Forum appears to have been hacked!

The place for discussion of episodes of The F1 Rejects Podcast and all other aspects of the F1Rejects.com website

Forum appears to have been hacked!

Postby Priceless » 03 Mar 2012, 23:53

Today when I came to the forum, I got greeted by a message by my anti-virus software (avast! 7, up-to-date) saying that it had blocked a malicious URL. Here's a picture of my screen as I came to the forum:

Image

The picture is cropped to show the relevant details to this thread. Original is 1920x1080 pixels. JPEG quality was chosen to minimize file size while preserving the relevant details. As the image shows, there are 3 other malicious URLs blocked, all belonging to the same domain.

There is some other site hanging on to the forum that appears not to be related to the forum, and is not blocked by the anti-virus software, but appears to be a hack, too. While browsing, between page loads I noticed
Code: Select all
Waiting for www.daysofyorr.com...

(if the forum shows this as a link, DO NOT click it, also DO NOT attempt to go there via your browser's address bar) but it appears only briefly, so I haven't been able to capture a screenshot or get the full URL. This appears to happen at every page load in the forum. My browser is Firefox 11 beta.

It is not my intention to create panic or alarmism or anything of the sort, but I thought it might be important to bring this to people's attention.
Keep your anti-virus always up-to-date, people... and I suggest that the administrators look into it.

Sorry for any inconvenience this message might cause.
User avatar
Priceless
 
Posts: 201
Joined: 24 Mar 2011, 23:55
Location: Rio de Janeiro, Brazil

Re: Forum appears to have been hacked!

Postby Nuppiz » 04 Mar 2012, 00:00

A bit of Googling reveals this:

Code: Select all
http://www.daysofyorr.com
= Days of Y'Orr - A Boston Bruins Blog
Managed to catch it on my browser:
Image

gloryhunterz.com = Malware according to this:
Code: Select all
http://www.gloryhunterz.com/z/xmlview | 82.192.87.28 | hosted-by.leaseweb.com. | exploit kit / requires referer


So, we do have a problem on our hands...
Last edited by Nuppiz on 04 Mar 2012, 06:11, edited 1 time in total.
PMMF Moderator, keeping that subforum tidy since 21st April 2013.

IFRC: not related to the charity foundation at all.
Life GP Series: where reliability is little more than a fancy word.
User avatar
Nuppiz
Moderator
 
Posts: 3488
Joined: 30 Mar 2009, 22:10
Location: Vantaa, Finland

Re: Forum appears to have been hacked!

Postby DanielPT » 04 Mar 2012, 01:27

Code: Select all
http://www.daysofyorr.com


looks to me as being legit... Seen several reports and people claim it is safe. It might have been hacked of course since I too receive that malware report in my Anti-virus (Panda in my work and AVG at home).
Colin Kolles on F111, 2011 HRT challenger: The car doesn't look too bad; it looks like a modern F1 car.
User avatar
DanielPT
 
Posts: 4617
Joined: 31 Dec 2010, 04:44
Location: Porto, Portugal

Re: Forum appears to have been hacked!

Postby Sunshine_Baby_[IT] » 04 Mar 2012, 01:31

I have Kaspersky antivirus and it happen the same thing, I had a message where it appeared the daysofyor link.
I'm Perry McCarthy and Taki Inoue's fan number 1 and I always will be.

My twitter: @Miluuu_Sunshine
User avatar
Sunshine_Baby_[IT]
 
Posts: 1072
Joined: 27 Nov 2011, 01:17
Location: Bologna (Italy)

Re: Forum appears to have been hacked!

Postby East Londoner » 04 Mar 2012, 01:59

I keep seeing that daysofyorr link whenever the forum is loading up. I hope it's not those pesky Indian hackers again :?
The 1990s were better. Fact. And you bloody well know it.

Murray Walker: There's a car coming into the pits now, they're so unreliable with all those electronics on board.
James Hunt: Actually, Murray, one of his wheels has just fallen off...
User avatar
East Londoner
 
Posts: 3495
Joined: 18 Jun 2010, 04:21
Location: The 1990s.

Re: Forum appears to have been hacked!

Postby tommykl » 04 Mar 2012, 02:45

I'm not getting that particular link, but I've had a few intrusions blocked by sites who also end with
Code: Select all
/z/wmlview

It says 'Malicious Exploit Kit Website 4'. I've been wondering where those came from...
AussieGrit wrote:At a VIP dinner last night an American woman asked me"where are you from?" I said Australia, she said "wow your English is amazing"

I am an F1 fan, snatched away by this forum. HELP ME TOM CRUISE! (until d'Ambrosio scores a point)
User avatar
tommykl
 
Posts: 3882
Joined: 08 Apr 2010, 03:10
Location: Sprimont, Belgium

Re: Forum appears to have been hacked!

Postby mario » 04 Mar 2012, 04:23

Sunshine_Baby_[IT] wrote:I have Kaspersky antivirus and it happen the same thing, I had a message where it appeared the daysofyor link.

It's one of those things where the link appears so briefly that to begin with I couldn't quite catch what was happening. I've also had the warnings over potentially dangerous links come up too, although in those instances it seems that they were related to spam posts on the forum at the same time.
Martin Brundle, on watching a replay of Grosjean spinning:
"The problem with Grosjean is that he want to take a look back at the corner he's just exited"
User avatar
mario
Moderator
 
Posts: 4495
Joined: 01 Nov 2009, 03:13

Re: Forum appears to have been hacked!

Postby dr-baker » 04 Mar 2012, 06:24

I've had something similar last week, but with
Code: Select all
srv.gazsrc.net
... :?
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby eytl » 04 Mar 2012, 07:55

I have also been receiving the avast malicious URL warnings. I must say I'm not sure what to do about any of this as I'm not tech savvy.

But I'll get Jamie to have a look into it.

Alternatively, anyone else got ideas?
I was born the day after HWNSNBM. Given time zone differences, we may have been born at the same time.

Check out http://www.flickr.com/photos/eytl
User avatar
eytl
Site Author and Senior Grand Prix Analyst
 
Posts: 955
Joined: 31 Mar 2009, 22:43
Location: Sydney, Australia

Re: Forum appears to have been hacked!

Postby FullMetalJack » 04 Mar 2012, 08:40

I have been immune to this so far.

Maybe i'm HWNSNBM's young apprentice.
Listen! Listen! I'm doing him an egg! You're not me and you paris! I'm sanding into your dumb redneck ass! - Scott Steiner
User avatar
FullMetalJack
 
Posts: 4605
Joined: 01 Apr 2009, 01:32
Location: Dunkin Donuts, Obesity

Re: Forum appears to have been hacked!

Postby dinizintheoven » 04 Mar 2012, 11:49

I am reading this forum on a Mac. Even so, I may be hurriedly archiving the F1RMGP threads and running them through Avast! on the laptop...

...although I'm seeing no content running through Chrome from either daysofyorr.com or the malware site. It says "waiting for www.f1rejects.com... as it should while the forum data is processing.

EDIT: hang on, I just did! "waiting for daysofyorr.com..."

Getting a bit worried now, even if I am on a Mac.
Join the campaign to bring to the world of F1 Rejects racing, the unpleasant log laid by British Leyland after communism crept, like an itchy red blanket, over the shop floor. MORRIS MARINA FOR THE REECCS!
User avatar
dinizintheoven
 
Posts: 2107
Joined: 09 Dec 2010, 11:24

Re: Forum appears to have been hacked!

Postby dinizintheoven » 05 Mar 2012, 00:07

Right, to keep myself safe, I am looking on this forum using Linux until this business is sorted out. The hackers will never get in that way.

Via the safest operating system I can get my hands on, I've taken a screenshot of daysofyorr.com and it does seem to be legit. But, just to be safe, I know there are a couple of "friends of a friend" on Faceache who have been using the Boston Bruins icon as their personal icon, so I'd assume they're Bruins fans; I'm now trying to track them down and see if any of them are regular readers of Days Of Y'Orr, and if so, have they noticed anything fishy going on there.

The weird thing is, it seems to be random pages where this URL shows up. The thought did occur that maybe one of our regular posters has an icon stored on daysofyorr.com... but even though we have some regulars here from around that area, there don't seem to be any of them on this thread, and I don't remember seeing anything Bruins-related in anyone's icon here, irrespective of where they're from.

I suppose what I should do is browse the main F1 Rejects site and see if the daysofyorr.com URL appears while I'm looking there.
EDIT: nothing untoward on that front. Not yet, anyway.
Last edited by dinizintheoven on 05 Mar 2012, 00:17, edited 1 time in total.
Join the campaign to bring to the world of F1 Rejects racing, the unpleasant log laid by British Leyland after communism crept, like an itchy red blanket, over the shop floor. MORRIS MARINA FOR THE REECCS!
User avatar
dinizintheoven
 
Posts: 2107
Joined: 09 Dec 2010, 11:24

Re: Forum appears to have been hacked!

Postby dr-baker » 05 Mar 2012, 00:13

dr-baker wrote:I've had something similar last week, but with
Code: Select all
Waiting for srv.gazsrc.net
... :?

Sam I the only one to have got this occasionally instead? And what is this?
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby tommykl » 05 Mar 2012, 00:41

dr-baker wrote:
dr-baker wrote:I've had something similar last week, but with
Code: Select all
Waiting for srv.gazsrc.net
... :?

Sam I the only one to have got this occasionally instead? And what is this?

No I've had it as well. I have no idea what it is though...
AussieGrit wrote:At a VIP dinner last night an American woman asked me"where are you from?" I said Australia, she said "wow your English is amazing"

I am an F1 fan, snatched away by this forum. HELP ME TOM CRUISE! (until d'Ambrosio scores a point)
User avatar
tommykl
 
Posts: 3882
Joined: 08 Apr 2010, 03:10
Location: Sprimont, Belgium

Re: Forum appears to have been hacked!

Postby Priceless » 05 Mar 2012, 01:45

What it might be, I think, is that all those sites which we see transferring information on page loads here may have been hacked, maybe even by the same people using the same exploit. daysofyorr.com looks legit to me too, by the way.

I did the test on the main page and got the same warning from avast!, pointing to
Code: Select all
http://statcounters.org/z/xmlview


Also, Firefox showed to be transferring data from daysofyorr.com, too. It seems to be the more frequent site the exploit script "/z/xmlview" links to, but there may be others, as dr-baker and tommykl have noticed.
This line
Code: Select all
<script type="text/javascript" src="http://www.daysofyorr.com/release.js"></script>


appears on line 125 of the HTML source of the f1rejects.com main page. What's it doing there? It may have been injected by the exploit, I think...
I tried to download the script using an external tool, and although the server replies with HTTP 200 (OK) the content is a simple HTTP 404 (Not Found) page with only plain HTML inside.

EDIT:
dr-baker wrote:I've had something similar last week, but with
Code: Select all
srv.gazsrc.net
... :?


I did a DNS reverse search on that domain. It points to 82.192.87.25. statcounters.org points to 82.192.87.16. Those sites are much likely in the same network.

I was able to have a look at the "release.js" script. I'm not a javascript wizard in any way, but to me it looks like that it targets Windows users running either Firefox or Internet Explorer (no version specified). Please note that this does not imply Google Chrome would be safe, however it might be a good choice for people on Windows. Those who can visit the forum from anything other than Windows, it would be best to do so while the problem is not cleared away.

If you have a firewall program on Windows, I think it would be good to add a rule on it to block connections to 82.192.87.0/24 IP range.
I think that's all I can do to contribute...
User avatar
Priceless
 
Posts: 201
Joined: 24 Mar 2011, 23:55
Location: Rio de Janeiro, Brazil

Re: Forum appears to have been hacked!

Postby Kuwashima » 05 Mar 2012, 08:29

OK, so I can't replicate the issue/s.

However, step 1 has been to update the BB's forum software to the latest release which often irons out a few bugs and holes in the code.

Please let me know how things look now and I'll move on to step 2.
User avatar
Kuwashima
Webmaster and Forum Admin
 
Posts: 252
Joined: 24 Mar 2009, 20:08
Location: Sydney, Australia

Re: Forum appears to have been hacked!

Postby East Londoner » 05 Mar 2012, 08:41

Nuppiz wrote:A bit of Googling reveals this:

Code: Select all
http://www.daysofyorr.com
= Days of Y'Orr - A Boston Bruins Blog
Managed to catch it on my browser:
Image

I'm still seeing this :?
The 1990s were better. Fact. And you bloody well know it.

Murray Walker: There's a car coming into the pits now, they're so unreliable with all those electronics on board.
James Hunt: Actually, Murray, one of his wheels has just fallen off...
User avatar
East Londoner
 
Posts: 3495
Joined: 18 Jun 2010, 04:21
Location: The 1990s.

Re: Forum appears to have been hacked!

Postby dr-baker » 05 Mar 2012, 08:52

Kuwashima wrote:OK, so I can't replicate the issue/s.

However, step 1 has been to update the BB's forum software to the latest release which often irons out a few bugs and holes in the code.

Please let me know how things look now and I'll move on to step 2.

Ahh, does this explain why I was not able to get onto the forums half-an-hour ago?
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby FullMetalJack » 05 Mar 2012, 08:53

dr-baker wrote:
Kuwashima wrote:OK, so I can't replicate the issue/s.

However, step 1 has been to update the BB's forum software to the latest release which often irons out a few bugs and holes in the code.

Please let me know how things look now and I'll move on to step 2.

Ahh, does this explain why I was not able to get onto the forums half-an-hour ago?


Even I was unable to get on the forum about half an hour ago.

Maybe i'm not invincible?
Listen! Listen! I'm doing him an egg! You're not me and you paris! I'm sanding into your dumb redneck ass! - Scott Steiner
User avatar
FullMetalJack
 
Posts: 4605
Joined: 01 Apr 2009, 01:32
Location: Dunkin Donuts, Obesity

Re: Forum appears to have been hacked!

Postby East Londoner » 05 Mar 2012, 08:56

redbulljack14 wrote:
dr-baker wrote:
Kuwashima wrote:OK, so I can't replicate the issue/s.

However, step 1 has been to update the BB's forum software to the latest release which often irons out a few bugs and holes in the code.

Please let me know how things look now and I'll move on to step 2.

Ahh, does this explain why I was not able to get onto the forums half-an-hour ago?


Even I was unable to get on the forum about half an hour ago.

Maybe i'm not invincible?

I think Jamie took the forums offline for a while just after 21:30 GMT...
The 1990s were better. Fact. And you bloody well know it.

Murray Walker: There's a car coming into the pits now, they're so unreliable with all those electronics on board.
James Hunt: Actually, Murray, one of his wheels has just fallen off...
User avatar
East Londoner
 
Posts: 3495
Joined: 18 Jun 2010, 04:21
Location: The 1990s.

Re: Forum appears to have been hacked!

Postby Kuwashima » 05 Mar 2012, 20:42

East Londoner wrote:I think Jamie took the forums offline for a while just after 21:30 GMT...

Correct. Still investigating.
User avatar
Kuwashima
Webmaster and Forum Admin
 
Posts: 252
Joined: 24 Mar 2009, 20:08
Location: Sydney, Australia

Re: Forum appears to have been hacked!

Postby dr-baker » 06 Mar 2012, 02:22

Kuwashima wrote:
East Londoner wrote:I think Jamie took the forums offline for a while just after 21:30 GMT...

Correct. Still investigating.

Well, keep up the good work.

By the way, for a long while, I also often get the following (including for the loading of this thread):

Code: Select all
Waiting for dl.dropbox.com/blahblahblah


...where blahblahblah represents what I cannot remember. I hadn't worried about this before because it happened often on these forums. Can anybody reassure me about this?
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby Priceless » 06 Mar 2012, 08:46

dr-baker wrote:By the way, for a long while, I also often get the following (including for the loading of this thread):

Code: Select all
Waiting for dl.dropbox.com/blahblahblah


...where blahblahblah represents what I cannot remember. I hadn't worried about this before because it happened often on these forums. Can anybody reassure me about this?


I for one host images I post on my personal Dropbox account, because it's convenient. I can do it quickly and straight from my desktop, it's available for Windows, Linux and Mac OS X, and offers 2 GB of online space for free with allowance for some more by performing certain actions (like inviting someone to the service). It can be used as an online backup and storage service, and has a "public" folder that makes files you put in it accessible to the Internet. The URLs of such files are in that format.

EDIT:By the way Jamie, the problem is not restricted to the forums, as I've found suspicious things in the main page as well. I'd say that it might be a problem with the web server. I may be able to provide dumps of the HTML in the page and the script I found there as seen by my browser, in case it helps.
User avatar
Priceless
 
Posts: 201
Joined: 24 Mar 2011, 23:55
Location: Rio de Janeiro, Brazil

Re: Forum appears to have been hacked!

Postby dr-baker » 06 Mar 2012, 09:19

Priceless wrote:
dr-baker wrote:By the way, for a long while, I also often get the following (including for the loading of this thread):

Code: Select all
Waiting for dl.dropbox.com/blahblahblah


...where blahblahblah represents what I cannot remember. I hadn't worried about this before because it happened often on these forums. Can anybody reassure me about this?


I for one host images I post on my personal Dropbox account, because it's convenient. I can do it quickly and straight from my desktop, it's available for Windows, Linux and Mac OS X, and offers 2 GB of online space for free with allowance for some more by performing certain actions (like inviting someone to the service). It can be used as an online backup and storage service, and has a "public" folder that makes files you put in it accessible to the Internet. The URLs of such files are in that format.

EDIT:By the way Jamie, the problem is not restricted to the forums, as I've found suspicious things in the main page as well. I'd say that it might be a problem with the web server. I may be able to provide dumps of the HTML in the page and the script I found there as seen by my browser, in case it helps.

It's what I thought, but thought I ought to check just in case... Thanks.
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby simonracer » 06 Mar 2012, 15:15

I just got the "Malicious Kit Exploit 4 has been blocked" message for about the fifth time while viewing this whole forum.

EDIT: I'm getting the daysofyorr.com thingy as well.
simonracer
 
Posts: 166
Joined: 10 Oct 2010, 18:00

Re: Forum appears to have been hacked!

Postby Stramala » 06 Mar 2012, 19:12

I've only been accessing F1 Rejects via my college PCs for 2 weeks now and I've not noticed any such problems. All network traffic is directed via a proxy server and they use Sophos on all workstations so it's a bit trickier for viruses to find their way into the system. I am afraid to look this up at home on my new Dell XPS which I only purchased 3 weeks ago :?
I O . S O N O . I N T E R I S T A
2015 INDYCAR CHAMPION
2015 REJECTS OF LFS DRIVER & TEAMS CHAMPION
2015 F2RWRS TEAMS & MANUFACTURERS CHAMPION
2015 F1RMGP WEC TEAMS CHAMPION
2015 SUPER TOURING CUP CHAMPION
User avatar
Stramala
 
Posts: 8681
Joined: 17 Aug 2009, 19:30

Re: Forum appears to have been hacked!

Postby DanielPT » 06 Mar 2012, 20:32

kostas22 wrote:I've only been accessing F1 Rejects via my college PCs for 2 weeks now and I've not noticed any such problems. All network traffic is directed via a proxy server and they use Sophos on all workstations so it's a bit trickier for viruses to find their way into the system. I am afraid to look this up at home on my new Dell XPS which I only purchased 3 weeks ago :?


It will be a test of fire for your brand new PC! :D
Colin Kolles on F111, 2011 HRT challenger: The car doesn't look too bad; it looks like a modern F1 car.
User avatar
DanielPT
 
Posts: 4617
Joined: 31 Dec 2010, 04:44
Location: Porto, Portugal

Re: Forum appears to have been hacked!

Postby RealRacingRoots » 07 Mar 2012, 06:19

kostas22 wrote:It will be a test of fire for your brand new PC! :D


My laptop is officially dead, so I will be getting a new one probably today. It will be a trial by Bristol once i get it and install all my lovely goodies on it. (Pinnacle Studio, Civ 5, etc)
Klon in the Chatroom wrote:Vettel is just straight-up bitch nigga.


Resident Kathryn Janeway hater.
User avatar
RealRacingRoots
 
Posts: 1036
Joined: 21 Oct 2011, 16:25
Location: Canuckistan

Re: Forum appears to have been hacked!

Postby dr-baker » 09 Mar 2012, 08:54

As one of the sub-forums (not a thread, a forum) was loading (and even slightly beyond its loading), I had this website mentioned at the bottom of my browser:

Code: Select all
jospics.net/z/xml...


I missed the last three letters where the dots are, otherwise that was the whole address...
As hardcore as a peach...

West Cliff Results 2015
F1RM WEC: 1st (drivers)/2nd (teams)
F3RWRS: 3rd (drivers)/3rd (teams)
Whoop whoop.
User avatar
dr-baker
 
Posts: 8275
Joined: 30 Mar 2009, 03:30
Location: at my laptop

Re: Forum appears to have been hacked!

Postby BlindCaveSalamander » 10 Mar 2012, 05:21

I think the problem's getting worse, Norton Antivirus' picked up a trojan on my PC that I'm almost certain came from here. daysofyorr is also apparently loading up more and more things, before it took only an instant, now it's taking about a second or so. I suspect somebody set up shop there and is using that as a base of operations since daysofyorr/release.js is also coming up on autocomplete for a bunch of websites (.js being an extension for javascript files, which makes sense since I believe the exploit kit was coded in Java).

tl;dr, make sure your antivirus program is fully up-to-date, if you can, turn up the settings to aggressive or high or something along those lines until this is fixed.
Canon manager for the PMMF... I guess...
KICKBOAT
Shadaza wrote:"I went to buy the HRT Brakes, I couldn't stop myself."
Stramala (mibbit chat) wrote:my god, let's tone down the serious shite and get infected with Voecklerreha, god damn
User avatar
BlindCaveSalamander
 
Posts: 4843
Joined: 30 Mar 2009, 06:59
Location: A place.

Re: Forum appears to have been hacked!

Postby Wizzie » 10 Mar 2012, 07:40

BlindCaveSalamander wrote:I think the problem's getting worse, Norton Antivirus' picked up a trojan on my PC that I'm almost certain came from here. daysofyorr is also apparently loading up more and more things, before it took only an instant, now it's taking about a second or so. I suspect somebody set up shop there and is using that as a base of operations since daysofyorr/release.js is also coming up on autocomplete for a bunch of websites (.js being an extension for javascript files, which makes sense since I believe the exploit kit was coded in Java).

tl;dr, make sure your antivirus program is fully up-to-date, if you can, turn up the settings to aggressive or high or something along those lines until this is fixed.


The problem I have is that most anti-virus software craps itself whenever I try to run CSM for GP4. AVG on the other hand doesn't do that. However, it has also been picking up a busload of trojans over the past few weeks. :|
Martin Brundle, at the 2005 San Marino GP wrote:You can sort of imagine in four or five years time talking about these guys we've got on the front two rows of the grid today, can't you? They're very much the future of Grand Prix Racing.
User avatar
Wizzie
 
Posts: 11821
Joined: 01 Apr 2009, 14:42
Location: The OTHER edge of the hole that is Penrith

Re: Forum appears to have been hacked!

Postby East Londoner » 10 Mar 2012, 10:42

I'm getting scared. I want to go home. Please HWNSNBM, make it stop :(
The 1990s were better. Fact. And you bloody well know it.

Murray Walker: There's a car coming into the pits now, they're so unreliable with all those electronics on board.
James Hunt: Actually, Murray, one of his wheels has just fallen off...
User avatar
East Londoner
 
Posts: 3495
Joined: 18 Jun 2010, 04:21
Location: The 1990s.

Re: Forum appears to have been hacked!

Postby Priceless » 10 Mar 2012, 11:23

BlindCaveSalamander wrote:I think the problem's getting worse, Norton Antivirus' picked up a trojan on my PC that I'm almost certain came from here. daysofyorr is also apparently loading up more and more things, before it took only an instant, now it's taking about a second or so. I suspect somebody set up shop there and is using that as a base of operations since daysofyorr/release.js is also coming up on autocomplete for a bunch of websites (.js being an extension for javascript files, which makes sense since I believe the exploit kit was coded in Java).


I agree. I found apparently the same trojan on my Windows 7 PC a few days after my second post, and I'm also almost sure it came from this exploit.
I have removed it manually. I noticed it after a spike in network traffic in my router and the Java icon popping up out of nowhere in my taskbar.
I'm now posting from my laptop, also running Firefox 11 but on Linux, and for starters it seems to be OK. I think this is another evidence of what I found earlier - the exploit targets Windows users running either Firefox or Internet Explorer, any version. This does not mean security precautions should not be taken on other platforms/browsers too!

I would like to reiterate my earlier suggestion: access the forum with anything other than Windows, and if you're stuck with Windows, don't use neither Firefox nor Internet Explorer to come here. I would suggest Google Chrome. Opera might be another option. Additionally, use a good anti-virus and firewall, and if you use Windows Vista or Windows 7, as annoying as it might be, turn UAC on and use a non-administrative account.
User avatar
Priceless
 
Posts: 201
Joined: 24 Mar 2011, 23:55
Location: Rio de Janeiro, Brazil

Re: Forum appears to have been hacked!

Postby AndreaModa » 10 Mar 2012, 12:16

I myself have just switched from Firefox to Chrome for this very reason, god knows why I didn't do it earlier because it's far superior anyway!
That's right Eddie, that was me with the banner, Spanish GP, 2002. This pile of legal forms won't fill itself in you know...
User avatar
AndreaModa
 
Posts: 3800
Joined: 31 Mar 2009, 03:51
Location: Bristol, UK

Re: Forum appears to have been hacked!

Postby Klon » 11 Mar 2012, 00:40

Bah, I'd rather have my PC die in viruses than use Chrome.
21:38 - Dark77 - *plays rfactor champcar 2007 mod*
21:38 - Dark77 - *3 copies of orial seriva start last*
21:38 - Dark77 - wat
21:38 - Salamander - wat
21:39 - Backmarker - wat
21:39 - Klon - wat
User avatar
Klon
 
Posts: 4149
Joined: 29 Mar 2009, 03:07
Location: Flensburg, Schleswig-Holstein

Re: Forum appears to have been hacked!

Postby AndreaModa » 11 Mar 2012, 00:58

Klon wrote:Bah, I'd rather have my PC die in viruses than use Chrome.


Mine's on the way out now anyway to be fair, so I'm not too fussed myself :P
That's right Eddie, that was me with the banner, Spanish GP, 2002. This pile of legal forms won't fill itself in you know...
User avatar
AndreaModa
 
Posts: 3800
Joined: 31 Mar 2009, 03:51
Location: Bristol, UK

Re: Forum appears to have been hacked!

Postby Ferrim » 11 Mar 2012, 02:20

Avast! keeps notifying me about malicious stuff blocked whenever I enter the forums.
Go home, Bernie Ecclestone!

"Adrian, stay off the kerbs during the run, stay off the kerbs."
"So, no KERS?"
"No kerbs, KERBS, as in the side of the circuit."

F1 Rejects Forums – going off-topic since 2009!
User avatar
Ferrim
 
Posts: 1663
Joined: 02 Apr 2009, 07:45

Re: Forum appears to have been hacked!

Postby wmetcalf68 » 11 Mar 2012, 12:24

I have Avast! as well, and it says that too! :?
RIP Dan Wheldon #77
RIP Marco Simoncelli #58
NEW Honourary Youngest Forum Member, Beat ya Jeroen!
Shut up Jeroen, I know what Honourary means! :p
User avatar
wmetcalf68
 
Posts: 515
Joined: 12 Oct 2011, 06:31
Location: Canada

Re: Forum appears to have been hacked!

Postby wmetcalf68 » 11 Mar 2012, 12:25

I hate hackers! Also spammers!
RIP Dan Wheldon #77
RIP Marco Simoncelli #58
NEW Honourary Youngest Forum Member, Beat ya Jeroen!
Shut up Jeroen, I know what Honourary means! :p
User avatar
wmetcalf68
 
Posts: 515
Joined: 12 Oct 2011, 06:31
Location: Canada

Re: Forum appears to have been hacked!

Postby Klon » 11 Mar 2012, 20:22

Interestingly, my Avast has ceased to warn me about this forum today.
21:38 - Dark77 - *plays rfactor champcar 2007 mod*
21:38 - Dark77 - *3 copies of orial seriva start last*
21:38 - Dark77 - wat
21:38 - Salamander - wat
21:39 - Backmarker - wat
21:39 - Klon - wat
User avatar
Klon
 
Posts: 4149
Joined: 29 Mar 2009, 03:07
Location: Flensburg, Schleswig-Holstein

Next

Return to The HWNSNBM Memorial Forum

Who is online

Users browsing this forum: No registered users and 0 guests