| 
		
			
			
				
			
			
				 
			
			
				
			
		 | 
		
			
			
				 
			
				
			
		 | 
	||||
| 
				Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.  You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us.  | 
		
		 
		![]()  | 
	
		
			
  | 	
	
	
		
		|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
| 
		 | 
	Thread Tools | 
| 
			
			 | 
		#1 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: May 2005 
				Location: EU - Czech republic 
				
				
					Posts: 3,025
				 
				
				
				
				 | 
	
	
	
	
		
			
			 
				
				Free Wordpress EXPLOIT remove utility here
			 
			Well my wordpress blogs were infected by some sort of exploit that allows hacker write files to my server and redirect traffic. It's really recommend to check your server for this shit+ upgrade to WP 2.51 asp! Here is handy tool I made to detect infected files + mysql database rows and remove this shit. 
		
	
		
		
		
		
		
	
	1) download tool here: http://64.15.156.39/remove_exploit.zip 2) download remove_exploit.zip -> unzip -> upload to your server 3) edit remove_exploit.php configuration part 4) login to your server via ssh 5) chdir to location where remove_exploit.php is located 5) run the tool: php remove_exploit.php notice: you must be logged as user who has rights to the files ('root' will work for sure) WARNING: USE THIS TOOL ON YOUR OWN RISK ![]()  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#2 | 
| 
			
			
			
			 i have man boobies 
			
		
			
				
			
			
			Join Date: Jul 2003 
				Location: van down by the river 
				
				
					Posts: 13,082
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Liar!!!!!!!!!!!!! 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	333-765-551  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#3 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Industry Role:  
				Join Date: Nov 2001 
				Location: NYC 
				
				
					Posts: 3,927
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Rrrrrrrrrrrrrrrrriiiiiiight........ 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#4 | |
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2008 
				
				
				
					Posts: 224
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#5 | 
| 
			
			
			
			 i have man boobies 
			
		
			
				
			
			
			Join Date: Jul 2003 
				Location: van down by the river 
				
				
					Posts: 13,082
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 that link is broken, try this one instead 
		
	
		
		
		
		
			correct link 
				__________________ 
		
		
		
		
	
	333-765-551  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#6 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: May 2005 
				Location: EU - Czech republic 
				
				
					Posts: 3,025
				 
				
				
				
				 | 
	
	|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#7 | |
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2008 
				
				
				
					Posts: 224
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	![]()  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#8 | |
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: May 2005 
				Location: EU - Czech republic 
				
				
					Posts: 3,025
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 for 110% paranoids is tool here: 
		
	
		
		
		
		
		
	
	Quote: 
	
  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#9 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: May 2005 
				Location: EU - Czech republic 
				
				
					Posts: 3,025
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Exploit described here: http://wordpress.org/support/topic/169246 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#10 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Join Date: Feb 2008 
				
				
				
					Posts: 137
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Great tool, running it now, thanks ilbb 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#11 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Industry Role:  
				Join Date: May 2005 
				Location: EU - Czech republic 
				
				
					Posts: 3,025
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 If you are not sure about the script, you can remove 'unlink' commands to be 100% safe. Tool will then report if infected files were found. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#12 | 
| 
			
			
			
			 there's no $$$ in porn 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jul 2005 
				Location: icq: 195./568.-230 (btw: not getting offline msgs) 
				
				
					Posts: 33,063
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 well intended but pretty useless. If your box has been compromised there's only 1 thing to do: wipe and reinstall. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#13 | 
| 
			
			
			
			 Confirmed User 
			
		
			
			
			Industry Role:  
				Join Date: Dec 2004 
				Location: Denver 
				
				
					Posts: 6,559
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 hackers suck 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	![]()  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#14 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Industry Role:  
				Join Date: Feb 2006 
				
				
				
					Posts: 22,511
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 anyone have a better solution? 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#15 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Nice catch. 
		
