Author Topic: Possible virus on site...  (Read 6705 times)

0 Members and 1 Guest are viewing this topic.

Possible virus on site...
Avast is currently freaking out over a JavaScript whenever I access a page on Hard Light.

Gives the name as "JS: Iframe-AHV", and classifies it as a Trojan.

Maybe Avast is being overzealous, but thought you folks should know just in case.

EDIT: Also, only happens on Firefox. Chrome doesn't give the same warning.
« Last Edit: March 19, 2013, 10:42:08 pm by Dark Hunter »
"You need to believe in things that aren't true. How else can they become?" -DEATH, Discworld

"You can fight like a krogan, run like a leopard, but you'll never be better than Commander Shepard!"

 

Offline An4ximandros

  • 210
  • Transabyssal metastatic event
Re: Possible virus on site...
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.

 
Re: Possible virus on site...
Yes, that too. :p
"You need to believe in things that aren't true. How else can they become?" -DEATH, Discworld

"You can fight like a krogan, run like a leopard, but you'll never be better than Commander Shepard!"

 

Offline Qent

  • 29
Re: Possible virus on site...
Mine, Firefox. I also get a bar saying that additional plugins are required to view the page.

 

Offline NGTM-1R

  • I reject your reality and substitute my own
  • 213
  • Syndral Active. 0410.
Re: Possible virus on site...
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.

Confirming for Firefox and Chrome.
"Load sabot. Target Zaku, direct front!"

A Feddie Story

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: Possible virus on site...
Nope, not a virus.  Should be good now
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 
Re: Possible virus on site...
Hmm... still getting it when I go to post a message. Otherwise it's gone.
"You need to believe in things that aren't true. How else can they become?" -DEATH, Discworld

"You can fight like a krogan, run like a leopard, but you'll never be better than Commander Shepard!"

 

Offline Fury

  • The Curmudgeon
  • 213
Re: Possible virus on site...
Nope, not a virus.  Should be good now
What was it?

 

Offline yuezhi

  • no u
  • 29
  • ¿¡you dare defy the commodore‽
Re: Possible virus on site...
Avast declaring war on Java?

and there was a little side discussion on Java elsewhere :p
ϟIn Neo-Terra we Trustϟ
ϟGreat Tin Can Run (Download
☭Gods and Conquerors  - mission design, tech descriptions, sounds; currently 5% Book of Invasions(reserved)☭


░░░░░░███████ ]▄▄▄▄▄▄▄▄        ︻╦╤─   Bob is building an army.
    ▂▄▅█████████▅▄▃▂          ☻/         This tank & Bob are against Google+
Il███████████████████].       /▌          Copy and Paste this all over
  ◥⊙▲⊙▲⊙▲⊙▲⊙▲⊙▲⊙◤...     / \          Youtube if you are with us!

 

Offline FUBAR-BDHR

  • Self-Propelled Trouble Magnet
  • 212
  • Master Drunk
    • 165th Beer Drinking Hell Raisers
Re: Possible virus on site...
HLP Mantis being in maintenance mode a result of this or is there actually maintenance going on?
No-one ever listens to Zathras. Quite mad, they say. It is good that Zathras does not mind. He's even grown to like it. Oh yes. -Zathras

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: Possible virus on site...
Yes, sorry, mantis access is back.  Side effect from the backups I restored from.
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 

Offline Fury

  • The Curmudgeon
  • 213
Re: Possible virus on site...
Assuming this was an actual virus infection again, perhaps it would be time to consider scrapping this old server and starting from scratch? This trend is honestly worrisome.

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: Possible virus on site...
Umm, no, not a virus.  It was an attack that injected the redirect code into the php files.

And yes, I agree that the server needs to be nuked and repaved with current versions of apache, php, and so on.

However, as we do not have remote console access in case something goes wrong and the OS will not boot, not to mention it's not 'our' machine (HLP and it's hosted sites are not the primary site, nor does it have it's name on the hosting bills/account), it's not that simple, nor is it something that I'm comfortable or willing to do.

That being said, I have made a tweak to the install at a filesystem level.  I don't know for sure if it will prevent it, we will have to see, but I'm hopeful that until the server is rebuilt, it will help prevent these things.
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 

Offline Lorric

  • 212
Re: Possible virus on site...
Anyone else's thread list suddenly gotten HUEG? Using Chrome, by the way.

It's doing that for me now. It wasn't before, I've read this topic before.

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Re: Possible virus on site...
Avast is giving me warnings again.
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline headdie

  • i don't use punctuation lol
  • 212
  • Lawful Neutral with a Chaotic outook
    • Skype
    • Twitter
    • Headdie on Deviant Art
Re: Possible virus on site...
avast + chrome and no warnings
Minister of Interstellar Affairs Sol Union - Retired
quote General Battuta - "FRED is canon!"
Contact me at [email protected]
My Release Thread, Old Release Thread, Celestial Objects Thread, My rubbish attempts at art

 

Offline niffiwan

  • 211
  • Eluder Class
Re: Possible virus on site...
Just wondering if you guys have considered using apache mod_security in front of the HLP websites?  At work we used this as a stop-gap measure until we could select & install a "real" web application firewall in front of our websites.
Creating a fs2_open.log | Red Alert Bug = Hex Edit | MediaVPs 2014: Bigger HUD gauges | 32bit libs for 64bit Ubuntu
----
Debian Packages (testing/unstable): Freespace2 | wxLauncher
----
m|m: I think I'm suffering from Stockholm syndrome. Bmpman is starting to make sense and it's actually written reasonably well...

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Re: Possible virus on site...
Here we go again. Avast just started complaining again.
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 
 

Offline 0rph3u5

  • 211
  • Oceans rise. Empires fall.
Re: Possible virus on site...
Same here but not sure its the same malware my AV is on about as Fury's

Quote
Details:
Web-Seite:http://www.hard-light.net/forums/
Gefundene Viren: JS:Trojan.JS.Iframe.DC
"As you sought to steal a kingdom for yourself, so must you do again, a thousand times over. For a theft, a true theft, must be practiced to be earned." - The terms of Nyrissa's curse, Pathfinder: Kingmaker

==================

"I am Curiosity, and I've always wondered what would become of you, here at the end of the world." - The Guide/The Curious Other, Othercide

"When you work with water, you have to know and respect it. When you labour to subdue it, you have to understand that one day it may rise up and turn all your labours into nothing. For what is water, which seeks to make all things level, which has no taste or colour of its own, but a liquid form of Nothing?" - Graham Swift, Waterland

"...because they are not Dragons."