1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

hey i site have be hacked with eval(base64_decode(

Discussion in 'Security' started by brightyoursite, May 1, 2010.

  1. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #21
    nikb, May 15, 2010 IP
  2. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #22

    Before anyone downloads that "m-walker" , make sure it is clean. You can get a worse
    infection at times from things that are advertised as "fixes". :eek:

    No offense to the poster, but this file is an "unknown player" at the moment.
     
    Blue Star Ent., May 15, 2010 IP
  3. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #23
    What are you talking about? Are you blind? Wat you want do download? Where?

    Please read first!
     
    Last edited: May 15, 2010
    nikb, May 15, 2010 IP
  4. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #24
    Read what ? Your site ? To answer that stupid question; "no".

    Why so defensive ? According to your post HERE

    ...that is your creation. You say : "M-Walker is a scheduled task". What schedules it if
    not software ?

    A full thirty percent of "anti-malware" is actually malware.

    Where are some ( believable ) reviews of your product ? You have questions, I do too. :)
     
    Blue Star Ent., May 15, 2010 IP
  5. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #25
    Ok, sorry for my bad english, software, software at my server. Internet Explorer and some other tools that can sniff internet traffic.
    All active connections are put in a log file and then be searched or IP addresses in malware ip databases appear. Than you just receive a email with result.
    I'm do not need to decode difficult scripts, everything does IE. If IE was connected with bad IP you receive email with warning.
    I walk into danger himself to get a virus and not offer others peoples to download something.
    You can not download m-walker!

    Only one link at my site offer people to download something. And this is an add-on for Firefox.
     

    Attached Files:

    • bad.jpg
      bad.jpg
      File size:
      90.2 KB
      Views:
      149
    • good.jpg
      good.jpg
      File size:
      57.4 KB
      Views:
      177
    nikb, May 16, 2010 IP
  6. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #26
    Okay, no problem.

    Do you have some reviews for your service/software ? If it is good, you could use an affiliate program. It would help you and help those who are suffering because of the bad guys and eventually end up getting rid of the problem, hopefully.


     
    Blue Star Ent., May 16, 2010 IP
  7. SecureCP

    SecureCP Guest

    Messages:
    226
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #27
    Here's a neat idea. grep your logs, if your not on a vps or dedicated server forget it, and see exactly how these are being adding to your files. I've seen these infections coming from foreign IPs compared to the user who is 'hacked' and is auth'ing with the username and password, and the other was an insecurity in TinyMCE.

    Everyone comes on to this forum to complain about these infections and no one has hard evidence proving their theory on how it happened, and others just want it fixed. When people begin to actually have root access to a server, then they can begin showing evidence of this and a solution can then be proposed. Look into SuHosin. It doesn't catch them all, but it will catch alot.
     
    SecureCP, May 17, 2010 IP
  8. whynotavps

    whynotavps Peon

    Messages:
    49
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #28
    If it is Godaddy related, then you should use the solution that is found on sucuri.net. Make a cronjob and let it run every our to search for the eval(base64 and let it remove. Should remove it for now until Godaddy fix there server problemens.
     
    whynotavps, May 19, 2010 IP
  9. brightyoursite

    brightyoursite Peon

    Messages:
    59
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #29
    this is a good way, its the dodaddy problem i think beause i have many other ftps at my pc only the godaddy have problem
     
    brightyoursite, May 20, 2010 IP
  10. brightyoursite

    brightyoursite Peon

    Messages:
    59
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #30
    who know is there a way to disable ob_start() i think this can fix this problem
     
    brightyoursite, May 20, 2010 IP
  11. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #31
    I don't think disabling output buffering would help any.
     
    phpSiteMinder, May 21, 2010 IP
  12. brightyoursite

    brightyoursite Peon

    Messages:
    59
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #32
    brightyoursite, May 21, 2010 IP
    Blue Star Ent. likes this.
  13. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #33
    Good work. I hope more people read your site, and help get rid of this nuisance.

     
    Blue Star Ent., May 21, 2010 IP
  14. AnonymousUser

    AnonymousUser Peon

    Messages:
    593
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #34
    Yep a Godaddy problem, Every1 needs to email them and let them know its THERE fault and not OURS
     
    AnonymousUser, May 21, 2010 IP
  15. Serious Workers

    Serious Workers Well-Known Member

    Messages:
    2,785
    Likes Received:
    65
    Best Answers:
    2
    Trophy Points:
    195
    #35
    You should first change your password and then scan all the computers you are using to login into your sites FTP. There is no need to blame the host, I think.
     
    Serious Workers, May 21, 2010 IP
  16. brightyoursite

    brightyoursite Peon

    Messages:
    59
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #36
    this the problem happen there is better but if can get rid of the hack source thats cool
     
    brightyoursite, May 21, 2010 IP
  17. Blue Star Ent.

    Blue Star Ent. Well-Known Member

    Messages:
    1,989
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    160
    #37
    Hmmm... I am looking at that statement two different ways; You can do it on your hosting account or you can go after the hackers.
     
    Blue Star Ent., May 22, 2010 IP
  18. webmaster365

    webmaster365 Greenhorn

    Messages:
    86
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    16
    #38
    i HAVE FACE THIS PROBLEM 3 TIMES LAST MONTH.IF YOU ARE USING ANY THIRD PARTY PHP CODE LIKE PLUGINS MINIFY JS AND CSS THEN REMOVE IT.
     
    webmaster365, May 30, 2010 IP
  19. chtdatweb

    chtdatweb Well-Known Member

    Messages:
    1,473
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    160
    #39
    I could be wrong, put if there inserting that code then surly its a permissions problem? I don't know about the hosts themselves as not used them be we had a problem with a iframe injection, where, in a simular case to this random code was inserted into the PHP files. Turned out the file permissions were wrong. Maybe locking them down to 644 might solve the problem.
     
    chtdatweb, Jun 2, 2010 IP
  20. drakha

    drakha Active Member

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    91
    #40
    drakha, Jun 7, 2010 IP