![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
![]() Every 3 days or so my website [possible virus link removed] will have some new encrypted code embeded to the top of the page causing lots of shit to go down.
Anyone have any info on any wordpress flaws? Or what this could be? To remove it I have to litteraly delete every file on the server and reupload or it wont go away. This is getting annoying. Thanks
__________________
ICQ: 619221 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Join Date: Nov 2002
Location: Glasgow, Scotland
Posts: 67,795
|
That's gay...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
8.8.8.8
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
|
yeah, how gay is that....
just playing ![]()
__________________
TAEMDLRMSKRJIXMRLSMRJ. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Serioulsy, how the fuck does this keep happening.
__________________
ICQ: 619221 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
So Fucking Banned
Industry Role:
Join Date: Feb 2006
Posts: 25,214
|
gotta switch up your paswwords or something
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Jul 2006
Location: Canada
Posts: 3,143
|
![]() Perhaps I can help you out... Please ICQ me at: 397994057
Later,
__________________
sig too big |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
The Dirty Frenchman
Industry Role:
Join Date: Nov 2005
Location: Lost Angeles
Posts: 8,904
|
that's very gay, some would say... homosexually gay.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Too lazy to set a custom title
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
|
What's your host? Better ask them no?
__________________
Questions? ICQ: 125184542 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Oct 2002
Location: Southcoast, Mass.
Posts: 1,521
|
What other scripts are on the server? Does the host have everything updated? Is telnet open?
__________________
Make bank by giving your surfers free pics every day and it costs you NOTHING! Use POTD Sponsors to find adult sponsors in more than 75 niches who offer a POTD feature! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Dec 2002
Location: Vancouver
Posts: 2,794
|
Using latest Wordpress version?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
whats that crap virus again everyone had some months ago
it added some code on top, many sites got hit with it
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Nov 2004
Posts: 2,779
|
NICE FUCKING TROJAN VIRUS ON THAT PAGE!!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Jul 2006
Location: los angeles
Posts: 825
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
Quote:
thats OLD at least 4-5 months lemme search
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Shit... Fuck! What the Hell?
Industry Role:
Join Date: Dec 2003
Posts: 7,567
|
glad i did my research on hosts before making my switch.. weblair has alot of bad things said about them here.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
damn what was it - wasnt it a local pc virus that attaches itself to any webpage if you FTP it? someone help
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Guest
Posts: n/a
|
It's not uniqcount.net is it? I keep getting hit by them
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
it was some VB virus that attached when uploading pages - ask Webair they should know for sure
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
here you go
its Win32:trojano-p also known as Win32/Anserin!generic.
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
Quote:
![]()
__________________
The Best Affiliate Software, Ever. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Confirmed User
Industry Role:
Join Date: Mar 2002
Location: Montreal
Posts: 2,710
|
Quote:
Here's a little suggestion to see what is running in the background: I'm pressuming this malicious script is being called by a cron job so log in by ssh with your root password and type in crontab -l See what is running in the background, if there is nothing then it's time to call in a security expert and have the whole box scanned.
__________________
Social profile assassination for hire |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Industry Role:
Join Date: Jan 2004
Location: Wisconsin
Posts: 4,517
|
Are you running an older version of AW Stats?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
I like Dutch Girls
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
|
Quote:
__________________
![]() ICQ 16 91 547 - SKYPE dutchteencash bob AT dutchteencash DOT com ... did you see our newest Sweet Natural Girl Priscilla (18)? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
Confirmed User
Industry Role:
Join Date: Mar 2002
Location: Montreal
Posts: 2,710
|
Quote:
__________________
Social profile assassination for hire |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Join Date: Oct 2002
Location: Southcoast, Mass.
Posts: 1,521
|
If you don't know how, ask your host to read Apache logs to see what was compromised and how.
Then, change hosts to someone who will actually help you.
__________________
Make bank by giving your surfers free pics every day and it costs you NOTHING! Use POTD Sponsors to find adult sponsors in more than 75 niches who offer a POTD feature! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
Secondly I have asked webair for help, honestly about 5 times with the same reply of "nothing we can do, its all on you, make sure your wordpress is uptodate."
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 | |
HOMICIDAL TROLL KILLER
Industry Role:
Join Date: Dec 2004
Location: Sunnybrook Institution for the Criminally Insane
Posts: 20,419
|
Quote:
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
I love to racism, bro!
Industry Role:
Join Date: Oct 2002
Location: USA! USA! USA!
