Exilian

Announcements and Articles: The Gatehouse Quarter => Announcements! The Town Crier! => Topic started by: Marcus on December 05, 2011, 10:27:18 AM

Title: MALWARE ISSUE ON SITE
Post by: Marcus on December 05, 2011, 10:27:18 AM
Hi guys, some of you may have noticed a malware warning when visiting Exilian lately, this was because the .htaccess file was modified to perform redirects to malware sites when exilian was clicked on from google. I have removed the offending file and am about to request a review of the site to get it taken off the blacklist, and I would strongly suggest everyone does a virus check on their systems, just to make sure nothing evil was downloaded.

Thanks,

Marcus.
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 05, 2011, 02:05:10 PM
If we didnt get the warning, do a check anyway?
Title: Re: MALWARE ISSUE ON SITE
Post by: Phoenixguard09 on December 05, 2011, 02:45:23 PM
Yes Ladyhawk, do the check anyway.

Thanks Marcus I was wondering about that.

Cheers mate,
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 05, 2011, 03:27:07 PM
Okay cool. Thank you for that.
Title: Re: MALWARE ISSUE ON SITE
Post by: comrade_general on December 05, 2011, 10:50:14 PM
I never saw anything related to this.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 06, 2011, 06:16:14 PM
It was only flagged up by the Chrome browser.
Title: Re: MALWARE ISSUE ON SITE
Post by: Captain Carthage on December 06, 2011, 07:26:49 PM
I just can't get on from my pc.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 06, 2011, 09:22:48 PM
What happens if you try, NA?
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 06, 2011, 10:47:44 PM
It has been flagged up on Chrome, but also Firefox and Google's built in system from Google search.

I'm going to update the forum software, then request a review, and in the mean time look at the php code for uploading news to the main site, and look for vulnerabilities.
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 07, 2011, 01:11:25 AM
Good luck with that my friend.
Title: Re: MALWARE ISSUE ON SITE
Post by: Phoenixguard09 on December 07, 2011, 02:16:10 AM
Hey NA have you tried getting in through your history? It worked for me.
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 07, 2011, 03:27:11 AM
Well everyone I was just attacked by a virus posting on this site. Luckly my computer blocked it, and (hopefully) no harm is done. I do recommend that everyone runs a scan please. :)
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 07, 2011, 05:17:45 AM
I tried to get on with my phone and it said it could be harmful.
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 07, 2011, 08:16:39 AM
Exilian is fine from my phone. But something attacked my pooter.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 07, 2011, 05:48:24 PM
Marcus, given Google hasn't removed us yet, does that mean there might be more redirects/malware issues?
Title: Re: MALWARE ISSUE ON SITE
Post by: Captain Carthage on December 07, 2011, 08:05:56 PM
Well I can get back on now, Google still shouts at me but it lets me in.
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 07, 2011, 08:22:06 PM
I'll try on my phone later again today.
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 08, 2011, 05:20:13 PM
Unfortunately, this one comes back as soon as you get rid of it, I'm going to remove the suspected vulnerability and see what happens.
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 08, 2011, 08:35:09 PM
I did it by typing the URL instead.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 14, 2011, 06:01:32 PM
I'm wondering if we should extend the election signup period until this gets fixed, since some people aren't going to want to come on at the moment I fear.
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 19, 2011, 01:40:11 PM
Ok, I've removed the poisoned .htaccess file and removed the news script as well, which does have gaping holes in it. I'm now going to request a review and update the forum software tonight. Fingers crossed we will be clear within 24-48 hours.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 19, 2011, 02:07:25 PM
Just taken a look at .htaccess, and it looks very much like the problem is back.  :(
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 19, 2011, 02:16:25 PM
Requested review. Discovered that this nasty has put a poisoned .htaccess file in every folder that has an index file. I think it was doing it via the news script, which is now gone, so fingers crossed our Googly overlords will grant us redemption! :D

Edit: Dammit, this means the malware is still there. I'm possibly going to have to take the site offline and clear it of everything, then add stuff bit by bit.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 19, 2011, 02:31:42 PM
Okay, if you do that is there any way to display a "Sorry, we're not available, please come back soon" page?
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 19, 2011, 06:31:11 PM
I'm going to leave the forums up and just focus on the site for the moment, and if that doesn't work I'll reinstall the forums as well. And yes, I can leave a 'sorry we're not available' message.

EDIT: In light of a message I received, it's struck the forums as well, so I'm going to take everything off the server, and reinstall bit by bit. Sorry for this guys, but It's the only way I can be sure of removing it. Don't worry about posts and data, they're stored on SQL databases which I don't think the virus has got to.

I will try to get the site, starting with the forums, back up tonight, but I can't make any guarantees. The forums at least will be up by tomorrow though. Thank you.
Title: Re: MALWARE ISSUE ON SITE
Post by: Phoenixguard09 on December 20, 2011, 12:16:51 PM
Thank you Marcus, best of luck mate. :D
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 20, 2011, 01:06:28 PM
Thanks Marcus. You doing great mate :)
Title: Re: MALWARE ISSUE ON SITE
Post by: Son of the King on December 20, 2011, 02:14:51 PM
Seems like a good job you've done here Marcus :) .

In fact, I still get redirected if I access Exilian from a Google search :/ .
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 20, 2011, 06:00:35 PM
Have you cleared your cache, SOTK? Your computer may be remembering the old .htaccess file in the absence of a file that gives a directly opposed command.
Title: Re: MALWARE ISSUE ON SITE
Post by: Son of the King on December 20, 2011, 07:20:40 PM
I have indeed. My brother's computer does the same thing too.
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 20, 2011, 08:50:39 PM
Oh for crying out loud!

Ok, this is out of my hands. I just need to contact my host and get them to sort it. I wiped everything on the server, the only thing I can think of that it could have come through is the database, although I sincerely hope not.
Title: Re: MALWARE ISSUE ON SITE
Post by: Son of the King on December 20, 2011, 09:06:48 PM
I only get redirected from Google search, not from typing in the link or using the one in my bookmarks like I did before if that makes any difference.
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 20, 2011, 09:21:30 PM
It seems that google's cache may be outdated. I'm fine when I access it from Google.
Title: Re: MALWARE ISSUE ON SITE
Post by: comrade_general on December 20, 2011, 10:49:34 PM
Mine also works fine from Google search.
Title: Re: MALWARE ISSUE ON SITE
Post by: Jubal on December 20, 2011, 11:44:47 PM
I re-sent Google our site via the webmaster tools, so the Google cache should now be fixed. It's working fine for me now.
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 21, 2011, 12:01:07 AM
Is anyone else having the issue with this website now... its white,blue and says simple machines forum up the top right of the screen O_o
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 21, 2011, 12:02:00 AM
Yes, that is what mine looks like.
Title: Re: MALWARE ISSUE ON SITE
Post by: comrade_general on December 21, 2011, 12:03:47 AM
Everything is in "basic" mode atm. No worries. ;)
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 21, 2011, 12:04:34 AM
Oh, sweet XD
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 21, 2011, 12:05:39 AM
Oh yay. and also that was a fast response? i only just woke up :P
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 21, 2011, 12:06:13 AM
Haha, I got up at 12 the other day. It was awesome XD
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 21, 2011, 12:08:40 AM
Yeah, my school holidays have just started so ill probably be posting allot more often now. Btw admins is it possible that Google will block this site or something? thats all i got from your previous posts :/
Title: Re: MALWARE ISSUE ON SITE
Post by: comrade_general on December 21, 2011, 12:11:36 AM
They had it on their "possible threat" list. Been taken off afaik.

BTW, Death Nade, run for office. ;D
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 21, 2011, 12:15:25 AM
Oh goodo,  at least we arent a "threat" anymore :P

How would i run for office. which thread?
Title: Re: MALWARE ISSUE ON SITE
Post by: Son of the King on December 21, 2011, 12:19:54 AM
The signup thread in the plaza (http://exilian.co.uk/forum/index.php?topic=1705.0) :)
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 21, 2011, 12:23:17 AM
Cheers, i ran for Tribounos :P
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 21, 2011, 12:28:03 AM
Like me :P
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 22, 2011, 08:18:51 AM
"We're currently upgrading software and making improvements to the site"

What's being upgraded and what are the improvements? Maybe you could though in a "Shout Box" and maybe a Mibbit Chat channel ;).
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 22, 2011, 08:24:45 AM
Haha, yor so demanding XD
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 22, 2011, 11:12:41 AM
They're just suggestions but I do demand a shout box though. We really need one of those.
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 22, 2011, 05:09:40 PM
At the moment, 'improvements' is making sure we never get hacked again. :P
Title: Re: MALWARE ISSUE ON SITE
Post by: Death Nade on December 23, 2011, 12:52:35 AM
Id rather the site didnt get hacked i think :P
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 24, 2011, 09:52:03 AM
Ok, everything is sorted for now, just reinstalling mods and a theme and everything will be back to normal. :D
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 24, 2011, 11:01:03 AM
On the entrance page it still says "Under Maintenance"
Title: Re: MALWARE ISSUE ON SITE
Post by: Marcus on December 24, 2011, 07:46:47 PM
Forum wise, I meant.
Title: Re: MALWARE ISSUE ON SITE
Post by: Cuddly Khan on December 25, 2011, 10:05:22 PM
The Session Length doesn't work.
Title: Re: MALWARE ISSUE ON SITE
Post by: Dimos on December 29, 2011, 12:21:43 AM
Well... First malware and then exilian turned white and now it's blue... Is it the end of the world? DOOM APROACHES! REDEEM!  ;D   ;D  ;D   ;D  :)  ;)  :D
Title: Re: MALWARE ISSUE ON SITE
Post by: Ladyhawk on December 29, 2011, 03:59:09 AM
The blue is better than the white at least :)
Title: Re: MALWARE ISSUE ON SITE
Post by: debux on December 31, 2011, 06:36:01 PM
I sure am glad that I only attempted to log into exilian from the school PC. Hope the central server there is okay, or at least doesn't register that it was me that infected the server :D