Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-11-2012, 04:32 PM   #1
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
1px iFrame randomly found in code on site.. anyone else experience this?

Hey guys

Found a 1px iframe with the following URL as the src randomly in the index file of one of our sites.. and code I'd put there earlier missing:

http://xzas.sytes.net/i/index.php

Anyone else experience this?
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:34 PM   #2
helterskelter808
So Fucking Banned
 
Industry Role:
Join Date: Sep 2010
Posts: 3,405
IIRC someone posted about that the other day. Sorry, can't remember who or what thread though.

Edit: and provided a code that apparently checks other pages for the same problem.

Last edited by helterskelter808; 01-11-2012 at 04:36 PM..
helterskelter808 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:35 PM   #3
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
I think SZYN posted about it.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:38 PM   #4
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Thanks. I'll search for the thread.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:39 PM   #5
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Quote:
Originally Posted by KlenTelaris View Post
I think SZYN posted about it.
Can't find anything by him, unless I suck at searching.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:42 PM   #6
TisMe
Confirmed User
 
Join Date: Aug 2008
Posts: 1,719
It was SZNY, here's the thread: https://gfy.com/showthread.php?t=1052856

Last edited by TisMe; 01-11-2012 at 04:44 PM..
TisMe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:46 PM   #7
PSD
PornSiteDomains.com
 
PSD's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: US
Posts: 1,265
Quote:
Originally Posted by TisMe View Post
It was SZNY, here's the thread: https://gfy.com/showthread.php?t=1052856
I get "threat detected" in that thread with avast and MS security essentials.
__________________
PornSiteDomains.com
PSD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:47 PM   #8
porno jew
Too lazy to set a custom title
 
Industry Role:
Join Date: Nov 2006
Posts: 10,166
Quote:
Originally Posted by TisMe View Post
It was SZNY, here's the thread: https://gfy.com/showthread.php?t=1052856
unable to open that thread. anyone else?
porno jew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:48 PM   #9
2MuchMark
Videochat Solutions
 
2MuchMark's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Canada
Posts: 48,711
How do you update your sites? I remember a virus of some kind being reporting in an FTP program that would add a little extra to every html or htm page on a site.
__________________

Custom Software | Server Management | Integration and Technology Solutions
https://www.2much.net
2MuchMark is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:54 PM   #10
helterskelter808
So Fucking Banned
 
Industry Role:
Join Date: Sep 2010
Posts: 3,405
Problems viewing, or warnings about, the thread may be due to the "anti-malware" code on the page triggering anti-virus.
helterskelter808 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 04:58 PM   #11
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Quote:
Originally Posted by ********** View Post
How do you update your sites? I remember a virus of some kind being reporting in an FTP program that would add a little extra to every html or htm page on a site.
via FileZilla
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:02 PM   #12
EroTechnology
Confirmed User
 
EroTechnology's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 117
Quote:
Originally Posted by ********** View Post
How do you update your sites? I remember a virus of some kind being reporting in an FTP program that would add a little extra to every html or htm page on a site.
Filezilla FTP client used to be vulnerable and was exploited heavily by hackers some years back. Possibly this you`re thinking of?
__________________

EroTechnology.com - Advertising Opportunities | Free Adult Hosting | Banner Exchange Network | Traffic Stats Analysis - soon!
Buy Adult Traffic & Advertising | Buy Low Cost Targeted Ads On Our Adult Free Hosts
[email protected]
EroTechnology is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:06 PM   #13
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Quote:
Originally Posted by EroTechnology View Post
Filezilla FTP client used to be vulnerable and was exploited heavily by hackers some years back. Possibly this you`re thinking of?
Oh great.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:08 PM   #14
LatinaCrazy
Confirmed User
 
LatinaCrazy's Avatar
 
Industry Role:
Join Date: Apr 2004
Location: South America
Posts: 323
Quote:
Originally Posted by JCK View Post
I get "threat detected" in that thread with avast and MS security essentials.
It is because of the php he has embedded in the tread... No worries
__________________


ICQ: 288-147-085 | Email: promolata [at] gmail.com
LatinaCrazy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:11 PM   #15
Caligari
Confirmed User
 
Industry Role:
Join Date: Oct 2009
Location: At The Mountains Of Madness
Posts: 5,414
i frame embeds a problem for a while now-
this might help-
http://mycodings.blogspot.com/2009/0...from-your.html
How to Remove Iframe virus?
Iframe tags will be written just below the body tag. Follow the steps to remove virus.
1. Login to your FTP & edit the file which you've got iframe tag.

