![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
Fucking Megacount iFrame
I just found that fucking pos iframe on 2 sites... I was under the assumption that it was a wordpress exploit but these 2 sites aren't running wp
site 1: Smart Thumbs and ATX site 2: Smart Thumbs and AT3 Here's the funny thing... A few weeks ago, I installed wordpress on a site and within 10 minutes that megacount iframe was on the main page... An ftp pw change fixed all 3 sites so far |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
|
That was one every one of my sites the other day! Fuck! "Except" the Wordpress/ABP one. It seemed to be running fine. And only on the index file of my pages as far as I can tell. Gone now, but shit thats fuct.
![]()
__________________
Sonarcash Competitive Content Shooting Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: Downtown LA
Posts: 2,276
|
Yup...just found that fucker on one of my sites too. It seemed to only write the iframe code on my TTT-Toplist and AXSLinks templates.
Fuckin Ghey.
__________________
ICQ-291.596.343 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
8.8.8.8
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
|
wow, this guy is going after everyone...
__________________
TAEMDLRMSKRJIXMRLSMRJ. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Mar 2003
Location: Seattle, WA
Posts: 1,771
|
Can someone please fill me in on exactly what this is and what it does.
Also, how do you check to see if you have it?
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
|
Basically they load an iframe on your page which tries to load a virus from megacount.net/ somethin somethin...
win32.wordpro some shit like that. Fucking fucks!!!! ![]()
__________________
Sonarcash Competitive Content Shooting Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: Porn Valley
Posts: 8,151
|
Try blocking all all symlink () php functions
Thats what Sami at http://serverprovider.com/ did for mine and it has not been back since.... If it works then you might want to hit up sami next time you need a new box since the service is excellent and he was the only one able to find a way to make this stop for me..
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Too lazy to set a custom title
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,150
|
![]()
__________________
FLASH SALE INSANITY! deal with a 100% Trusted Seller Buy Traffic Spots on a High-Quality Network 1 Year or Lifetime — That’s Right, Until the Internet Explodes! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Macdaddy coder
Industry Role:
Join Date: Feb 2002
Location: MacDaddy pimp coder
Posts: 2,806
|
Got it to a couple of weeks ago, no wordpress or smartthumbs or other software installed, seems a php exploit ir something. If you ask me it has nothing to do with Wordpress.
B.
__________________
MacDaddy Coder. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Same here...
gofuckyourself.com/showthread.php?t=666473 Problem is, I'm not sure how they got the password to begin with.LOL, we wish it was just one guy... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
|
I would have to agree, the only domain on my server that "wasn't" affected was my wordpress blog.
__________________
Sonarcash Competitive Content Shooting Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Jan 2006
Location: Austria
Posts: 226
|
Take a look on your server - maybe you have a file called iframe.php - delete it - change your FTP pass. It should fix your problem.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Has anyone bothered to allow themselves to be infected to see what the asswipe is up to? I am betting pretty good money that he is the fuckwad sending out all the stock tip pump and dump scam mails right now, using many computers as zombies to do the mailing for him.
I would really be interested to see what the payload really ends up being. Alex |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
Quote:
![]() btw, site 1 was hit again this morning.... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
$100,000
Join Date: Dec 2001
Posts: 11,452
|
got hit on a dozen plus sites too. it reminds me i need to check my sites at least weekly or else i'd never notice these types of things.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
$100,000
Join Date: Dec 2001
Posts: 11,452
|
and its not wordpress, it happened on sites that didnt have wp installed, happened on a wp one too though.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
it's fucking amazing that no one has come up with a fucking solution to this shit yet....
I wonder when the asshole is going to start pushing Zango installs... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Aug 2006
Location: Atlanta, Georgia ICQ 276-218-214
Posts: 1,288
|
this fucking sucks big time
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
...
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
|
yeah ive seen this on a bunch of sites lately
__________________
... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Jun 2005
Location: ▓NY▓
Posts: 2,080
|
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK
__________________
Each persons' level of stupidity makes us different. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
anyone know how to fix this shit? It hit me again this morning. this time a new url http://fdghewrtewrtyrew [DOT] biz
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
HOMICIDAL TROLL KILLER
Industry Role:
Join Date: Dec 2004
Location: Sunnybrook Institution for the Criminally Insane
Posts: 20,419
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
happened again today with read only perms on the file.
it's not the symlink thing either. C'mon SOMEONE has to know how to stop this shit. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
buuuuuump
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
buuuuump just got hit AGAIN today
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Confirmed User
Join Date: Oct 2005
Posts: 111
|
Just bumping, hopefully someone can figure something out for you.
__________________
ICQ: 619221 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
thanks rob
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
In Tushy Land
Join Date: Oct 2002
Location: Nebraska
Posts: 40,149
|
had the same thing happen, glad to get it fixed though
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
...
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
|
this fucker must be stopped!
__________________
... |
![]() |
![]() ![]() ![]() ![]() ![]() |