Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-17-2006, 01:14 PM   #1
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Fucking Megacount iFrame

I just found that fucking pos iframe on 2 sites... I was under the assumption that it was a wordpress exploit but these 2 sites aren't running wp

site 1: Smart Thumbs and ATX
site 2: Smart Thumbs and AT3

Here's the funny thing... A few weeks ago, I installed wordpress on a site and within 10 minutes that megacount iframe was on the main page...

An ftp pw change fixed all 3 sites so far
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 08:32 PM   #2
Lance69
Confirmed User
 
Lance69's Avatar
 
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
That was one every one of my sites the other day! Fuck! "Except" the Wordpress/ABP one. It seemed to be running fine. And only on the index file of my pages as far as I can tell. Gone now, but shit thats fuct.
__________________
Sonarcash Competitive Content Shooting
Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog
ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ)
Lance69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 08:55 PM   #3
BiggleJones
Confirmed User
 
BiggleJones's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Downtown LA
Posts: 2,276
Yup...just found that fucker on one of my sites too. It seemed to only write the iframe code on my TTT-Toplist and AXSLinks templates.

Fuckin Ghey.
__________________
ICQ-291.596.343
BiggleJones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 08:56 PM   #4
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
wow, this guy is going after everyone...
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 10:23 PM   #5
looky_lou
Confirmed User
 
Industry Role:
Join Date: Mar 2003
Location: Seattle, WA
Posts: 1,771
Can someone please fill me in on exactly what this is and what it does.

Also, how do you check to see if you have it?
__________________
PUSSY - PUSSY - PUSSY!
Wet & Puffy - Wet & Pissy - We Like To Suck
Puffy Cash
looky_lou is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 11:11 PM   #6
Lance69
Confirmed User
 
Lance69's Avatar
 
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
Basically they load an iframe on your page which tries to load a virus from megacount.net/ somethin somethin...
win32.wordpro some shit like that.
Fucking fucks!!!!
__________________
Sonarcash Competitive Content Shooting
Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog
ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ)
Lance69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 11:18 PM   #7
RevSand
Confirmed User
 
RevSand's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: Porn Valley
Posts: 8,151
Try blocking all all symlink () php functions


Thats what Sami at http://serverprovider.com/ did for mine and it has not been back since.... If it works then you might want to hit up sami next time you need a new box since the service is excellent and he was the only one able to find a way to make this stop for me..
__________________


BadBitchesGoodWeed


Hire me for all your video shooting needs!!
Skype = RevSandx
RevSand is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 11:25 PM   #8
CaptainHowdy
Too lazy to set a custom title
 
CaptainHowdy's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 93,147
!!
__________________
FLASH SALE INSANITY! deal with a 100% Trusted Seller
Buy Traffic Spots on a High-Quality Network

1 Year or Lifetime — That’s Right, Until the Internet Explodes!
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2006, 11:49 PM   #9
boldy
Macdaddy coder
 
Industry Role:
Join Date: Feb 2002
Location: MacDaddy pimp coder
Posts: 2,806
Got it to a couple of weeks ago, no wordpress or smartthumbs or other software installed, seems a php exploit ir something. If you ask me it has nothing to do with Wordpress.

B.
__________________
MacDaddy Coder.
boldy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 05:19 AM   #10
Naughty-Pages
Confirmed User
 
Naughty-Pages's Avatar
 
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
Quote:
Originally Posted by SPeRMiNaToR View Post
An ftp pw change fixed all 3 sites so far
Same here...

gofuckyourself.com/showthread.php?t=666473

Problem is, I'm not sure how they got the password to begin with.
Quote:
Originally Posted by madawgz View Post
wow, this guy is going after everyone...
LOL, we wish it was just one guy...
Naughty-Pages is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 11:16 AM   #11
Lance69
Confirmed User
 
Lance69's Avatar
 
Join Date: Jan 2005
Location: Vancouver BC
Posts: 2,266
Quote:
Originally Posted by boldy View Post
Got it to a couple of weeks ago, no wordpress or smartthumbs or other software installed, seems a php exploit ir something. If you ask me it has nothing to do with Wordpress.

B.
I would have to agree, the only domain on my server that "wasn't" affected was my wordpress blog.
__________________
Sonarcash Competitive Content Shooting
Handgasm HD Handjobs Janessa Jordan Ultimate Wife Make Money Fucking Blog
ICQ: 307 975 028 lance {at} sonarcash {dot} com (<- Need amateur content? Email or ICQ)
Lance69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 11:22 AM   #12
remii
Confirmed User
 
Join Date: Jan 2006
Location: Austria
Posts: 226
Take a look on your server - maybe you have a file called iframe.php - delete it - change your FTP pass. It should fix your problem.
remii is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 11:49 AM   #13
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Has anyone bothered to allow themselves to be infected to see what the asswipe is up to? I am betting pretty good money that he is the fuckwad sending out all the stock tip pump and dump scam mails right now, using many computers as zombies to do the mailing for him.

I would really be interested to see what the payload really ends up being.

Alex
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 12:51 PM   #14
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Quote:
Originally Posted by RawAlex View Post
Has anyone bothered to allow themselves to be infected to see what the asswipe is up to? I am betting pretty good money that he is the fuckwad sending out all the stock tip pump and dump scam mails right now, using many computers as zombies to do the mailing for him.

I would really be interested to see what the payload really ends up being.

Alex
it always crashes my shit and I've run spyware scans and virii scans and they never find anything.

btw, site 1 was hit again this morning....
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 02:18 PM   #15
bdld
$100,000
 
Join Date: Dec 2001
Posts: 11,452
got hit on a dozen plus sites too. it reminds me i need to check my sites at least weekly or else i'd never notice these types of things.
bdld is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 02:18 PM   #16
bdld
$100,000
 
Join Date: Dec 2001
Posts: 11,452
and its not wordpress, it happened on sites that didnt have wp installed, happened on a wp one too though.
bdld is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 04:42 PM   #17
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
it's fucking amazing that no one has come up with a fucking solution to this shit yet....

I wonder when the asshole is going to start pushing Zango installs...
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 06:57 PM   #18
King of Queens
Confirmed User
 
Join Date: Aug 2006
Location: Atlanta, Georgia ICQ 276-218-214
Posts: 1,288
this fucking sucks big time
King of Queens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 08:03 PM   #19
Kimo
...
 
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
yeah ive seen this on a bunch of sites lately
__________________
...
Kimo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-21-2006, 09:11 PM   #20
ridikuloz
Confirmed User
 
ridikuloz's Avatar
 
Join Date: Jun 2005
Location: ▓NY▓
Posts: 2,080
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK
__________________
Each persons' level of stupidity makes us different.
ridikuloz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-22-2006, 01:57 AM   #21
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Quote:
Originally Posted by ridikuloz View Post
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK

JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-24-2006, 07:43 AM   #22
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
anyone know how to fix this shit? It hit me again this morning. this time a new url http://fdghewrtewrtyrew [DOT] biz
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-24-2006, 07:43 AM   #23
marketsmart
HOMICIDAL TROLL KILLER
 
Industry Role:
Join Date: Dec 2004
Location: Sunnybrook Institution for the Criminally Insane
Posts: 20,419
Quote:
Originally Posted by ridikuloz View Post
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK
hahahahaha
marketsmart is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-25-2006, 07:44 AM   #24
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
happened again today with read only perms on the file.

it's not the symlink thing either. C'mon SOMEONE has to know how to stop this shit.
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-25-2006, 10:45 AM   #25
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
buuuuuump
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 10:33 AM   #26
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
buuuuump just got hit AGAIN today
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 10:59 AM   #27
RobV
Confirmed User
 
Join Date: Oct 2005
Posts: 111
Quote:
Originally Posted by SPeRMiNaToR View Post
buuuuump just got hit AGAIN today
Just bumping, hopefully someone can figure something out for you.
__________________
ICQ: 619221
RobV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 11:19 AM   #28
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
thanks rob
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 11:26 AM   #29
Sosa
In Tushy Land
 
Sosa's Avatar
 
Join Date: Oct 2002
Location: Nebraska
Posts: 40,149
had the same thing happen, glad to get it fixed though
Sosa is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-20-2006, 11:45 AM   #30
Kimo
...
 
Join Date: Jan 2006
Location: Maryland ICQ:87038677
Posts: 11,542
this fucker must be stopped!
__________________
...
Kimo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.