Snowden Posted December 28, 2017 Share Posted December 28, 2017 2 hours ago, Wow said: Ok. Yes, the guest box with a couple of ads should be there. The popups after clicking links was the big clue. Had an old account called Viglink still running that alters link redirects for certain key words. I've removed the old script.. I guess someone had hacked the old code and injecting the malicious crap into them. Just tested, it's not fixed. Link to comment Share on other sites More sharing options...
jacindc Posted December 28, 2017 Share Posted December 28, 2017 Yeah, just tested in an incognito tab on my tablet and got a redirect. (Incognito shouldn't access the cache, right? Because I was thinking cache issues might keep the old code in play.) Link to comment Share on other sites More sharing options...
thess Posted December 28, 2017 Share Posted December 28, 2017 Just another "me too". It's far worse when not logged in, literally every single click. Link to comment Share on other sites More sharing options...
birdsofprey02 Posted December 28, 2017 Share Posted December 28, 2017 The malicious code is hard to find as it is encrypted and appears under certain conditions only. The malicious code looks like this (virus is framed red) Usually it is injected in the main template (in the database) and in the template cached copy (in the file) The malicious code can be detected by searching for “strstr($mds”, “preg_replace($i” or “#c#.substr” within database dump or skin cache files. Forum administrators should remove the code from the database and then clean skin cache to completely remove the malware from the site. Do not delete the code in cached skins only as it’ll appear again upon cache rebuild. Link to comment Share on other sites More sharing options...
Wow Posted December 28, 2017 Share Posted December 28, 2017 I never cleared the cache so that may be the issue. Just did. At worst all I ever got was a single pop-up on first click of any link while logged out and ad block disabled. Thereafter, never got anything. Seems it acts differently for everyone. Link to comment Share on other sites More sharing options...
vespasian70 Posted December 28, 2017 Share Posted December 28, 2017 Happened to me just now while logging back in. Otherwise it seems to be just fine ... but the again I'm using AdBlock. Link to comment Share on other sites More sharing options...
Wow Posted December 28, 2017 Share Posted December 28, 2017 Ok I finally was able to get in front of a computer and found the code. Should be ok now. Link to comment Share on other sites More sharing options...
jacindc Posted December 28, 2017 Share Posted December 28, 2017 1 hour ago, Wow said: Ok I finally was able to get in front of a computer and found the code. Should be ok now. Yes, I just logged in without getting any redirects. Sorry that this happened during your vacation, but glad you found and fixed! Thank you! Link to comment Share on other sites More sharing options...
birdsofprey02 Posted December 28, 2017 Share Posted December 28, 2017 3 hours ago, Wow said: Ok I finally was able to get in front of a computer and found the code. Should be ok now. Nice, thank you... was it anything similar to what I posted above? Link to comment Share on other sites More sharing options...
Wow Posted December 28, 2017 Share Posted December 28, 2017 1 hour ago, birdsofprey02 said: Nice, thank you... was it anything similar to what I posted above? It wasn't php code, but a modified HTML language that the template bits use to eval php scripts. Located just before the closing body tag. Originated from Ukraine based on the IP who hacked into the CP and inserted the code. Link to comment Share on other sites More sharing options...
Snowden Posted December 28, 2017 Share Posted December 28, 2017 3 hours ago, Wow said: It wasn't php code, but a modified HTML language that the template bits use to eval php scripts. Located just before the closing body tag. Originated from Ukraine based on the IP who hacked into the CP and inserted the code. Nice! Do you know how they got into the CP? (known exploits, default username/password, etc.) and can we confirm there was nothing else comprised like account passwords? Link to comment Share on other sites More sharing options...
Casualbrain Posted December 29, 2017 Author Share Posted December 29, 2017 Thanks for the work to fix this issue all! Link to comment Share on other sites More sharing options...
Wow Posted December 29, 2017 Share Posted December 29, 2017 18 hours ago, Snowden said: Nice! Do you know how they got into the CP? (known exploits, default username/password, etc.) and can we confirm there was nothing else comprised like account passwords? The CP logs record every action of anyone who logs into yur CP and all that was done was throwing alteration to the global template coding. All accounts with access to CP have new passwords in place and additonal security measures have been taken as well. Link to comment Share on other sites More sharing options...
mattie g Posted January 18, 2018 Share Posted January 18, 2018 Thanks @Wow for your work on this, but (and there’s always a “but”) a heads up that it just happened to me again - twice within a couple minutes. Link to comment Share on other sites More sharing options...
nzucker Posted January 18, 2018 Share Posted January 18, 2018 Why do we need pop-ups at all? Pathetic cash grab. Link to comment Share on other sites More sharing options...
