Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-08-2005, 06:44 AM   #1
Gals4free
Confirmed User
 
Join Date: Apr 2003
Posts: 428
$100 reward to be won

Hey guys,

Allright, i posted my problem a few days ago without to much usefull feedback to get the problem solved. So since i need this solved, im offering $100 to anyone who can permanently solve my problem.

I run www.gals4free.net, and since about a week, when i click to see galleries i sometimes get www.mea-movies.com (NOTE: not the original mia-movies.com, but someone who is ripping that site). This is very odd, as:

1. I dont trade with that site
2. Its not gallery specific, as i checked this and got it even on my own galleries
3. its not some other trade trying to fuck me
4. its no spy/adware as i checked this from many different pc's by now.

I had the more common stuff ruled out, ATX got checked twice and its for sure not that. My bet is on comus, but with Tony in hospital and someone else checking, who said its not comus, i cant be 100%. Apache got checked, and so did htaccess.

So basicly, anyone who knows the permanent solution to this and it actually works, ill be more then happy to send $100.

ICQ me if you think you know : 59661018

Regards

Steve

Link to old topic incase you can pick up usefull info there : http://www.gofuckyourself.com/showthread.php?p=7518727
__________________
At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!
Gals4free is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 06:47 AM   #2
FunForOne
Confirmed User
 
Join Date: Nov 2003
Location: USA
Posts: 8,704
Only help I can give you is a bump
FunForOne is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 06:53 AM   #3
DamageX
Marketing & Strategy
 
DamageX's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: Former nomad
Posts: 14,293
Quote:
Originally Posted by FunForOne
Only help I can give you is a bump
I second that, for now.
__________________
Whitehat is for chumps

If you don't do it, somebody else will - true story!
DamageX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 06:55 AM   #4
xXxtreme2005
Confirmed User
 
Join Date: Feb 2005
Location: st louis/IL metro area
Posts: 717
strange but ill bump it for ya
__________________


GOT TRAFFIC?.......
I BUY TRAFFIC
ICQ 318-368-640
xXxtreme2005 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 07:32 AM   #5
ssp
Confirmed User
 
Join Date: Jan 2005
Location: United Kingdom
Posts: 7,990
Are you using a free tradescript? Could it be that the 1% of your traffic is sent to a website of the tradescript owner? Perhaps you clicked too much and excessive clicks get sent to that site. Hope this helps you.
ssp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 08:07 AM   #6
Gals4free
Confirmed User
 
Join Date: Apr 2003
Posts: 428
nope... clearly states in my first post i use ATX
__________________
At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!
Gals4free is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 09:29 AM   #7
klinton
So Fucking Banned
 
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
Quote:
Originally Posted by Gals4free
3. its not some other trade trying to fuck me
are you 100 % sure that none of your trades doesn't redirect to mia-movies in any way ?

anyway, bump for you.

Last edited by klinton; 06-08-2005 at 09:31 AM..
klinton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 09:31 AM   #8
brilsmurf
Confirmed User
 
Join Date: Feb 2005
Location: Belgium
Posts: 3,405
bump for you!
__________________
The Best Adult Web Hosting of 2008 - http://www.adulthosting.com
Affiliate Program – http://www.sxcash.com
brilsmurf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 10:58 AM   #9
nosey
Talk Hard
 
nosey's Avatar
 
Join Date: Feb 2003
Posts: 14,413
add mea-movies.com to your trade script & disable it
__________________

| Domain whois privacy Free || GFY favored Hosting |
$Chaturbate || FpcTraffic FPCPlugs || PlugRush Traffic

nosey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 11:08 AM   #10
boner 2.0
Too lazy to set a custom title
 
Join Date: Jul 2004
Posts: 10,970
Another bump... Very strange
__________________
boner 2.0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 11:53 AM   #11
Gals4free
Confirmed User
 
Join Date: Apr 2003
Posts: 428
Quote:
Originally Posted by boner 2.0
Another bump... Very strange
Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.
__________________
At Kodify we have in excess of 5M visitors a day through our network that consists of www.PornTube.com www.4Tube.com www.PornerBros.com and www.Fux.com. We operate a very successful Content Publishing Platform at http://content.porntube.com where you can expose your content to our audience!
Gals4free is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 12:05 PM   #12
nosey
Talk Hard
 
nosey's Avatar
 
Join Date: Feb 2003
Posts: 14,413
Quote:
Originally Posted by Gals4free
Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.
yeah its not atx...

clear cache & cookies,
click here > http://www.gals4free.net/ct/cx.php?i=000&s=100&t=1
second click redirects to mea-movies.com

re-install comus, script is corrupt
__________________

| Domain whois privacy Free || GFY favored Hosting |
$Chaturbate || FpcTraffic FPCPlugs || PlugRush Traffic

nosey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 12:08 PM   #13
wdsguy
Ryde or Die
 
Industry Role:
Join Date: Dec 2002
Location: California-Shanghai
Posts: 19,568
bump for ya
wdsguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 12:16 PM   #14
tranza
ICQ: 197-556-237
 
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
Damn, that's a tough one... I have no idea...
__________________
I'm just a newbie.
tranza is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-08-2005, 12:30 PM   #15
taibo
Confirmed User
 
Join Date: May 2005
Posts: 3,720
bump.. somebody in here should know
taibo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-10-2005, 03:37 AM   #16
sixzeros
Registered User
 
Join Date: Aug 2002
Location: Las Vegas
Posts: 53
Just took a look at Comus for you.

It looks like someone has stolen your FTP account and has placed their own code on the system, and have removed comus.

They've renamed the main cx.php to ctx.php and they are using zend encoded PHP scripts, so it is hard to see exactly what they have dumped on there, but we know at least it is a simple script of less than 1000 bytes long.

It would appear that they have also dumped a trojan on the machine, because they appear to be able to change files that neither comus nor your FTP account would naturally have the ability/permissions to change.

One way someone can test if they might be infected is to check the file size of /ct/cx.php if it less than 10k then you have a very suspect situation.

I suggest you move everything to a new server, and be very selective about what PHP files you copy over, best bet is to reinstall comus and your trade scripts clean, and then import the data and templates only.

I thought I posted earlier but it didnt seem to take, I suggested using commview, its a packet sniffer that lets you see what headers are being generated, so you can see exactly what is happening in your browser.. You would have been able to see that clicks were bouncing from index page -> cx.php -> ctx.php -> ATX .. and by comparing the path to a non-hacked site you'd see the different path and the culprit files. ctx.php should not be there.

I've never actually seen anyone do this before, its a first, but now that it has happened, I'll make something in Comus that will run an auto integrity check of the main files, it should make it impossible for anyone to do this again.

I feel for ya bro, F@$@#$'n hackers suck

-----------------
sixzeros - Comus Thumbs Author

Last edited by sixzeros; 06-10-2005 at 03:38 AM..
sixzeros is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-10-2005, 04:29 AM   #17
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
Well at least you know where to find the asswiper. Contact his host and shit.
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-10-2005, 04:30 AM   #18
brilsmurf
Confirmed User
 
Join Date: Feb 2005
Location: Belgium
Posts: 3,405
franck, you still need a transfer? i can do it now
__________________
The Best Adult Web Hosting of 2008 - http://www.adulthosting.com
Affiliate Program – http://www.sxcash.com
brilsmurf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.