Help - Search - Members - Calendar
Full Version: Important: Malicious e-mails
Unexplained Mysteries Discussion Forums > Other > Web Site & Forum News, Updates & Support
Saru
This evening someone succeeded in exploiting a security vulnerability in the Invision Board software and was able to gain access to the UM administration section. They proceeded to send out a number of malicious e-mails to some of our members containing a virus. They also made a virus popup appear on the forum. It appears that we weren't alone, several other Invision Board forums have also been hit in a similar manner in the last few days.

If you have received a strange e-mail containing a lot of garbage and a weird link that appears to have come from this web site - delete it immediately.

The security hole has been plugged now thankfully, I must emphasise my loathing for the type of individuals who get their pleasures from doing this kind of thing

We apologise sincerely for any problems this issue may have caused, and very much hope that it will not discourage you from participating on the site again in future.
__Kratos__
Awesome job, SaRuMaN! clap.gif Thanks for the warnings and work. original.gif
Snowbaby
Not your fault in the least saru. You did and are doing a mighty fine job reassuring everyone.

*hugs saru*
Bahamut_0
Scripting... I understand nothing of it (refering to a window that appeared in this website, along with some virus trying to come in a dozen of times)
Reincarnated
zomg
justcallmefox
Thanks for the warning, SaRu. thumbsup.gif
Waspie_Dwarf
There is a word to describe the people that do things like this, but I won't use it in polite company.
Chokmah
ah that explains the other members wierd email, that he posted in another thread in this section. thumbsup.gif thanks for the warning and for fixing it happy.gif
jobot37
thanks for the warning, I don't usually get any mail from here, but now I know.
Michelle
You can't guard against everything, Saru.... thumbsup.gif
Celumnaz
times like this I really really want to believe in Karma

Thanks for all you do SaRuMaN!
Waspie_Dwarf
It's time to stop calling these people hackers, they should be given a name that really describes them, cyber-vandals would be my suggestion.
BurnSide
Indeed, there's something to be said for the type of people who do this, it's simply dispicable but gladly, it's all been taken care off and hopefully that'll be the last of it.
Raptor
Good job getting it fixed so quickly. thumbsup.gif

When I used I.E. to access the board I got a pop up telling me that something was installing, but I when I tried using Firefox nothing came up. I guess if anyone was on the board using Firefox they should scan their computer.
Reincarnated
calling them hackers would be complimenting them, they are script-kiddies. check the IP logs, he probably didn't even use a proxy.

p.s. - if you are still using internet explorer, smack yourself then download FireFox!
cryptosporidium137
Wow! Thanks alot for the warning, Saruman! I will now be carful if I see an e-mail that seems like the one mentioned and delete it.

alien.gif alien.gif crypto alien.gif alien.gif
TooFarGone
It's a disgrace to call them hackers...true hackers are in it for the developtment of software, not lame cyber vandelism.


Any, I'm glad its sorted out!
Daughter of the Nine Moons
SaRu, your quick response was phenomenal.

*hugs*

A+Certified
people are just that messed up...

im going to check my e-mail, if i got one........things will happen to this sikkos computer........bad things, lol
DR. YO
Thanks SaRuMaN. I had a hard time deleting all the infected files. I was hoping the files wouldn’t spread and infect the other computers at my office. I’ll find out in the morning. Thanks again . thumbsup.gif thumbsup.gif
Acenaspheru
*sigh* doing a V scan now. so the script prompt thing was a virus? i didn't click okay so do you think i'm still safe? no.gif we'll find out soon enough. in the mean time i'd suggest everyone running a scan who visited at that time. freakin people man, wtf is with people like that???
^SolidSnake^
There was a weird chap on here posting random bollocks with weird links...any connection?
Subtemperate
When isnt there a person doing that? lol

Unfortunately even if you do not press OK, you are not safe...as the prompt has nothing to do with it. Whilst the prompt is coming up, the virus is dlíng to your computer... unless you have good security or a virus blocker....
Shakezulah
I got the virus from this site not once, but TWICE!

