![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
![]() Hi u all!
I'm having this issue at programs url. When I try to access to a promo tool, the link leads me to an URL that gives me access to admin page 'r57Shell'. This is a little weird! I get this URL from their NATs program. Anyone trying to access that tool will also see it and my try to cause some troubles i guess... ![]() I havent received any email confirming my subscription to their nats system. I have sent a support ticket warning them. Best regards
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
|
webair.com....
why am I not supprised...
__________________
Make a bank with Chaturbate - the best selling webcam program ![]() ![]() ![]() Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!! PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email: ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,585
|
That shell script gives root acess to your server :
http://www.nullamatix.com/find-r57-a...and-txt-files/ Do a rootkit scan and address this urgently ![]()
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
I guess someone needs to reinstall his server....
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
I have sent a support mail ...
i will try to talk with the owner here...
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Join Date: Jun 2007
Posts: 160
|
Quote:
__________________
dlXer - web design, developing, managed hosting, website optimizations |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Sep 2006
Posts: 43
|
looks like that NATS install is on a virtual plan?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Join Date: Oct 2002
Location: netherlands
Posts: 248
|
check your installed scripts for exploits and updates asap.
but probably there are more scripts like that on your server or their server if its a dedicated and you are the owner. turn on safe mode... or turn it on temp. before the get deeper |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
Its not mine.
I'm just an affiliated. I'm sent an email to the programs support, added the owner to ICQ and I have sent a message to him here in GFY... cant get in contact with him. How does NATs handels with password? I guess that is saved on a database and not encoded by md5 or something :S
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
The attacker was able to install that r57shell script. That does tell you one thing: the server has been compromised. It doesn't tell you how they got in, what they did or what level of access they eventually acquired.
Once you've determined that the server has been compromised, there is one thing you absolutely need to do: wipe and reinstall the server. While going through your logs, scanning for rootkits, auditing your scripts etc is recommended to find out more information about how they got in. Information you can use to prevent future compromises, but it does not change the fact that the server needs to be reinstalled. A system that has been compromised is a system that can no longer be trusted. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
The server is not mine.
I'm just a lousy webmaster that registered on the server's owner NATs program, and that the RSS links send me to the r57shell script... i'm afraid that my password may have been stolen..
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Oct 2002
Location: netherlands
Posts: 248
|
once you got a c99 or r57 shell on the box , you can get all data , logs , databases etc. everything on that box
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Nov 2009
Location: Heaven
Posts: 4,306
|
u r screwed
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
I'm going to warn that webair guy that uses GFY!...
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Feb 2002
Location: NYC, NY
Posts: 8,531
|
dick =)
![]() ------------------------ Looks like they got in via a vulnerable script. Thanks for the report MrGusMuller and for contacting me. I got my guys on it now.
__________________
![]() ~ Webair Dedicated Cloud Servers™ ~ WEBAIR VSYS™ Virtual Hosting Platform ~ Superior CDN Network ~ ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~ ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
I have warned the webair, and few minutes later the problem was corrected.
Now, to anyone who might me interested, the affiliated program was HYPEDOUGH.COM. I was able to read the wp-config.php and see the username/password for the database. ![]()
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Oct 2002
Location: netherlands
Posts: 248
|
it probably was wordpress which was exploited, last version had vulnerabilities
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,391
|
Usually it is a forum or a support form coded in 1998.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,585
|
or a pirated " nulled " script or addon in which the exploit was integrated and became active at the install .
As U-Bob stated, once a box is compromised , it is better to reinstall OS. Accounts could always be moved to another box, but must be clean of the shell script.
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | ||
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
Quote:
The wp-config.php that I have read had STRANGE embebed code! I'v warned webair guys 'cause no one from HYPE has said anything to me. Are they on vacations? Quote:
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: Nov 2009
Location: Heaven
Posts: 4,306
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |