I have an adult site that was hacked and caused my account to be suspended yesterday he got in and changed my index.php page to the following:
The portion of this script I find most disturbing is:
I'm wondering what sort of nastyness is in this script!!!
If he was able to get in witch I have to think was pretty easy for him where else did he leave this bundle of joy inside my site???
How do I secure my site from these assholes, its written in PHP and I don't know what to do from here.
Can I get some help please
Keith
PHP:
<html xmlns="http://www.w3.org/1999/xhtml">
<link rel="shortcut icon" type="image/png" href="https://fbcdn-sphotos-d-a.akamaihd.net/hphotos-ak-snc7/399305_118448341652178_1642885313_n.jpg" />
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>~Hacked By Grey D0R43M0N~</title>
<br/>
<blink><font face="snap itc" size="8" color="red" class="a">HACKED </font><font face="Chiller" size="6" color="yellow" class="a">BY</font><font face="Nosifer" size="7" color="gray" class="a"> Grey </font><font face="Nosifer" size="8" color="green" class="a">D0r43m0n</font></blink>
<meta name="Description" content="Grey D0r43m0n">
<script language="JavaScript">
</script>
<script language="javascript">
var text='Grey D0r43m0n WAS HERE';
var delay=5;
var Xoff=0;
var Yoff=-30;
var txtw=10;
var beghtml='<font face="Agency FB" color="#FFFFFF" style="" size="4em"><b>';
var endhtml='</b></font>';
ns4 = (navigator.appName.indexOf("Netscape")>=0 && document.layers)? true: false;
ie4 = (document.all && !document.getElementById)? true : false;
ie5 = (document.all && document.getElementById)? true : false;
ns6 = (document.getElementById && navigator.appName.indexOf("Netscape")>=0 )? true: false;
var txtA=new Array();
text=text.split(');
var x1=0;
var y1=-50;
var t=';
for(i=1;i<=text.length;i++){
t+=(ns4)? '<layer left="0" top="-100" width="'+txtw+'" name="txt'+i+'" height="1">' : '<div id="txt'+i+'" style="position:absolute; top:-100px; left:0px; height:1px; width:'+txtw+'; visibility:visible;">';
t+=beghtml+text[i-1]+endhtml;
t+=(ns4)? '</layer>' : '</div>';
}
document.write(t);
function moveid(id,x,y){
if(ns4)id.moveTo(x,y);
else{
id.style.left=x+'px';
id.style.top=y+'px';
}}
function animate(evt){
x1=Xoff+((ie4||ie5)?event.clientX+document.body.scrollLeft:evt.pageX);
y1=Yoff+((ie4||ie5)?event.clientY+document.body.scrollTop:evt.pageY);
}
function getidleft(id){
if(ns4)return id.left;
else return parseInt(id.style.left);
}
function getidtop(id){
if(ns4)return id.top;
else return parseInt(id.style.top);
}
function getwindowwidth(){
if(ie4||ie5)return document.body.clientWidth+document.body.scrollLeft;
else return window.innerWidth+pageXOffset;
}
function movetxts(){
for(i=text.length;i>1;i=i-1){
if(getidleft(txtA[i-1])+txtw*2>=getwindowwidth()){
moveid(txtA[i-1],0,-100);
moveid(txtA[i],0,-100);
}else moveid(txtA[i], getidleft(txtA[i-1])+txtw, getidtop(txtA[i-1]));
}
moveid(txtA[1],x1,y1);
}
window.onload=function(){
for(i=1;i<=text.length;i++)txtA[i]=(ns4)?document.layers['txt'+i]:(ie4)?document.all['txt'+i]:document.getElementById('txt'+i);
if(ns4)document.captureEvents(Event.MOUSEMOVE);
document.onmousemove=animate;
setInterval('movetxts()',delay);
}
</script>
<center>
<style>
body {cursor:cross;
background: #000000 url(http://www.alboraaq.com/jpg/CpD39032.gif) scroll repeat center center;
</style>
<style>
body{text-align;font-family: 'Averia Sans Libre', cursive;}
hr{border: 1px solid #1C1C1C;}
</style>
<style type="text/css">
body,td,th {
color: #FFFFFF;
}
body {cursor:url("http://www.fbvideo.16mb.com/files/cur.cur"),default;
background-color: #000000;
}
a { text-decoration:none; }
a:link { color: #00FF00}
a:visited { color: #00FF00}
a:hover { color: #00FF00}
a:active { color: #00FF00}
.style2 {Helvetica, sans-serif; font-weight: bold; font-size: 15px; }
.style3 {Helvetica, sans-serif; font-weight: bold; }
.style4 {color: #FFFF00}
.style5 {color: #FF0000}
.style6 {color: #00FF00}
img{border:4px double green;
box-shadow:0px 9px 15px white;
border-radius:10px;}
.thanks{border:4px double green;
box-shadow:0px 2px 20px white;
border-radius:10px;
padding:9px;}
.a{text-shadow:0px 1px 10px lime;}
</style>
</head>
<body>
<script language="JavaScript1.2">var rector=3
var stopit=0
var a=1
function init(which){
stopit=0
shake=which
shake.style.left=0
shake.style.top=0
}
function
rattleimage(){
if ((!document.all&&!document.getElementById)||stopit==1)
return
if (a==1){
shake.style.top=parseInt(shake.style.top)+rector+"px"
}else if (a==2){
shake.style.left=parseInt(shake.style.left)+rector+"px"
}
else if (a==3){
shake.style.top=parseInt(shake.style.top)-rector+"px"
}else{
shake.style.left=parseInt(shake.style.left)-rector+"px"
}
if (a<4)
a++
else
a=1
setTimeout("rattleimage()",10)
}
function stoprattle(which){
stopit=1
which.style.left=0
which.style.top=0
}</script><style type="text/css"><!--
body,td,th {;
text-align: center;
} {
color: #0C3;
font-size: 20px;
}
body {}
.shakeimage{
position:relative
}
.glow {}
.contact {
}{}
.lol {}
#owned{_top:expression(document.documentElement.scrollTop+document.documentElement.clientHeight-this.clientHeight);
_left:expression(document.documentElement.scrollLeft + document.documentElement.clientWidth - offsetWidth);
}
a:l--></style>
<center><img alt="" src="http://sphotos-b.xx.fbcdn.net/hphotos-ash3/p206x206/540456_108180799354338_730264429_n.jpg" width="45%" height="45%"" border="0" class="shakeimage" onMouseover="init(this);rattleimage()"
onload="init(this);rattleimage()"></a></span></center>
<center>
</br></br></br>
<a style="display:scroll;position:fixed;bottom:5px;right:5px;" href="http://www.facebook.com/Grey.D0r43m0n" title="Freedom Palestine , Vanish Israhell"><img src="http://i49.tinypic.com/mrnmu.gif" width="450" height="90" /></a>
</div>
<hr />
<span class="a"> Hello Admin , We hacked because your security website need to patch. Contact us if you need something to discuss ! </span><br>
<span class="style4"> Contact Us</span><br />
<span class="style6"><a href="https://www.facebook.com/BDGREYHATHACKERS"> BGHH </a></span><br><br>
<hr />
<center>
<a target=blank href="https://www.facebook.com/BDGREYHATHACKERS" style="text-decoration: none"><font color=#A8A5A5 size=2>
<b><blink>[+] WE ARE BD GREY HAT HACKERS [+]</blink></b></font></a></font></p>
</center>
</script>
<!-- HTML Codes by Grey D0r43m0nn -->
</a></p><p style="font-size: 11px;">
</p><p align="center"><a><font color="#1D00DA"><b><i><i></i></i></b><i><i></i></i></font></a></p>
<p align="center"><a><i><i><font color="#1D00DA"><b><i><i></i></i></b><i><i></i></i></font></i></i></a></p>
<!--TEXT SMART-->
<script language="javascript">
// ENTER TEXT BELOW. CAN *NOT* INCLUDE NORMAL HTML CODE.
var text='-=Grey D0r43m0n=-';
var delay=40; // SPEED OF TRAIL
var Xoff=0; // PIXEL COUNT FROM THE LEFT OF THE CURSOR (- VALUES GO TO LEFT)
var Yoff=-30; // PIXEL COUNT FROM THE TOP OF THE CURSOR (- VALUES GO UP)
var txtw=14; // AMOUNT OF PIXEL SPACE EACH CHARACTER OCCUPIES
var beghtml='<font color="#F8E801 "><b>'; // OPTIONAL HTML CODE THAT EFFECTS WHOLE TEXT STRING SUCH AS FONT COLOR, SIZE, ETC.
var endhtml='</b></font>'; // END HTML CODE. MOSTLY USED IF ABOVE SETTING IS USED.
//********** NO NEED TO EDIT BELOW HERE **********\\
ns4 = (navigator.appName.indexOf("Netscape")>=0 && document.layers)? true : false;
ie4 = (document.all && !document.getElementById)? true : false;
ie5 = (document.all && document.getElementById)? true : false;
ns6 = (document.getElementById && navigator.appName.indexOf("Netscape")>=0 )? true: false;
var txtA=new Array();
text=text.split('');
var x1=0;
var y1=-1000;
var t='';
for(i=1;i<=text.length;i++){
t+=(ns4)? '<layer name="txt'+i+'" top="-100" left="0" width="'+txtw+'" height="1">' : '<div id="txt'+i+'" style="position:absolute; top:-100px; left:0px; height:1px; width:'+txtw+'; visibility:visible;">';
t+=beghtml+text[i-1]+endhtml;
t+=(ns4)? '</layer>' : '</div>';
}
document.write(t);
function moveid(id,x,y){
if(ns4)id.moveTo(x,y);
else{
id.style.left=x+'px';
id.style.top=y+'px';
}}
function animate(evt){
x1=Xoff+((ie4||ie5)?event.clientX+document.body.scrollLeft:evt.pageX);
y1=Yoff+((ie4||ie5)?event.clientY+document.body.scrollTop:evt.pageY);
}
function getidleft(id){
if(ns4)return id.left;
else return parseInt(id.style.left);
}
function getidtop(id){
if(ns4)return id.top;
else return parseInt(id.style.top);
}
function getwindowwidth(){
if(ie4||ie5)return document.body.clientWidth+document.body.scrollLeft;
else return window.innerWidth+pageXOffset;
}
function movetxts(){
for(i=text.length;i>1;i=i-1){
if(getidleft(txtA[i-1])+txtw*2>=getwindowwidth()){
moveid(txtA[i-1],0,-1000);
moveid(txtA[i],0,-1000);
}else moveid(txtA[i], getidleft(txtA[i-1])+txtw, getidtop(txtA[i-1]));
}
moveid(txtA[1],x1,y1);
}
window.onload=function(){
for(i=1;i<=text.length;i++)txtA[i]=(ns4)?document.layers['txt'+i]:(ie4)?document.all['txt'+i]:document.getElementById('txt'+i);
if(ns4)document.captureEvents(Event.MOUSEMOVE);
document.onmousemove=animate;
setInterval('movetxts()',delay);
}
</script>
<script type='text/javascript'>
var DADrightclicktheme = 'Dark';
var DADrightclickimage = 'http://i42.tinypic.com/69josm.jpg';</script>
<script type='text/javascript' src="http://tuyulz-blogspot.googlecode.com/files/Anti%20Klik.js"> </script>
<body oncontextmenu='return false;' onkeydown='return false;' onmousedown='return false;'>
<SCRIPT LANGUAGE="JavaScript">
<!-- Disable
function disableselect(e){
return false
}
function reEnable(){
return true
}
//if IE4+
document.onselectstart=new Function ("return false")
document.oncontextmenu=new Function ("return false")
//if NS6
if (window.sidebar){
document.onmousedown=disableselect
document.onclick=reEnable
}
//-->
</script>
<center><font face= 'tahoma' class='wglow' color='white'>Greetz To:</font><center>
<marquee>
<font class='whiteglow' face='tahoma'> | </font>
<font face='tahoma' color='green' class='wglow'>Bd Xtor - TiGER-M@TE - Rotating Rotor - cr4ck br4iN - Ablaze ever - Mahayrab Ferdous - Krad X!n - Murkho Manob - Core Tuner - Red Core </font>
<font class='whiteglow' face='tahoma'> || </font>
<font face='tahoma' color='red' class='redglow'>Ashik Iqbal - Space Fighter - B|_@CK J4CK - Black Man - Reza BGHH </font>
<font class='whiteglow' face='tahoma'> || </font>
<font face='tahoma' color='green' class='redglow'>Sharif BGHH - Ly Ly - Dr@cul@ - Fakessh - R3D Dr4G0N - Ac3@n - r00t3xpl0i7 ~ Kp ~ ShopnoPathik Aion </font>
<font class='whiteglow' face='tahoma'> || </font>
<font face='tahoma' color='orange' class='wglow'>ALL BANGLADESHI HACKERS!</font>
<font class='whiteglow' face='tahoma'> || </font>
<font face='tahoma' color='purple' class='blueglow'>ALL MUSLIM HACKERS</font>
<font class='whiteglow' face='tahoma'> || </font>
<font face='tahoma' color='white' class='wglow'>And Also u Admin</font>
<font class='whiteglow' face='tahoma'> | </font>
</marquee>
</b>
<div align="center" class="shdw">Remember we can see you</div><br /><div align="center"><img src="http://www.123myip.co.uk/ip-address/?size=468x60" border="0" width="500" height="60" alt="BDGHH" /></div>
<font color="purple">
<div align="center">Copyright © <span>BD GREY HAT HACKERS</span>. All rights Reserved.</div></font>
<script>
<!-- Made By Grey D0r43m0n --> </body></html>
The portion of this script I find most disturbing is:
PHP:
<script type='text/javascript' src="http://tuyulz-blogspot.googlecode.com/files/Anti%20Klik.js"> </script>
I'm wondering what sort of nastyness is in this script!!!
If he was able to get in witch I have to think was pretty easy for him where else did he leave this bundle of joy inside my site???
How do I secure my site from these assholes, its written in PHP and I don't know what to do from here.
Can I get some help please
Keith