Too lazy to set a custom title
 
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
What host is it? And do you manage the box or is it managed?

Andre
__________________
Questions?

ICQ: 125184542
justsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:50 AM   #20
TheMob
Confirmed User
 
Join Date: Jan 2003
Location: 2006
Posts: 8,584
is it reall worth dealing with?
TheMob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 10:51 AM   #21
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
Quote:
Originally posted by SmokeyTheBear
not hacked , but you have a virus on the server that re-wrote your html files.

dont just delete them.

notify your host that they have been hacked and make them fix it.
not a virus on a linux server
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:24 AM   #22
Project-Shadow
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Posts: 7,340
Quote:
Originally posted by fris
not a virus on a linux server
http://math-www.uni-paderborn.de/~axel/bliss/
Project-Shadow is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:43 AM   #23
lb_vee
Confirmed User
 
Join Date: May 2004
Posts: 886
Here are a few things you can do to prevent this from happening again:

1) switch to ssh from telnet and kill the telnet daemon.

2) kill the ftp daemon and use scp (with ssh)

3) modify the hosts.allow files to allow access from only a few IPs (for ssh)
lb_vee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:47 AM   #24
inabon
Good Old Fat Webmaster
 
inabon's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Boquete, Panamá
Posts: 970
and check your file permissions it is pretty weird that they rewrote all your files.
somehow they gained ftp access with privileges
or your permissions or server are not safely configured.

i have only seen virus attack IIS not apache.
__________________
Whoever dies with most toys wins.
inabon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:49 AM   #25
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by inabon
and check your file permissions it is pretty weird that they rewrote all your files.
somehow they gained ftp access with privileges
or your permissions or server are not safely configured.

i have only seen virus attack IIS not apache.
Holy fuck i think i know what happend thanks all
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:54 AM   #26
jade_dragon
Confirmed User
 
Join Date: May 2004
Location: NEW ORLEANS/Baton Rouge BABY!
Posts: 1,737
If you were being hacked 9 times out of 10 your keys would be logged. And there is nothing a malicious hacker hates more than when you go running around talking about you got hacked. So in the future, get on another computer that is not infected or call someone and ask them to help or get help. Chatting with your friends or typing "Man I think I am being hacked" does nothing more than empower the person there watching you, they feed on fear and when they are found out, usually punish you by deleting files or using the info they have found about you.
__________________
even ADULTS need TOYS
icq: 3 6 3 2 6 6 6 7 | aim: conglomorateman
open for business, affiliates and friendships
jade_dragon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-11-2004, 11:59 AM   #27
Va2k
I’m still alive barley.
 
Va2k's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Va
Posts: 10,060
Quote:
Originally posted by jade_dragon
If you were being hacked 9 times out of 10 your keys would be logged. And there is nothing a malicious hacker hates more than when you go running around talking about you got hacked. So in the future, get on another computer that is not infected or call someone and ask them to help or get help. Chatting with your friends or typing "Man I think I am being hacked" does nothing more than empower the person there watching you, they feed on fear and when they are found out, usually punish you by deleting files or using the info they have found about you.
Damn never thought about it like that, but it wasn't me being hacked Think we fig it out a simple mistake. But my hosting company is top notch and I really was never scared only thing I was, was pissed thinking I had to re upload things over again..

Thanks everyone for your input and inabon



Tom
__________________
Va2k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.