Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-07-2005, 11:36 AM   #1
jpoker
Confirmed User
 
Join Date: Feb 2003
Location: Vancouver
Posts: 362
hacker alert

one of our MGPs just got hacked and was dishing out a trojan. I discovered an iframe in the HTML code that had this as the src:

"hahaha104;hahaha116;hahaha116;hahaha112;hahaha58; hahaha47;hahaha47;hahaha116;hahaha114;hahaha97;hah aha102;hahaha102;hahaha115;hahaha97;hahaha108;haha ha101;hahaha46;hahaha98;\
hahaha105;hahaha122;hahaha47;hahaha100;hahaha108;h ahaha47;hahaha97;hahaha100;hahaha118;hahaha52;haha ha52;hahaha49;hahaha46;hahaha112;hahaha104;hahaha1 12;"

I've just heard of this happening to a couple of other people as well so I suggest you check your sites to see if it has occured to you as well.

So far I have no idea how the code was actually inserted. We run autogallery sql 3.03 and tm3. The server otherwise looks clean from what the security guys can tell.

- jpoker
jpoker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 12:18 PM   #2
diggz
Registered User
 
Join Date: Apr 2005
Location: Sig Spot. Check.
Posts: 302
You are using a version of AGSQL with a security hole. I suggest you visit jmbsoft.com and PATCH!
diggz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 02:20 PM   #3
jpoker
Confirmed User
 
Join Date: Feb 2003
Location: Vancouver
Posts: 362
Thanks, I will look into that.
jpoker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 02:22 PM   #4
KyleHoppes
So Fucking Banned
 
Join Date: Sep 2005
Posts: 354
Quote:
Originally Posted by jpoker
one of our MGPs just got hacked and was dishing out a trojan. I discovered an iframe in the HTML code that had this as the src:

"hahaha104;hahaha116;hahaha116;hahaha112;hahaha58; hahaha47;hahaha47;hahaha116;hahaha114;hahaha97;hah aha102;hahaha102;hahaha115;hahaha97;hahaha108;haha ha101;hahaha46;hahaha98;\
hahaha105;hahaha122;hahaha47;hahaha100;hahaha108;h ahaha47;hahaha97;hahaha100;hahaha118;hahaha52;haha ha52;hahaha49;hahaha46;hahaha112;hahaha104;hahaha1 12;"

I've just heard of this happening to a couple of other people as well so I suggest you check your sites to see if it has occured to you as well.

So far I have no idea how the code was actually inserted. We run autogallery sql 3.03 and tm3. The server otherwise looks clean from what the security guys can tell.

- jpoker

Is your autogallery username and password "admin" ?
KyleHoppes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 02:42 PM   #5
Makingcoin
Confirmed User
 
Makingcoin's Avatar
 
Join Date: Aug 2002
Location: The Ditch
Posts: 8,919
Sorry to hear that bro, I will check out my sites now.
__________________

www.MAKINGCOIN.com

icq. 166-662-831
"Start making large coin!"


Daddy I Get Paid To Be A Whore - Coming Soon
Makingcoin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:12 PM   #6
jpoker
Confirmed User
 
Join Date: Feb 2003
Location: Vancouver
Posts: 362
Quote:
Originally Posted by KyleHoppes
Is your autogallery username and password "admin" ?
I've been known to do silly things, but I didn't leave the default password
as admin, though i did leave the username as 'admin' and that opens me up to brute force attacks i guess.
jpoker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:17 PM   #7
Fucksakes
Shit... Fuck! What the Hell?
 
Fucksakes's Avatar
 
Industry Role:
Join Date: Dec 2003
Posts: 7,567
my server been pretty fucking slow too
Fucksakes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:19 PM   #8
Fucksakes
Shit... Fuck! What the Hell?
 
Fucksakes's Avatar
 
Industry Role:
Join Date: Dec 2003
Posts: 7,567
may I ask where you are hosted?
Fucksakes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:22 PM   #9
High Quality
Confirmed User
 
Join Date: Feb 2002
Location: Vegas
Posts: 5,741
Ouch, that sounds no fun.
__________________

RecurCash.com - Averaging $38/sale with 60% revshare in the first 4 months alone!

Convert your TEEN traffic today @ better than 1:500 guaranteed. ICQ me: 18287590!
High Quality is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:22 PM   #10
Ace_luffy
www.creationcrew.com
 
Ace_luffy's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM CREATIONCREW.COM
Posts: 12,110
that's scares me
__________________


++ Adult and Mainstream Websites Designs | 10 banners for only $50 | html5 Banners ++
email : [email protected] Telegram : https://t.me/creationcrew | HTML5/Responsive Site - Div/CSS - ElevatedX - NATs - Wordpress

Ace_luffy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:24 PM   #11
phonesex
Confirmed User
 
Join Date: Mar 2005
Location: Phone Sex Pays! Believe it!
Posts: 3,437
Id call the hosting company fast
phonesex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:27 PM   #12
darksoul
Confirmed User
 
darksoul's Avatar
 
Join Date: Apr 2002
Location: /root/
Posts: 4,997
do you have any php scripts ?
those are usually the culprit.
__________________
1337 5y54|)m1n: 157717888
BM-2cUBw4B2fgiYAfjkE7JvWaJMiUXD96n9tN
Cambooth
darksoul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:33 PM   #13
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
that doesnt look like the full code..

traffsale.biz ?
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:38 PM   #14
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
looks like thats the domain registered a few days ago..


oh its that idiot..

http://traffsale.biz/dl/adv435.php
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:38 PM   #15
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
same guy that got sleazy and thehun
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:40 PM   #16
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
pretty sure this site has something to do with it ( affiliate / trade partner)

http://marta.sexmadams.net/?rev=variusmanx
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:42 PM   #17
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
http://traffsale.biz/dl/

theres the directory of the crapola
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-07-2005, 11:45 PM   #18
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
looks like a directory of ip's of infected users..

http://traffsale.biz/dl/ips/
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-08-2005, 01:32 PM   #19
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
looks like he changed a few things
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-08-2005, 01:49 PM   #20
ServerGenius
Confirmed User
 
Join Date: Feb 2002
Location: Amsterdam
Posts: 9,377
chkrootkit
__________________
| http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |
ServerGenius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-08-2005, 01:54 PM   #21
pornguy
Too lazy to set a custom title
 
pornguy's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,911
The good thing is, that this guy will continue to get away with this, because itis far more important to arrest pornographers than hackers.
__________________
PornGuy skype me pornguy_epic

AmateurDough The Hottes Shemales online!
TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME!
pornguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.