По ссылке из поисковика открывает левую страницу

Discussion in 'Вопросы безопасности' started by klenov, Jun 13, 2012.

  1. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    По ссылке из поисковика открывает левую страницу. Что делать где капать и что искать. Помогите.
     
  2.  
  3. Offline

    Airis Недавно здесь

    Joined:
    Mar 13, 2010
    Messages:
    452
    Likes Received:
    18
    Gender:
    Female
    Просмотрите сайт на наличие вирусов и той ссылки на которую ведет поисковик.
     
  4. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    Простите за глупый вопрос но чем посмотреть.
     
  5. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    Все файлы js and .htaccess
    И поищи код base64_decode в файлах
     
  6. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    Смотреть как я понял ручками и глазками...?
     
  7. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    На хостинге- сканер http://joomla-support.ru/post152220-25.html
    Или скачать на комп,если антивирусник не выявит при скачивании,то
    Notepad++ - поиск в файлах,указать директорию
     
  8. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    Search "base64_decode" (10169 hits in 882 files)
    анитивирус DR.Web ни чего не нашел в папке сайта

    онлайн сканером нашлось вот что
    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/worldpay_notify.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html/shop.recommend.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html/checkout.without_register_form.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html/basket.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html/ro_basket.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html/store.payment_method_keychange.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html__/shop.recommend.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html__/checkout.index.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html__/ro_basket.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html__/store.payment_method_keychange.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/htmlTools.class.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_userfield.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_user.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_shopper.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_html.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/payment/ps_paypal_api.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_main.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_config.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/menuBar.class.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_checkout.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/ps_product_category.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/classes/request.class.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html_old/shop.recommend.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html_old/checkout.index.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html_old/basket.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html_old/ro_basket.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/html_old/store.payment_method_keychange.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_virtuemart/notify.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_content/admin.content.html.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_akeeba/views/buadmin/view.html.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_trash/admin.trash.html.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/administrator/components/com_xmap/ajaxResponse.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/libraries/joomla/html/toolbar/button/confirm.php
    String:: confirm(

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/libraries/joomla/environment/request.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/components/com_virtuemart/themes/jv-shop/templates/checkout/login_registration.tpl.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/components/com_virtuemart/themes/default/templates/checkout/login_registration.tpl.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/components/com_mailto/controller.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/inst/includes/xajax/xajax.inc.php
    String:: $_POST[

    File: /home/users1/t/top-shoping/domains/dslrshop.ru/inst/template/tmpl/mainconfig.html
    String:: confirm(

    Done
     
  9. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    Ну иди на ресурс,которые расшифровывают base64_ .А то можно удалить и нужные закодированные вставки.
    Выложи в архиве js.файлы редактора
     
  10. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    какие конкретно...прости я новичок...чайник одним словом:D
     
  11. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    /media/system/js и из папки шаблона /template/you_template/js
     
  12. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
  13. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    Чисто. Выложи index.php и .htaccess . Отключи в браузере яваскрипт,и попробуй свой сайт в поиск.
     
  14. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
  15. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    клубный шаблон- откуда взял,покупал ?
    теперь нужно defines.php , framework.php
     
  16. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    какие конкретно их несколько:)или все?
     
  17. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    где структура шаблона прописана <body></body> или смотри сам в них base64_decode and display:none
    еще смотри /logs/access.log and error.log
     
  18. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    эххххх....вот же заморочка....караул....спасибо за помощь и советы....
     
  19. OlegK
    Offline

    OlegK Russian Joomla! Team Staff Member ⇒ Профи ⇐

    Joined:
    Jan 17, 2011
    Messages:
    7,812
    Likes Received:
    771
    Gender:
    Male
    Еще вариант- тянешь скрипт с рекламы,партнёрки
     
  20. Offline

    klenov Недавно здесь

    Joined:
    Sep 21, 2011
    Messages:
    16
    Likes Received:
    0
    Gender:
    Male
    так вот нету рекламы на сайте
     

Share This Page

Loading...