![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 | |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
![]() Some of my sites that using TGPX, TEVS and Comus thumbs are getting malware injection attack. One of my dedicated servers got hit by malware distributer.
Below code is injected right after the body tag of html, tmpl and some php files. Quote:
But they are constantly adding this JS code even if I removed it... Since the box is unmanagged, Maybe I will have to reload server OS and restore whole files from backup. but I'm worry about the backup is infected as well.. ![]() Beware guys, check your server security, file/dir permission etc. also your PC is not safe as well. Install a good anti-malware and don't save password at your local ftp client. http://www.webhostingtalk.com/showth...rame+injection
__________________
254-282-542 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Aug 2008
Posts: 1,609
|
change your index page delete the page having that code, then change all your access
__________________
LUSTY LIFES : Dad & Daughter Wild Adventures : Naughty Wild Sister Contact : ICQ : 372109 Email add: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,019
|
Is it this one?
forums.digitalpoint.com/showthread.php?t=901622 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
This is usually caused by a virus on your computer. Have your host check ftp logs, and i bet you will have a bunch of unknown logins. These viruses append this code to any file named index.php index.html etc.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
So Fucking Banned
Join Date: Nov 2005
Posts: 1,515
|
i am amazed how much webhosts have easy to hack ftp logins ...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jun 2009
Location: Asheville, NC
Posts: 2,277
|
If it's not caused by your own computer it may be also be caused from something on your site...
If you have photo uploads... it's possible someone has uploaded a fake image that is actually running code... You may also have your permissions set wrong on the files on your server allowing someone to exploit your box and add things to the content...
__________________
ICQ: 258-202-811 | Email: eric{at}bestxxxporn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Join Date: Jul 2006
Location: NoHo
Posts: 5,970
|
Quote:
Good luck getting that code outta ur sites 2 ...
__________________
![]() ICQ: 266990876
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,585
|
maybe you should replace " webhosts " by " webmasters "
![]()
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT ! But I can't figure out how he can breathe or type , at the same time .... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
|
Do yourself a favor and find the security hole before you fix the site.
You need to find how they got in (assuming they hacked your server).
__________________
--- ICQ 14-76-98 <-- I don't use this at all |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
|
here's my guide:
step 1: update your adobe reader to latest version (9.xx) or even better remove it and put FoxIt Reader (much smaller and faster). step 2: update flash player plugins for IE and FF step 3: download 2-3 anti-spyware softwares and check your computer step 4: once you are clean login and change all your paswords and fix the sites. step 5: monitor what's going on... - - - - extra steps * Download and use Total Commander 7.5 that has password encryption option that makes your passwords safe (this I haven't found on any other software and that's the weakest point of most of ftp clients) * always have anti-virus, firewall and anti-spyware app active (I use Nod32 Smart Security AV+FW + AdAware) * use only firefox and chrome instead of IE all mentioned software you may find and download at http://www.filehorse.com
__________________
Make a bank with Chaturbate - the best selling webcam program ![]() ![]() ![]() Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!! PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email: ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Aug 2002
Location: UK
Posts: 3,198
|
Dude its a comus thumbs issue as far as i'm aware. I'm currently deleting all my comus installs (over 40) and replacing the script with a new one as i have been hit with this hack 3 days ago and still fixing it.
I have used comus for over 5 years and these hacks are all to regular these days, they never update comus and its going to the shit so i would delete it and rebuild site with new script. my 2cents
__________________
Take it Easy !!! ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Join Date: Nov 2005
Posts: 1,515
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Registered User
Join Date: Jan 2008
Location: wenatchee WA
Posts: 75
|
Where you using Filezilla to upload? i know a while back their was a problem with that program letting a virus in to change your .php files
__________________
You can contact me via the following: AIM - playazdb0y ICQ - 459454282 Email - [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Jan 2005
Posts: 2,270
|
Okay a few things here,
what scripts are you running on your server. Are you running joomla? What are the directory permissions of your php files? Hit me up on aim or icq if your host isnt going to fix it for you, as I hate people that hack sites more then anything on the face of the damn planet.
__________________
E-mail marketing - Automation Scripting - IP Space AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
Not sure but looks like it.
![]()
__________________
254-282-542 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
![]() When the script is executed(I visited a infected site accidently yesterday. I guess) it loaded malware which disguised as .pdf or .swf file that steals username/password data from PC.
