Author Topic: out.php looks infected  (Read 7168 times)

0 Members and 1 Guest are viewing this topic.

Offline gerd

  • Newbie
  • *
  • Posts: 8
    • View Profile
out.php looks infected
« on: February 18, 2011, 08:59:49 AM »
this week i realised that every second time when I clicked on a thumb i got redirected to http://itrxx.com/fr.php.
first i thought smart thumbs was hacked. but it was not.

then i replaced trade pulse with a different trade script and the redirect was completely gone.
so i have disabled trade pulse completely now on my server.

my tp/out.php looks infected.
i have attached the file to this thread.


might it be possible that this file is infected?
maybe you could give me some tips that this will not happen again.

Offline Andrew

  • Full Member
  • ***
  • Posts: 114
    • View Profile
Re: out.php looks infected
« Reply #1 on: February 18, 2011, 03:50:47 PM »
Well I'm not from TP but for a start there must be something odd going on because out.php is supposed to be Zend encoded - and the attached file is not.

Personally I would delete that TP install asap and do a fresh install from the scriptpulse site - and check that the files are properly encoded

Offline ip0li

  • miSearkXD
  • Administrator
  • Hero Member
  • *****
  • Posts: 1952
    • View Profile
    • Premier Сasual Dating Real-life Girls
Re: out.php looks infected
« Reply #2 on: February 19, 2011, 03:02:52 AM »
Hi, this exploit happens because of other scripts on your server and it simply targets TP out.php since its used on MANY sites with MANY traffic hence attack makes sense.

To solve this issue ask your host to secure your server, update all scripts to latest versions, remove unneeded scripts and make sure all is 500% clean before doing UPDATE of tp, you can update TP by going into tools/updater, and it will replace out.php with original one.