GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Fucking Megacount iFrame (https://gfy.com/showthread.php?t=667326)

JD 10-17-2006 01:14 PM

Fucking Megacount iFrame
 
I just found that fucking pos iframe on 2 sites... I was under the assumption that it was a wordpress exploit but these 2 sites aren't running wp

site 1: Smart Thumbs and ATX
site 2: Smart Thumbs and AT3

Here's the funny thing... A few weeks ago, I installed wordpress on a site and within 10 minutes that megacount iframe was on the main page...

An ftp pw change fixed all 3 sites so far

Lance69 10-17-2006 08:32 PM

That was one every one of my sites the other day! Fuck! "Except" the Wordpress/ABP one. It seemed to be running fine. And only on the index file of my pages as far as I can tell. Gone now, but shit thats fuct. :mad:

BiggleJones 10-17-2006 08:55 PM

Yup...just found that fucker on one of my sites too. It seemed to only write the iframe code on my TTT-Toplist and AXSLinks templates.

Fuckin Ghey.

madawgz 10-17-2006 08:56 PM

wow, this guy is going after everyone...

looky_lou 10-17-2006 10:23 PM

Can someone please fill me in on exactly what this is and what it does.

Also, how do you check to see if you have it?

Lance69 10-17-2006 11:11 PM

Basically they load an iframe on your page which tries to load a virus from megacount.net/ somethin somethin...
win32.wordpro some shit like that.
Fucking fucks!!!! :321GFY

RevSand 10-17-2006 11:18 PM

Try blocking all all symlink () php functions


Thats what Sami at http://serverprovider.com/ did for mine and it has not been back since.... If it works then you might want to hit up sami next time you need a new box since the service is excellent and he was the only one able to find a way to make this stop for me..

CaptainHowdy 10-17-2006 11:25 PM

:mad: !!

boldy 10-17-2006 11:49 PM

Got it to a couple of weeks ago, no wordpress or smartthumbs or other software installed, seems a php exploit ir something. If you ask me it has nothing to do with Wordpress.

B.

Naughty-Pages 10-21-2006 05:19 AM

Quote:

Originally Posted by SPeRMiNaToR (Post 11096397)
An ftp pw change fixed all 3 sites so far

Same here...

gofuckyourself.com/showthread.php?t=666473

Problem is, I'm not sure how they got the password to begin with.
Quote:

Originally Posted by madawgz (Post 11099698)
wow, this guy is going after everyone...

LOL, we wish it was just one guy...

Lance69 10-21-2006 11:16 AM

Quote:

Originally Posted by boldy (Post 11100754)
Got it to a couple of weeks ago, no wordpress or smartthumbs or other software installed, seems a php exploit ir something. If you ask me it has nothing to do with Wordpress.

B.

I would have to agree, the only domain on my server that "wasn't" affected was my wordpress blog.

remii 10-21-2006 11:22 AM

Take a look on your server - maybe you have a file called iframe.php - delete it - change your FTP pass. It should fix your problem.

RawAlex 10-21-2006 11:49 AM

Has anyone bothered to allow themselves to be infected to see what the asswipe is up to? I am betting pretty good money that he is the fuckwad sending out all the stock tip pump and dump scam mails right now, using many computers as zombies to do the mailing for him.

I would really be interested to see what the payload really ends up being.

Alex

JD 10-21-2006 12:51 PM

Quote:

Originally Posted by RawAlex (Post 11126286)
Has anyone bothered to allow themselves to be infected to see what the asswipe is up to? I am betting pretty good money that he is the fuckwad sending out all the stock tip pump and dump scam mails right now, using many computers as zombies to do the mailing for him.

I would really be interested to see what the payload really ends up being.

Alex

it always crashes my shit :( and I've run spyware scans and virii scans and they never find anything.

btw, site 1 was hit again this morning....

bdld 10-21-2006 02:18 PM

got hit on a dozen plus sites too. it reminds me i need to check my sites at least weekly or else i'd never notice these types of things.

bdld 10-21-2006 02:18 PM

and its not wordpress, it happened on sites that didnt have wp installed, happened on a wp one too though.

JD 10-21-2006 04:42 PM

it's fucking amazing that no one has come up with a fucking solution to this shit yet....

I wonder when the asshole is going to start pushing Zango installs...

King of Queens 10-21-2006 06:57 PM

this fucking sucks big time :mad:

Kimo 10-21-2006 08:03 PM

yeah ive seen this on a bunch of sites lately

ridikuloz 10-21-2006 09:11 PM

LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK

JD 10-22-2006 01:57 AM

Quote:

Originally Posted by ridikuloz (Post 11128695)
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK


:1orglaugh :1orglaugh

JD 10-24-2006 07:43 AM

anyone know how to fix this shit? It hit me again this morning. this time a new url http://fdghewrtewrtyrew [DOT] biz

marketsmart 10-24-2006 07:43 AM

Quote:

Originally Posted by ridikuloz (Post 11128695)
LOL, I totally ignored your messaged and watched that monkey sig of yours for a good 5 minutes... what the FUCK

hahahahaha :1orglaugh :1orglaugh

JD 10-25-2006 07:44 AM

happened again today with read only perms on the file.

it's not the symlink thing either. C'mon SOMEONE has to know how to stop this shit.

JD 10-25-2006 10:45 AM

buuuuuump

JD 11-20-2006 10:33 AM

buuuuump just got hit AGAIN today

RobV 11-20-2006 10:59 AM

Quote:

Originally Posted by SPeRMiNaToR (Post 11353012)
buuuuump just got hit AGAIN today

Just bumping, hopefully someone can figure something out for you.

JD 11-20-2006 11:19 AM

thanks rob

Sosa 11-20-2006 11:26 AM

had the same thing happen, glad to get it fixed though

Kimo 11-20-2006 11:45 AM

this fucker must be stopped!


All times are GMT -7. The time now is 06:16 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123