![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 | |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
*** IMPORTANT: New worm or wtf?! ***
I've received this e-mail today. I've analyzed the directory where that html document was located (Google Blog from Blogger, hosted on my site) and tried to remove files, but I was unable. Looks like this worm files (or whatever it is?!) have root ownership. I'm not accusing Blogger (Google), because it looks like my Apache server is infected. I was only able to rename the directory...
What do you think I should do now, except to report this to the root of the server? Quote:
__________________
--- Busy ranking websites on Google... ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Aug 2002
Location: Toro'no
Posts: 1,887
|
Owned.
![]()
__________________
ICQ: 61689996 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
Looks like this is the truth... This html is sending you to that banking site and using their security flow in url, to redirect to god-knows-whose location and to grab visitor's user:pass for their banking accounts... root is already contacted...
I'm still unable to find out which mechanism they used to inject that worm. Was that Blogger's bug or my server's Apache is exploitable?
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
probably it is up to blogger...
![]()
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
bump for the cause...
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Feb 2003
Location: Closer now
Posts: 4,321
|
another *bump*
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Jul 2005
Posts: 7,865
|
bump for other poster's info
__________________
Increase your sales. Up to $4 per click. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jul 2005
Posts: 9,640
|
sorry to hear that nettrust, fucked up times really happens.
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
ouch that sucks.. seems strange its in that directory
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
let them know thi sserver was compromised in the same fashion
http://www.stack.nl/~stefanvz/blog/i..._login-submit/
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
notice the directory there
stack.nl/~stefanvz/blog/images/secure/cgi.paypal.com/osCommerce/pub/webscr/cmd/_login-submit/
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
hmm interesting...anyone have an idea what this could be ?
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
i think blogger has some major problems! where should i report this so guys from google can know?
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
any idea what should this be?
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Registered User
Join Date: Feb 2005
Location: Banned
Posts: 1,025
|
i had something like this shit when i downloaded crack for Cofee tycoon :D
if i correctly understood the problem... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
noone has access ftp access to my root directory. blogger has it's own ftp account on my host (it's hosted there). apparently it is up to blogger... ?! have no idea at all...
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Biz Dev and SEO
Industry Role:
Join Date: Jun 2005
Posts: 15,180
|
i've sent a reply to that company (refer to post #1). they almost shut down the server where's my domain hosted. but once i have replied to them, everything is ok now... still cannot figure out what has happened here... any opinion?
__________________
--- Busy ranking websites on Google... ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |