Site Infected

Discuss anything pertinent to this website.

Moderator:Æron

Softpaw
Posts:1348
Joined:Sun Oct 05, 2003 6:42 pm
Location:Washington, DC
Contact:

Postby Softpaw » Tue Jan 31, 2006 4:41 pm

On the O&M mailing list, The J.A.M discovered a spyware/virus infection in the code for the forum. Before doing anything on this site, please read my reply to him, and do NOT visit any URLs in this message:<br><br><br>When I accessed the actual board, I got a blocked cookie request from toolbardollars.biz, it seems than an infected file has embedded itself in the forum.<br><br>Upon viewing the source code, it seems that there's an Iframe embedded in the source code for the forum that loads <a href='http://definecynical.mancubus.net/forum ... topic=2724' target='_blank'>http://toolbardollars.biz/dl/adv553.php</a>.<br><br>To view the site safely, add the following lines to your HOSTS file (on WinXP, it's in C:\WINDOWS\System32\drivers\etc):<br><br>127.0.0.1 toolbardollars.biz<br>127.0.0.1 www.toolbardollars.biz<br><br>This will prevent any access to the malicious site, and allow safe browsing until the forum is repaired. If you do not have antivirus software installed, and you've visited the Define Cynical board, please do a full system scan before viewing any sensitive data on your computer.<br><br>EDIT: This is not an isolated incident, as reported by <a href='http://syndicated.livejournal.com/f_secure/186317.html' target='_blank'>F-Secure</a>.<br><span style='color:#64008D'>Mod Edit: changed destination of link in case foolish readers click the link anyway.</span>
Last edited by Softpaw on Wed Feb 01, 2006 12:54 am, edited 1 time in total.

User avatar
Taren
Posts:44
Joined:Mon Jan 30, 2006 12:32 am
Location:North America
Contact:

Postby Taren » Tue Jan 31, 2006 6:46 pm

<!--QuoteBegin-FelixSoftpaw+Jan 31 2006, 11:41 AM--> <table border='0' align='center' width='95%' ><tr><td class='quotetop'><b>Quote:</b> (FelixSoftpaw @ Jan 31 2006, 11:41 AM)</td></tr><tr><td class='quotebody'> To view the site safely, add the following lines to your HOSTS file (on WinXP, it's in C:\WINDOWS\System32\drivers\etc):<br><br>127.0.0.1 toolbardollars.biz<br>127.0.0.1 www.toolbardollars.biz <!--QuoteEnd--> </td></tr></table> <!--QuoteEEnd--><br> I just did so. This seems like serious business, and I hope it gets straightened out soon. Spammers are quite a bother.
"When the chips are down, when you're at the end of your
rope, you need someone you can count on. And that's what
you'll find here. Someone who'll go all the way, who'll protect
you no matter what. Don't lose hope."
-- Doyle, "Hero"

Richard K Niner
Posts:4297
Joined:Wed Oct 20, 2004 5:08 pm
Location:On hiatus
Contact:

Postby Richard K Niner » Tue Jan 31, 2006 7:22 pm

0.0.0.0 can be even safer than 127.0.0.1, because 0.0.0.0 refuses every connection, every time (localhost only does so until you install a web server)
<center>Image
K9U | Dog House | Av rotation</center>

User avatar
Taren
Posts:44
Joined:Mon Jan 30, 2006 12:32 am
Location:North America
Contact:

Postby Taren » Tue Jan 31, 2006 7:31 pm

<!--QuoteBegin-Richard K Niner+Jan 31 2006, 02:22 PM--> <table border='0' align='center' width='95%' ><tr><td class='quotetop'><b>Quote:</b> (Richard K Niner @ Jan 31 2006, 02:22 PM)</td></tr><tr><td class='quotebody'> 0.0.0.0 can be even safer than 127.0.0.1, because 0.0.0.0 refuses every connection, every time (localhost only does so until you install a web server) <!--QuoteEnd--> </td></tr></table> <!--QuoteEEnd--><br> I did those as well, just to be safe.
"When the chips are down, when you're at the end of your
rope, you need someone you can count on. And that's what
you'll find here. Someone who'll go all the way, who'll protect
you no matter what. Don't lose hope."
-- Doyle, "Hero"

User avatar
GreenReaper
Posts:8
Joined:Mon Dec 19, 2005 5:40 am
Location:Northville, MI, USA
Contact:

Postby GreenReaper » Tue Jan 31, 2006 7:51 pm

I would guess that <a href='http://forums.invisionpower.com/index.p ... pic=204627' target='_blank'>this</a> has something to do with it.
Laurence "GreenReaper" Parry
GreenReaper Studios - WikiFur - Flayrah - Creatures Wiki

Softpaw
Posts:1348
Joined:Sun Oct 05, 2003 6:42 pm
Location:Washington, DC
Contact:

Postby Softpaw » Tue Jan 31, 2006 7:56 pm

Yes, patching would definitely help, though that doesn't seem to be a priority for the admins here (we've been hacked how many times, and still haven't patched the holes?).

User avatar
Taren
Posts:44
Joined:Mon Jan 30, 2006 12:32 am
Location:North America
Contact:

Postby Taren » Tue Jan 31, 2006 9:03 pm

<!--QuoteBegin-FelixSoftpaw+Jan 31 2006, 02:56 PM--> <table border='0' align='center' width='95%' ><tr><td class='quotetop'><b>Quote:</b> (FelixSoftpaw @ Jan 31 2006, 02:56 PM)</td></tr><tr><td class='quotebody'> Yes, patching would definitely help, though that doesn't seem to be a priority for the admins here (we've been hacked how many times, and still haven't patched the holes?). <!--QuoteEnd--> </td></tr></table> <!--QuoteEEnd--><br> Is updating the board hard to do?
"When the chips are down, when you're at the end of your
rope, you need someone you can count on. And that's what
you'll find here. Someone who'll go all the way, who'll protect
you no matter what. Don't lose hope."
-- Doyle, "Hero"

Softpaw
Posts:1348
Joined:Sun Oct 05, 2003 6:42 pm
Location:Washington, DC
Contact:

Postby Softpaw » Tue Jan 31, 2006 11:27 pm

Nope, unless the code has been modified, and that doesn't appear to be the case.

Ankaris
Posts:471
Joined:Tue Mar 23, 2004 7:20 am
Location:Locked In My Study

Postby Ankaris » Wed Feb 01, 2006 12:02 am

<!--emo&:angry:--><img src='http://definecynical.mancubus.net/forum ... ns/mad.gif' border='0' style='vertical-align:middle' alt='mad.gif' /><!--endemo--> <br><br>Screw virus-writers. Screw 'em in their asocial lil' ears.<br><br> <!--emo&:angry:--><img src='http://definecynical.mancubus.net/forum ... ns/mad.gif' border='0' style='vertical-align:middle' alt='mad.gif' /><!--endemo--> <br><br>Anyway, was about to make a post on this, good to see you're already aware. My AV caught it and I deleted it. Going to run a full-scan, though.<br><br>Question - If my AV caught the trojan, should I make any other modifications, or is it not worth it?
Oh dear lord sig is fubar. o_o

User avatar
GhostWay
Posts:1381
Joined:Sun Nov 14, 2004 7:55 pm
Location:Somewhere, probably
Contact:

Postby GhostWay » Wed Feb 01, 2006 12:39 am

I thought the main reason the board hasn't been updated in ages is that IPB has since become a pay-per-license based board system, starting at around version 2.0 (I think). And if memory serves, the board can't be updated to anything above v.2 unless 5h or likeafox has a subscription with IPB. Which, unless somebody here gets $70 for a one-year license or $185 for an endless license, probably isn't going to happen soon.<br><br>Granted, I could be wrong. Wouldn't be anywhere near the first time.
<i>Hold the newsreader's nose squarely, waiter, or friendly milk will countermand my trousers.</i>

Zaaphod
Moderator (retired)
Posts:6319
Joined:Tue Oct 28, 2003 7:16 pm

Postby Zaaphod » Wed Feb 01, 2006 3:04 am

Yay for spyware. <!--emo&<_<--><img src='http://definecynical.mancubus.net/forum ... ns/dry.gif' border='0' style='vertical-align:middle' alt='dry.gif' /><!--endemo--> <br><br>HOSTS file modified, so all is good for me.<br>
Image
Made by Angela. :D

Softpaw
Posts:1348
Joined:Sun Oct 05, 2003 6:42 pm
Location:Washington, DC
Contact:

Postby Softpaw » Wed Feb 01, 2006 4:07 am

<!--QuoteBegin-Ankaris+Jan 31 2006, 07:02 PM--> <table border='0' align='center' width='95%' ><tr><td class='quotetop'><b>Quote:</b> (Ankaris @ Jan 31 2006, 07:02 PM)</td></tr><tr><td class='quotebody'> Question - If my AV caught the trojan, should I make any other modifications, or is it not worth it? <!--QuoteEnd--></td></tr></table> <!--QuoteEEnd--><br>I'd highly recommend HOSTS-blocking the domain, since no good can come from it, and it'll prevent future attempted downloads. Aside from that, make sure you delete your cache, you should be fine. My antivirus caught it, and I did an extensive check, with no infection (and I'm not even running XP SP2).<br><br><!--QuoteBegin-GhostWay+--> <table border='0' align='center' width='95%' ><tr><td class='quotetop'><b>Quote:</b> (GhostWay)</td></tr><tr><td class='quotebody'> I thought the main reason the board hasn't been updated in ages is that IPB has since become a pay-per-license based board system, starting at around version 2.0 (I think). And if memory serves, the board can't be updated to anything above v.2 unless 5h or likeafox has a subscription with IPB. Which, unless somebody here gets $70 for a one-year license or $185 for an endless license, probably isn't going to happen soon.<!--QuoteEnd--></td></tr></table> <!--QuoteEEnd--><br><br>I did some checking, and you're right, there isn't even an option to download the free version anymore. In which case, we should really switch to something else, because these attacks aren't going to stop simply by ignoring them. Migrating to another board isn't difficult, provided that it's something that's still being supported.

User avatar
likeafox
Administrator
Posts:1841
Joined:Sat Oct 18, 2003 10:32 pm
Location:Canada
Contact:

Postby likeafox » Wed Feb 01, 2006 4:51 am

I reset the board so, for the time being, there should be no problems. This attack is certainly something I will look into.<br><br>Felix pray tell what browser do you use?


Return to “The Site”

Who is online

Users browsing this forum: No registered users and 54 guests