Hard Light Productions Forums

Site Management => Site Support / Feedback => Topic started by: Nohiki on October 28, 2012, 06:21:33 am

Title: Avast reporting exploit on HLP
Post by: Nohiki on October 28, 2012, 06:21:33 am
Code: [Select]
Infection DetailsURL: http://hard-light.net/manager/media/script/scriptaculous/scriptaculous.js|{gzip}
Process: C:%5CProgram Files (x86)%5COpera%5Copera.exe
Infection: JS:Blacole-CX [Expl]

Avast spat this out on me when i accessed the main site, dunno how big a threat that is (if any), but it felt like worth mentioning.
Title: Re: Avast reporting exploit on HLP
Post by: Tyrian on October 28, 2012, 10:35:21 am
You're not the only one who's getting it.  It's also showing up in this file here:

Code: [Select]
http://www.hard-light.net/manager/media/script/scriptaculous/prototype.js
It's the same exploit package.  The Blacole-CX pack is an exploit package for loading malware onto machines that visit a compromised site.  More details here, along with a list of programs it attacks:  http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=JS/Blacole
Title: Re: Avast reporting exploit on HLP
Post by: Beskargam on October 28, 2012, 11:05:08 am
Norton popped up with a a similar message
Title: Re: Avast reporting exploit on HLP
Post by: Mr. Vega on October 28, 2012, 06:33:02 pm
I got the exact same alert as Nohiki.
Title: Re: Avast reporting exploit on HLP
Post by: Iss Mneur on October 28, 2012, 07:00:22 pm
I just downloaded the official Scriptaculcus 1.6.4 and that file that is on HLP has a blob of text appended to the end that does not exist in the official release.
Title: Re: Avast reporting exploit on HLP
Post by: Zacam on October 28, 2012, 07:10:21 pm
Test doing a reload (clear cache or CTRL+F5) and tell me if anything breaks.
Title: Re: Avast reporting exploit on HLP
Post by: Iss Mneur on October 28, 2012, 07:21:43 pm
The site still appears to work.
Title: Re: Avast reporting exploit on HLP
Post by: Fury on October 29, 2012, 12:38:31 am
Does the manager directory belong to EE or MODx? If EE, smells like security updates were neglected. If MODx, same as before plus what the **** does MODx STILL exist for? There should have been ample time to move everything needed over to EE and remove MODx entirely.

You should run a search to see what files have been modified in a given time frame to see if any other files have been created or modified, even outside manager dir.

:sigh:
Title: Re: Avast reporting exploit on HLP
Post by: Tyrian on November 07, 2012, 08:13:27 am
We may have a more serious problem than just the malicious code we found.  When I went to HLP this morning, I got a nice, big alert page that said HLP had been blacklisted as an attack site.  We were flagged by https://www.stopbadware.org/home/index, which works closely with the Mozilla group.  Given the likely fact that a lot of people who visit the site probably use Firefox, it means a large number of people are seeing it and getting scared away.  That can't be good for publicity.  You may want to consider a PSA on the homepage to explain to people what's going on and provide updates on what's being done.  In the meantime, you may want to contact StopBadware and inform them that the site was hacked by a 3rd party.
Title: Re: Avast reporting exploit on HLP
Post by: Luis Dias on November 07, 2012, 08:58:58 am
Google Chrome visitors are having the exact same issue.
Title: Re: Avast reporting exploit on HLP
Post by: Iss Mneur on November 07, 2012, 10:31:59 am
Specifically, http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http%3A%2F%2Fwww.hard-light.net%2Fforums%2Findex.php%3Ftopic%3D82809.new%23new&client=googlechrome&hl=en-GB

It seems HLP has not served any malware, but is hanging out with those that are....
Title: Re: Avast reporting exploit on HLP
Post by: Starman01 on November 07, 2012, 11:14:15 am
Yup, Firefox is also displaying a warning message, this site is dangerous....
Title: Re: Avast reporting exploit on HLP
Post by: yuezhi on November 07, 2012, 11:41:23 am
scary.
Title: Re: Avast reporting exploit on HLP
Post by: Dragon on November 07, 2012, 11:47:30 am
Google Chrome visitors are having the exact same issue.
I'm also getting a Google Chrome warning. And the new UI is hideous. What's happening to this site?
Title: Re: Avast reporting exploit on HLP
Post by: PeterX on November 07, 2012, 11:56:00 am
My pale moon and fire fox as avira says the same. :-O
Peter
Title: Re: Avast reporting exploit on HLP
Post by: LHN91 on November 07, 2012, 01:42:51 pm
Just letting you know, Chrome has now gone beyond a basic warning to pretty much telling you you WILL be infected if you continue and attempts to not let you into the site. There's an option on the page to open advanced options and continue anyways, but they REALLY don't want people to come here.
Title: Re: Avast reporting exploit on HLP
Post by: Crybertrance on November 07, 2012, 01:47:13 pm
Just letting you know, Chrome has now gone beyond a basic warning to pretty much telling you you WILL be infected if you continue and attempts to not let you into the site. There's an option on the page to open advanced options and continue anyways, but they REALLY don't want people to come here.

Yes, I can confirm. Damn hacker noobs...
Title: Re: Avast reporting exploit on HLP
Post by: LHN91 on November 07, 2012, 02:06:37 pm
Just so it's here and present, here's what Google found on here today. This is different from what was coming up earlier today. Actually kind of unpleasant, seeing it:

Malicious software includes 2 trojan(s), 2 exploit(s). Successful infection resulted in an average of 7 new process(es) on the target machine.

Malicious software is hosted on 3 domain(s), including bbwitnia.mynumber.org/, tngvjzg.almostmy.com/, mp3soft.pro/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including mp3soft.pro/.
Title: Re: Avast reporting exploit on HLP
Post by: Tyrian on November 07, 2012, 06:51:26 pm
Whatever exploits are active on HLP are pulling malware from those servers.  It's probably worth it for the admins to file an abuse report with Google about those links.  It'll help keep the exploits from being distributed through HLP, plus any other sites they may be supplying.

What I'm worrying about though is that any exploits that get forwarded to other sites through us will look like we're attacking them.  If their admins file abuse reports against us, then it could result in HLP losing its hosting.

This is a question for the site admins.  How many people are going through the code and logs looking for signs of tampering?  If you guys need help, I do have some security knowledge beyond firewalls and AV programs.  If you want help, let me know.
Title: Re: Avast reporting exploit on HLP
Post by: rev_posix on November 07, 2012, 07:59:29 pm
This is a question for the site admins.  How many people are going through the code and logs looking for signs of tampering?  If you guys need help, I do have some security knowledge beyond firewalls and AV programs.  If you want help, let me know.
At least three of us. :P

Zacam and myself spent most of our evening after work cleaning up the main forum install by putting in place a fresh copy of the latest version, reusing only the DB data.  The custom additions were put back into place by hand as well so no scripts from the old install were used.

Sandwich has also been working on getting the stop malware warnings removed and fixing up the CSS for the menus and such, as well as tracking down any lingering smelly stuff that may have been missed.
Title: Re: Avast reporting exploit on HLP
Post by: Sandwich on November 07, 2012, 09:07:21 pm
Does the manager directory belong to EE or MODx? If EE, smells like security updates were neglected. If MODx, same as before plus what the **** does MODx STILL exist for? There should have been ample time to move everything needed over to EE and remove MODx entirely.

Manager belongs to MODx. MODx still being around is probably my fault... :(
Title: Re: Avast reporting exploit on HLP
Post by: Goober5000 on November 08, 2012, 01:11:11 am
Well, we've kind of been bugging you about that for years now. :p
Title: Re: Avast reporting exploit on HLP
Post by: Sandwich on November 08, 2012, 02:31:39 pm
Yes, indeed. It's gone now, although if there's any databases for it, they can/should be deleted as well.