Hard Light Productions Forums

Site Management => Site Support / Feedback => Topic started by: Dark Hunter on March 19, 2013, 10:39:01 pm

Title: Possible virus on site...
Post by: Dark Hunter on March 19, 2013, 10:39:01 pm
Avast is currently freaking out over a JavaScript whenever I access a page on Hard Light.

Gives the name as "JS: Iframe-AHV", and classifies it as a Trojan.

Maybe Avast is being overzealous, but thought you folks should know just in case.

EDIT: Also, only happens on Firefox. Chrome doesn't give the same warning.
Title: Re: Possible virus on site...
Post by: An4ximandros on March 19, 2013, 10:45:13 pm
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.
Title: Re: Possible virus on site...
Post by: Dark Hunter on March 19, 2013, 10:52:21 pm
Yes, that too. :p
Title: Re: Possible virus on site...
Post by: Qent on March 19, 2013, 10:53:13 pm
Mine, Firefox. I also get a bar saying that additional plugins are required to view the page.
Title: Re: Possible virus on site...
Post by: NGTM-1R on March 19, 2013, 11:23:33 pm
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.

Confirming for Firefox and Chrome.
Title: Re: Possible virus on site...
Post by: rev_posix on March 19, 2013, 11:28:43 pm
Nope, not a virus.  Should be good now
Title: Re: Possible virus on site...
Post by: Dark Hunter on March 19, 2013, 11:33:19 pm
Hmm... still getting it when I go to post a message. Otherwise it's gone.
Title: Re: Possible virus on site...
Post by: Fury on March 20, 2013, 12:18:56 am
Nope, not a virus.  Should be good now
What was it?
Title: Re: Possible virus on site...
Post by: yuezhi on March 20, 2013, 12:36:40 am
Avast declaring war on Java?

and there was a little side discussion on Java elsewhere :p
Title: Re: Possible virus on site...
Post by: FUBAR-BDHR on March 20, 2013, 01:02:11 am
HLP Mantis being in maintenance mode a result of this or is there actually maintenance going on?
Title: Re: Possible virus on site...
Post by: rev_posix on March 20, 2013, 09:42:05 pm
Yes, sorry, mantis access is back.  Side effect from the backups I restored from.
Title: Re: Possible virus on site...
Post by: Fury on March 21, 2013, 03:07:27 pm
Assuming this was an actual virus infection again, perhaps it would be time to consider scrapping this old server and starting from scratch? This trend is honestly worrisome.
Title: Re: Possible virus on site...
Post by: rev_posix on March 21, 2013, 03:13:48 pm
Umm, no, not a virus.  It was an attack that injected the redirect code into the php files.

And yes, I agree that the server needs to be nuked and repaved with current versions of apache, php, and so on.

However, as we do not have remote console access in case something goes wrong and the OS will not boot, not to mention it's not 'our' machine (HLP and it's hosted sites are not the primary site, nor does it have it's name on the hosting bills/account), it's not that simple, nor is it something that I'm comfortable or willing to do.

That being said, I have made a tweak to the install at a filesystem level.  I don't know for sure if it will prevent it, we will have to see, but I'm hopeful that until the server is rebuilt, it will help prevent these things.
Title: Re: Possible virus on site...
Post by: Lorric on March 21, 2013, 07:30:40 pm
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.

It's doing that for me now. It wasn't before, I've read this topic before.
Title: Re: Possible virus on site...
Post by: karajorma on March 21, 2013, 07:39:45 pm
Avast is giving me warnings again.
Title: Re: Possible virus on site...
Post by: headdie on March 21, 2013, 08:01:28 pm
avast + chrome and no warnings
Title: Re: Possible virus on site...
Post by: niffiwan on March 22, 2013, 06:09:11 pm
Just wondering if you guys have considered using apache mod_security in front of the HLP websites?  At work we used this as a stop-gap measure until we could select & install a "real" web application firewall in front of our websites.
Title: Re: Possible virus on site...
Post by: karajorma on March 28, 2013, 03:23:46 am
Here we go again. Avast just started complaining again.
Title: Re: Possible virus on site...
Post by: Fury on March 28, 2013, 03:29:00 am
Yup.

http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?name=Trojan%3aJS%2fBlacoleRef.CZ&threatid=2147679781
Title: Re: Possible virus on site...
Post by: 0rph3u5 on March 28, 2013, 03:52:45 am
Same here but not sure its the same malware my AV is on about as Fury's

Quote
Details:
Web-Seite:http://www.hard-light.net/forums/
Gefundene Viren: JS:Trojan.JS.Iframe.DC
Title: Re: Possible virus on site...
Post by: niffiwan on March 28, 2013, 04:44:25 am
hmmm. NoScript is telling me that "studentexchanges.org.ua" wants to run some javascript on HLP.  How about.... no.
Title: Re: Possible virus on site...
Post by: newman on March 28, 2013, 05:34:14 am
Can't even get on hlp without disabling AVG. Firefox on my end. Can also confirmed all the sizes got weird.
Title: Re: Possible virus on site...
Post by: deathspeed on March 28, 2013, 05:39:21 am
I'm not seeing any of this stuff, using IE10 (with javascript enabled) and Avast.  BitDefender used to give me fits though.
Title: Re: Possible virus on site...
Post by: CommanderDJ on March 28, 2013, 06:06:40 am
Font sizes are weird over here too. Also seeing the same NoScript warning as niffiwan.

EDIT: Firefox here as well.
Title: Re: Possible virus on site...
Post by: NGTM-1R on March 28, 2013, 06:13:59 am
Giant text here.
Title: Re: Possible virus on site...
Post by: jg18 on March 28, 2013, 08:02:04 am
Yeah, giant text here, too, at least for the listing of boards on the main page. FF 19.0.2 on OS X 10.6.

After FF said "Transferring data from studentexchanges.org.ua..." or something similar in the status bar, I instantly got NoScript :nervous: although I haven't gotten the warning that niffiwan and CommanderDJ did.
Title: Re: Possible virus on site...
Post by: Rodo on March 28, 2013, 08:36:41 am
Getting giant text and this warning from ESET: "js/kryptic.aiu troyano" as well.
Title: Re: Possible virus on site...
Post by: MP-Ryan on March 28, 2013, 11:17:56 am
Giant text, some unusual things in NoScript, but no security flags - yet.
Title: Re: Possible virus on site...
Post by: Mongoose on March 28, 2013, 10:46:02 pm
Nothing wrong here, text or otherwise, while running MSE.
Title: Re: Possible virus on site...
Post by: Dark Hunter on March 29, 2013, 12:20:07 am
Looks like it's fixed now...


Running FF.
Title: Re: Possible virus on site...
Post by: BritishShivans on March 29, 2013, 06:02:00 am
I'm getting similar. Some huge text, and NoScript picks up that studentexchanges.org.ua thing as well. It's probably our possible virus.
Title: Re: Possible virus on site...
Post by: newman on March 29, 2013, 06:05:05 am
Sizes are back to normal and AVG stopped throwing tantrums on my end (Windows 7 / ffox)
Title: Re: Possible virus on site...
Post by: Rodo on March 29, 2013, 01:57:13 pm
Clean now and font issue fixed, good work admins :yes:
Title: Re: Possible virus on site...
Post by: Lorric on March 29, 2013, 02:10:39 pm
Mine said it was a blackhole exploit kit. It's gone now.
Title: Re: Possible virus on site...
Post by: Zacam on March 29, 2013, 05:03:38 pm
And Lorric would win a gold star, if I felt like handing any out.

So, make sure you have NoScript on yer browsers cause guess what? We're not the only place that's ever been hit with it. And even after cleaning it up, we'll still get hit again.

A solution is being worked on to ultimately address the issue, but it is going to take a while to do.
Title: Re: Possible virus on site...
Post by: An4ximandros on March 29, 2013, 05:50:09 pm
Thanks for the heads up, installed NoScript. Shame this sort of bull happens though.
Title: Re: Possible virus on site...
Post by: Lorric on March 29, 2013, 06:09:36 pm
And Lorric would win a gold star, if I felt like handing any out.

So, make sure you have NoScript on yer browsers cause guess what? We're not the only place that's ever been hit with it. And even after cleaning it up, we'll still get hit again.

A solution is being worked on to ultimately address the issue, but it is going to take a while to do.

No, gimme my gold star, damn it! It's mine!  :lol:
Title: Re: Possible virus on site...
Post by: Spoon on March 29, 2013, 06:14:21 pm
I've got avast installed but it never told me anything (I told it to be quiet with the popups though...) nothing in the logs either. Then again ive been running noscript for a while now so maybe thats why.
Title: Re: Possible virus on site...
Post by: Fury on March 30, 2013, 02:22:27 am
I've never liked using NoScript or ScriptSafe (Chrome) because they make browsing of websites really difficult at times. The best method is to block only javascript that points to another domain. But even that renders many websites semi-functional or even unusable. You may not even realize important parts of the page have been blocked because NoScript or ScriptSafe is listing domains that have nothing to do with domain of origin.

All browsers these days have their own methods to protect against cross-site scripting attacks. Of course they are not as safe as disabling scripts altogether unless explicitly allowed, but couple browser's native protection with Adblock Plus' Malware Domains subscription and it gets slightly better. But at least this is not as much an exercise in frustration as running NoScript/ScriptSafe is. http://adblockplus.org/en/subscriptions
Title: Re: Possible virus on site...
Post by: Zacam on March 30, 2013, 06:57:33 pm
While yes, NoScript can be frustrating to set up, you can't get something for nothing.

Some people may not want to be bothered with having to be aware of their own surfing habits or paying attention to what links to where they go. Myself, I can't imagine NOT being as aware of that as I can be.

And while AdBlockPlus is useful (I use it in conjunction with NoScript), it still has to rely on subscriptions outside of a users control. And you would have no idea if a subscription got compromised on you until you got hit with it. Which still leads into the whole user awareness bit. Or you have to start filling in either a whitelist or blacklist yourself, which can be time consuming.

I'd rather have a site only partial load and look funky until I examine the NoScript blocked elements than be surprised by random application or desktop popup "X" suddenly showing up on my machine.

I should also point out, I can only converse on the two above as they relate to FireFox. I don't use Chrome for anything but NetFlix and Hulu and even then, I use the Iron Browser variant.
Title: Re: Possible virus on site...
Post by: Lorric on April 01, 2013, 09:17:05 am
Beware
Title: Re: Possible virus on site...
Post by: Lorric on April 01, 2013, 09:17:17 am
something
Title: Re: Possible virus on site...
Post by: Lorric on April 01, 2013, 09:17:26 am
wrong
Title: Re: Possible virus on site...
Post by: Oddgrim on April 01, 2013, 09:20:02 am
Someone set us up the bomb, today we all speak engrish.
Title: Re: Possible virus on site...
Post by: Angelus on April 01, 2013, 09:51:05 am
There's something wrong indeed:

Anyway, site is moving on the screen like ...well, like when relaxing UVs.
Most noticeable in the Aprils Newsletter, pics in there have a slight rotation - see attachment.
Size of the Font is switching from small to big and back, the spacing of text changes every few seconds...
Mouse cursor disappears when hovering over a link or anything clickable for that matter.

Is this related to the Aprils Fool prank?


[attachment deleted by ninja]
Title: Re: Possible virus on site...
Post by: An4ximandros on April 01, 2013, 10:13:27 am
Probably Goober screwing with us for all the Java whining! :P
Title: Re: Possible virus on site...
Post by: jg18 on April 01, 2013, 11:52:47 am
Probably Goober screwing with us for all the Java whining! :P
Since adding tapioca pudding to the main page took him three days (http://www.hard-light.net/forums/index.php?topic=83447.msg1667267#msg1667267), probably not. :P
Title: Re: Possible virus on site...
Post by: Yarn on April 01, 2013, 02:41:04 pm
There's something wrong indeed:

Anyway, site is moving on the screen like ...well, like when relaxing UVs.
Most noticeable in the Aprils Newsletter, pics in there have a slight rotation - see attachment.
Size of the Font is switching from small to big and back, the spacing of text changes every few seconds...
Mouse cursor disappears when hovering over a link or anything clickable for that matter.

Is this related to the Aprils Fool prank?
I'm not experiencing any of this in Firefox...
Title: Re: Possible virus on site...
Post by: Angelus on April 01, 2013, 02:58:36 pm
I'm on FF too, but it seems the April fools zoomscript is still working.
Title: Re: Possible virus on site...
Post by: Yarn on April 01, 2013, 03:21:21 pm
I'm on FF too, but it seems the April fools zoomscript is still working.

What version are you using? I'm using 19.0.2 on Windows 7.

Also, are you getting upside-down smileys? They look normal to me in Firefox, but they're upside-down in Internet Explorer 10. (All of this forum's April Fools effects seem to be working there, actually.)