![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
SZNY
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,799
|
Better check your JS and PHP files [new malware injects]
Just wanted to share this with you as it might affect your traffic. Funny thing is that Google doesn't report it yet as badware.
There is a new kind of JS malware virus that injects code to make 1pixel iframes and connects to certain sites. I just scanned 150 domains and some of my WP installs where infected. Here is a link from a German coder offering a workable solution. Copy the code in a php file and upload it to the root of your server. Once done type www.xxxx.xx/filename.php to start scanning your files. It also disinfects your code. Here the links: http://forum.nexoneu.com/NXEU.aspx?g=posts&m=3143118 http://blog.insidecomp.com/?p=33#more-33 PHP Code:
__________________
Telegram: sandroanthonio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
emperor of my world
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
|
how will this virus affect your server? Will this cause load issues and eventually a mysql crash?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
SZNY
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,799
|
Well it will cause extra load on your server (makes more connections) plus your sites are flagged as Malware by various AV software apps
__________________
Telegram: sandroanthonio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a custom title
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,912
|
this is hitting Blogs or over all sites in general?
Can you find it by looking at the code of the index or is it hidden?
__________________
PornGuy skype me pornguy_epic AmateurDough The Hottes Shemales online! TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
SZNY
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,799
|
Doesn't matter, all sites that are using JS files
__________________
Telegram: sandroanthonio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,912
|
OK thanks
Damn.. More work.
__________________
PornGuy skype me pornguy_epic AmateurDough The Hottes Shemales online! TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Thanks, I'll add that signature to our scanner. I'll actually be interpreting and reducing the signature to catch other variations if the same thing. The posted code is awefully specific.
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jan 2006
Location: Pt
Posts: 1,673
|
Thanks for the heads up
![]() All check and clean |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Making PHP work
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,227
|
Cleaning up your files is good but that doesn't fix the problem.
How did that get into your site to begin with is the question.
__________________
Make Money with Porn |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
SZNY
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,799
|
Quote:
All is pretty closed now. Took me some time but all is cleaned and hope it can help others.
__________________
Telegram: sandroanthonio |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,391
|
crazy h4x0r5
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Horsing Around
Industry Role:
Join Date: Sep 2002
Location: AU
Posts: 5,861
|
Thanks for this, will have to check mine out.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Jul 2001
Location: 127.0.0.1
Posts: 9,266
|
the cleaning code itself makes my antivirus goes bananas
__________________
This post is endorsed by CIA, KGB, MI6, the Mafia, Illuminati, Kim Jong Il, Worldwide Ninjas Association, Klingon Empire and lolcats. Don't mess around with it, just accept it and embrace the truth |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Registered User
Industry Role:
Join Date: Mar 2011
Location: Austria
Posts: 20
|
thanks for the code, i will check my domains too.
__________________
![]() Saboom.com - interactive porn monetization solution for a free porn internet |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Dec 2002
Posts: 459
|
If you don't think you're vulnerable read about my nightmare below. It's quite embarrassing. I don't post much. No one wants to write a story like this, hopefully it helps someone.
I was hit Thanksgiving day of last year. 12 years running adult sites and never a problem. In my case, the permissions on 1 php file within openx were wide open. Permissions don't sync across servers and malware was injected on my splash redirecting to a Russian site. Multiple shells were installed and if you have ever seen your backend/library via a shell with Russian headers and tags, it's the scariest thing ever. Quite elegant too, all your folders and files are color coded, everything wide open. The second scariest thing is looking at the code injected on to the page itself. In my case the code was 7 or 8 strange characters, you can't even see the redirect buried at the very bottom of the page. The page is straight HTML, a simple warning page. Super clean. The characters look like the innocent copyright tags. That code referenced scripts buried far in my file structure. Ad Words suspended, Banned from Google. Cybercat pulling me, TJ yanked me. Kenny emailing me, Paperstreet emailing me. Pornhub video b gone. Exo paused. NIGHTMARE! That was my Thanksgiving. The good part is it didn't last long. Once clean I resubmitted to google and within 5 seconds I was approved and it was like nothing ever happened. All references to us distributing malware within google search vanished. What saved us was clonebox and Ray, having a great host and my man Konrad. The very early symptoms won't be apparent. First extremely vague warnings from Avast, then AVG then it gets wide out and the messages start rolling in from customers and partners. The nightmare really starts once you get banned from google. All paid SEO Gone, all organic SEO replaced with malware warnings. Multiple servers on lockdown, thousands of folders each with perfect permissons set and yet 1 file wide open. Looking back it's probably best it happened because other measures are now in place to ensure that never happens again. Check your permissions and and at the very least, get a script installed that alerts you to any changes on your boxes. Having a firewall on your FTP/SSH isn't enough. These new malware injections are pretty clever. Rather embarrassing, I had to learn the hard way. Hopefully you won't have to. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |