Si Veteran Posted July 8, 2006 Veteran Share Posted July 8, 2006 Didn't know you were a mod. Maybe not, but he's right. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681549 Share on other sites More sharing options...
u_diddy Posted July 8, 2006 Share Posted July 8, 2006 Didn't know you were a mod. On topic- You had me worried as I have no virus scanner till I read that it didn't work in firefox *pets firefox* :D You shouldn't pet foxes (especially one's that are on fire), they may bite your hand off or you may get burnt. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681553 Share on other sites More sharing options...
DaveLegg Developer Posted July 8, 2006 Developer Share Posted July 8, 2006 Can I request people don't post code samples from the virus involved in this, people who get email subscriptions to the thread will receive the code and may result in a virus warning (I almost lost my entire inbox, spent a while recovering it). If you want to post a code sample, please post elsewhere and link to it. NOTE: This is a personal request, I'm not writing that as a staff member, I just don't want to see people lose their emails. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681556 Share on other sites More sharing options...
DreadBoat89 Posted July 8, 2006 Share Posted July 8, 2006 You shouldn't pet foxes (especially one's that are on fire), they may bite your hand off or you may get burnt. you shouldn't meet with ie cuz you could get sick... and cant listen to opera cuz you could get your ears destroyed >.> quality of invision products had been going downhill... the money they are making is getting to their heads Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681603 Share on other sites More sharing options...
RootWind Posted July 8, 2006 Share Posted July 8, 2006 From IPB: We've seen recently a number of 'new' hack attempts in adding iframes to a board wrapper. This is because a previous exploit allowed access to the ACP and to upload a 'trojan' PHP file which has been dormant. The hacker has simply come back and started to use the trojan files to deface boards. As it stands, the very latest IPB 2.1.6 is secure against all known attacks and if you find your board defaced or an iFrame pop-up appears it's likely to be because of a trojan file which is somewhere in your installation. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681621 Share on other sites More sharing options...
Ferret Posted July 8, 2006 Share Posted July 8, 2006 You had me worried as I have no virus scanner till I read that it didn't work in firefox *pets firefox* :D Moi too - So have just installed the AV. I completly forgot about, since I formatted about a month ago. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681629 Share on other sites More sharing options...
Neil Posted July 8, 2006 Share Posted July 8, 2006 you shouldn't meet with ie cuz you could get sick... and cant listen to opera cuz you could get your ears destroyed >.> quality of invision products had been going downhill... the money they are making is getting to their heads No forum is 100% secure, however Neowin is a target because of the fact it is a technology site and one of the biggest IPB boards, but I hate the way people criticised phpBB said "well I am secure now because I am with IPB", well your not no forum is safe but keeping it up to date helps..... Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681642 Share on other sites More sharing options...
thollian Posted July 8, 2006 Share Posted July 8, 2006 always someone trying to mess things up... Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681675 Share on other sites More sharing options...
Allan Posted July 8, 2006 Share Posted July 8, 2006 Whois.ws shows ... Registrant Contact Information: Name: Steven Mears Organization: N/A Address 1: Sagewind City: Houston State: Texas Zip: 77089 Country: US Phone: +001.2814846065 Email: zchxsikpgz@mail.ru IP Address: 81.95.145.173 Website Status: inactive Cache Date: 2006-07-08 10:34:06 MST I don't know if Admin can use this info, but thought it might be useful. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681699 Share on other sites More sharing options...
lerum Posted July 8, 2006 Share Posted July 8, 2006 Allan?: Its probebly fake, which means you *could* try and get the domain removed:)) Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681713 Share on other sites More sharing options...
Axon Posted July 8, 2006 Share Posted July 8, 2006 Looks like this attacker has been busy: http://forums.invisionpower.com/index.php?...=2&bug_cat_id=9 And it seems that people with cleaned forums (meaning they'd removed the trojan and had a new 2.1.6) were still getting attacked... -Ax Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681721 Share on other sites More sharing options...
sn00pie Posted July 8, 2006 Share Posted July 8, 2006 I was getting a MySQL error page, I'm on XP Pro with NOD32/ZA no notifications here. :| Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681732 Share on other sites More sharing options...
Slimy Posted July 8, 2006 Share Posted July 8, 2006 Does this have anything to do with having a new admin? I just noticed FrogBoy :laugh: - forgive me if he's been around for a while! Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681799 Share on other sites More sharing options...
fr33k Posted July 8, 2006 Share Posted July 8, 2006 that was 13,000 post slimy BTW can't there be an announcement/warning on the front page to block "zchxsikpgz.biz"? Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681813 Share on other sites More sharing options...
mad_onion Posted July 8, 2006 Share Posted July 8, 2006 yeah i am getting this on ie7 beta 3 everytime i go to the forums i added that to restricted to stop it. i used firefox to find out what to do ;) so you still get the warnings even if you have fixed the exploit right? my pc is completely up to date and it still happen to me but notihng has happened to my pc i guess cause i have patched it? what would have happened if i hadnt? would my pc have destroyed itself? oh ps: on firefox, no users seem to have signatures and there intellitext ads in the forums, this doesnt happen on ie7 :s Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681847 Share on other sites More sharing options...
2shae Posted July 8, 2006 Share Posted July 8, 2006 2 Of my forums got hacked and i was about to put on the 2.1.6 update today here is a tracert of his domain, someone should contact the companys listed to tell them what this site is doing ___________ Microsoft Windows XP [Version 5.1.2600] © Copyright 1985-2001 Microsoft Corp. C:\Documents and Settings\jamie>tracert zchxsikpgz.biz Tracing route to zchxsikpgz.biz [81.95.145.173] over a maximum of 30 hops: 1 58 ms 63 ms 63 ms 159.134.155.63 2 65 ms 63 ms 59 ms 159.134.126.49 3 75 ms 63 ms 72 ms 159.134.127.29 4 82 ms 75 ms 79 ms 83.71.112.202 5 105 ms 83 ms 83 ms 195.66.226.185 6 77 ms 99 ms 75 ms sougreat-limited.demarc.cogentco.com [149.6.80.2 50] 7 128 ms 127 ms 104 ms 96.194.linkey.ru [213.159.96.194] 8 130 ms 123 ms 132 ms 96.22.linkey.ru [213.159.96.22] 9 117 ms 127 ms 127 ms ip-145-173.rbnnetwork.com [81.95.145.173] Trace complete. C:\Documents and Settings\jamie> _____________ Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587681853 Share on other sites More sharing options...
DaveLegg Developer Posted July 8, 2006 Developer Share Posted July 8, 2006 on firefox, no users seem to have signatures and there intellitext ads in the forums, this doesnt happen on ie7 :s I'm guessing you haven't signed in on Firefox. We disable signatures for guests to save on the bandwidth and have ads for a bit of added revenue from the lurkers :) Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682028 Share on other sites More sharing options...
Matrix XII Posted July 8, 2006 Share Posted July 8, 2006 Firefox is keeping me safe :) :D Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682054 Share on other sites More sharing options...
mad_onion Posted July 8, 2006 Share Posted July 8, 2006 Firefox is keeping me safe :) actually any browser that doesnt run on the ie core is keeping you safe. firefox isnt actively doing anything. I'm guessing you haven't signed in on Firefox. We disable signatures for guests to save on the bandwidth and have ads for a bit of added revenue from the lurkers :) oh yeah thats it obvious. i should have thought of that. im always logged in so ive never had that happen before Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682282 Share on other sites More sharing options...
primexx Posted July 8, 2006 Share Posted July 8, 2006 I came here and I saw the iFrame....and I knew something was wrong, the same thing happened at Invisionize a few days ago. NoScript completely blocked it though, so no troubles here :D http://forums.invisionize.com/index.php?showtopic=107880 And their solution: http://forums.invisionize.com/index.php?showtopic=107874 Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682348 Share on other sites More sharing options...
simsie Posted July 8, 2006 Share Posted July 8, 2006 Opera is good, didn't even notice until i saw this post Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682399 Share on other sites More sharing options...
Orange Posted July 8, 2006 Share Posted July 8, 2006 I'm in Firefox now, but when I was viewing Neowin in Internet Explorer seven different trojans appeared. :p Same here well i always browse in Firefox but i gave IE ago and bamm got hit. So gonna be a fan boy here and say go with Firefox or Opera :devil: Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682481 Share on other sites More sharing options...
James123 Posted July 8, 2006 Share Posted July 8, 2006 I don't mean to offend but... what are the coders doing? Two or three different people have posted official invision links of how to fix this (at least, temporarily), and the code of the exploit itself has been posted so they would be able to see what's happening and how to stop it but the problem is STILL there! Do you not think it's unacceptable for a site of this size to have a script potentially infecting any unsuspecting user for over 12 hours (15+ now), plus "Neowin Coder(s)" have been posting here since this morning, so they've been aware of it for ages. Again, no offence intended, just pointing out that it's taking an awful long time to patch a small security hole, with patches available from invision, or even to write a custom fix, and yes, I know you're not affected if you don't use IE or you have a anti-virus, but that's no excuse. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682524 Share on other sites More sharing options...
Shof Posted July 8, 2006 Share Posted July 8, 2006 I don't mean to offend but... what are the coders doing? Two or three different people have posted official invision links of how to fix this (at least, temporarily), and the code of the exploit itself has been posted so they would be able to see what's happening and how to stop it but the problem is STILL there! Do you not think it's unacceptable for a site of this size to have a script potentially infecting any unsuspecting user for over 12 hours (15+ now), plus "Neowin Coder(s)" have been posting here since this morning, so they've been aware of it for ages. Again, no offence intended, just pointing out that it's taking an awful long time to patch a small security hole, with patches available from invision, or even to write a custom fix, and yes, I know you're not affected if you don't use IE or you have a anti-virus, but that's no excuse. what if it is already fixed and you dont know yet? Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682534 Share on other sites More sharing options...
aos101 Posted July 8, 2006 Share Posted July 8, 2006 I don't mean to offend but... what are the coders doing? Two or three different people have posted official invision links of how to fix this (at least, temporarily), and the code of the exploit itself has been posted so they would be able to see what's happening and how to stop it but the problem is STILL there! Um, where is it? The only iframes I can see in the code are Neowin ones. Link to comment https://www.neowin.net/forum/topic/476942-have-the-forums-been-hacked/page/4/#findComment-587682539 Share on other sites More sharing options...
Recommended Posts