![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
![]() Just imagine losing ALL Google SE Traffic and ALL Firefox Surfer traffic on ALL of your sites OVERNIGHT!! potentially for days, weeks even months.. (it could happen to you).
There are a few threads circulating around about Comus Thumbs being vulnerable (again) to a backdoor/trojan issue: I got hit... (FYI.. I have multiple servers, but out of the 250+ sites on the server i had my only copy of Comus on, only about 35-40 or so other sites got infected before I was able to catch it... ) BUT it jumped to over 18 different master accounts on that server.. because of that, it made it extremely frustrating and time consuming to remove... Anywhoo.. This thread has some info on how to remove the backdoors/trojans: Secure/Delete your Comus Installation, ALL HTML/PHP Files on Server infected (credit to hjnet) My approach was slightly different, I used these two commands to search: a) grep -R "6966202873" * > list_of_backdoor_files b) grep -R "59} else if" * > list_of_infected_files my second scan for infected files (b) is different than what was in the thread I mentioned because with the help of my host we found that the code mutated spontaneously and the code you were using did not always catch them... I think that because many of my toplists that were infected were set to re-rank every 10 minutes so the mutation was more noticeable. This is not just about the hassle of finding/ removing the backdorrs/trojans and losing traffic until you figure it out... The sucky part about all of this is Google (safebrowsing.clients.google.com) flagged a bunch of my sites before I could remove the trojans, thereby killing the traffic on at least 8-10 or so of them. (not only killed SE traffic by saying my site will harm your computer in the search engine results pages, but also Firefox users get a big red warning screen, so the toplists are pretty much dead as far as surfers using firefox, except for IE surfer traffic). Now I have to go request that the flagging be removed.. I wonder how long that will friggin take??????????? (This is where my first line comes in about losing that traffic for days/weeks/months). Never going back to Comus... that was not a fun ordeal.. took several days to narrow it down and then 2 days to remove (1 of which was figuring it out)... between the lost work time and lost traffic this was kind of expensive. Anyone who has Comus thumbs really should not gamble with keeping the script with the "Wait and See" attitude.. (especially if you have your own servers with multiple sites on them)... This could potentially put some people completely out of business.. ![]() Even though it hurt me, I got lucky... I only had one copy of Comus on one server, but if i would have had it on all of my servers, and had been on vacation giving it time to spread to all of my sites (nearly 1000 sites) that would have killed me. Don't be reading this today and then posting here next week crying... ![]()
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Nov 2005
Location: ICQ - 703894
Posts: 1,949
|
fuck your avatar is sexy
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: May 2002
Location: European Union
Posts: 3,815
|
Good to mention this again, the Google Warning gets removed rather quickly, took ~24h for MOST of my sites, unfortunately for one of my sites it took almost 2 weeks.....
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
Thanks man.. I can shoot some content of her if ya need some ;) (problem is lately her availability has been kinda sucky).. ![]() ![]()
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Apr 2008
Posts: 271
|
comus already lost a great deal of webmasters.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
from what i know, tony is working on it, he found where they possibly came in and is removing the files/dependencies.
forum is currently offline as they hit that one as well. Im trying to get him to work as fast as possible on it, but it a hell of a job. also involves thinning comus out to the pure basics of the script namely a thumb rotator, nothing more and nothing less. He also had to move the license admin cause of the hacks, and that is one hell of a beast to move around. google is fast in removing the sites from blocked to unblocked, takes less then 12 hours if done properly.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
No Refunds Issued.
Industry Role:
Join Date: Apr 2003
Posts: 14,809
|
Bump for the cause. good luck to all affected webmasters.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Apr 2005
Location: Vegas
Posts: 4,499
|
Delete your Comus installs right away or you will be totally fucked. I caught them a few hours after they hit me and was able to straighten it out pretty quickly but it can really fuck your shit up bad.
__________________
бабки, шлюхи, сила |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
even if it is 12 to 24 hours, I'm sure if any webmasters who have toplist accounts visit the toplists, they'll probably pull their links, even though the infections were removed, due to the warning in firefox.. ![]() I guess I can't complain too much, it could have been far worse had I not caught it when I did, or if I had Comus on all of my servers.
