News:

Wondering if this will always be free?  See why free is better.

Main Menu

runtime error

Started by iain sherriff, January 24, 2014, 06:41:36 AM

Previous topic - Next topic

iain sherriff

will the host be able to tell where it came from ?
SMF 2.0.12

Arantor

Maybe. Ask them.

@Shambles: it is not wrong to appreciate the subtlety and ingenuity of something like that. I just wish they'd channel their skills into producing new good software rather than attacking things.

iain sherriff

Im a bit at arms length as I Admin the forum, have FTP access but not CP or dB access. The host is looking at it.
I have gone through what I can and removed all traces I can see.
The forum is for a business that is subject to a lot of flack from trolls and has been attacked before unfortunately.
SMF 2.0.12

iain sherriff

I've just realised the bit about one line  :o
that is sneaky
SMF 2.0.12

Arantor

Not just the fact it's on one line, it's one line - but with enough spaces that to the casual observer, you'd never notice anything was amiss. When I first looked at it in Notepad++, I thought... there's something weird here, because I couldn't *immediately* see something awry.

iain sherriff

that code was in every index.php file.

SMF 2.0.12

kat

Quote from: Sir Cumber-Patcher on January 24, 2014, 06:33:33 PMI couldn't *immediately* see something awry.

When I looked, it was the fact that the scrollbar, at the bottom, indicated that there was a LONG line, somewhere, that gave me the hint. So, I whacked it over to the far-right and voila! There it was.

iain sherriff

I cottoned onto that in the end. Also the file size was way too big.
I thnik it is all OK now...........just not sure if the dB and server will be infected but that is being checked
SMF 2.0.12

kat

Do yourself a favour, Iain... Read my sig. ;)

Click it, for the "How?". :)

If you think it's clean, do it right now.

You know you want to.

iain sherriff

SMF 2.0.12

kat

Only the one? ;)

Seriously, I take two, now, in case one's corrupt. Especially when I get the db.

iain sherriff

OK
Have to rely on the owner to get the dB
SMF 2.0.12

kat

Make sure he does something. Regularly. Your forum can be rebuilt, easily enough. But, the database, which stores all of your members, posts, &c?

Not so easy. (Fookin' difficult, really)

iain sherriff

I know it is regularly backed up by the host. Going to see if I can get phpmyadmin access after this.
SMF 2.0.12

kat


iain sherriff

K@  I have PMd you about this.
SMF 2.0.12

kat

Goddit. :)

I don't see anything weird, though. Does one have to be logged-in?

iain sherriff

Nothing shows visually and it seems to behave as it should. I assume the code is some sort of data harvesting ?
SMF 2.0.12

kat

You're getting that some chunk of code, in index.php, are you?

Might be an idea to have a word with your host. They should have raw access logs and be able to figure-out who's getting in and how.

iain sherriff

It's exactly the same as you saw at the start of this topic, in every index.php.

Host is looking at it now.
SMF 2.0.12

Advertisement: