Re: I found something in snarkpit's code
Posted by Crono on
Tue Jun 17th 2008 at 4:47am
Crono
super admin
6628 posts
700 snarkmarks
Registered:
Dec 19th 2003
Location: Oregon, USA
It looks like someone (or rather a bot) got access to the php files and added some generation code, they added a giant list of links (somewhere around 300) and they're all marked as hidden. They're at the very end of the HTML generation on, at least, index.php and forum.php.
Might want to see what's going on guys.
Blame it on Microsoft, God does.
Re: I found something in snarkpit's code
Posted by RedWood on
Tue Jun 17th 2008 at 5:00am
RedWood
member
719 posts
652 snarkmarks
Registered:
Sep 13th 2006
Hay! What the hell!? The Snark Pit has been hiding the horse and incest porn form me. No fair!
What would be the purpose of this? Does it give clicks to someone some how?
Reality has become a commodity.
Re: I found something in snarkpit's code
Posted by larchy on
Tue Jun 17th 2008 at 7:19am
larchy
fluffy teim
super admin
496 posts
87 snarkmarks
Registered:
Jan 14th 2008
Occupation: kitten fluffer
Location: UK
Gwil asked me to take a look at the errors that were appearing over the last few days - sorted the problems there.
Saw this and decided to take a look too.
The following line had been inserted into the file footer.php:
Basically that is a function that decrypts the encapsulated string. It returns the html code for those sites which you found.
According to the file timestamps footer.php was modified on 13th May
I have removed the offending line of code, and would suggest Gwil checks out who has ftp access to the host as that really is a very, very strange thing to happen.
Re: I found something in snarkpit's code
Posted by Gwil on
Tue Jun 17th 2008 at 10:12am
Posted
2008-06-17 10:12am
Gwil
super admin
2864 posts
315 snarkmarks
Registered:
Oct 13th 2001
Occupation: Student
Location: Derbyshire, UK
Very strange indeed. Needless to say all passwords have been changed (double changed even) since May, so whoever found a way hopefully won't be able to again. My only other thought is that someone perhaps got round Globats security and added it to all their httpdocs/page.php files.
Re: I found something in snarkpit's code
Posted by Crono on
Wed Jun 18th 2008 at 4:02am
Crono
super admin
6628 posts
700 snarkmarks
Registered:
Dec 19th 2003
Location: Oregon, USA
Gotta love hex encoding, not really.
Glad you found it.
Blame it on Microsoft, God does.
Re: I found something in snarkpit's code
Posted by larchy on
Thu Jun 19th 2008 at 1:58pm
larchy
fluffy teim
super admin
496 posts
87 snarkmarks
Registered:
Jan 14th 2008
Occupation: kitten fluffer
Location: UK
I've taken a look and there are two database tables corrupted again - this time 'sessions' (again) and 'comments' (thats what the problems were the other day, albeit with different tables IIRC )
Unfortunately mysql doesn't seem able to repair them this time, returning an error that is unable to write to or modify the files for these tables (Mysql errno 28)
This error code indicates that the server has run out of space on whatever partition mysql is using - so time to fwap globat :/
Re: I found something in snarkpit's code
Posted by larchy on
Thu Jun 19th 2008 at 3:56pm
larchy
fluffy teim
super admin
496 posts
87 snarkmarks
Registered:
Jan 14th 2008
Occupation: kitten fluffer
Location: UK
Fixed.... for the time being.
Re: I found something in snarkpit's code
Posted by Gwil on
Thu Jun 19th 2008 at 5:45pm
Gwil
super admin
2864 posts
315 snarkmarks
Registered:
Oct 13th 2001
Occupation: Student
Location: Derbyshire, UK
Thanks again larchy, you are a truly a prince among men. Also, the new black theme on the beta site looks fantastic, definitely will be me style of choice when we make the full migration - white can be oppressive on the eyes after a while (it still looks good though!)
Re: I found something in snarkpit's code
Posted by Crono on
Fri Jun 20th 2008 at 7:18pm
Crono
super admin
6628 posts
700 snarkmarks
Registered:
Dec 19th 2003
Location: Oregon, USA
Blame it on Microsoft, God does.