NEW #1
Avatar
Zero2Cool Elite Member
Joined: Oct 14, 2006
Posts: 44,952
Avatar
Zero2Cool
Elite Member
Joined:Oct 14, 2006
Posts:44,952
Words can not depict how pissed off I am right now. Someone reported PackersHome.com as a SPAM website, that sends spam.

If I can not find the malicious script, PackersHome.com will be deleted, permanently and I can't do anything about it. Arvixe was nice enough to allow me this time to search for the issue and resolve it.

I'm doing another full site backup as we speak.


This is the email that could end PH.com
MIME element (message/feedback-report)
Encapsulated message (message/rfc822)
Headers of embedded message (message/rfc822)
Delivered-To: x
Received: by 10.90.132.18 with SMTP id f18cs52994agd;
Thu, 13 Jan 2011 18:14:35 -0800 (PST)
Received: by 10.91.8.20 with SMTP id l20mr467016agi.147.1294971275657;
Thu, 13 Jan 2011 18:14:35 -0800 (PST)
Return-Path:
Received: from rhino.arvixe.com (stats.rhino.arvixe.com [74.86.163.xxx])
by mx.google.com with ESMTPS id 1si1480406ano.176.2011.01.13.18.14.35
(version=TLSv1/SSLv3 cipher=RC4-MD5);
Thu, 13 Jan 2011 18:14:35 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of doogie@rhino.arvixe.com designates 74.86.163.xxx as permitted sender) client-ip=74.86.163.xxx;
Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of doogie@rhino.arvixe.com designates 74.86.163.xxx as permitted sender) smtp.mail=xxx@rhino.arvixe.com
Received: from xxxby rhino.arvixe.com with local (Exim 4.69)
(envelope-from )
id 1PdZBT-0004of-PC
for x; Thu, 13 Jan 2011 18:14:35 -0800
To: x
Subject: I've come across an interesting download

X-PHP-Script: www.packershome.com/index.php for 112.201.206.16
Date: Thu, 13 Jan 2011 18:14:35 -0800
From: jotam
Message-ID:
X-Priority: 3
X-Mailer: PHPMailer [version 1.73]
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_211ffbc2d5b41ba727c216efb6a5ec07"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - rhino.arvixe.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [881 878] / [47 12]
X-AntiAbuse: Sender Address Domain - rhino.arvixe.com
0
SlickVision, Methodikal, Kevin and 5 others
NEW #2
Avatar
Pack93z Select Member
Joined: Mar 17, 2007
Posts: 13,278
Avatar
Pack93z
Select Member
Joined:Mar 17, 2007
Posts:13,278
Anything that we can do to help?
0
SlickVision, Methodikal, Kevin and 5 others
NEW #3
Avatar
Zero2Cool Elite Member
Joined: Oct 14, 2006
Posts: 44,952
Avatar
Zero2Cool
Elite Member
Joined:Oct 14, 2006
Posts:44,952
"Pack93z"Anything that we can do to help?


I don't know, man. I'm so pissed off and discouraged right now, its just not good.

I hate spam and hate script kiddies even more.


I don't know what to do. I'm deleting the other software's that I had running and hoping that it was one of them that was the culprit and doing a few other things to prevent a shut down.
0
SlickVision, Methodikal, Kevin and 5 others
NEW #4
Avatar
Zero2Cool Elite Member
Joined: Oct 14, 2006
Posts: 44,952
Avatar
Zero2Cool
Elite Member
Joined:Oct 14, 2006
Posts:44,952
I've done several things behind the scenes to prevent this issue occurring again and one that directly effects each of you. Unfortunately, you will need to enter a numerical security code when you log in to help ensure you're not a robot.

I'm still digging through options and files to see what else I can do.
0
SlickVision, Methodikal, Kevin and 5 others
NEW #5
Avatar
peteralan71 Registered
Joined: Dec 15, 2008
Posts: 1,221
Avatar
peteralan71
Registered
Joined:Dec 15, 2008
Posts:1,221
fuuuuuuuuuuuuuck.
sorry man.
good luck.
0
SlickVision, Methodikal, Kevin and 5 others
NEW #6
Avatar
longtimefan Registered
Joined: Nov 30, 2006
Posts: 3,501
Avatar
longtimefan
Registered
Joined:Nov 30, 2006
Posts:3,501
Just cuz someone reported you as spam the host takes their word for it?
0
SlickVision, Methodikal, Kevin and 5 others
NEW #7
Avatar
Pack93z Select Member
Joined: Mar 17, 2007
Posts: 13,278
Avatar
Pack93z
Select Member
Joined:Mar 17, 2007
Posts:13,278
The jig is up, the news is out, they've finally found me.. ;)



Now.. seriously.. can you block the bots from hitting the pages?
0
SlickVision, Methodikal, Kevin and 5 others
NEW #8
Avatar
wpr Preferred Member
Joined: Aug 08, 2008
Posts: 20,215
Avatar
wpr
Preferred Member
Joined:Aug 08, 2008
Posts:20,215
Man that is terrible.
MUST HAVE BEEN A BEARS FAN.
0
SlickVision, Methodikal, Kevin and 5 others
NEW #9
Avatar
Nonstopdrivel Preferred Member
Joined: Sep 14, 2008
Posts: 18,544
Avatar
Nonstopdrivel
Preferred Member
Joined:Sep 14, 2008
Posts:18,544
How did it not occur to the host that your domain and IP address may have been (probably were) spoofed?
Back up your database onto a thumb drive just in case the worst happens.

I have unlimited web space and bandwidth that I'd be happy to donate if it came to that, though I doubt it will.
0
SlickVision, Methodikal, Kevin and 5 others
NEW #10
Avatar
Zero2Cool Elite Member
Joined: Oct 14, 2006
Posts: 44,952
Avatar
Zero2Cool
Elite Member
Joined:Oct 14, 2006
Posts:44,952
"Pack93z"Now.. seriously.. can you block the bots from hitting the pages?


Yes, the flood control does that, but if you click a few links too fast, it'll ban you for 60 seconds or something like that, maybe 10 minutes? I had it on the site for awhile, which seemed to speed things up, but Wade got lost, lol.

"longtimefan"Just cuz someone reported you as spam the host takes their word for it?

Yes, one person, sent one email and BYE BYE PH.com
pretty disturbing huh?
0
SlickVision, Methodikal, Kevin and 5 others