![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
init.php ??? A Backdoor Files ????
Filename: wp-content/themes/init.php
File Type: Not a core, theme, or plugin file from wordpress.org. Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: de($x)));');$b374k("H4sIAAAAAAACA+z9eZ+jyLEwCv/vT1GuZ+6p7kNPg0ALTLvHB0ksEhJCgCTA9u0fO4hVbAJsf/cLaCmpqnoZj895n/c+d/xzF8olMjIyIjIiMzLzT3+OnfjhJ2qxGuML4S9PQWTkvvkli774 kWo8/e3h84OaJGr17tEsYz9KzOTxw8NjZiaB.... The infection type is: A backdoor known as 18aaaa. Should i push Deleted this files?, got Notice by wordfence but sometimes those mean not much ![]() Serious question here . Thanks
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed Fetishist
Industry Role:
Join Date: Mar 2005
Location: Fetishland
Posts: 11,521
|
i would reinstall the whole site, who knows which wp files did that init.php modify.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
So Fucking Banned
Industry Role:
Join Date: Aug 2013
Location: Princeton, New Jersey
Posts: 4,011
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | ||
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
Quote:
![]() SUCKS was getting good SE traffic with that site running WP-Script ![]() Starting fresh not so tempting ![]() Quote:
I only saw 5 post reply. Thanks for your replied. ![]()
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
That won't help. There is a breach somewhere. It can be a backdoor (99% of so-called nulled plugins and themes for WordPress have it). Or it can be a problem with server itself. E.g. Ubuntu OS - the system that can be hacked in a minute by even a monkey.
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
↑↑↑ Truth
So many WordPress thrmes & plugins are not secure. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
They have injected Mining Code to the site.
<div style="position:absolute;left:-4865px;top:-3595px;"> <a href="http://grainesdesol.fr/index.php?gnregr=lenovo-miix-2-8-factory-reset">grainesdesol.fr</a> </div> <div style="position:absolute; left:-5477px;top:-1560px;"> <a href="http://market4.ir/index.php?hnhjkl=can-you-make-money-selling-bitcoins">market4.ir</a> <a href="http://market4.ir/index.php?hnhjkl=cara-mining-bitcoin-di-android">earn on android</a> earn bitcoin on android 2017 <a href="http://market4.ir/index.php?hnhjkl=is-it-good-idea-to-invest-in-bitcoin">here</a> <a href="http://market4.ir/index.php?hnhjkl=bitcoin-conversion-calc">http://market4.ir</a> </div> <div style="position:absolute;left:-4865px;top:-3595px;"> <a href="http://grainesdesol.fr/index.php?gnregr=lenovo-miix-2-8-factory-reset">grainesdesol.fr</a> </div> <div style="position:absolute; left:-5477px;top:-1560px;"> <a href="http://market4.ir/index.php?hnhjkl=can-you-make-money-selling-bitcoins">market4.ir</a> <a href="http://market4.ir/index.php?hnhjkl=cara-mining-bitcoin-di-android">earn on android</a> earn bitcoin on android 2017 <a href="http://market4.ir/index.php?hnhjkl=is-it-good-idea-to-invest-in-bitcoin">here</a> <a href="http://market4.ir/index.php?hnhjkl=bitcoin-conversion-calc">http://market4.ir</a> But but but This happened While the Server WP-script was down 2x during the month for roughly a week each time. ![]() ![]() SO i wonder IF that WP-Script Server issue Could have made my site become WEAK by using his WEAK FREE Theme while license server down... IS over a week i got a bad feeling about it. WEIRDDDDDDDD
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
Let's do some business!
Industry Role:
Join Date: Sep 2004
Location: Austin, TX
Posts: 31,289
|
Quote:
There is a very common practice of "build and forget" in the affiliate marketing industry. Unfortunately with WordPress this is a disaster waiting to happen because there are so many vulnerabilities. The best way to prevent mass disaster is creating a proper environment as mentioned above and updating religiously. Even this does not guarantee victory. As the old saying goes "it is what it is." Take the best precautions you can, do the best maintenance you can and accept that things may/can go wrong. By the way, you can rebuild your site without losing the search engine traffic that you spoke of. We have done it for literally hundreds of sites. Rebuilding the site does not mean total failure. It simply means some good ol' elbow grease. ;-)
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Wanted: CCBill pay sites for sale |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
God Bless You
Industry Role:
Join Date: Aug 2014
Location: Glasgow, $cotland
Posts: 1,467
|
are u use a free theme or a nulled plugin?
__________________
magneto664 📧 gmail.com Adult Backlinks 💘Best Website Stats 💘 Best CDN for Adult Content My Fav: 👍Chaturbate 👍 Stripchat 👍 Dateprofits 👍 AdultFriendFinder |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
Quote:
So no dev to blame about it ![]()
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
WP-script WEAK free theme 2 week in the last month ( Not change by me BTW ) is like a magic shit going on with French Sebastien LMAO
![]() Nulled plug in are removed when wordfence gives a warning about it or a plug in let down. I only use plug in from respiratory if i have too.
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
God Bless You
Industry Role:
Join Date: Aug 2014
Location: Glasgow, $cotland
Posts: 1,467
|
Quote:
![]() shit work for a few hours
__________________
magneto664 📧 gmail.com Adult Backlinks 💘Best Website Stats 💘 Best CDN for Adult Content My Fav: 👍Chaturbate 👍 Stripchat 👍 Dateprofits 👍 AdultFriendFinder |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Quote:
Is their ecrypted code on that script? If so, it's likely that's your backdoor. This is why I never have any scripts that have encrypted code because you never know what the owners going to do with it and if there's a back door which there usually is because it needs to connect with the server and verify info to work. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Let's do some business!
Industry Role:
Join Date: Sep 2004
Location: Austin, TX
Posts: 31,289
|
Quote:
These exploits can remain dormant for months, even years. Then a particular event triggers them in action and boom.
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Wanted: CCBill pay sites for sale |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
#Alberta51
Industry Role:
Join Date: Oct 2014
Location: USA Territory (Alberta)
Posts: 7,882
|
I know if i would be a client of VACARES/ SLY they would have take over and fix all this already for me
![]() But unfortunetly for me im with King-Servers.com and will see what i can get from them done today or tomorrow ![]() Their very good to me usually, so will see whats up this weekend hopefuly. Shitty weekend ahead ![]()
__________________
Tube - Cam - Escorts - Top List Menu Tab - Banner - Header Link - Blog Post DM me ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |