PDA

View Full Version : Forums Hacked??



LA_MERC_YellowDog
December 6th, 2011, 04:41 PM
Ok either I have a problem or WE have a problem, take a look at the screen shot?

http://i274.photobucket.com/albums/jj245/yellowdog02/Warning.jpg

LA_MERC_FragFood
December 6th, 2011, 06:31 PM
NOD32 agrees and showed the home page as hosting a JS/Iframe.AS trojan (link to some info (http://www.wilderssecurity.com/showthread.php?t=313169)). Went to it again using Chrome and the same version of NOD32 on an XP VM and had no issues or warnings from Google... odd.

May need to talk to the hosting company.

MUCH more extensive information here (http://blog.unmaskparasites.com/2011/11/09/tmpwp_inc-or-not-your-typical-wordpress-attack/).

LA_MERC_YellowDog
December 6th, 2011, 07:12 PM
Well, Im not going to act like i understood 80%of what I just read, but I think I got a 20% grasp on it :)

It sounds like we may have something that's managed to gain a backdoor into our web server. Hopefully Onji will chime in, I would like to hear what he thinks.

LA_MERC_goose
December 7th, 2011, 04:44 AM
Frag's being nice as he calls "Operator Error" ....

LA_MERC_Onji
December 7th, 2011, 09:01 AM
thanks guys, let me try to track this down

LA_MERC_Onji
December 7th, 2011, 10:05 AM
well for the life of me i cannot replicate this error

LA_MERC_YellowDog
December 7th, 2011, 11:17 AM
I had it hit the other day, but the message disapered in a split second, this time it stuck. It dose not hit every time, as a mater of fact I think this is only the second time I've seen it.

LA_MERC_FragFood
December 7th, 2011, 05:11 PM
That's why I'm thinking possible offsite hosted content? Onji - Is there any rotating content that might be the culprit?

LA_MERC_Spark
December 9th, 2011, 07:01 AM
I had an issue with the old BF sigs before... Every thread the Toby posted it lol!

LA_MERC_th33_r00k
December 9th, 2011, 02:17 PM
I think it has a relation to an outdated java script. It has been doing it for quite some time.

SnAkEbItE
December 14th, 2011, 12:04 PM
Here is what I had show up on my scan.

http://i13.photobucket.com/albums/a293/Firebelow/LAMERCVirus.jpg

LA_MERC_YellowDog
December 16th, 2011, 01:22 PM
I got the exact same thing poped up when I hit the forums :(


Humm somting fishy goin on???

LA_MERC_th33_r00k
December 19th, 2011, 10:35 AM
I get this:
did not save corectly, but it was the same as above in chrome, but a different site was mentioned.
when entering site,
and this:
http://www.robertwhited.com/uploads/lamerc2.jpg
when uploading a file through the special page.

42d3e78f26a4b20d412==