TalkPHP
 
 
Account Login
Latest Articles
» The basic usage of PHPTAL, a XML/XHTML template library for PHP
» Vulnerable methods and the areas they are commonly trusted in.
» Simple way to protect a form from bot
» The Basics On: How Session Stealing Works
» How to keep your forms from double posting data
IRC Channel
IRC Speech Bubble Join the friendly bunch on IRC...
(#TalkPHP on Freenode)

...Also available via a web interface.

See this thread for information on the TalkPHP Free Hugs Initiative™. Subject to availability.
Associates
Associates
CSS Tutorials
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 06-12-2009, 09:19 PM   #21 (permalink)
The Contributor
 
cecilia's Avatar
 
Join Date: May 2009
Location: LA, CA
Posts: 93
Thanks: 0
cecilia is on a distinguished road
Default

No I dont use anything else, I write it myself all of it. .. wait...

I just checked it, there is something its this Fantastico SMF Discussion board that we never really used, I just tried to see what it looks like and forgot to remove it. Im removing this NOW. It also says theres an update for it.

This I guess has been a fault of mine too. Honestly, I dismissed the thought that the site could be attacked through something that Im getting from my web host. That if it would be its from my own scripting.

Ive been thinking about it. The iframes may point to other locations outside of lunarpages but maybe the agent thats actually spreading it is from a site hosted by lunarpages and is affecting its neighbors somehow.

Well, I didnt get attacked today atleast thats cool. Ill still check the index everyday at different intervals I guess.

As for logging, I will start to do something like that now. Im getting tired of this really. Ill add things to the login page too, things that ive always wanted to put but never had the time.
cecilia is offline  
Reply With Quote
Old 06-13-2009, 01:05 AM   #22 (permalink)
The Acquainted
 
Randy's Avatar
 
Join Date: May 2007
Location: Your G/F's Closet
Posts: 114
Thanks: 7
Randy is on a distinguished road
Default

Fantastico is technically not on LunarPages side, it is a 'plugin' for cPanel so it would be on their end but if they got in via phpbb then it was phpbb's scripting, still looking into this myself.
__________________
Real Programmers always confuse Christmas and Halloween because Oct31 == Dec25 - Andrew Rutherford
Send a message via AIM to Randy Send a message via MSN to Randy
Randy is offline  
Reply With Quote
Old 06-14-2009, 06:49 AM   #23 (permalink)
The Acquainted
 
Randy's Avatar
 
Join Date: May 2007
Location: Your G/F's Closet
Posts: 114
Thanks: 7
Randy is on a distinguished road
Default

Same thing has happened to my friend, he is hosted at: vivical hosting. different code different ip but looked into it, seems to be the same basic stuff, all he is running is wordpress.

Avast Forum:
http://forum.avast.com/index.php?topic=45142.0
Google Forum:
http://www.google.com/support/forum/...1cdd4279&hl=en
__________________
Real Programmers always confuse Christmas and Halloween because Oct31 == Dec25 - Andrew Rutherford
Send a message via AIM to Randy Send a message via MSN to Randy
Randy is offline  
Reply With Quote
Old 06-15-2009, 07:44 AM   #24 (permalink)
The Contributor
 
Join Date: Jun 2009
Location: Seattle, WA
Posts: 79
Thanks: 1
rguy84 is on a distinguished road
Default

@Cecila Iam guessing that your server has had a dDOS attack. I would pull your site for now and alert your tech support at your host asap.
__________________
Ryan | Blog | Twitter
Send a message via AIM to rguy84 Send a message via MSN to rguy84 Send a message via Yahoo to rguy84 Send a message via Skype™ to rguy84
rguy84 is offline  
Reply With Quote
Old 06-25-2009, 03:00 PM   #25 (permalink)
The Contributor
 
cecilia's Avatar
 
Join Date: May 2009
Location: LA, CA
Posts: 93
Thanks: 0
cecilia is on a distinguished road
Default

Thank you all for the support. Sorry I was out for a while... just personal problems. Somehow its somewhat simpler to deal with programming problems than those with humans. Just that... somehow theres always a way to fix things and... well this is not supposed ot be for such talks so Ill end it there i guess. So far til my last post I havent been attacked and for that I am glad, all 3 accounts that I manage, uhm 4 now.

