![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Jul 2006
Posts: 620
|
![]() So we were hitted by a fucking trojan that appends a script at the beginning of several php files and at the end of all .js files. This mofo apparently comes on pdf files and some swf using an Acrobat vulnerability. It will then create a pdf and 2 swf files which will be used to infect your server, from there your site will try to load 94.247.2.195/news/?id=100 and/or 94.247.2.195/news/?id=101 . If successful, it will infect your visitor and so on and so on. It's spreading wildly and last week the count of affected websites was over 20000 (and counting). The only remedy is to wipeout everything in your server, change passwords and such, just take a look to your php files, it will append to most (or all) php files containing index or config in the name, which makes Wordpress, Drupal and Joomla extremely vulnerable
Just look for this (don't worry, it's just a tiny bit of the code, but enough to find out) in your hosted files: Code:
<?php if(!function_exists('tmp_lkojfghx')) it's not confirmed if it attacks databases and some people says it also attacks filezilla, so be careful |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Show Yer Tits!
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
|
Wow, thanks for the thread.
__________________
![]() Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Jul 2006
Posts: 620
|
no problem, we're researching on what this crap intends to do, will keep you updated, in the meanwhile, no need to panic or anything, just check your files
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Nomad
Posts: 5,196
|
normally that comes from your computer when you upload things to your server
__________________
. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Aug 2007
Posts: 2,985
|
Yeah, a doctor friend of mine runs a little website that had some code injected into all the pages. I cleaned it all out, but it came back. I cleaned it again and switched servers, and it came back. Then he told me has someone do some minor HTML work now and then. Turns out his computer had some kind of virus that was adding the code when he uploaded via Filezilla. I made him stop uploading and the problem went away. Very strange.
__________________
jim (at) amateursconvert . com Amateurs Convert
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Join Date: Jul 2006
Posts: 620
|
Quote:
This trojan is quite obnoxious once you have it in your computer, it will disallow regedit, will fake program uninstall and slow down your computer A LOT, so it's quite easy to know you have it, and as far as I know, it uses several names, although Superantispyware catchs it. Anyway, just letting you guys know since it's spreading fast, at least our headaches may help someone here |
|
![]() |
![]() ![]() ![]() ![]() ![]() |