Archive for October, 2007
…not to be a worry wart…the problems are mine. I have been dealing with hackers a LOT the past couple of months. Most of the problems have been due to a server level hack on my hosting company’s servers, affecting not just my site, but THOUSANDS of web sites on the companies dozens of servers.
I’ve seen spam appended to hundreds of files, using css code to hide the spam links (the worst hack adding 2508 spam links to nearly every index, login, home, default, auth, and admin file in hundreds of my directories), and I had to edit them by hand.
I’ve just found tonight, in a script I’ve been using for over a year, an URL shortener found here…
that a subfolder of this short URL script had been hacked (I had NO CHMOD 777 folders ANYWHERE on my site), and that the same spam I had been removing from my pages, that were pointing to OTHER hacked sites on mostly .edu college and university websites, was now SOURCING and FORWARDING from my site.
I can not tell you how bloody angry I became at finding this.
The appended spam code was and is looking like this…
< u style=display:none >< a href="http://survivalring.org/url/ 1/2/30/840505780197.html">cheap cialis < a href="http://survivalring.org/url/ 1/2/30/8411792520159.html">order cialis < a href="http://survivalring.org/url/ 1/2/30/8421918768617.html">hydrocodone withdrawal < a href="http://survivalring.org/url/ 1/2/30/potentiate-hydrocodone/">potentiate hydrocodone < a href="http://survivalring.org/url/ 1/2/30/8502024412430.html">cialis compare levitra viagra < a href="http://survivalring.org/url/ 1/2/30/8441589492944.html">levitra vs cialis < a href="http://survivalring.org/url/ 1/2/30/phentermine-without-prescription/">phentermine without prescription < a href="http://survivalring.org/url/ 1/2/30/8471141010198.html">phentermine side effects … and on and on…
It took a good 20 minutes for my FTP program to delete thousands of spam files from that subfolder above at /url/1/2/.
The latest hack that affected me BEFORE this hack was one that hit, again, the index/admin/default/etc php and him files, and REPLACED all of my code with the following code.
Click to continue reading “Not a good day…weekend…or even near future…”






