Ill look more into this dDOS attack. Though I dont deal with them personally, Id like to know more about it. As for pulling it out I cant. Honestly im starting to consider other webhosts now seriously even if its gonna be such a big hassle to move that thing.
cecilia is offline  
Reply With Quote
Old 06-25-2009, 03:41 PM   #26 (permalink)
La Vida es Sueño
Advanced Programmer Top Contributor 
 
Wildhoney's Avatar
 
Join Date: Sep 2007
Location: Oldham
Posts: 2,215
Thanks: 90
Wildhoney is on a distinguished road
Default

You have a point there, Cecilia. Don't be afraid to share your problems with us We are a community after all! One big family!

Thankfully you've had no more attacks recently. Are you still on the same host? It may be that they simply got an influx of attacks on that particular day.
__________________
The man who comes back through the Door in the Wall will never be quite the same as the man who went out.
Send a message via AIM to Wildhoney Send a message via MSN to Wildhoney Send a message via Yahoo to Wildhoney
Wildhoney is offline  
Reply With Quote
Old 06-25-2009, 04:56 PM   #27 (permalink)
Super Moderator
Inquisitive 
 
codefreek's Avatar
 
Join Date: Sep 2007
Location: Near you.
Posts: 687
Thanks: 240
codefreek is on a distinguished road
Default

@Cecilia, i added some highlight to make your code more, readable

Last edited by codefreek : 06-25-2009 at 07:42 PM.
codefreek is offline  
Reply With Quote
Old 06-25-2009, 07:35 PM   #28 (permalink)
The Contributor
 
cecilia's Avatar
 
Join Date: May 2009
Location: LA, CA
Posts: 93
Thanks: 0
cecilia is on a distinguished road
Default

Guess what, after I said its been ok, I found out that it did it again. Another incarnation of this thing was found again at the index.php. Too bad I wasnt able to save a copy. This time I made a ticket to lunarpages.

I read somewhere that these attacks are server farm wide, when they happen. Just one more and im leaving that host.

As for my problems, Ill think about it, but thank you still for the thought.

Codefreek, what do you mean?
cecilia is offline  
Reply With Quote
Old 06-25-2009, 07:45 PM   #29 (permalink)
Super Moderator
Inquisitive 
 
codefreek's Avatar
 
Join Date: Sep 2007
Location: Near you.
Posts: 687
Thanks: 240
codefreek is on a distinguished road
Default

Quote:
Originally Posted by cecilia
Codefreek, what do you mean?
Prettifying Pasted Code on TalkPHP

I, wrapped your code in [highlight] tags..
__________________
I will be Offline for a while, (Working)..

Last edited by codefreek : 06-25-2009 at 07:47 PM. Reason: More Txt Added..
codefreek is offline  
Reply With Quote
Old 07-07-2009, 06:16 PM   #30 (permalink)
The Contributor
 
cecilia's Avatar
 
Join Date: May 2009
Location: LA, CA
Posts: 93
Thanks: 0
cecilia is on a distinguished road
Default

After some more reading it was said that:

It appears to be caused on shared webhosting servers. Infected accounts gain access to change other users files. Doing so changes the ownership of the file to the infected user's account name.

One Solution is to chmod the index.php to 444

I also tried redirecting the domain to another file, the page doesnt even open even if it still gets infected after that.

After reading again, it seems that is what other people are doing too to deal with this problem.

Atleast I have a clear name for it now, I believe this malicious crap is called iframe injection
cecilia is offline  
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
the index File. hello-world Absolute Beginners 1 03-18-2009 02:45 AM
inserting multiple checkbox selections on one row sarmenhb Absolute Beginners 3 01-10-2009 06:32 PM
Inserting New Row With ASP.NET? StevenF MySQL & Databases 7 12-07-2008 11:21 PM
PHP & MySQL Inserting multiple entires from range. Acrylic Absolute Beginners 3 10-02-2008 02:27 AM


All times are GMT. The time now is 11:44 AM.

 
     

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Inactive Reminders By Icora Web Design