The malware is hosted at another infected site and loaded via iframe then excuted on the browser. Now the hacker got my site's login and infected my sites too. I don't know how he connected my box though. I guess he's using remote script that doesn't leave log info. Even if I remove those malwares in my PC and change ftp password, the hacker can get my new password easily since I had to load my sites to check. So it is very important that never load the sites during troubleshooting. This is what I did and seems like the code is gone finally. but still monitering.. 1. reboot PC and scan it for spyware. 2. reboot again and change all server passwords. 3. remove the code from all server files(index.html, category.html, index.php, etc..) with serverside text editor. 4. Never load infected webpages on browser during #3. 5. install mod_security and change file permissons. This thing reminds me of BackOrifice at 98'. It's the most annoying fuckware I had ever. it passed mcafee. Remember to use a good antivirus on your PC. I had good result with Malwarebytes.org Thanks for advices.
__________________
254-282-542 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
and another reason to not use ftp, but sftp....
Quote:
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
Quote:
Yep. looks like Comus is gonna dead soon. lots of security holes and no updates. also going to drop it asap.
__________________
254-282-542 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
Quote:
most are 644, data/tempates dir and files were set to 777. I changed lots of files to 444 for monitering. will contact you if I get codes again. Thanks!
__________________
254-282-542 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: In a Tater Patch
Posts: 2,321
|
this exploit is going around and it seems to be comus is the problem from watching the audit logs and investigating. Even if a server has comus installed unless setup with 1 domain per login etc due to permissions i.e having 777 on things you should not it will infect a whole mess of files and leave backdoors everywhere.
__________________
Managed Hosting - Colocation - Network Services Yellow Fiber Networks icq: 19876563 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Welcome to the club,my one old unsecured machine is also hacked with completely same crap.I working now on removing it.And yes i do have several comus installations there.But i dont see how can comus bug affect all possible sites,no matter are they based on st,tgpx or something else(and i have all three rotator scripts installed)
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Aug 2004
Posts: 151
|
Yep my Comus sites are hacked too for the last couple of days....fucking me off thinking how many will not return cos of warnings thrown up by their anti virus....already had a email from google saying they have tagged my highest traffic site with a "this site could harm your computer" in their search pages...just waiting for more emails from them for my other comus sites!
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: In a Tater Patch
Posts: 2,321
|
Quote:
__________________
Managed Hosting - Colocation - Network Services Yellow Fiber Networks icq: 19876563 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Join Date: Aug 2004
Posts: 151
|
thing is, I dont see any malicious code in view source...just the anti virus pop up warning...after a refresh dont get any warnings at all...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
So Fucking Banned
Join Date: Aug 2009
Posts: 3,164
|
look at all the morons in here
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Join Date: Aug 2004
Posts: 151
|
heres a quote from my hosts when I told them not to bother scanning my sites as it looks like a comus issue...
"Yes, Comus Thumbs has been causing a lot of issues lately ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Ok so we concluded comus is cause of this?So i can start removing it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Join Date: Aug 2004
Posts: 151
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,019
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Confirmed User
Join Date: Jun 2009
Location: Asheville, NC
Posts: 2,277
|
"But in addition to running an Apache webserver to dish up benign content, they've also been hacked to run a second webserver known as nginx, which serves malware."
Hahhahaha not only does it serve up malware, it serves up malware faster and more efficiently, hhahahah man that really cracks me up in a very geeky way, hahhhaha
__________________
ICQ: 258-202-811 | Email: eric{at}bestxxxporn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 | |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,019
|
Quote:
The infection did not even take place on any of my office PC's, but in the office a few blocks down the street where the designers and programmers have the office. One guy there had an infected PC that had FTP access to one of my servers. Not sure if they use comus or not but I don't think so. Infection takes place thru adult infected websites in all popular browsers without anti-virus programs seeing it. Hidden custom build (FTP) logs show somebody using my FTP user/pass without brute force entering and adding some files and making some changes similar to all infected victims. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Jun 2009
Location: Asheville, NC
Posts: 2,277
|
Setting to 644 alone won't help you... What is the owner and group of the file? If it's set to the same as the webserver runs as then any exploit which is passing through your webserver will have full access to the file...
If someone has already hacked your box you have way more issues to worry about... First things first: http://www.rootkit.nl/projects/rootkit_hunter.html Download it, install it, run it, then you can rule out most root kits and learn if your box has been compromised or not... If it has, you know the problem... if it hasn't then you can move onto the next step. GL!
__________________
ICQ: 258-202-811 | Email: eric{at}bestxxxporn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,391
|
Actually, old Comus is hackable... These are usually NOT FTP access problems and are problems with PHP scripts being hackable.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Here are copy pastes of java script codes:
http://pastebin.com/m53fc9126 http://pastebin.com/m1b861dd8 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Confirmed User
Join Date: Aug 2002
Location: UK
Posts: 3,198
|
All My sites were hacked through comus, If you use comus, I advise deleting it and using another script, this appears to be only fix for me :2cents
__________________
Take it Easy !!! ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
Found this from Webhostingtalk.com
Quote:
Then again, It' not recommended to install unreliable php scripts anyway..
__________________
254-282-542 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Well first thing which i did is to disable completely ftp but that didnt helped anything.Anyway my computer was not compromised since i am not using ftp at all,only sftp.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Confirmed User
Join Date: Jun 2009
Location: Asheville, NC
Posts: 2,277
|
My favorite exploit is the fake image upload that has a correct image header...
If the image gets stored "as is" the first line of it is <?eval($_REQUEST['someVar']?> If the host is configured to parse image files (tracking, dynamic images, etc...) anything they pass in to the request gets evaled... so elegant, so simple, so devastating...
__________________
ICQ: 258-202-811 | Email: eric{at}bestxxxporn.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 |
I love to racism, bro!
Industry Role:
Join Date: Oct 2002
Location: USA! USA! USA!
Posts: 22,819
|
Anyone heard from Comus regarding this problem? Is a fix being worked on or should I change scripts?
__________________
Unvaxxed, still alive. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
i think you might need a managed host.
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
Quote:
ATM this is where we stand, im not saying comus is the prob but it is most likely the cause of all probs. Comus license key admin login page file is broken atm, one of the things that happened to my girlfriend wordpress site during the hacks. tbh with you guys, i myself am ditching comus as my script and am going for an alternative. For now its smart thumbs, and as i got over 100 comus sites i got a long and hard task ahead to switch em all over. Im really hoping that all is well with tony but since i havent heard or seen him online in the past three weeks makes me wonder what the fuck is going on. I hope im not getting loaded with 1000s of messages on my icq... thnx yall, Ed
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 | |
Anti Communist
Industry Role:
Join Date: Nov 2003
Location: Null
Posts: 29,765
|
Quote:
Duke
__________________
My mother said, to get things done You'd better not mess with Major Tom |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#46 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
I am not sure how can you be so sure that actually comus is the root of your problems? I am using comus too, but with tightened security on the server itself and with my OS security I never get hacked, neither get into troubles with any of my sites.
This time I haven't been affected by this comus hack (which I think is not comus hack, just a malware insertion) and my sites are running smoothly. The only thing I don't like about comus is that its admin interface loads iframe from their website, so if their website has the malware, then technically every site that runs comus has it too. To get rid of malwares and to actually avoid getting them, just install normal os, like Linux, or buy Mac. Oh, and just one remark: before doing anything on your own, have host run clamAV on your box/v. acc. and scan for potential infected files, as well as run the rootkit detection tools. Then it's your turn to make your own box clean and more secure. Good luck!
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#47 |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Agreed.... it's comus, but even after you kill Comus, you've got to check every site on the server comus was on even if the site is not using Comus... (I've got 14 sites so far that were affected )
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#48 |
ICQ: 197-556-237
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
|
Look at your .htaccess and check if it's everything working nicely.
__________________
I'm just a newbie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#49 |
Guest
Posts: n/a
|
ive had this before!!
Webair reverted my sites abck before the infection and changed all ftp info |
![]() ![]() ![]() ![]() ![]() |
![]() |
#50 |
Confirmed User
Join Date: Sep 2003
Posts: 2,255
|
Old thread. Yes I was wrong. it's a Comus thumbs hack. No ftp password issue.
I misunderstood it was another iframe injection attack that caused from viruses on local machine. I installed mod_security then it stopped code injection but I thought it fixed by removing viruses on my PC. Anyway it's completely fixed by removing all backdoor scripts and infected files. If anyone still faces this froblem, refer this thread. http://www.gfy.com/fucking-around-and-business-discussion/928915-secure-delete-comus-installation-html-php-files-server-infected.html
__________________
254-282-542 |
![]() |
![]() ![]() ![]() ![]() ![]() |