IndexScript Forum  

Go Back   IndexScript Forum > IndexScript > IndexScript - Directory Script
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #21  
Old 08-01-2007, 12:56 AM
Smotmaheegan Smotmaheegan is offline
Junior Member
 
Join Date: Aug 2007
Posts: 2
Default

Look in the <META KEYWORD> or <META DESCRIPTION> field in your database. The plankton that do this sort of thing generally aren't very bright (even as far as plankton go!) They usually simply run a scipt that embeds a META REFRESH in one of these fields permitted to hold data that is (poorly sanitised and) used as raw HTML.
Reply With Quote
  #22  
Old 08-01-2007, 12:57 AM
Smotmaheegan Smotmaheegan is offline
Junior Member
 
Join Date: Aug 2007
Posts: 2
Default

One more thing. You might be able to evade this sort of outcome if you choose non-standard db prefixes. As mentioned earlier the pond life that do this are not that bright and usually do not consider non-standard prefixes when composing their scripts.
Reply With Quote
  #23  
Old 08-02-2007, 09:45 AM
st1905 st1905 is offline
Junior Member
 
Join Date: Aug 2007
Posts: 6
Default

Thanks to hakon. The stupid morons searching for this allintext: "This site is powered by IndexScript" in google so i decided to do something different for them when they search and come via this referrer to my directory there will be a trojan waiting for them. My site was not patched and was not hacked but every single day i receive this referrers allintext: "This site is powered by IndexScript". I do have my backups and now applied the fix, lets hope morons die very soon.

I really dont know why milworm publishes these things to public? If they find a bug why they dont report it to the author only inspite of giving it to some stupid %0 brain morons (Aka lamers, script kiddies) ?

Thanks to creater of this beautiful script i`ll use it no matter how many idiots around my directory.
Reply With Quote
  #24  
Old 08-03-2007, 04:30 AM
imteaz imteaz is offline
Junior Member
 
Join Date: Sep 2006
Posts: 14
Default

ok i have done all manual code as you said.
but umm can you help me to fix it? please



just to let you know i got hacked 5 days ago. and i noticed it today.
im using index script version 2.4
please help....
__________________
WebHigh General Directory
Reply With Quote
  #25  
Old 08-03-2007, 11:57 AM
techpro techpro is offline
Member
 
Join Date: May 2007
Location: Cumbria UK
Posts: 72
Default

Quote:
Originally Posted by st1905 View Post
i decided to do something different for them when they search and come via this referrer to my directory there will be a trojan waiting for them.
I understand your feelings entirely. I just looked at my weblogs and there are dozens of the b*st*rds. But not everyone searching for this string will necessarily be a hacker. (Actually w*nker might be a more appropriate description, since 99.9% of them will be thinking they are so smart copying the instructions someone else has worked out.) Someone might simply be trying to find how many IndexScript sites there are, or something like th*t.
__________________
Julian Moss
Tech Directory - Ham Directory - Site Backup for cPanel
Reply With Quote
  #26  
Old 08-04-2007, 01:24 PM
st1905 st1905 is offline
Junior Member
 
Join Date: Aug 2007
Posts: 6
Default

Quote:
Originally Posted by techpro View Post
I understand your feelings entirely. I just looked at my weblogs and there are dozens of the b*st*rds. But not everyone searching for this string will necessarily be a hacker. (Actually w*nker might be a more appropriate description, since 99.9% of them will be thinking they are so smart copying the instructions someone else has worked out.) Someone might simply be trying to find how many IndexScript sites there are, or something like th*t.

Most terrible thing is when they search for that string in google my website pops in the first page.(I mean if they search from my location of country)

Thats why i feel really angry for those stupid, no-life people.
Reply With Quote
  #27  
Old 08-04-2007, 04:28 PM
techpro techpro is offline
Member
 
Join Date: May 2007
Location: Cumbria UK
Posts: 72
Default

Yep. The security nerds say there is no such thing as security by obscurity but these copyright strings just make it easy for hackers and spammers to find sites to attack. Too late to prevent the current problem but perhaps some slight change in the wording might help prevent any future attacks. Or of course one could purchase the right to remove it altogether.

I had a SMF Forum once which was plagued by spam and I had a long and hopeless argument with the developers who would not permit the changing of the copyright credit wording by one single byte nor replacing it with a GIF that looked exactly the same but could not be searched for as text.
__________________
Julian Moss
Tech Directory - Ham Directory - Site Backup for cPanel
Reply With Quote
  #28  
Old 08-07-2007, 02:05 PM
hakon hakon is offline
Administrator
 
Join Date: Jan 2006
Posts: 1,682
Default

well, that i'd say is that no script is truly secure... so backup often.
__________________
Get your IndexScript skins HERE
Some other interesting sites: Pneumococcal Diseases | Learn about Colic | Pregnancy Articles | Humor Portal
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 04:09 AM.



Same Author: URL Shortening Script ]

Partners: IT Support Blog | Free Games | iWebzen Web Directory | PR Home Pages Web Directory ]





Powered by vBulletin® Version 3.6.9
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.