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
I don't know how you people got infected? Was it your computer and then when accessing the server via FTP it spread there too? I myself, never had problems with comus thumbs and I believe that's because I keep my server very clean and maintained properly. Among all the security mechanisms I've implemented there I have mod_security on apache, and few password protected directories where comus resides.
I also have clamAV for scanning and removing infected files. So far, only one account on the server got infected, and that's my friend's account who had his computer infected. But all my sites are totally ok. That's why I am wondering how the hell did you get hit by this shit? What security hole is exploited on comus, from where?
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
It is not an FTP issue (checked all FTP logs, nothing other than my IP and everything was exactly what I had uploaded/downloaded). I ran ClamAV when I first noticed the problem, it picked up shit.. it found nothing even though the server was infected. "Somewhere" in Comus is a vulnerability which allows backdoor files to be created, then those backdoors create the trojans across the server. If you have not been hit, it is simply because your script has not yet been targetted. It could be an hour from now, a week from now, a year from now, or never. Just because it is vulnerable, does not mean you WILL get infected.. it just means it's possible.. but if I were a betting man, I would say it will probably happen sooner or later to you. Comus thumbs site has been messed up for some time, and then this issue occured.. with no mention from them about what's up, with the exception of boneless commenting in a few threads that they are trying to deal with it.
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
|
Fucking peice of shit Comus... I got hit as well... thousands of galleries etc! Fuck the free/skim traffic traders for this guy! Pisses me is I use love Epower.. bought it years ago but guess who bought that from Epower... anything that has to do with Comus creators is coming off my servers!!!!
__________________
HaHaHa |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
Quote:
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Confirmed User
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
|
Quote:
![]()
__________________
HaHaHa |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
so what changed? the fact that epower now runs from an ept dir? has an auto upgrade function? easier licensing system? or something else i missed as being the tech support for epower?
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Feb 2003
Location: Dreamland
Posts: 1,685
|
Cool... wish I would of found you after Comus bought the script and I did there upgrade and I never did it to work right for me anymore!
__________________
HaHaHa |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Posts: 1,605
|
I'm just glad I heeded the warnings about Comus a few weeks ago and got rid of it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Aug 2002
Location: UK
Posts: 3,198
|
I really don't see why tony is bothering to work on comus, its name has been dragged through the mud so badly now no one is going to be stupid enough to touch it again.
![]()
__________________
Take it Easy !!! ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
Quote:
I am not playing with this, but i want to make sure comus is really vulnerable.
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
Quote:
- Delete menu.php from the admin dir - htpasswd protected the admin dir i noticed lots of peeps not affected they all had their admin dir htpasswd protected. regards, Ed
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
perhaps you made a mistake when you upgraded, can happen to anyone, but saying you need to ditch epower cause comus ahs a problem right now is just plain stupid.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
Quote:
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
mod_security is set by default on all of our servers.. And as far as which file was hit first, i cannot tell you.. I was traveling out of state the week that it happened and my time online was limited.. Because of my limited time, to begin with I was frantically removing everything I could (which they just came back). Had I not been traveling I would have taken the time to notice time stamps, etc (although those can also be faked). I did not narrow it down to Comus until a few days ago when I was searching for a solution and noticed a common issue that others using Comus were having the same exact issue and that most of the backdoors were in Comus (although they had spread to dozens of other sites, those other sites only had about 1-3 backdoor files). And the deciding factor (aside from what everyone else is saying) was that I was not able to begin to remove the backdoors and trojans permanently until i deleted Comus. You can take boneless/Ed's advice to try to secure it if you want, I just know that the risks for me far outweigh the benefits.. Maybe I would feel differently if I had 100 sites running Comus and had to worry about the labor involved to convert them over to some other script.. but I only had one Comus script that I had just setup like 3 months ago.. so it is far easier for me to just ditch it. If this isn't all you do, you might not be as scared as I am.. I've been doing this since the late 90's and full time as my sole source of income since 2002, so I simply cannot gamble with things like this.. Just don't need the risk...
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
well.. i dunno.. but i do know that this time comus's site had issues right before all of this went down..
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Too lazy to set a custom title
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
|
I just hope they can solve this issue as fast as possible because they will get ruined if they don't...
__________________
Do you need cheap, fast and reliable porn website hosting? Host Head is the way to go!! Asian Gay Special | Live on MSN - Live Webcam Chat | Live Adult Webcam Performances | MY SWEET BLACKS LIVE ON CAM Pukka Tranny | Tattooed Shemales | She's A He | Menu Porno | Porn Performances | All Chubby MY ICQ# 169833797 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
no public notifications to help people solve the problem, nor no warnings on their site or elsewhere.... makes them seem not too focused on customer service, so in the end their lack of response could be a death sentence..
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
So Fucking Banned
Join Date: Nov 2005
Posts: 1,515
|
all firefox surfer traffic ... then i am done reading ...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
Quote:
Tony is working around the clock on it, he just doesnt like to get mixed in all the drama atm surrounding the issue. I have been sending him messages with all the board threads and he is aware off all the issues peeps had. For now he just tries to focus on the dev of the script and mainly figuring how they got in, we looked at the menu.php code and theres according ot us 0 that can be exploited. In the first beta that is going out tonight menu.php is removed. Plus there will be some minor tweaks on it. Just a FYI the menu.php file is tied into a lot of different files on comus so taking it out is a daunting task. Hope to have some news shortly for you guys. regards, Ed
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
also theres gonna be a lot of moving around of folders and files in the script. this is all for added security.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
google SE results should have been the bigger scare..
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
I just hope he won't miss something in the process and hence make the bigger problem.
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Feb 2001
Location: Land of OZ
Posts: 2,337
|
unbelievable that this script still has so many fucking holes in it and that Tony never bothered to properly lock down this script after so many attacks over the years
anyone who uses comus still needs their head checked
__________________
I am not a megalomaniac.. I just rule the world Need Quality Hardlinks? We have several packages and custom deals available. *High Quality Hard Links For Sale* ICQ: 394016570 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
well, what do you suggest Nurgle? Just switching over to something else? I've been tweaking my site for years to properly tune it. Also, sudden change of the links structure would have evident affect to SE rankings.
But, I think ST does better job in maintaining the productivity than CT, though.
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 | |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
Quote:
tony pushed the first beta upgrade out last night when i was sleeping so my post is a bit late (i tend to sleep at odd hours) Beta will kill menu.php from the ct folder. it will copy htaccess htpasswd from your ept install (if present) to the ct admin dir and the templates folder to make em more secure. these are only temp fixes atm. easiest way to make ya secure, is to remove menu.php for now and htpasswd the admin dir. Tony is resting atm after coding for over 18hours and will be going further into the code once he gets up again.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
|
i tend to disagree, i switched an entire box over to smart thumbs and prod on smaller sites is simply horrifying. To me its like st was designed for bigger sites, small sites tend to have a hard time getting their prod right.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 | |
Confirmed User
Industry Role:
Join Date: Oct 2006
Location: SWFL
Posts: 4,533
|
Quote:
thank god..
__________________
400 HARDL1NKS only $117! - (100 for $45)
BL0G P0STS $1.85+ | 55,000 Word Comprehensive Synonym Database 2 REVIEW COPIES AVAIL AT 50% OFF! | 16 yr old Aged Domains 4Sale ICQ: 265-593-735 ~ Skype: Naughty-Pages ~ email: ez_money4u(at)comcast(dot)net |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
ICQ: 197-556-237
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
|
Quote:
![]()
__________________
I'm just a newbie. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
Rock 'n Roll Baby!
Join Date: Sep 2004
Location: USA, temporarly
Posts: 22,562
|
what kind of prod booster do you use on your sites? I tried wide variety of prod boosters, but categories populated with less than 100 galleries tend to get their thumbs on the site more often, because of spin... i guess i'll have to move all my gals into one big category and set its spin to around 99% and see how it goes.
__________________
Sig for sale. Affordable prices. Contact me and get a great deal ;) My contact: ICQ: 944-320-46 e-mail: manca {AT} HotFreeSex4All.com |
![]() |
![]() ![]() ![]() ![]() ![]() |