ApacheTrout Posted January 18, 2018 Share Posted January 18, 2018 I'm getting new tabs (State Farm ad) when I click on 'new post by ...." when using Firefox on a pc. Link to comment Share on other sites More sharing options...
25thamendmentfan Posted January 18, 2018 Share Posted January 18, 2018 I think we need to get Mueller in here to find out "what the hel! Is going on" as trump would say. Link to comment Share on other sites More sharing options...
25thamendmentfan Posted January 18, 2018 Share Posted January 18, 2018 8 hours ago, nzucker said: Why do we need pop-ups at all? Pathetic cash grab. I have no problem with them monetizing the site if this is indeed happening. This business model is beginning to work for the ny times. Link to comment Share on other sites More sharing options...
25thamendmentfan Posted January 18, 2018 Share Posted January 18, 2018 I've often wondered if anyone's making money off this site? There's enough snow lovers from dc to Maine to sell winter subscriptions and make a decent amount of money. And then a separate annual tier for year round members who post year round like many of the New England bros. Link to comment Share on other sites More sharing options...
tstate21 Posted January 18, 2018 Share Posted January 18, 2018 FYI I have been getting a ton of redirects and ads on the mobile version of the site in the past couple days. Wasnt having this issue before. Link to comment Share on other sites More sharing options...
Baroclinic Zone Posted January 18, 2018 Share Posted January 18, 2018 9 hours ago, nzucker said: Why do we need pop-ups at all? Pathetic cash grab. Well this site doesn't pay for itself. Costs money to develop and host monthly. So either you go with ads or you set up a monthly subscription to access. The owners of this board chose the former. This being said, all your concerns are duly noted and have been passed on so they can be rectified. Link to comment Share on other sites More sharing options...
MJO812 Posted January 18, 2018 Share Posted January 18, 2018 42 minutes ago, tstate21 said: FYI I have been getting a ton of redirects and ads on the mobile version of the site in the past couple days. Wasnt having this issue before. Same here It's annoying Link to comment Share on other sites More sharing options...
forkyfork Posted January 18, 2018 Share Posted January 18, 2018 2 hours ago, Baroclinic Zone said: Well this site doesn't pay for itself. Costs money to develop and host monthly. So either you go with ads or you set up a monthly subscription to access. The owners of this board chose the former. This being said, all your concerns are duly noted and have been passed on so they can be rectified. what was wrong with donation drives? Link to comment Share on other sites More sharing options...
the ghost of leroy Posted January 18, 2018 Share Posted January 18, 2018 16 minutes ago, forkyfork said: what was wrong with donation drives? they worked years ago before the staff squandered good will with the member base and became complacent Link to comment Share on other sites More sharing options...
mappy Posted January 18, 2018 Share Posted January 18, 2018 started getting pop ups last night. i can handle the large banner ads at the top and bottom of pages, but legit pop ups in the middle of my page is super annoying. Link to comment Share on other sites More sharing options...
the ghost of leroy Posted January 18, 2018 Share Posted January 18, 2018 Just now, mappy said: started getting pop ups last night. i can handle the large banner ads at the top and bottom of pages, but legit pop ups in the middle of my page is super annoying. that's that fire ass year 2002 web monetization strategy Link to comment Share on other sites More sharing options...
mappy Posted January 18, 2018 Share Posted January 18, 2018 1 minute ago, cmasty1978 said: that's that fire ass year 2002 web monetization strategy oh. im back at 4pm. Link to comment Share on other sites More sharing options...
Baroclinic Zone Posted January 18, 2018 Share Posted January 18, 2018 28 minutes ago, forkyfork said: what was wrong with donation drives? Good question. Not sure they've been as successful in the past few years. Link to comment Share on other sites More sharing options...
Rjay Posted January 18, 2018 Share Posted January 18, 2018 24 minutes ago, mappy said: oh. im back at 4pm. Lol Link to comment Share on other sites More sharing options...
mappy Posted January 18, 2018 Share Posted January 18, 2018 4 minutes ago, Rjay said: Lol 3:57 to be exact. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.