NOTICE: Possible trojan on C&F

Socializing and general posts on wide-ranging topics. Remember, it's Poststructural!
User avatar
missy
Posts: 5833
Joined: Sun Sep 14, 2003 7:46 am
Please enter the next number in sequence: 1
Location: Cincinnati, OH
Contact:

Post by missy »

Lambchop - that's exactly the warning I got with Symantec, too.

I just wiped out my temp file - since that's where it was trying to go.
Missy

"When facts are few, experts are many"

http://www.strothers.com
User avatar
Dale
The Landlord
Posts: 10293
Joined: Wed May 16, 2001 6:00 pm
Please enter the next number in sequence: 1
Location: Chiff & Fipple's LearJet: DaleForce One
Contact:

Post by Dale »

It's all pretty odd. SOMETHING happened, for sure. The problem is that Rich, who knows phpbb thoroughly, can't find any evidence of any changed php files. So, there's nothing to fix. I wonder if whatever got hacked got un-hacked. I dunno.

So, you know,
Image

I would recommend that we put the AE-35 unit back in operation and let it fail. It should then be a simple matter to track down the cause. We can certainly afford to be out of communication for the short time it will take to replace it.

Break
User avatar
peeplj
Posts: 9029
Joined: Mon Jan 21, 2002 6:00 pm
Please enter the next number in sequence: 1
Location: forever in the old hills of Arkansas
Contact:

Post by peeplj »

I wonder if it came in inside one of the ad frames, or if C&F is big enough that it uses load balancing and only some of the servers were affected?

Asus.com also got hit via that second route.

http://isc.sans.org/diary.html?storyid=2582 might be worth reading.

--James
http://www.flutesite.com

-------
"Though no one can go back and make a brand new start, anyone can start from now and make a brand new ending" --Carl Bard
User avatar
missy
Posts: 5833
Joined: Sun Sep 14, 2003 7:46 am
Please enter the next number in sequence: 1
Location: Cincinnati, OH
Contact:

Post by missy »

Dale,Dale,Dale - c'mon - it was the Crystal People!!!!
Missy

"When facts are few, experts are many"

http://www.strothers.com
User avatar
djm
Posts: 17853
Joined: Sat May 31, 2003 5:47 am
Please enter the next number in sequence: 1
Location: Canadia
Contact:

Post by djm »

Open the pod bay doors, HAL.

Image

djm
I'd rather be atop the foothills than beneath them.
User avatar
Nanohedron
Moderatorer
Posts: 38239
Joined: Wed Dec 18, 2002 6:00 pm
antispam: No
Please enter the next number in sequence: 8
Tell us something.: Been a fluter, citternist, and uilleann piper; committed now to the way of the harp.

Oh, yeah: also a mod here, not a spammer. A matter of opinion, perhaps.
Location: Lefse country

Post by Nanohedron »

Say, does anybody else find this change? Cursor over the email clicky no longer reveals the email address; clicking to email, my Outlook Express no longer applies to the process. Instead, I just get a page with a space for the subject line and a space on which to write text, and a "send" clicky.

As a mod, I sometimes have to judge spammers by the nature of their email addresses, so this is something of an inconvenience.

I wonder what else is up.
Last edited by Nanohedron on Sun Apr 08, 2007 9:23 am, edited 1 time in total.
"If you take music out of this world, you will have nothing but a ball of fire." - Balochi musician
User avatar
Joseph E. Smith
Posts: 13780
Joined: Sat Mar 06, 2004 2:40 pm
antispam: No
Location: ... who cares?...
Contact:

Post by Joseph E. Smith »

My guess, it is a privacy matter for the recipient.
Image
User avatar
Nanohedron
Moderatorer
Posts: 38239
Joined: Wed Dec 18, 2002 6:00 pm
antispam: No
Please enter the next number in sequence: 8
Tell us something.: Been a fluter, citternist, and uilleann piper; committed now to the way of the harp.

Oh, yeah: also a mod here, not a spammer. A matter of opinion, perhaps.
Location: Lefse country

Post by Nanohedron »

Joseph E. Smith wrote:My guess, it is a privacy matter for the recipient.
It's a totally new thing, then. 'Twas never thus, before.
"If you take music out of this world, you will have nothing but a ball of fire." - Balochi musician
User avatar
Joseph E. Smith
Posts: 13780
Joined: Sat Mar 06, 2004 2:40 pm
antispam: No
Location: ... who cares?...
Contact:

Post by Joseph E. Smith »

Nanohedron wrote:
Joseph E. Smith wrote:My guess, it is a privacy matter for the recipient.
It's a totally new thing, then. 'Tws never thus, before.

After yesterdays shut down, I am thinking so.
Image
User avatar
izzarina
Posts: 6759
Joined: Sat Jun 28, 2003 8:17 pm
Please enter the next number in sequence: 1
Location: Limbo
Contact:

Post by izzarina »

I have a Mac (which I'm assuming means that I'm fine), but of course, me being ME, I'm feeling paranoia coming on (yikes! where is my tin foil hat??). Is there a way I can do a search to find out if it's in my system?
Someday, everything is gonna be diff'rent
When I paint my masterpiece.
User avatar
Dale
The Landlord
Posts: 10293
Joined: Wed May 16, 2001 6:00 pm
Please enter the next number in sequence: 1
Location: Chiff & Fipple's LearJet: DaleForce One
Contact:

Post by Dale »

At this point, I'm convinced that some kind of trojan was picked up by some of us yesterday via the board. But, unfortunately, there's just no way of knowing, at least yet, where it came from. My understanding is that jpg files can now transmit trojans...and I kind of like the idea that it might have been a banner ad.

Weird stuff.
User avatar
burnsbyrne
Posts: 1345
Joined: Thu Apr 11, 2002 6:00 pm
Please enter the next number in sequence: 1
Location: Cleveland, Ohio

Post by burnsbyrne »

My Macafee virus scan gave me a trojan alert yesterday just after I opened C&F. It neutralized and destroyed the intruder and went on to check my entire hard drive. I am glad that Dale and the other moderators stay on top of things. It's good to know that C&F is safe
Mike
User avatar
Brian Lee
Posts: 3059
Joined: Tue Jun 26, 2001 6:00 pm
antispam: No
Please enter the next number in sequence: 8
Location: Behind the Zion Curtain
Contact:

Post by Brian Lee »

Have been using Firefox exclusively for about three years now - didn't get so much as a peep on this thing, and the boards all loaded fine yesterday. Makes me glad I'd made the switch.
User avatar
rich
i see what you did there
Posts: 609
Joined: Mon May 14, 2001 6:00 pm
Please enter the next number in sequence: 1
Location: Toronto, Ontario
Contact:

Post by rich »

Nanohedron wrote:Say, does anybody else find this change? Cursor over the email clicky no longer reveals the email address; clicking to email, my Outlook Express no longer applies to the process. Instead, I just get a page with a space for the subject line and a space on which to write text, and a "send" clicky.
The switch to disable display of email addresses is not only right below the switch to enable or disable the board, but is also labeled "enable" and "disable" while the board-disable switch is labeled "yes" and "no" -- AND setting the former to "enable" disables direct email. So my guess is that in all of the enabling and disabling of the board, either Dale or I hit the wrong switch once.

It should be back to normal (displaying email addresses) now.

-Rich
TelegramSam
Posts: 2258
Joined: Thu Jul 26, 2001 6:00 pm
Please enter the next number in sequence: 1
Location: Nashville, TN
Contact:

Post by TelegramSam »

Yay for Firefox! Yay for Ubuntu Linux!



I feel sorry for you poor suckers stuck with internet exploder and windblows. :P
<i>The very powerful and the very stupid have one thing in common. They don't alter their views to fit the facts. They alter the facts to fit their views. Which can be uncomfortable if you happen to be one of the facts that needs altering.</i>
Post Reply