Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Site hacked! Found "base64" in 2 files
#6
I'm trying to investigate deeper by using the firefox plugin "TamperData", which give you all the request done by the browser.
__

Here is the last request to your website, and the first one to hotglass :


Code:
18:01:59.898[202ms][total 202ms] État: 200[OK]
GET http://psewer.com/?id=forms Indicateurs chargement[LOAD_DOCUMENT_URI  LOAD_INITIAL_DOCUMENT_URI  ] Taille contenu[-1] Type Mime[text/html]
  En-têtes requête:
     Host[psewer.com]
     User-Agent[Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0]
     Accept[text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8]
     Accept-Language[fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3]
     Accept-Encoding[gzip, deflate]
     DNT[1]
     Referer[http://psewer.com/?id=frequently-asked-questions]
     Connection[keep-alive]
  En-têtes réponse:
     Date[Sat, 05 Mar 2016 17:02:00 GMT]
     Content-Type[text/html]
     Server[Microsoft-IIS/6.0]
     X-Powered-By[ASP.NET]
     Vary[Accept-Encoding]
     Transfer-Encoding[chunked]


18:02:00.136[1033ms][total 5108ms] État: 200[OK]
GET http://www.hotglasses.us/#psewer.com Indicateurs chargement[LOAD_DOCUMENT_URI  LOAD_INITIAL_DOCUMENT_URI  ] Taille contenu[-1] Type Mime[text/html]
  En-têtes requête:
     Host[www.hotglasses.us]
     User-Agent[Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0]
     Accept[text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8]
     Accept-Language[fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3]
     Accept-Encoding[gzip, deflate]
     DNT[1]
     Referer[http://www.hotglasses.us/]
     Cookie[__cfduid=dd50a9736e3ef8112b64553f77f1d2fd91457195326; cookie_test=please_accept_for_session; zenid=8addf2d3e3eed50eb5af2931942e252d]
     Connection[keep-alive]
  En-têtes réponse:
     Date[Sat, 05 Mar 2016 17:02:01 GMT]
     Content-Type[text/html; charset=iso-8859-1]
     Transfer-Encoding[chunked]
     Connection[keep-alive]
     X-Powered-By[PHP/5.3.29]
     Set-Cookie[cookie_test=please_accept_for_session; expires=Mon, 04-Apr-2016 17:04:30 GMT; path=/; domain=www.hotglasses.us]
     Expires[Thu, 19 Nov 1981 08:52:00 GMT]
     Cache-Control[no-store, no-cache, must-revalidate, post-check=0, pre-check=0]
     Pragma[no-cache]
     Vary[Accept-Encoding,User-Agent]
     Server[cloudflare-nginx]
     CF-RAY[27ef2217431f25fe-MRS]

edit : did some more tests, many times I'm redirected on hotglass. This can happen from any pages of the site. Can't really find anything usefull. Here is a screenshot of the wireshark-like plugin I mentionned before : http://nsa37.casimages.com/img/2016/03/0...692481.jpg
Just a thing : each time I'm redirected to hotglass site, It first start to load the normal page I asked for, then switch to hotglass. Something like if their was a <meta http-equiv="Refresh" content="0; url=http://hotglass...." />
But there is not any header like this one in your page, so please check carefully your .htaccess
And enable debug mode! (http://get-simple.info/forums/showthread.php?tid=877)


Plz tell us if you find the trick!
__
Contact me if you need a french translation file for your plugin.
Reply


Messages In This Thread
RE: Site hacked! Found "base64" in 2 files - by Charpy1 - 2016-03-06, 02:50:57



Users browsing this thread: 1 Guest(s)