Posts: 22,823
|
Quote:
__________________
Unvaxxed, still alive. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 | |
Guest
Posts: n/a
|
Quote:
![]() |
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Confirmed User
Join Date: Sep 2003
Posts: 509
|
To be fair, it's not really the hosts fault you got hacked unless it was done through a hole in the OS/Kernel.
I would argue it's the customers responsibility to ensure any scripts on their sites are up to date, as would many hosting companies both adult and mainstream. Certainly there are hosts who will take care of things like that but for the price point many adult webmasters are looking for it's simply not realistic to expect your host to keep your scripts up to date for you unless you are paying a premium. Having said that, once something has been exploited it's my opinion that it's the host's responsibility to find the cause of the problem and correct it if you are unable to do so on your own. There's a plethora of tools and methods out there to combat these exploits as well as remove them from your server. Any host who values their clients, as well as the integrity of their client's sites should do whatever they can to assist you in getting the issue resolved. If they refuse, there are hosting companies out there who would be happy to take care of you. There are many things the average webmaster can do to make sure things like this are unlikely to happen. Scripts are not Ronco Rotisseries. You can't just "set it and forget it" with a script. Many popular scripts have older versions with giant-gaping-goatse-like holes in them that do not exist in current versions. You should check weekly (At the very least monthly) for updates to your scripts, and if there are updates update them immediately |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
Confirmed User
Industry Role:
Join Date: Nov 2004
Posts: 2,779
|
YOUR PAGE IS INFECTING EVERYONE WHO VISITS IT WITH THE VIRUS!!
BE RESPONSIBLE AND STOP DIRECTING PEOPLE TO YOUR PAGE!@! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: Porn Valley
Posts: 8,151
|
THis shit is going around.. I have been hit by this bullshit also every few days now it seems. I took a look at sherms site and mine and we are not running ANY similar scripts...
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Confirmed User
Industry Role:
Join Date: Nov 2004
Posts: 2,779
|
NAME: Exploit.HTML.Mht
ALIAS: MS04-025, CAN-2004-0549, HTML/MHT@EXPL, Mht Summary An exploit is a short code or script that uses a vulnerability to perform malicious actions. The HTML.Mht exploit is embedded to HTML web pages. It attempts to download and install a malicious program on your computer by using a security vulnerability in Internet Explorer. More information about this security vulnerability, including a fix, is available from Microsoft: http://www.microsoft.com/technet/sec.../MS04-025.mspx ================================================== === |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 | |
President of Canada
Join Date: Sep 2003
Location: Leaving Hell, Entering Limbo
Posts: 23,141
|
Quote:
Remember who else did something like this? ... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
Hosts that wont help in this situation really piss me off, its obvious the guy doesnt know what the problem is , and he will just leave if he cant get it fixed so its hardly not worth it to the host to quicly tell them what the problem is , if the customer INSISTS on running something unsecure , thats a diff story but if they are just clueless it seems a no-brainer to help them out for the 10 minutes it might take to fix the problem for a tech
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 |
Too lazy to set a custom title
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
|
do you have any counter on your page?
__________________
Do you need cheap, fast and reliable porn website hosting? Host Head is the way to go!! Asian Gay Special | Live on MSN - Live Webcam Chat | Live Adult Webcam Performances | MY SWEET BLACKS LIVE ON CAM Pukka Tranny | Tattooed Shemales | She's A He | Menu Porno | Porn Performances | All Chubby MY ICQ# 169833797 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 | |
Confirmed User
Industry Role:
Join Date: Nov 2004
Posts: 2,779
|
Quote:
no i dont? who the fuck is this guy? my fucking computer has this shit now! ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 | |
Outside looking in.
Industry Role:
Join Date: Feb 2005
Location: To Hell You Ride
Posts: 14,243
|
Quote:
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
Again I would like to share that there is NOTHING ELSE aside from the most up to date verison of wordpress running. Thats it. My system has been scanned, re scanned, cleaned, anything to make sure nothing was on my end, I am clean. So where do I go now? Or.... Who takes the next step?
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 |
Confirmed User
Join Date: Feb 2005
Location: Money Land
Posts: 1,370
|
well , a good idea is to have a new password setup .. huge one .. about 12+
with numbers and Letters + have your host put in a firewall for you.. so only your ip can ssh or ftp to your server and if this dosn't work .. have someone check all your scripts also .. have your own system at home or the office checkes for spyware.. just incase good luck |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |