spacer

Welcome Guest ( Log In | Register )

 
Digg this topic Save to del.icio.us Submit to Reddit Slashdot It
Reply to this topicStart new topic
> Forums Hacked
Pete
post 8th May 2006, 4:39pm
Post #1


Administrator
*****

Group: Admin
Posts: 3,039
Joined: May 2002
From: Cheshire, England
Member No.: 1



Yesterday, an exploit in our forum software allowed a malicious script to alter the templates and cause a script to run for every visitor viewing the forums using Internet Explorer at that time.

We are therefore advising that anyone who has visited the forum in the past 48 hours should run a virus scan on their system to see if anything has infected their system. It seems that only visitors using Internet Explorer were affected as this particular browser has security issues that Microsoft have not yet patched.

Also, the attack allowed the script in question to abuse the Mass Email feature of our forum software and as a result many members will have received an email from admin@strategycore.co.uk

Delete this email

This is not a real email account and unfortunately the security hole was big enough to allow the script to send a rather legitimate-looking email to many users.

The security hole has since been patched and we can only apologise for the inconvenience and recommend that all visitors to any website on the internet be vigilant and have an up-to-date antivirus system installed on their PC.


--------------------
Go to the top of the page
 
+Quote Post
Pete
post 8th May 2006, 4:44pm
Post #2


Administrator
*****

Group: Admin
Posts: 3,039
Joined: May 2002
From: Cheshire, England
Member No.: 1



As an addendum to the main post above, I'm making a suggestion regarding internet browsers below.

I didn't want to make it sound like I'm lecturing, so this is merely some free advice which you may be interested in.

Internet Explorer is, whilst the easiest choice for an internet browser as it is pre-installed with the operating system, full of bugs and not a good choice for an internet browser if you are concerned about the security of your PC.

Two excellent and very secure alternatives are: Firefox and Opera


--------------------
Go to the top of the page
 
+Quote Post
Bomb Bloke
post 8th May 2006, 10:30pm
Post #3


The Smily Admin
*****

Group: Admin
Posts: 2,990
Joined: September 2002
From: Tasmania (AU)
Member No.: 152



Given that the nature of attacks against our users tends to be Java based, I would also recommend keeping your VM up to date.


--------------------
BB's X-Com Projects Page
You're just jealous 'cause the voices only talk to me :P
We love Tammy! :)
Go to the top of the page
 
+Quote Post
Kernel
post 9th May 2006, 2:16pm
Post #4


Her Majesty's Imperial Guard
****

Group: Members
Posts: 122
Joined: May 2003
Member No.: 623



QUOTE(Pete @ 8th May 2006, 5:39pm) *
It seems that only visitors using Internet Explorer were affected as this particular browser has security issues that Microsoft have not yet patched.


Well that's MS for ya. tongue.gif


--------------------
"Any rumors of a military coup by the Imperial Guard are greatly exaggerated."

Duct tape is like the force. It has a light side, a dark side, and it holds the universe together....
-- Carl Zwanzig
Go to the top of the page
 
+Quote Post
uriaheep
post 9th May 2006, 3:08pm
Post #5


Fire Imp - Cat? Me? No never!
****

Group: Members
Posts: 203
Joined: November 2005
From: England
Member No.: 4,033



Ahhh, I was attacked and I'm using Firefox. I've got OE though. I managed to spot it faily quick though.


--------------------
LAST OF A DYING BROOD.
Go to the top of the page
 
+Quote Post
Praetoris
post 9th May 2006, 3:22pm
Post #6


Sergeant
***

Group: Members
Posts: 63
Joined: December 2005
From: Kil, Sweden
Member No.: 4,163



The mail sent out was a bit too obvious for me to fall for. no greetings, no content, no nothing.

Just this sentence and a link to an *.exe file:
"We have made a small tool for our site, I think you will guess what to do with it...."


While on the subject of browsers I thought this could be interesting to you:

http://www.thecounter.com/stats/2006/April/browser.php

There are also some other neat stats on that site if you click around for a bit.
Go to the top of the page
 
+Quote Post
Pete
post 9th May 2006, 3:44pm
Post #7


Administrator
*****

Group: Admin
Posts: 3,039
Joined: May 2002
From: Cheshire, England
Member No.: 1



Hmm, that's odd because the W3C website (I've lost the link to the stats at the mo) had Firefox at 25% of the market.

Good to see you two were quick off the mark though wink.gif


--------------------
Go to the top of the page
 
+Quote Post
Praetoris
post 9th May 2006, 3:49pm
Post #8


Sergeant
***

Group: Members
Posts: 63
Joined: December 2005
From: Kil, Sweden
Member No.: 4,163



I think the stats are based only off sites that has a membershp or something with the counter, I'm not entirely sure but the stats are still pretty clear.

IE dominates the market...sadly
Go to the top of the page
 
+Quote Post
uriaheep
post 9th May 2006, 7:21pm
Post #9


Fire Imp - Cat? Me? No never!
****

Group: Members
Posts: 203
Joined: November 2005
From: England
Member No.: 4,033



I have this address that the file links too - *http://traffweb.biz/*

Not sure if it ties in but it calls itself a test page for the Apache HTTP Server.


--------------------
LAST OF A DYING BROOD.
Go to the top of the page
 
+Quote Post
Pete
post 9th May 2006, 7:52pm
Post #10


Administrator
*****

Group: Admin
Posts: 3,039
Joined: May 2002
From: Cheshire, England
Member No.: 1



It's possible that it's masquerading as a test page or the person's webhost has taken the site offline.

Either way I'd avoid it, but cheers for the info smile.gif


--------------------
Go to the top of the page
 
+Quote Post
Space Voyager
post 10th May 2006, 10:39am
Post #11


I've got my eye on you!
****

Group: Site Staff
Posts: 511
Joined: November 2002
From: Slovenia
Member No.: 1,078



Look at the bright side of IE - with such a prevailing chunk of the pie it's also (almost) the only target. Nobody is going to waste his/her energy (if you don't consider creating viruses a total waste of energy in itself) for 8% if they can hurt 90...
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts   12 Pete 1,478 29th August 2004, 2:19pm
Last post by: Kret
No New Posts   8 Aralez 1,821 6th November 2003, 7:14pm
Last post by: Siegfried
No New Posts   0 Biggles 1,196 3rd December 2003, 12:19pm
Last post by: Biggles
No New Posts   5 vs322 872 12th July 2005, 6:55pm
Last post by: Slaughter
No new   21 Solitaire 1,394 29th July 2005, 9:30pm
Last post by: FullAuto

RSS Lo-Fi Version Time is now: 6th October 2008, 4:33pm