![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#51 | |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: Porn Valley
Posts: 8,151
|
For those in the know who might have some ideas since I have seen this shit on at least a half dozen sites that are all running diff configs and scripts, here is the coding that seems to get attached to parts of the page..
Quote:
![]() ![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#52 | |
Confirmed User
Industry Role:
Join Date: Nov 2004
Posts: 2,779
|
Quote:
he said his page was getting hacked he didnt fucking say there is a virus on his page that will spread to other users that visit his page ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#53 |
Show Yer Tits!
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
|
The script kiddies creating this shit should be hunted down and killed.
__________________
![]() Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#54 | |
Confirmed User
Industry Role:
Join Date: Sep 2006
Posts: 2,921
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#55 | |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: Porn Valley
Posts: 8,151
|
Quote:
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#56 |
Confirmed User
Industry Role:
Join Date: Oct 2004
Location: Cancun, Mexico
Posts: 5,883
|
these virus things scare me....
![]()
__________________
Affordable video and picture editing. junior[at]jampackproductions[DOT]com ICQ: 605429331 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#57 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#58 |
Confirmed User
Join Date: Oct 2004
Location: Boston, MA
Posts: 1,723
|
this has happened to a couple customers of ours.
the first issue was that the customer had WordPress installed and was using some 3rd party template or counter which was inserting a javascript trojan downloader in to the page on the fly. once the customer removed the template/counter, the issue went away. the second issue was permissions. the customer had some script running with a file owned by apache.apache and 777. once we changed the permissions the javascript trojan went away, and the iframe insertion to uniqcontent went away as well. contact me if you have any other questions.
__________________
![]() ICQ# 273099174 - monthly specials - 2 Month Free Credit on All Plans - 100% Referrals - chris@ for details Virtual from $14.95/month, Dedicated from $149.95/month Dual-Core Xeon > 1000GB @ $149.95 | 1500GB @ $169.95 | 10Mbps @ $269.95 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#59 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#60 | |
Confirmed User
Join Date: Oct 2004
Location: Boston, MA
Posts: 1,723
|
Quote:
from what you pasted above for the code, it definitely sounds like wrong permissions on some of your files. for wordpress i believe it should be: Folders => 755 Files => 644
__________________
![]() ICQ# 273099174 - monthly specials - 2 Month Free Credit on All Plans - 100% Referrals - chris@ for details Virtual from $14.95/month, Dedicated from $149.95/month Dual-Core Xeon > 1000GB @ $149.95 | 1500GB @ $169.95 | 10Mbps @ $269.95 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#61 |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
get a decent host, if everything is tight on the server, your sites shouldn't get owned even with security bugs in any scripts you may use....
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#62 |
Confirmed User
Join Date: Dec 2004
Posts: 3,891
|
bump for this
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#63 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
It doesn't really matter if that file is 777 (some scripts really need that) most php writes that are not run through cgi. The problem is with the script that allows an attacker to execute/upload on your server. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#64 |
Confirmed User
Join Date: May 2006
Posts: 2,640
|
try what we called antivirus
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#65 | |
Too lazy to set a custom title
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
|
Quote:
![]()
__________________
Questions? ICQ: 125184542 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#66 |
Dialer Kingpin
Join Date: Jun 2003
Location: New York
Posts: 10,816
|
Wow, that's nasty.
I cant believe webair wasent more helpfull. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#67 |
Confirmed User
Join Date: Dec 2001
Location: Tampa, FL
Posts: 3,420
|
I'm having the same problem and have contacted Webair about it twice now. they are 'looking' into it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#68 |
Outside looking in.
Industry Role:
Join Date: Feb 2005
Location: To Hell You Ride
Posts: 14,243
|
Where is webair in this thread to try and help out their customer? They seem to manage to make it to every thread that is looking for hosting but not this one?
![]()
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#69 | |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#70 |
Confirmed User
Join Date: Feb 2003
Location: Getting messy...
Posts: 763
|
keep us posted...
__________________
![]() Splosh Cash Wet and Messy Fetish Program I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#71 |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Not much you can do about it, looks like the virtual hosting box is compromised and this is likely happening to everyones pages on the box.
It probably searches for any web content and adds that into every file. :/ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#72 |
Adult Content Provider
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
|
I have the same problem with my sites on webair, trojan javascript at the top of the page just pops out of nowhere...
WEBAIR SOLVE. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#74 | |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Quote:
Thank You.
__________________
ICQ: 619221 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#75 |
Too lazy to set a custom title
Join Date: Apr 2006
Location: pink adult dreams
Posts: 13,557
|
Ask your hosting.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#76 |
Outside looking in.
Industry Role:
Join Date: Feb 2005
Location: To Hell You Ride
Posts: 14,243
|
did u get it fixed?
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#77 | |
Confirmed User
Join Date: Oct 2004
Location: Boston, MA
Posts: 1,723
|
Quote:
__________________
![]() ICQ# 273099174 - monthly specials - 2 Month Free Credit on All Plans - 100% Referrals - chris@ for details Virtual from $14.95/month, Dedicated from $149.95/month Dual-Core Xeon > 1000GB @ $149.95 | 1500GB @ $169.95 | 10Mbps @ $269.95 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#78 |
Too lazy to set a custom title
Join Date: Jul 2003
Location: Netherlands
Posts: 10,127
|
redo your complete server setup (including OS install) and the problems will go away.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#79 |
Confirmed User
Join Date: May 2003
Posts: 2,734
|
anyone on webair knows more about it?
i found some of my domains hosted on webair hacked too (only root index.php files although)...not sure if its coming from my computer or it was some hack of webair accounts. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#80 |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
I started a new thread.
__________________
ICQ: 619221 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#81 |
Confirmed User
Join Date: Aug 2006
Location: Montevideo
Posts: 1,391
|
Whenever a server has been compromised, it is best to start from scratch. Reinstall the OS, reupload everything, import dbs.
The attacker might have left stuff on there that you didn't catch. That's why, in most cases, it happens over and over again. So my advice is that you format your server, start from scratch and search the web for security information of every single script or software that you plan to put on there. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#82 |
Affiliate
Join Date: Jul 2004
Posts: 28,735
|
this shit sucks... I working on the wordpress chmod now! Also installing the latest version.
__________________
M&A Queen |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#83 | |
Dialer Kingpin
Join Date: Jun 2003
Location: New York
Posts: 10,816
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#84 |
Dialer Kingpin
Join Date: Jun 2003
Location: New York
Posts: 10,816
|
RobV what is the status on your situation?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#85 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
buuuuump just got hit AGAIN today
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#86 |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Webair changed my password (however my original password was VERY strong). Since the second password change I have not been hacked.
And oddly enough this only hit 1 blog I had on the server, everything else was untouched.
__________________
ICQ: 619221 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#87 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Beach
Posts: 5,275
|
same thing happened to me, my host was CANDID HOSTING though, got the same reply from them......... So I said fuck you and switched hosts. Haven't had any problems since.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#88 |
Registered User
Join Date: Jan 2006
Posts: 44
|
trojan alert!!!!!!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#89 | |
Confirmed User
Join Date: Jun 2006
Location: Do you care?
Posts: 4,147
|
Quote:
![]()
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |