Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Shawn

Pages: [1] 2 3
1
Trade Pulse Support / Re: How to deal with TP hack
« on: June 11, 2012, 05:20:06 AM »
hire the cleanout package of the soft-com.biz guys, they charge 75$ one time fee for the cleanout and they keep monitoring your box for hacks for some time after it,
How'd you get that price?  They are charging me 25/hour

2
Trade Pulse Support / Re: How to deal with TP hack
« on: June 06, 2012, 11:30:31 AM »
I'm not real interested in paying yet more money for someone to just run a scanner unless they've got some real insight into how to remove all this hackers files.
I moved to mojohost awhile ago and they've managed to create custom signatures for the scanners that automatically stop this guy so they've been pretty good except for a week or two ago he used something new that took them a day to figure out which is why I figured these soft-com guys would be worth a try but so far all I've seen is their scanners find the same files and then email them rather then auto fixing stuff.

3
Trade Pulse Support / Re: How to deal with TP hack
« on: June 06, 2012, 08:52:15 AM »
I'm not real impressed with soft-com guys.  so far they seem to have done exactly what my host already does and then try and upsell me 'optimization' services.  and it took them 8 hours to clean my server at $25/hour that seems steep to just run a scanner.  I thought they had some specific knowledge about how to find this guys shells scripts but doesn't look that way.

4
I get the following error for some but not all my sites when looking at Network > Stats
Strict Standards: Non-static method TP_Crypt::endecrypt() should not be called statically in /domain.com/tp/gs.php

Any idea?  The gs.php files are 644 and 51kb, both on the sites that show stats and the ones that don't....

5
I use <?php virtual("/tp/ssi_in.php")?>
I put it in the header template... although I'm running an older bunny version, if you are running new ones maybe that's the problem.

6
Seems up now

7
Trade Pulse Support / Re: New update available everyday!
« on: March 13, 2012, 07:17:05 PM »
I just got a notice from my host that the tp/geoip.inc file had been attacked and the base 64 injection on them so I'd suggest taking a close look.  I've been unable to run the full clean and lock procedure up until now so that explains why mine happened, unsure about your situation.

8
Keep me updated, kthnx

9
Trade Pulse Change Log / Re: TP Version 1.0.9 build 44
« on: March 05, 2012, 09:11:17 AM »
Awesome!
I ran the updater manually on each domain but then I ran a massupdate and it changed the vtop.php permissions, any idea why that happened?  I redid each one manually before asking to lock the files just in case.

10
Trade Pulse Support / Re: build 43 / hacked again
« on: February 28, 2012, 04:57:56 PM »
I found malicious code outside of tp scattered in various domains that didn't even have tp.  So I'd check out everything if you can...

11
Trade Pulse Support / Re: build 43 / hacked again
« on: January 31, 2012, 12:42:19 PM »
I've noticed the newer injected ads seem to only appear for me once but other people get them repeatedly and the search engines and browsers throw warnings, guess the hackers getting smarter.

12
Trade Pulse Support / Re: build 43 / hacked again
« on: January 30, 2012, 04:22:03 PM »
And the ads are back again.  Ran scanner, No wrong files found.
Ran scan.php Scan was completed 15370 d 0:14:29 ago. No suspicious code found
And yet it's there, google's nice enough to give my sites a virus warning now so no wonder my sales suck.

Once I delete tpupdater.php and rerun the massupdate it downgrades to Version 1.0.6 build 35, reupgrading to current version works then but scanner now finds twilight_loader.php file  I'll send that to kildoozer

13
Trade Pulse Support / Re: build 43 / hacked again
« on: January 23, 2012, 10:23:51 AM »
I'm still finding files scattered throughout tp that shouldn't be there, scanner doesn't notice them at all....

14
Trade Pulse Support / Re: build 43 / hacked again
« on: January 23, 2012, 09:24:31 AM »
I've got similar problems even after kildoozer ran the scan and removed a bunch of php shells.  Now my host is saying
"It is injected through filter.

tp is not sanitizing input, and, since it is ioncube encoded, difficult to say where the injection occurs.

I found a number of iframes and javascripts in pt_request - which appears to be a partner request form. Since they aren't validating info there, I would suspect they aren't validating it anywhere."

15
Just did the manual update and now I get Updates not available currently (error code: 2)

Pages: [1] 2 3