2. Look for the iframe tag just below the Body or Head tag.

3. Remove the coding & overwrite the file.

4. Now right click the file and click properties/File attributes and make it to "444". So that no hackers have privilege to write the file with iframe code.

5. Once you've cleaned this, the other type of virus will slowly raise, that is it will search the files that are included on the index.php file (ie dbconnect.php, general.php, configure.php, common.php, functions.php, classes.php etc) and it will write a php coding at the top of the page where it will dynamically write the javascript code at the time of execution of the file in the web - browser. The script will redirect the page to gumblar.cn/rss?id=2

6. To remove these type of error carefully look into the above mentioned filename, you can easily find out the php coding at the top of the page. Just remove the coding and make sure it is write protected, so that the php coding wont be written.
__________________
ATTN Webmasters Cruel Bucks - LIVE Gonzo Does Not Pay
------------------------------------------------
Animal Rescue Click Here to Feed An Animal for Free
Caligari is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:17 PM   #16
SZNY
SZNY
 
SZNY's Avatar
 
Industry Role:
Join Date: May 2004
Location: Sexy Republic
Posts: 2,800
  1. Copy/paste the php code and save the file as php
  2. Upload it to the root of your site
  3. and run it like www.yourdomain.dom/filename.php

http://blog.insidecomp.com/?p=33#more-33
http://forum.nexoneu.com/NXEU.aspx?g=posts&m=3143118 (some background info)

Hope it helps
__________________
Telegram: sandroanthonio
SZNY is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 05:41 PM   #17
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Thanks guys. Our host tackled the issue pretty quickly.

I'll bump this in a day or so just in case anyone else gets it.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 06:09 PM   #18
bobby666
boots are my religion
 
bobby666's Avatar
 
Join Date: Nov 2005
Location: Heart of europe
Posts: 21,765
it's a "great" way to include toplists on your site to get invisible hits
__________________
bobby666 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 09:17 PM   #19
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Bump for others
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-11-2012, 09:31 PM   #20
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 77,047
you running arrow scripts?
__________________
TRUMP 2025 KEKAW!!! - The Laken Riley Act Is Law!
DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com
brassmonkey is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 01:34 PM   #21
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Quote:
Originally Posted by brassmonkey View Post
you running arrow scripts?
No I am not.

A popular tube script on this particular site. Haven't seen it on any others yet.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 01:53 PM   #22
CrazyWhiteMan
Confirmed User
 
Join Date: Nov 2005
Posts: 170
seems like you got hacked. same shit happen to me...

best bet is to format your server
CrazyWhiteMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 01:55 PM   #23
CurrentlySober
Too lazy to wipe my ass
 
CurrentlySober's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,548
i cant afford an iframe...
__________________


👁️ 👍️ 💩
CurrentlySober is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 02:00 PM   #24
MediaGuy
Confirmed User
 
MediaGuy's Avatar
 
Industry Role:
Join Date: Sep 2004
Location: Montrealquebecanada
Posts: 5,500
Yep I got that too. It's either an exploit at your host (I called GoDaddy support and told them about it - they cleaned it up in a minute and then told me to change wordpress passwords regularly; though it's been said GoDaddy had been having this problem on their end) or something on your local machine that uses a weakness in FTP clients to write itself in hashed form into your templates or files when you do an upload.

Apparently, after a clean up and regular password changes, it doesn't re-occur - which is what happened in my case...
__________________

YOU Are Industry News!
Press Releases: pr[at]payoutmag.com
Facebook: Payout Magazine! Facebook: MIKEB!
ICQ: 248843947
Skype: Mediaguy1
MediaGuy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 02:03 PM   #25
CyberHustler
Unregistered Abuser
 
Industry Role:
Join Date: Feb 2006
Posts: 25,419
It happens...
CyberHustler is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 09:24 PM   #26
Operator
So Fucking Banned
 
Industry Role:
Join Date: May 2009
Location: ΠπΠ
Posts: 2,419
Sure doesn't have to happen
Operator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-15-2012, 10:56 PM   #27
trevesty
Confirmed User
 
trevesty's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Midwest
Posts: 3,802
Quote:
Originally Posted by MediaGuy View Post
Yep I got that too. It's either an exploit at your host (I called GoDaddy support and told them about it - they cleaned it up in a minute and then told me to change wordpress passwords regularly; though it's been said GoDaddy had been having this problem on their end) or something on your local machine that uses a weakness in FTP clients to write itself in hashed form into your templates or files when you do an upload.

Apparently, after a clean up and regular password changes, it doesn't re-occur - which is what happened in my case...
It was FTP.

My A/V finally caught onto it just now and went nutso.
trevesty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.