Spoke too soon :(

Avlis Headlines - www.avlis.org

Moderator: Event DM

Post Reply
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Spoke too soon :(

Post by spool32 » Mon Jun 08, 2009 6:06 am

I'll attempt to fix it again in the morning... until then, add go00ogle . net (remove spaces) to your
adblock preferences under Tools-->adblock Plus Preferences.
Non-firefox users, please watch out for trojans.
User avatar
PlasmaJohn
CCC / Release Admin
CCC / Release Admin
Posts: 9010
Joined: Fri Dec 26, 2003 10:37 pm
Timezone: US/Eastern
Location: Negaria
Contact:

Re: Spoke too soon :(

Post by PlasmaJohn » Mon Jun 08, 2009 12:34 pm

Another way to block it is to add the following to your hosts file:

Code: Select all

127.0.0.1 go00ogle(dot)net
Calvin: This is so cool!
Hobbes: This is so stupid.
User avatar
gutemensch
CCC
CCC
Posts: 11850
Joined: Sun Sep 12, 2004 3:25 am
Timezone: -5
Location: Republic of Texas
Contact:

Re: Spoke too soon :(

Post by gutemensch » Mon Jun 08, 2009 1:43 pm

Here is what Kaspersky complained about when I logged in.

6/8/2009 8:25:50 AM Detected: cximnik.cn/* Firefox http://cximnik.cn/img1/index.php Databases
6/8/2009 8:25:50 AM Denied: cximnik.cn/* Firefox http://cximnik.cn/img1/index.php Databases
6/8/2009 8:25:51 AM Denied: Exploit.JS.Pdfka.gu Firefox http://xfcg.info/evo/count.php?o=11
6/8/2009 8:25:51 AM Detected: Exploit.JS.Pdfka.gu Firefox http://xfcg.info/evo/count.php?o=11
6/8/2009 8:25:52 AM Detected: peskufex.cn/* Firefox http://peskufex.cn/ss/in.cgi?7 Databases
6/8/2009 8:25:52 AM Denied: peskufex.cn/* Firefox http://peskufex.cn/ss/in.cgi?7 Databases
User avatar
Grunt
Team Member; Retired with Honors
Posts: 9579
Joined: Sat Jun 05, 2004 12:37 am
Timezone: I AM A TIME LORD
Location: Boston, MA

Re: Spoke too soon :(

Post by Grunt » Mon Jun 08, 2009 1:54 pm

PlasmaJohn wrote:Another way to block it is to add the following to your hosts file:

Code: Select all

127.0.0.1 go00ogle(dot)net
In case anyone doesn't know how to do so:
Hosts file is found under C:\WINDOWS\SYSTEM32\drivers\etc
You can edit it with notepad.
BROWSER FAIL
Not everyone can choose their browser or what can be installed on their machine. The "Firefox or Fail" attitude and giving the MSFT smirk is a bit much considering the real fail is on the website.

Thaylis Beign: Morgan, did you cast recitation?
Morgan Thornheart: Yes
Thaylis Beign: *nods*
Morgan Thornheart: Aarilax blesses you all. Now get the fuck out of here.
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Re: Spoke too soon :(

Post by spool32 » Mon Jun 08, 2009 2:48 pm

Yeah, I know. :P

Working on a real solution...
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
krackq
Demigod of Posts
Posts: 7598
Joined: Thu Jun 17, 2004 7:30 pm
Timezone: GMT-5
Location: Maryland, USA

Re: Spoke too soon :(

Post by krackq » Mon Jun 08, 2009 3:55 pm

Please be sure to dump your web browser cache too if it hasn't been in a few days. Its the link you typically use to clear out your history and temp files in IE or Firefox when you're trying to hide your pr0n from your boss or spouse.....
[Celedor Dedwend: [Talk] *turns around and shakes ass before giving it a sharp slap*
Celedor Dedwend: [Party] ((this is my finest RP beyond a shadow of a doubt.. my zenith if you will))
Fydonya Ivythorn: [Party] that's sad celedor..
User avatar
Mulu
Lord of Blithering Idiots
Posts: 140
Joined: Wed Jul 05, 2006 7:59 pm
Timezone: Pacific
Location: California

Re: Spoke too soon :(

Post by Mulu » Tue Jun 09, 2009 2:36 am

PlasmaJohn wrote:Another way to block it is to add the following to your hosts file:

Code: Select all

127.0.0.1 go00ogle(dot)net
I already show that mapped to "localhost."
Playing AD&D since 1979.

On NWVault by me:
X-INV, X-COM, War of the Worlds, Lantan University.
User avatar
Grunt
Team Member; Retired with Honors
Posts: 9579
Joined: Sat Jun 05, 2004 12:37 am
Timezone: I AM A TIME LORD
Location: Boston, MA

Re: Spoke too soon :(

Post by Grunt » Tue Jun 09, 2009 2:47 am

Mulu wrote:
PlasmaJohn wrote:Another way to block it is to add the following to your hosts file:

Code: Select all

127.0.0.1 go00ogle(dot)net
I already show that mapped to "localhost."
Yes, you can map more than one thing to 127.0.0.1 (your local machine). What this particular fix will do is keep the script from being able to be run because it will try to access the go00ogle site, and point back to your machine, and no script will run (because it's not there).

Thaylis Beign: Morgan, did you cast recitation?
Morgan Thornheart: Yes
Thaylis Beign: *nods*
Morgan Thornheart: Aarilax blesses you all. Now get the fuck out of here.
StormShadows
Prince of Bloated Discourse
Posts: 200
Joined: Fri Apr 17, 2009 9:25 pm

Re: Spoke too soon :(

Post by StormShadows » Tue Jun 09, 2009 2:56 am

Well, you can point as many of them to your machine as you want, though I am not sure how it will react (if you don't have a server running likely you will just get a destination unreachable error or some such). At the moment I have a full LAMP package with around 10 virtual hosts running on my machine with an entry for every single one in my hosts file.

But anyway, I have been meaning to ask what is the problem with the site? I doubt I can do anything to help with it, but since I can not even tell what is wrong I can't even guess...
User avatar
Mulu
Lord of Blithering Idiots
Posts: 140
Joined: Wed Jul 05, 2006 7:59 pm
Timezone: Pacific
Location: California

Re: Spoke too soon :(

Post by Mulu » Tue Jun 09, 2009 2:59 am

Sounds good. Haven't actually had an issue yet, I use Safari, but better safe than sorry.
Playing AD&D since 1979.

On NWVault by me:
X-INV, X-COM, War of the Worlds, Lantan University.
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Re: Spoke too soon :(

Post by spool32 » Tue Jun 09, 2009 3:55 am

StormShadows wrote:Well, you can point as many of them to your machine as you want, though I am not sure how it will react (if you don't have a server running likely you will just get a destination unreachable error or some such). At the moment I have a full LAMP package with around 10 virtual hosts running on my machine with an entry for every single one in my hosts file.

But anyway, I have been meaning to ask what is the problem with the site? I doubt I can do anything to help with it, but since I can not even tell what is wrong I can't even guess...
The basic problem was that someone was injecting code into the styles/subsilver2/templates/overall_header.html file... an advQuery function that, when executed, executed a file if.php at the site go00ogle dot net. if.php contained malicious code that attempted to do a series of nasty things to the client machine.

I *think* it's fixed again for good... if anyone sees differently, please let me know ASAP.

Thanks,

-spool32
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
User avatar
jaythespacehound
Apprentice Scholar
Posts: 940
Joined: Wed Sep 22, 2004 6:52 am
Location: Hobart Australia (feels like a small island sometimes...hang on it is) GMT+10

Re: Spoke too soon :(

Post by jaythespacehound » Tue Jun 09, 2009 4:25 am

You know... I can't help but ask..
How did the code get there?
StormShadows
Prince of Bloated Discourse
Posts: 200
Joined: Fri Apr 17, 2009 9:25 pm

Re: Spoke too soon :(

Post by StormShadows » Tue Jun 09, 2009 4:36 am

Spool:
Injecting? Makes me think of that big hole in a basic SQL DB interface. I would not think that would be the case on Avlis though, not as old and established as this thing is. I would think the portal should have been secured by now, and PHPBB should have SQL Injection protection built right in. I would assume that the Wiki was a pre-packaged CMS much like the forums, in which case it should be protected as well.

*Shrugs* Oh well, it is another one of those things that was sorely neglected in my education. Still, I find the whole thing rather fascinating. *Grins* I kind of built my casters after myself in that way. I rather enjoy learning new things and acquiring knowledge.

I am curious though Spool, how much knowledge/training/experience/whatever do you have with this kind of stuff?
---------

Jay:
Likely that is the million dollar question. It actually might not be a bad idea to have everyone with general server, FTP, and DB access change their passwords. But then again, if that were the problem it just might let him get everyone's passwords instead of one or two peoples... That is the problem with hackers and such. Until you know just what it was they did you can't tell how to fight them.
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Re: Spoke too soon :(

Post by spool32 » Tue Jun 09, 2009 5:23 am

Going on 15 years in the computer industry, most of it windows admin and network design... the last three in information security :)

We're all patched up right now, so sql injections are unlikely. It's either a new vulnerability, or something I've missed so far. Now that we seem to be OK again, the forensics starts!

Our logs are huge. :)
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
User avatar
loki70
Master Sage
Posts: 6988
Joined: Mon Aug 23, 2004 3:34 pm
Timezone: gmt -7
Location: Seattle, WA

Re: Spoke too soon :(

Post by loki70 » Tue Jun 09, 2009 12:17 pm

Server logs are teh suck. Just be lucky you aren't trying to find a printer in TS configurations for a remote location
User avatar
Grunt
Team Member; Retired with Honors
Posts: 9579
Joined: Sat Jun 05, 2004 12:37 am
Timezone: I AM A TIME LORD
Location: Boston, MA

Re: Spoke too soon :(

Post by Grunt » Tue Jun 09, 2009 12:36 pm

The wiki is still infected.

Thaylis Beign: Morgan, did you cast recitation?
Morgan Thornheart: Yes
Thaylis Beign: *nods*
Morgan Thornheart: Aarilax blesses you all. Now get the fuck out of here.
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Re: Spoke too soon :(

Post by spool32 » Tue Jun 09, 2009 5:03 pm

Grunt wrote:The wiki is still infected.
"again", not still... but yeah. Thanks for the catch... headed over there now to fix.
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
User avatar
ninja
Legacy DM
Legacy DM
Posts: 6600
Joined: Wed Apr 07, 2004 1:01 am
Timezone: GMT -5
Location: Chicago, IL, USA

Re: Spoke too soon :(

Post by ninja » Tue Jun 09, 2009 6:05 pm

I think this is just another ruse to allow Spool32 to increase his post count.
Go here for your custom DM item.
"Mages are over powered" - Spool32, previous head DM, said 300 times during Austin meet.
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

Re: Spoke too soon :(

Post by spool32 » Tue Jun 09, 2009 6:34 pm

8-)
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
User avatar
Sarmanos
Major Event DM
Major Event DM
Posts: 4004
Joined: Mon Aug 04, 2003 7:04 am
Timezone: GMT -5
DM Avatar: Chareth
Location: Massillon, OH

Re: Spoke too soon :(

Post by Sarmanos » Fri Jun 19, 2009 10:08 pm

Please make sure you have anti-malware or malicious site software or what not. It seems now Adblock is no longer completely stopping these attacks and I am now getting attempts to be sent to a malicious site.
Vetinari: I have noted before that you have a definite anti-authoritarian streak, Commander.
Vimes: Sir?
Vetinari: You seem to have retained this even though you are Authority.
Vimes: Sir?
Vetinari: That's practically Zen.
User avatar
PlasmaJohn
CCC / Release Admin
CCC / Release Admin
Posts: 9010
Joined: Fri Dec 26, 2003 10:37 pm
Timezone: US/Eastern
Location: Negaria
Contact:

Re: Spoke too soon :(

Post by PlasmaJohn » Sat Jun 20, 2009 12:19 am

blocking the google imposter stops it cold
Calvin: This is so cool!
Hobbes: This is so stupid.
User avatar
Demonseed
Apprentice Scholar
Posts: 765
Joined: Tue Mar 29, 2005 2:37 pm
Location: the dank, dark underbelly of Brissle

Re: Spoke too soon :(

Post by Demonseed » Sat Jun 20, 2009 12:28 am

If you have firefox, get Noscript. Stops this dead in it's tracks
Kard Fynolds, Warrior of Dru'El
Zero Wefer, Sereg'Wethrin Assassin-in-training
Post Reply