	
		
		
		
		
		
	
	Do you have any idea how you caught it ?  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#16 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 And by caught it I mean, how you came to be infected. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#17 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Industry Role:  
				Join Date: Feb 2006 
				
				
				
					Posts: 22,511
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 trying to find out. was using the latest version of wp - when outdated versions were thought to be the culprit. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#18 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Industry Role:  
				Join Date: Feb 2006 
				
				
				
					Posts: 22,511
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 it's only on one of my smaller virtual hosts - so that may be the problem. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#19 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 The big concern is if wp is inherently vulnerable, through some mysql injection or xss issue maybe. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#20 | 
| 
			
			
			
			 best designer on GFY 
			
		
			
				
			
			
			Join Date: Mar 2003 
				Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384 
				
				
					Posts: 30,307
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Yeah... 
		
	
		
		
		
		
			Upgrade your current version with the newest one. 
				__________________ 
		
		
		
		
	
	![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 |  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#21 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Industry Role:  
				Join Date: Feb 2006 
				
				
				
					Posts: 22,511
				 
				
				
				
				 | 
	
	|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#22 | 
| 
			
			
			
			 Registered User 
			
		
			
			
			Industry Role:  
				Join Date: Feb 2006 
				
				
				
					Posts: 22,511
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 disabling plugins seems to work ... on some of my blogs anyway. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#23 | |
| 
			
			
			
			 So fuckin' bored 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jun 2003 
				
				
				
					Posts: 32,386
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 
				__________________ 
		
		
		
		
	
	Obey the Cowgod  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#24 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 I've spent hours poring over this matter, and I have to my satisfaction resolved that  
		
	
		
		
		
		
		
	
	1. The point of infection is template/widget installation. 2. The version number has no bearing. You can get it just as well on 251. 3. It's not an inherent flaw in the wp php/mysql code.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#25 | 
| 
			
			
			
			 So fuckin' bored 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jun 2003 
				
				
				
					Posts: 32,386
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Did you find out how exactly they are using this vulnerability? It's very important to know in order to make an universal protection algorithm. 
		
	
		
		
		
		
			
				__________________ 
		
		
		
		
	
	Obey the Cowgod  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#26 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 It's not really a vulnerability per se. 
		
	
		
		
		
		
		
	
	Upon installing a new template, you grant code in there same rights as the wp package. An infected template then alters the p_footer() hook, wp_head() hook or both, ads some entries in a bogus wp_options entrace in the options table, and voila. You're infected. Moral is, never install code you haven't read. Don't be shy to crack "protected" stuff, especially if it's widgets, templates and the like.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#27 | |
| 
			
			
			
			 So fuckin' bored 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jun 2003 
				
				
				
					Posts: 32,386
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 
				__________________ 
		
		
		
		
	
	Obey the Cowgod  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#28 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Actually, what I say is, encrypted code should never be run. Decrypt, read, consider, install. DRCI. 
		
	
		
		
		
		
		
	
	If you don't know how to crack your wp template, I've just explained it in my blog.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#29 | |
| 
			
			
			
			 So fuckin' bored 
			
		
			
				
			
			
			Industry Role:  
				Join Date: Jun 2003 
				
				
				
					Posts: 32,386
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Quote: 
	
 ![]() 
				__________________ 
		
		
		
		
	
	Obey the Cowgod  | 
|
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#30 | 
| 
			
			
			
			 So Fucking Banned 
			
		
			
			
			Join Date: May 2006 
				
				
				
					Posts: 2,187
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 Which reasoning explains why blackhat seo or nigerian scams don't exist.  
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#31 | 
| 
			
			
			
			 Confirmed User 
			
		
			
				
			
			
			Join Date: Jan 2006 
				Location: Gringo in Puerto Rico 
				
				
					Posts: 4,204
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		 im 100% against any themes that contain encrypted elements. 
		
	
		
		
		
		
		
	
	 | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 | 
| 
			
			 | 
		#32 | 
| 
			
			
			
			 ICQ: 197-556-237 
			
		
			
			
			Join Date: Jun 2003 
				Location: BRASIL !!! 
				
				
					Posts: 57,559
				 
				
				
				
				 | 
	
	
	
	
		
		
		
		
		
	
		
		
		
		
			 
				__________________ 
		
		
		
		
	
	I'm just a newbie.  | 
| 
		 | 
	
	
	
		
                 
		
		
		
		
		
		
		
			
			
		
	 |