Page 1 of 5

main site infected?

Posted: Sun Jun 01, 2014 4:05 pm
by drm_wayne
when going to inside3d.com i get a warning from my antivirus and something gets blocked, you should check this asap...

Re: main site infected?

Posted: Sun Jun 01, 2014 7:31 pm
by leileilol
Definitely is some sql injection attack - the affected area is a Jan 1 2014 newspost, replaced with a XSS refresh attack.

Re: main site infected?

Posted: Sun Jun 01, 2014 9:24 pm
by Spiney

Re: main site infected?

Posted: Sun Jun 01, 2014 10:32 pm
by leileilol
RequestPolicy is a nice extension to have for these situations.

Re: main site infected?

Posted: Mon Jun 02, 2014 11:03 pm
by ceriux
i entered the main page through my companys intranet o.O i hope its okay...

Re: main site infected?

Posted: Mon Jun 02, 2014 11:29 pm
by revelator
Hmm kaspersky not picking anything up but better safe than sorry.

Re: main site infected?

Posted: Tue Jun 03, 2014 1:34 am
by Dr. Shadowborg
Neither scar3crow or myself have access to that part of i3d, so unless we can get in touch with FrikaC or marv (atomicgamer), theres nothing that can be done. :/

Re: main site infected?

Posted: Tue Jun 03, 2014 1:46 am
by ceriux
get on irc

Re: main site infected?

Posted: Tue Jun 03, 2014 2:07 am
by Dr. Shadowborg
I did. FrikaC's not around, and I'm too scared to bug marv about it. (besides I don't know marv's e-mail!)

Re: main site infected?

Posted: Tue Jun 03, 2014 5:13 am
by jjsullivan5196
I don't get why people do this kind of stuff, this is such a small website, why are we a target?

leileilol's recommendation of the plugin got me around that stupid redirect, but this is kinda unexpected.

Re: main site infected?

Posted: Tue Jun 03, 2014 1:33 pm
by revelator
Everyones a valid target this day.

Most users use the same passwords for several other sites and sometimes even for homebanking (very bad idea btw) not saying that was the intent here but be aware.

Re: main site infected?

Posted: Sat Jun 07, 2014 10:05 pm
by scar3crow
Problem appears to be resolved, it was made possible by compromised credentials, feel free to change your passwords. I haven't seen evidence the forum was compromised, but unlike Taylor Swift I am not a security expert, so don't rely on me for that.

Re: main site infected?

Posted: Sat Jun 07, 2014 11:02 pm
by leileilol
If it were compromised i'd imagine a higher profile target also hosted would have a big issue raised about it.

Re: main site infected?

Posted: Tue Jun 10, 2014 1:24 pm
by revelator
Heh that plugin really reveals some scary stuff around the net :shock:

Re: main site infected?

Posted: Tue Jun 10, 2014 2:32 pm
by Spirit
If you find that scary, try https://addons.mozilla.org/en-US/firefo ... lightbeam/
As far as Quake sites are concerned, you can start at http://www.quakeone.com , http://www.inside3d.com or http://www.quakewiki.net to get some tracking stuff down your throat...