PDA

View Full Version : malware detected



czar
03-04-2012, 02:12 AM
Today my chrome browser began coming up with this message.

--------------------------------
Warning: Something's Not Right Here!
www.pascalgamedevelopment.com contains content from frina.in, a site known to distribute malware. Your computer might catch a virus if you visit this site.
Google has found malicious software may be installed onto your computer if you proceed. If you've visited this site in the past or you trust this site, it's possible that it has just recently been compromised by a hacker. You should not proceed, and perhaps try again tomorrow or go somewhere else.
We have already notified frina.in that we found malware on the site. For more about the problems found on frina.in, visit the Google Safe Browsing diagnostic page.


-----------------------
Anyone else getting this?

Colin
03-04-2012, 02:35 AM
yep i had something similar, but comodo blocked an exe trying to be downloaded and executed from temp directory when opening this site.

Cybermonkey
03-04-2012, 08:35 AM
Same here. Interesting thing is it came up after about 5 min. reading new posts ...

czar
03-04-2012, 07:14 PM
Any response from sysops?

AthenaOfDelphi
03-04-2012, 07:26 PM
Can you provide a few more details regarding the pages this issue occurred on please?

I'll have a quick look around and see if I can see anything.

User137
03-04-2012, 07:26 PM
Yeah this message started to come up constantly here with Google Chrome. Every time i open a forum thread in new tab it shows the big red malware detected page first.

AthenaOfDelphi
03-04-2012, 07:31 PM
Don't worry about providing more information. I found the culprit and have removed it.

If there are any further problems, please let us know.


Thanks

WILL
03-04-2012, 09:20 PM
Great response everyone! I just found out this morning, but my own internet went down just as I was reading and couldn't attend to it myself. Thankfully Athena kicked it's butt and we are now "as safe as houses" as I'm sure many of her fellow countrymen/women would say. ;)

SilverWarior
04-04-2012, 02:28 AM
Don't worry about providing more information. I found the culprit and have removed it.

Can you be more specific on this please?

AthenaOfDelphi
04-04-2012, 07:49 AM
Can you be more specific on this please?

I can. Basically, an admin account was compromised and it was used to modify the templates to include a DIV containing an IFRAME that loaded from the site specified above. Removing this from the templates was easy (quick search and destroy) and then it was just a case of identifying the account and sorting that out. The account itself appears to have been the very first admin account that was setup when PGD was first born many years ago. It's been migrated from forum to forum. Neither WILL or I use it, ever, so I guess we'd forgotten about it. It has had it's password reset and it's undergone a permanent demotion to regular user.

It wasn't a script based exploit that I'm aware of. I think it was a password hack job on something that is quite obviously an admin account.

Anyhow, if we get any more similar occurrences, let WILL or I know and we'll get it sorted ASAP.

SilverWarior
04-04-2012, 05:47 PM
Was this a vBuletin acount or general site managment account?
I have done some searching and reading on internet and from what I gathered Godaddy doesn't have best security for site administration. In the past the were lots of hacks done trough hacking cPanel accounts. Some even suggest that cPanel security was so weak that it was posible to hack certain account by runing brute force for pasword hacking. What wories me most is the fact some pepole say that Godaddy has neglected many warnings from its user about security vulnerabilites that were found on their servers. In many cases Godaddy administration has been blaming its customers to be using outdated software wich resulted in security volnerabilities even if that wasn't true.

AthenaOfDelphi
04-04-2012, 06:04 PM
It was a vBulletin account that was compromised.

SilverWarior
04-04-2012, 07:21 PM
Oh good. I feared for the worst.
BTW do we have Site Scaner in our webhosting package. Acording to http://www.godaddy.com/security/website-security.aspx GoDaddy offers ability for dayli scaning of our site for various hacks. If we don't maybe we should consider it. I know it cost some money but we might lose a lot of potentional users if our site would present a security thread for their computers.