Только вчера вечером с бэкапа восстанавливали весь сайт. Сегодня обнаружили что сайт взломан, и вместо него открывается какие-то турецкие данные (на нашем же домене), с флагами, да еще и с музыкой, и еще была ссылка на фэйсбук. Забавно было на это смотреть. Оказывается заменили данные файла index.php, админского тоже.
Вот их код:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title></title>
</head>
<body>
<script language="JavaScript1.2">
function ClearError() {return true;}
window.onerror = ClearError;
</script>
<title>Hacked By International Force</title>
<html xmlns:v="urn:schemas-microsoft-com:vml"
xmlns:o="urn:schemas-microsoft-com:office:office"
xmlns:w="urn:schemas-microsoft-com:office:word"
xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=Content-Type content="text/html; charset=iso-8859-9">
<META HTTP-EQUIV="Refresh" CONTENT="50; URL= https://www.facebook.com/ayyildiztim.com.tr" /><title>AYYILDIZ T?M ?NTERNAT?ONAL FORCE</title>
<style>
<!--body
{min-width:650px;
background-clip:box;
background-origin:padding-box;
background-size:cover;
background-position-x:50%;
background-position-y:50%;
background-attachment:fixed;}
/* Font Definitions */
@font-face
{font-family:calibri;
panose-1:0 0 0 0 0 0 0 0 0 0;
mso-font-alt:"Times New Roman";
mso-font-charset:0;
mso-generic-font-family:roman;
mso-font-format:other;
mso-font-pitch:auto;
mso-font-signature:0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{mso-style-parent:"";
margin:0cm;
margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:12.0pt;
font-family:"Times New Roman";
mso-fareast-font-family:"Times New Roman";}
p.metin, li.metin, div.metin
{mso-style-name:metin;
margin:0cm;
margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:12.0pt;
font-family:"Times New Roman";
mso-fareast-font-family:"Times New Roman";}
span.SpellE
{mso-style-name:"";
mso-spl-e:yes;}
span.GramE
{mso-style-name:"";
mso-gram-e:yes;}
@page Section1
{size:595.3pt 841.9pt;
margin:70.85pt 70.85pt 70.85pt 70.85pt;
mso-header-margin:35.4pt;
mso-footer-margin:35.4pt;
mso-paper-source:0;}
div.Section1
{page:Section1;}
a {
color:red;
}
.metin {
margin:0px auto;
width: 600px;
text-align:center;
}
.style1 {color: #FFFFFF}
.style3 {
font-family: Verdana, Arial, Helvetica, sans-serif;
font-size: 12px;
}
#_x0000_i1025
{
height: 269px;
width: 571px;
}
-->
</style>
</head>
<body bgcolor=black
background="http://b1211.hizliresim.com/13/1/fj5hc.png" lang=TR
style="tab-interval:35.4pt">
<div class=Section1>
<h2 align=center style="text-align:center"><span class=SpellE><span
style="font-family:calibri;color:white"><span style="font-family:calibri;
color:white"><span class="MsoNormal" style="margin-bottom:12.0pt;text-align:center"><img
src="http://a1303.hizliresim.com/17/7/ktx57.jpg" name="_x0000_i1025"
id="_x0000_i1025"></span></span></span></span></h2>
<h2 align=center style="text-align:center">
<marquee align="middle" scrollamount="1" width="100%" direction="up"scrolldelay="1"
style="height: 116px; color: #FFFFFF; font-size: medium;">Vatanımıza,Dinimize Karşı Kötü Fikirlere Sahip Olan <br />
Tüm Ülkelere Sanal Savaş Açılacaktır..!<br />Biz Türk Devletleri Olarak Hep Birlikteyiz<br />
Kimseden Korkmayız Gerektiği Yerde<br />
Gereken Cevabı Veririz..!
</marquee>
<img src="http://www.ayyildiz.org/portal/images/internationalforce.png"
style="height: 167px; width: 253px"></h2>
<h4 align="center" class="style1"><span class="style3">Cedkan | Kerem Sah Noyan | Hun Kar | Siyah Muhafiz | Oguz Han | Toprak Han | OrhanGazi | DoGuKaN | GuRKaN | GoLGe | Alp Man | Baybars AyyıldızTim | Aydemir Ayt </span><br/>
</h4>
<h4 align="center" class="style1">
<a href="http://www.uploadmusic.org"><object type="application/x-shockwave-flash" width="17"
height="17"data="http://www.uploadmusic.org/musicplayer.swf?song_url=http://www.uploadmusic.org/MUSIC/9281041362647298.mp3&autoplay=true"><param name="movie"value="http://www.uploadmusic.org/musicplayer.swf?song_url=http://www.uploadmusic.org/MUSIC/9281041362647298.mp3&song_title=uploadmusic.org&autoplay=true"
/></object>
<span
style="font-family:calibri;color:white"><br>
</span><span style="font-size:9.0pt;font-family:calibri;color:white"><br>
Facebook : <a href="http://www.facebook.com/ayyildiztim.com.tr">http://www.facebook.com/ayyildiztim.com.tr</a><br style="mso-special-character:line-break">
<![if !supportLineBreakNewLine]>
<br style="mso-special-character:line-break">
<![endif]>
</span><span style="font-family:calibri;color:white">
<o:p></o:p>
</span></h4>
</div>
</body>
</html>
</body>
</body>
</html>
Как Взломали-то?