NOTICE: Possible trojan on C&F
- Dale
- The Landlord
- Posts: 10293
- Joined: Wed May 16, 2001 6:00 pm
- Please enter the next number in sequence: 1
- Location: Chiff & Fipple's LearJet: DaleForce One
- Contact:
It's all pretty odd. SOMETHING happened, for sure. The problem is that Rich, who knows phpbb thoroughly, can't find any evidence of any changed php files. So, there's nothing to fix. I wonder if whatever got hacked got un-hacked. I dunno.
So, you know,
I would recommend that we put the AE-35 unit back in operation and let it fail. It should then be a simple matter to track down the cause. We can certainly afford to be out of communication for the short time it will take to replace it.
Break
So, you know,
I would recommend that we put the AE-35 unit back in operation and let it fail. It should then be a simple matter to track down the cause. We can certainly afford to be out of communication for the short time it will take to replace it.
Break
- peeplj
- Posts: 9029
- Joined: Mon Jan 21, 2002 6:00 pm
- Please enter the next number in sequence: 1
- Location: forever in the old hills of Arkansas
- Contact:
I wonder if it came in inside one of the ad frames, or if C&F is big enough that it uses load balancing and only some of the servers were affected?
Asus.com also got hit via that second route.
http://isc.sans.org/diary.html?storyid=2582 might be worth reading.
--James
Asus.com also got hit via that second route.
http://isc.sans.org/diary.html?storyid=2582 might be worth reading.
--James
http://www.flutesite.com
-------
"Though no one can go back and make a brand new start, anyone can start from now and make a brand new ending" --Carl Bard
-------
"Though no one can go back and make a brand new start, anyone can start from now and make a brand new ending" --Carl Bard
- Nanohedron
- Moderatorer
- Posts: 38239
- Joined: Wed Dec 18, 2002 6:00 pm
- antispam: No
- Please enter the next number in sequence: 8
- Tell us something.: Been a fluter, citternist, and uilleann piper; committed now to the way of the harp.
Oh, yeah: also a mod here, not a spammer. A matter of opinion, perhaps. - Location: Lefse country
Say, does anybody else find this change? Cursor over the email clicky no longer reveals the email address; clicking to email, my Outlook Express no longer applies to the process. Instead, I just get a page with a space for the subject line and a space on which to write text, and a "send" clicky.
As a mod, I sometimes have to judge spammers by the nature of their email addresses, so this is something of an inconvenience.
I wonder what else is up.
As a mod, I sometimes have to judge spammers by the nature of their email addresses, so this is something of an inconvenience.
I wonder what else is up.
Last edited by Nanohedron on Sun Apr 08, 2007 9:23 am, edited 1 time in total.
"If you take music out of this world, you will have nothing but a ball of fire." - Balochi musician
- Joseph E. Smith
- Posts: 13780
- Joined: Sat Mar 06, 2004 2:40 pm
- antispam: No
- Location: ... who cares?...
- Contact:
- Nanohedron
- Moderatorer
- Posts: 38239
- Joined: Wed Dec 18, 2002 6:00 pm
- antispam: No
- Please enter the next number in sequence: 8
- Tell us something.: Been a fluter, citternist, and uilleann piper; committed now to the way of the harp.
Oh, yeah: also a mod here, not a spammer. A matter of opinion, perhaps. - Location: Lefse country
- Joseph E. Smith
- Posts: 13780
- Joined: Sat Mar 06, 2004 2:40 pm
- antispam: No
- Location: ... who cares?...
- Contact:
- Dale
- The Landlord
- Posts: 10293
- Joined: Wed May 16, 2001 6:00 pm
- Please enter the next number in sequence: 1
- Location: Chiff & Fipple's LearJet: DaleForce One
- Contact:
At this point, I'm convinced that some kind of trojan was picked up by some of us yesterday via the board. But, unfortunately, there's just no way of knowing, at least yet, where it came from. My understanding is that jpg files can now transmit trojans...and I kind of like the idea that it might have been a banner ad.
Weird stuff.
Weird stuff.
- burnsbyrne
- Posts: 1345
- Joined: Thu Apr 11, 2002 6:00 pm
- Please enter the next number in sequence: 1
- Location: Cleveland, Ohio
- rich
- i see what you did there
- Posts: 609
- Joined: Mon May 14, 2001 6:00 pm
- Please enter the next number in sequence: 1
- Location: Toronto, Ontario
- Contact:
The switch to disable display of email addresses is not only right below the switch to enable or disable the board, but is also labeled "enable" and "disable" while the board-disable switch is labeled "yes" and "no" -- AND setting the former to "enable" disables direct email. So my guess is that in all of the enabling and disabling of the board, either Dale or I hit the wrong switch once.Nanohedron wrote:Say, does anybody else find this change? Cursor over the email clicky no longer reveals the email address; clicking to email, my Outlook Express no longer applies to the process. Instead, I just get a page with a space for the subject line and a space on which to write text, and a "send" clicky.
It should be back to normal (displaying email addresses) now.
-Rich
-
- Posts: 2258
- Joined: Thu Jul 26, 2001 6:00 pm
- Please enter the next number in sequence: 1
- Location: Nashville, TN
- Contact:
Yay for Firefox! Yay for Ubuntu Linux!
I feel sorry for you poor suckers stuck with internet exploder and windblows.
I feel sorry for you poor suckers stuck with internet exploder and windblows.
<i>The very powerful and the very stupid have one thing in common. They don't alter their views to fit the facts. They alter the facts to fit their views. Which can be uncomfortable if you happen to be one of the facts that needs altering.</i>