GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   $100 reward to be won (https://gfy.com/showthread.php?t=478210)

Gals4free 06-08-2005 06:44 AM

$100 reward to be won
 
Hey guys,

Allright, i posted my problem a few days ago without to much usefull feedback to get the problem solved. So since i need this solved, im offering $100 to anyone who can permanently solve my problem.

I run www.gals4free.net, and since about a week, when i click to see galleries i sometimes get www.mea-movies.com (NOTE: not the original mia-movies.com, but someone who is ripping that site). This is very odd, as:

1. I dont trade with that site
2. Its not gallery specific, as i checked this and got it even on my own galleries
3. its not some other trade trying to fuck me
4. its no spy/adware as i checked this from many different pc's by now.

I had the more common stuff ruled out, ATX got checked twice and its for sure not that. My bet is on comus, but with Tony in hospital and someone else checking, who said its not comus, i cant be 100%. Apache got checked, and so did htaccess.

So basicly, anyone who knows the permanent solution to this and it actually works, ill be more then happy to send $100.

ICQ me if you think you know : 59661018

Regards

Steve

Link to old topic incase you can pick up usefull info there : http://www.gofuckyourself.com/showthread.php?p=7518727

FunForOne 06-08-2005 06:47 AM

Only help I can give you is a bump

DamageX 06-08-2005 06:53 AM

Quote:

Originally Posted by FunForOne
Only help I can give you is a bump

I second that, for now.

xXxtreme2005 06-08-2005 06:55 AM

strange but ill bump it for ya

ssp 06-08-2005 07:32 AM

Are you using a free tradescript? Could it be that the 1% of your traffic is sent to a website of the tradescript owner? Perhaps you clicked too much and excessive clicks get sent to that site. Hope this helps you.

Gals4free 06-08-2005 08:07 AM

nope... clearly states in my first post i use ATX :)

klinton 06-08-2005 09:29 AM

Quote:

Originally Posted by Gals4free
3. its not some other trade trying to fuck me

are you 100 % sure that none of your trades doesn't redirect to mia-movies in any way ?

anyway, bump for you.

brilsmurf 06-08-2005 09:31 AM

bump for you!

nosey 06-08-2005 10:58 AM

add mea-movies.com to your trade script & disable it

boner 2.0 06-08-2005 11:08 AM

Another bump... Very strange :helpme

Gals4free 06-08-2005 11:53 AM

Quote:

Originally Posted by boner 2.0
Another bump... Very strange :helpme

Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.

nosey 06-08-2005 12:05 PM

Quote:

Originally Posted by Gals4free
Wont stop it.. i was checking the ATX logs with ATX scripter today, and the hits that go to mea-movies are not going through ATX.. so im pretty sure its something on comus site, before they send the url to atx.

yeah its not atx...

clear cache & cookies,
click here > http://www.gals4free.net/ct/cx.php?i=000&s=100&t=1
second click redirects to mea-movies.com

re-install comus, script is corrupt

wdsguy 06-08-2005 12:08 PM

bump for ya

tranza 06-08-2005 12:16 PM

Damn, that's a tough one... I have no idea...

taibo 06-08-2005 12:30 PM

bump.. somebody in here should know

sixzeros 06-10-2005 03:37 AM

Just took a look at Comus for you.

It looks like someone has stolen your FTP account and has placed their own code on the system, and have removed comus.

They've renamed the main cx.php to ctx.php and they are using zend encoded PHP scripts, so it is hard to see exactly what they have dumped on there, but we know at least it is a simple script of less than 1000 bytes long.

It would appear that they have also dumped a trojan on the machine, because they appear to be able to change files that neither comus nor your FTP account would naturally have the ability/permissions to change.

One way someone can test if they might be infected is to check the file size of /ct/cx.php if it less than 10k then you have a very suspect situation.

I suggest you move everything to a new server, and be very selective about what PHP files you copy over, best bet is to reinstall comus and your trade scripts clean, and then import the data and templates only.

I thought I posted earlier but it didnt seem to take, I suggested using commview, its a packet sniffer that lets you see what headers are being generated, so you can see exactly what is happening in your browser.. You would have been able to see that clicks were bouncing from index page -> cx.php -> ctx.php -> ATX .. and by comparing the path to a non-hacked site you'd see the different path and the culprit files. ctx.php should not be there.

I've never actually seen anyone do this before, its a first, but now that it has happened, I'll make something in Comus that will run an auto integrity check of the main files, it should make it impossible for anyone to do this again.

I feel for ya bro, F@$@#$'n hackers suck

-----------------
sixzeros - Comus Thumbs Author

Dirty F 06-10-2005 04:29 AM

Well at least you know where to find the asswiper. Contact his host and shit.

brilsmurf 06-10-2005 04:30 AM

franck, you still need a transfer? i can do it now


All times are GMT -7. The time now is 12:52 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123