Results 1 to 10 of 13

Thread: malware detected

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2
    Don't worry about providing more information. I found the culprit and have removed it.

    If there are any further problems, please let us know.


    Thanks
    :: AthenaOfDelphi :: My Blog :: My Software ::

  2. #2
    Co-Founder / PGD Elder WILL's Avatar
    Join Date
    Apr 2003
    Location
    Canada
    Posts
    6,107
    Blog Entries
    25
    Great response everyone! I just found out this morning, but my own internet went down just as I was reading and couldn't attend to it myself. Thankfully Athena kicked it's butt and we are now "as safe as houses" as I'm sure many of her fellow countrymen/women would say.
    Jason McMillen
    Pascal Game Development
    Co-Founder





  3. #3
    Quote Originally Posted by AthenaOfDelphi View Post
    Don't worry about providing more information. I found the culprit and have removed it.
    Can you be more specific on this please?

  4. #4
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2
    Quote Originally Posted by SilverWarior View Post
    Can you be more specific on this please?
    I can. Basically, an admin account was compromised and it was used to modify the templates to include a DIV containing an IFRAME that loaded from the site specified above. Removing this from the templates was easy (quick search and destroy) and then it was just a case of identifying the account and sorting that out. The account itself appears to have been the very first admin account that was setup when PGD was first born many years ago. It's been migrated from forum to forum. Neither WILL or I use it, ever, so I guess we'd forgotten about it. It has had it's password reset and it's undergone a permanent demotion to regular user.

    It wasn't a script based exploit that I'm aware of. I think it was a password hack job on something that is quite obviously an admin account.

    Anyhow, if we get any more similar occurrences, let WILL or I know and we'll get it sorted ASAP.
    :: AthenaOfDelphi :: My Blog :: My Software ::

  5. #5
    Was this a vBuletin acount or general site managment account?
    I have done some searching and reading on internet and from what I gathered Godaddy doesn't have best security for site administration. In the past the were lots of hacks done trough hacking cPanel accounts. Some even suggest that cPanel security was so weak that it was posible to hack certain account by runing brute force for pasword hacking. What wories me most is the fact some pepole say that Godaddy has neglected many warnings from its user about security vulnerabilites that were found on their servers. In many cases Godaddy administration has been blaming its customers to be using outdated software wich resulted in security volnerabilities even if that wasn't true.

  6. #6
    PGD Community Manager AthenaOfDelphi's Avatar
    Join Date
    Dec 2004
    Location
    South Wales, UK
    Posts
    1,245
    Blog Entries
    2
    It was a vBulletin account that was compromised.
    :: AthenaOfDelphi :: My Blog :: My Software ::

  7. #7
    Oh good. I feared for the worst.
    BTW do we have Site Scaner in our webhosting package. Acording to http://www.godaddy.com/security/website-security.aspx GoDaddy offers ability for dayli scaning of our site for various hacks. If we don't maybe we should consider it. I know it cost some money but we might lose a lot of potentional users if our site would present a security thread for their computers.
    Last edited by SilverWarior; 04-04-2012 at 07:23 PM.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •