Overunity.com Archives is Temporarily on Read Mode Only!



Free Energy will change the World - Free Energy will stop Climate Change - Free Energy will give us hope
and we will not surrender until free energy will be enabled all over the world, to power planes, cars, ships and trains.
Free energy will help the poor to become independent of needing expensive fuels.
So all in all Free energy will bring far more peace to the world than any other invention has already brought to the world.
Those beautiful words were written by Stefan Hartmann/Owner/Admin at overunity.com
Unfortunately now, Stefan Hartmann is very ill and He needs our help
Stefan wanted that I have all these massive data to get it back online
even being as ill as Stefan is, he transferred all databases and folders
that without his help, this Forum Archives would have never been published here
so, please, as the Webmaster and Creator of this Forum, I am asking that you help him
by making a donation on the Paypal Button above
Thanks to ALL for your help!!


Explicit content site opens when I enter overunity.com

Started by Fred Flintstone, May 09, 2009, 04:43:32 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

hansvonlieven

It somehow is tied to the login. I booted up the browser as guest and the minute I logged in as me the second browser window came up. I think there are several triggers sitting on the server.

When booting up the browser, if you look at the bottom bar in firefox where it tells you what the computer is doing it very very quickly shows Russian addresses before coming up with "transferring data from overunity.com"

Perhaps it is only visible here because I have a landline, broadband might be too fast to show up.

Hans von Lieven
When all is said and done, more is said than done.     Groucho Marx

AquariuZ

Quote from: hartiberlin on May 10, 2009, 08:22:26 PM
Cookies are just only stored in your browser,
so the user has to clear his cookies in the browser.

What are session IDs in cookies ?

eh, yeah that´s what I meant. Everyone get rid of the .ru cookies

Quote
Do they call up automatically the sites ?

One I threw away contained a PHP sessid, this can be used for various purposes..

Quote
How could they access the template files if they just managed to use
an older script that just updated the .htaccess file ?

They probably used the spider-trap script to somehow
add their code into the .htaccess file.

The spider-trap script is now disabled,
so I am looking for a different website firewall script now.

I don´t think they had FTP access, otherwise they would have been doing
much more nasty things..

You can execute any command (i.e via PHP) when they have write access to .htaccess. (via via via) assuming you are running Apache on Linux

Please check PM for details

hartiberlin

Hmm,
it really must be related to Session IDs,
very strange, do not know yet this trick.

If I clear my browsers cache and cookies and
klick this link:
http://www.overunity.com/index.php?action=unreadreplies

and then press the
HOME button

Then the p.or.n site is loading...

The Home  button has some session cookie attached.

I guess I try to change the cookie, that SMF is sending,
maybe this will help ?
Stefan Hartmann, Moderator of the overunity.com forum

hansvonlieven

Take the browser off automatic log in. Make overunity your default homepage. close the browser.

Re-open the browser, it will come up as guest. click on login and log in and the Russian site appears in a new window. Seems to work every time.

Hans von Lieven
When all is said and done, more is said than done.     Groucho Marx

AquariuZ

Quote from: hansvonlieven on May 10, 2009, 08:55:12 PM
Take the browser off automatic log in. Make overunity your default homepage. close the browser.

Re-open the browser, it will come up as guest. click on login and log in and the Russian site appears in a new window. Seems to work every time.

Hans von Lieven

Yes that fits what I think is going on... Did you explicitly remove your .ru cookies locally? I have not had the popup for an hour now....

They are using a server reference to the session id and may have injected some code in a handler via PHP. This should not be possible if PHP is up to date though-