News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Parse error: unexpected T_LNUMBER in Subs.php

Started by fabteam, May 01, 2010, 09:18:48 AM

Previous topic - Next topic

fabteam

Hi all

Everything was working fine until one morning I got this message:

Parse error: syntax error, unexpected T_LNUMBER in /homez.158/fabteam/www/forum/Sources/Subs.php  on line 3422

I am using SMF SMF 2.0 RC1-1 and PortaMX mod and attached the Subs.php file to my message.

I have no clue about what happened and I cannot understand what is this issue with line 3422.

Thank you for your help.


CapadY

For me it looks like the file is infected.

Give it a try withe the attached file (rename is to subs.php)
Please, don't PM me for support unless invited.
If you don't understand this, you will be blacklisted.

fabteam

#2
thanks Capady

Now I have this message:

Parse error: syntax error, unexpected T_LNUMBER, expecting ',' or ';' in /homez.158/fabteam/www/forum/Sources/Load.php on line 2029

when you said 'infected' what do you mean ?
my forum has been hacked or something ?

edit: i added Load.php

Kays

That file is probably infected, I can't even download it. Yes there's a good chance that your forum was hacked.

Download the large upgrade package for your version SMF from here. And reupload all of the files in it to your forum overwriting the existing files. This will remove all of the mods you have installed.

Also please see: How do I make my forum safer against hacker attacks?

If at first you don't succeed, use a bigger hammer. If that fails, read the manual.
My Mods

fabteam

ok thank very much you for you reply and your help
I deleted all the .php files

Norv

fabteam: if you don't mind, could you please send it in a security report (link in my signature) - or PM, or post it as I'll remove it as soon as I download it? I would be very interested to take a look at it.
Thank you very much, and sorry for the trouble.
To-do lists are for deferral. The more things you write down the later they're done... until you have 100s of lists of things you don't do.

File a security report | Developers' Blog | Bug Tracker


Also known as Norv on D* | Norv N. on G+ | Norv on Github

CapadY

Quote from: Norv on May 01, 2010, 02:49:58 PM
fabteam: if you don't mind, could you please send it in a security report (link in my signature) - or PM, or post it as I'll remove it as soon as I download it? I would be very interested to take a look at it.

If you are interested, I still have the infected Subs.php on my local computer.

There is a javascript infection in it at two places.
Please, don't PM me for support unless invited.
If you don't understand this, you will be blacklisted.

Norv

To-do lists are for deferral. The more things you write down the later they're done... until you have 100s of lists of things you don't do.

File a security report | Developers' Blog | Bug Tracker


Also known as Norv on D* | Norv N. on G+ | Norv on Github

CapadY

Quote from: Norv on May 01, 2010, 05:36:40 PM
Yes, please. :)

Because I can't add an attachement to a PM I'll post it right here as an attachement. (renamed).

Please, don't PM me for support unless invited.
If you don't understand this, you will be blacklisted.

Norv

Thank you very much capady!
I think there should be no much worries about the file, it can't run properly anyway even if put in a web browser. It's a hack, of course, but at least in this file, not one with much consequences. (except that it gave errors and we could find out about it, well)

fabteam: I would appreciate any other files, or access to them, if it's possible and acceptable. In case you agree, please feel free to send me by PM anything you may wish, FTP access or control panel access included if it's okay. Of course, in case you are not comfortable with it, then please don't.
Any other files from SMF or other web software you may have installed, are appreciated, in any form.
Thank you for considering it.
To-do lists are for deferral. The more things you write down the later they're done... until you have 100s of lists of things you don't do.

File a security report | Developers' Blog | Bug Tracker


Also known as Norv on D* | Norv N. on G+ | Norv on Github

fabteam

ok let me check with my hoster how I can change my ftp lgn/pwd

what do you mean by "security report " ?

smp420

In Norv's signature you will see a link to file a security report.
"Things turn out best for those who make the best of the way things turn out." -Jack Buck

Antechinus

Upgrade to RC3 immediately too. RC1-1 has a lot of security holes.

fabteam

#13
Security report sent

Advertisement: