Saru
May 4 2006, 10:49 PM
This evening someone succeeded in exploiting a security vulnerability in the Invision Board software and was able to gain access to the UM administration section. They proceeded to send out a number of malicious e-mails to some of our members containing a virus. They also made a virus popup appear on the forum. It appears that we weren't alone, several other Invision Board forums have also been hit in a similar manner in the last few days.
If you have received a strange e-mail containing a lot of garbage and a weird link that appears to have come from this web site - delete it immediately.
The security hole has been plugged now thankfully, I must emphasise my loathing for the type of individuals who get their pleasures from doing this kind of thing
We apologise sincerely for any problems this issue may have caused, and very much hope that it will not discourage you from participating on the site again in future.
__Kratos__
May 4 2006, 11:00 PM
Awesome job, SaRuMaN!

Thanks for the warnings and work.
Snowbaby
May 4 2006, 11:01 PM
Not your fault in the least saru. You did and are doing a mighty fine job reassuring everyone.
*hugs saru*
Bahamut_0
May 4 2006, 11:08 PM
Scripting... I understand nothing of it (refering to a window that appeared in this website, along with some virus trying to come in a dozen of times)
Reincarnated
May 4 2006, 11:09 PM
zomg
justcallmefox
May 4 2006, 11:09 PM
Thanks for the warning, SaRu.
Waspie_Dwarf
May 4 2006, 11:10 PM
There is a word to describe the people that do things like this, but I won't use it in polite company.
Chokmah
May 4 2006, 11:13 PM
ah that explains the other members wierd email, that he posted in another thread in this section.

thanks for the warning and for fixing it
jobot37
May 4 2006, 11:15 PM
thanks for the warning, I don't usually get any mail from here, but now I know.
Michelle
May 4 2006, 11:15 PM
You can't guard against everything, Saru....
Celumnaz
May 4 2006, 11:17 PM
times like this I really really want to believe in Karma
Thanks for all you do SaRuMaN!
Waspie_Dwarf
May 4 2006, 11:19 PM
It's time to stop calling these people hackers, they should be given a name that really describes them, cyber-vandals would be my suggestion.
BurnSide
May 4 2006, 11:21 PM
Indeed, there's something to be said for the type of people who do this, it's simply dispicable but gladly, it's all been taken care off and hopefully that'll be the last of it.
Raptor
May 4 2006, 11:24 PM
Good job getting it fixed so quickly.

When I used I.E. to access the board I got a pop up telling me that something was installing, but I when I tried using Firefox nothing came up. I guess if anyone was on the board using Firefox they should scan their computer.
Reincarnated
May 4 2006, 11:28 PM
calling them hackers would be complimenting them, they are script-kiddies. check the IP logs, he probably didn't even use a proxy.
p.s. - if you are still using internet explorer, smack yourself then download
FireFox!
cryptosporidium137
May 4 2006, 11:36 PM
TooFarGone
May 4 2006, 11:47 PM
It's a disgrace to call them hackers...true hackers are in it for the developtment of software, not lame cyber vandelism.
Any, I'm glad its sorted out!
Daughter of the Nine Moons
May 4 2006, 11:51 PM
SaRu, your quick response was phenomenal.
*hugs*
A+Certified
May 4 2006, 11:53 PM
people are just that messed up...
im going to check my e-mail, if i got one........things will happen to this sikkos computer........bad things, lol
DR. YO
May 5 2006, 12:18 AM
Thanks SaRuMaN. I had a hard time deleting all the infected files. I was hoping the files wouldn’t spread and infect the other computers at my office. I’ll find out in the morning. Thanks again .
Acenaspheru
May 5 2006, 12:19 AM
*sigh* doing a V scan now. so the script prompt thing was a virus? i didn't click okay so do you think i'm still safe?

we'll find out soon enough. in the mean time i'd suggest everyone running a scan who visited at that time. freakin people man, wtf is with people like that???
^SolidSnake^
May 5 2006, 12:20 AM
There was a weird chap on here posting random bollocks with weird links...any connection?
Subtemperate
May 5 2006, 12:34 AM
When isnt there a person doing that? lol
Unfortunately even if you do not press OK, you are not safe...as the prompt has nothing to do with it. Whilst the prompt is coming up, the virus is dlíng to your computer... unless you have good security or a virus blocker....
Shakezulah
May 5 2006, 12:51 AM
I got the virus from this site not once, but TWICE!
I came home from school, refreshed the page of UM first thing, and then all of a sudden something downloads and I get a strange Trojan virus. Soooo.....I ended rebooting my entire hard-drive again, so I unfortunately lost everything (I've lost count of how many times I've had to do that). Thinking nothing of it, I reinstalled my Internet software, and went back to UM right away, where I got the virus again, thus forcing me to reboot my hard-drive again. That time I knew it had to be that someone hacked into UM. I was hesitant to come back here this time, but thankfully, I come to read that Saru has fixed the problem. Thanks for fixing the problem!
I HATE people who put viruses into computers. I seriously wish they would all die violently.
frogfish
May 5 2006, 01:09 AM
Good job SaRu!
I might know who did this...PM if you want to know.
Nighteyes
May 5 2006, 02:34 AM
Thanks I read this before checking my mail, and guess what. There was an email I deleted it right away. Thank you so much, I need my computer for 3 projects. Thank You.
Boltwave
May 5 2006, 03:03 AM
QUOTE(SaRuMaN @ May 4 2006, 10:49 PM) [snapback]1174839[/snapback]
This evening someone succeeded in exploiting a security vulnerability in the Invision Board software and was able to gain access to the UM administration section. They proceeded to send out a number of malicious e-mails to some of our members containing a virus. They also made a virus popup appear on the forum.
If you have received a strange e-mail containing a lot of garbage and a weird link that appears to have come from this web site - delete it immediately.
The security hole has been plugged now thankfully, I must emphasise my loathing for the type of individuals who get their pleasures from doing this kind of thing
We apologise sincerely for any problems this issue may have caused, and very much hope that it will not discourage you from participating on the site again in future.
That's why I was getting virus notices earlier today! Now it makes sense, I was wondering why my internet was being all funny after visiting here from occasion to occasion.
Great job SaRuMaN, hopefully you found the guy(s) who did this, it almost put an infected virus on my computer, HOPE YOUR HAPPY JACKASSES!
Furthermore, if you took care of the problem or were able to find the source of it then I wouldn't expect too many problems, my advice about this whole ordeal is to get some elight personnel or some technical backup to watch over your forum from time to time, perhaps contact any vital support, or the Invision Power Board forum.
Another thing you might want to consider are some security installments, right now at the point I'm not the biggest techy when it comes to websites, I'm okay with management, but I'm too all about HTML, guess I have stuff to work on myself.
I'd say to prevent this from happening again, just install mods of some type, security bots, if this forum provides them, or if there installable (I would imagine they are with the extensions to an IPB board), at least, I'd want to make sure it doesn't happen again for the most part of the greater concern.
Saru
May 5 2006, 07:54 AM
QUOTE
at least, I'd want to make sure it doesn't happen again for the most part of the greater concern.
I will be making some changes to implement additional security features to try and prevent this from happening again. Although the security hole in Invision Board which allowed this user access has been patched, you never know when another will surface.
Reincarnated
May 5 2006, 08:02 AM
i have a question for the people who got infected; what browser were you using at that time? i wonder if it could have been avoided by using
firefox. for anyone still using IE i suggest to switch anyways, its more secure. and how exactly did it infect your computers? though the browser and through email?
Paranoid Android
May 5 2006, 10:18 AM
I don't know if this is related to the email, but I sent a PM to one of our members - tyleriscool. He hasn't received it yet, and I checked my message tracker and it says it's now been posted to R3LOAD. I'm guessing the problem was either to do with the hacking, or tyleriscool has had his username changed......
That aside, seriously Saruman, no need to apologise for the problem. These things happen on the web these days. It's sad that people feel the need to destroy other people's work for no reason, but it's not your fault, no system is hack-proof, and it's the hacker's job to get around it, after all.
Thanks for the quick response time, plugging the gap, fixing it all up.
Regards, PA
Saru
May 5 2006, 10:30 AM
QUOTE
I don't know if this is related to the email, but I sent a PM to one of our members - tyleriscool. He hasn't received it yet, and I checked my message tracker and it says it's now been posted to R3LOAD.
He did actually request a name change, so he's nothing to do with it.
QUOTE
i wonder if it could have been avoided by using firefox.
I had to use Firefox to access the forum to disable the malicious script as Internet Explorer kept crashing. I don't think the code that was embedded on the forum actually had any effect on Firefox.
=Jak=
May 5 2006, 10:32 AM
GR8..
Paranoid Android
May 5 2006, 10:39 AM
QUOTE(SaRuMaN @ May 5 2006, 08:30 PM) [snapback]1175471[/snapback]
He did actually request a name change, so he's nothing to do with it.
Ah, thanks.
Lottie
May 5 2006, 10:45 AM
SaRu, You were incredibly quick at sorting this out. From now on I am calling you Super'S'
Thankyou for your hard work and quick response and its not your fault so don't worry.
((((Big Hugs))))
Chokmah
May 5 2006, 12:42 PM
I use firefox, so would I still be infected? or am i safe?
EDIT
forget that, Saru already mentioned something on it 3 posts up >_<
Lottie
May 5 2006, 12:52 PM
I don't think its anything to do with the browser you use. The virus could effect anyone who doesn't have the appropriate security and anti-virus features on windows.
Chokmah
May 5 2006, 02:20 PM
QUOTE(Lottie @ May 5 2006, 01:52 PM) [snapback]1175591[/snapback]
I don't think its anything to do with the browser you use. The virus could effect anyone who doesn't have the appropriate security and anti-virus features on windows.
aye, but Firefox is better protected than IE. you get less spyware, viruses ect than if you were to use IE.
Saru
May 5 2006, 02:35 PM
It's not that Firefox is better protected, it's that most viruses etc. are designed to work with IE, since most people use it.
DR. YO
May 5 2006, 02:43 PM
QUOTE(Reincarnated @ May 5 2006, 04:02 AM) [snapback]1175384[/snapback]
i have a question for the people who got infected; what browser were you using at that time? i wonder if it could have been avoided by using
firefox. for anyone still using IE i suggest to switch anyways, its more secure. and how exactly did it infect your computers? though the browser and through email?
My cpu would freeze and the UM site would close, followed by a message from my virus scanner stating I had infected files.
This happened 5 times in 35 min. Each and every time I logged on the infected files would change, on one occasion I had 5 infected files and on another I had 18.
What concerns me the most is that I log on to UM when I’m at work. I was afraid the virus would spread throughout my entire office and spread via email.
All the computers here seem to be working properly, so far nobody has complained about an unsuspecting virus.
Thanks again SaRu.

*Bleap* those people who infected UM
epicstorm
May 6 2006, 05:50 PM
Yea, i just found one of those in my inbox , to bad they dont have the brains to compose a more convincing mail ..

CODE
Please, take a part in our new cup.
Just register in the programm below:
Edited to remove malicious link- Dot
isis-999
May 7 2006, 07:20 AM
I'm still getting a pop up window on here..I didn't know what the deal was until i read this..It happen once a few hour's ago...Do i need to run a virus scan or is the pop-up's safe..Just a pain to deal with....
Saru
May 7 2006, 08:06 AM
What section of the site do you see a popup, and whats on it ?
Mr. Fahrenheit
May 24 2006, 01:41 AM
I'm especially angry about this type of thing because I just got infected with spyware (luckily Raptor X7 helped me). I can see if you're a hacker in the way of modding a game to add a level and practice coding, but what kind of lowly urchin sits around creating traps for people's computers? Grr.
ZEeSh@n (Is) Back
May 24 2006, 04:51 PM
Thanks For Informing Saru....
U r the Best Admin!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.