GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   HACKED: How to Remove ATX2 Tradescript Hack? 2nd click out goes to HACK. (https://gfy.com/showthread.php?t=1027418)

boneprone 06-21-2011 08:39 AM

HACKED: How to Remove ATX2 Tradescript Hack? 2nd click out goes to HACK.
 
People using ATX 2. This seems to be common among not just ATX but other trade scripts as well. There is a hack that a hacker puts into out.cgi in trade script that when the surfer clicks twice it goes to the hackers desired site..

Ive dealt with this before with old trade scripts and removed them without problem. Normally you can see a file installed that doesnt look right in the trade script folder.

This time its a little more complex.

What's strange is we've even changed out the versions of the script.

boneprone 06-21-2011 08:40 AM

and anyone know how they get in to do this in the first place?
I always run the latest version.

Are they getting in via an old version with a hole in php? Apache? OS??

Juicy D. Links 06-21-2011 08:47 AM

bump bump

Just Alex 06-21-2011 09:49 AM

Anal Probe is fucking with your script again?
Bustard. :2 cents:

cybermike 06-21-2011 09:52 AM

Lots of scripts getting hacked :\

GrouchyAdmin 06-21-2011 09:52 AM

http://i.imgur.com/Plq9Y.jpg

u-Bob 06-21-2011 09:52 AM

wipe the server and reinstall everything.

seeandsee 06-21-2011 10:03 AM

Quote:

Originally Posted by u-Bob (Post 18230348)
wipe the server and reinstall everything.

what he said if nothing helpes, who knows where is vulnerability on

Phoenix 06-21-2011 10:06 AM

wipe it if you cant block it

Qbert 06-21-2011 10:07 AM

If the peeps at Arrow Scripts don't have the answers on how to fix and prevent this problem than I'd be changing to a different trade script.

ThatOtherGuy - BANNED FOR LIFE 06-21-2011 10:16 AM

My only advice would be...

Stop using software that gets hacked and has no support to fix it:)

brassmonkey 06-21-2011 10:21 AM

have your host clean it. i had two sites hacked with arrow scripts :(

Agent 488 06-21-2011 10:21 AM

dynamite the server. start over.

KillerK 06-21-2011 10:50 AM

time for a new trade script

Klen 06-21-2011 11:30 AM

Quote:

Originally Posted by cybermike (Post 18230343)
Lots of scripts getting hacked :\

Not mine since i applied simple security trick :)

critical 06-21-2011 02:36 PM

You should host your box with Critical.net. We would, as your host, have tracked that down and locked down the box for you.

Just sayin' - Your host should be checking that out for you.

96ukssob 06-21-2011 02:38 PM

Quote:

Originally Posted by KlenTelaris (Post 18230618)
Not mine since i applied simple security trick :)

what is that?

rowan 06-21-2011 06:22 PM

Quote:

Originally Posted by Qbert (Post 18230384)
If the peeps at Arrow Scripts don't have the answers on how to fix and prevent this problem than I'd be changing to a different trade script.

I wouldn't be jumping up and down about ATX just yet. You don't know for sure whether the trade script itself is vulnerable, or the hacker is getting in some other way and simply using the trade script as a redirect point (which is common, since that's where all clicks go...)

MrBottomTooth 06-21-2011 07:50 PM

Ask Vince Russo or Anal Hobbitt.

Klen 06-22-2011 02:28 PM

Quote:

Originally Posted by bossku69 (Post 18231166)
what is that?

You simply need to disable tmp folder to execute.


All times are GMT -7. The time now is 11:05 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123