I came home from school, refreshed the page of UM first thing, and then all of a sudden something downloads and I get a strange Trojan virus. Soooo.....I ended rebooting my entire hard-drive again, so I unfortunately lost everything (I've lost count of how many times I've had to do that). Thinking nothing of it, I reinstalled my Internet software, and went back to UM right away, where I got the virus again, thus forcing me to reboot my hard-drive again. That time I knew it had to be that someone hacked into UM. I was hesitant to come back here this time, but thankfully, I come to read that Saru has fixed the problem. Thanks for fixing the problem!

I HATE people who put viruses into computers. I seriously wish they would all die violently.
frogfish
Good job SaRu!

I might know who did this...PM if you want to know.
Nighteyes
Thanks I read this before checking my mail, and guess what. There was an email I deleted it right away. Thank you so much, I need my computer for 3 projects. Thank You. grin2.gif
Boltwave
QUOTE(SaRuMaN @ May 4 2006, 10:49 PM) [snapback]1174839[/snapback]

This evening someone succeeded in exploiting a security vulnerability in the Invision Board software and was able to gain access to the UM administration section. They proceeded to send out a number of malicious e-mails to some of our members containing a virus. They also made a virus popup appear on the forum.

If you have received a strange e-mail containing a lot of garbage and a weird link that appears to have come from this web site - delete it immediately.

The security hole has been plugged now thankfully, I must emphasise my loathing for the type of individuals who get their pleasures from doing this kind of thing

We apologise sincerely for any problems this issue may have caused, and very much hope that it will not discourage you from participating on the site again in future.



That's why I was getting virus notices earlier today! Now it makes sense, I was wondering why my internet was being all funny after visiting here from occasion to occasion.

Great job SaRuMaN, hopefully you found the guy(s) who did this, it almost put an infected virus on my computer, HOPE YOUR HAPPY JACKASSES! angry.gif

Furthermore, if you took care of the problem or were able to find the source of it then I wouldn't expect too many problems, my advice about this whole ordeal is to get some elight personnel or some technical backup to watch over your forum from time to time, perhaps contact any vital support, or the Invision Power Board forum.

Another thing you might want to consider are some security installments, right now at the point I'm not the biggest techy when it comes to websites, I'm okay with management, but I'm too all about HTML, guess I have stuff to work on myself. grin2.gif

I'd say to prevent this from happening again, just install mods of some type, security bots, if this forum provides them, or if there installable (I would imagine they are with the extensions to an IPB board), at least, I'd want to make sure it doesn't happen again for the most part of the greater concern.
Saru
QUOTE
at least, I'd want to make sure it doesn't happen again for the most part of the greater concern.

I will be making some changes to implement additional security features to try and prevent this from happening again. Although the security hole in Invision Board which allowed this user access has been patched, you never know when another will surface.
Reincarnated
i have a question for the people who got infected; what browser were you using at that time? i wonder if it could have been avoided by using firefox. for anyone still using IE i suggest to switch anyways, its more secure. and how exactly did it infect your computers? though the browser and through email?
Paranoid Android
I don't know if this is related to the email, but I sent a PM to one of our members - tyleriscool. He hasn't received it yet, and I checked my message tracker and it says it's now been posted to R3LOAD. I'm guessing the problem was either to do with the hacking, or tyleriscool has had his username changed......

That aside, seriously Saruman, no need to apologise for the problem. These things happen on the web these days. It's sad that people feel the need to destroy other people's work for no reason, but it's not your fault, no system is hack-proof, and it's the hacker's job to get around it, after all.

Thanks for the quick response time, plugging the gap, fixing it all up.

Regards, PA
Saru
QUOTE
I don't know if this is related to the email, but I sent a PM to one of our members - tyleriscool. He hasn't received it yet, and I checked my message tracker and it says it's now been posted to R3LOAD.

He did actually request a name change, so he's nothing to do with it.

QUOTE
i wonder if it could have been avoided by using firefox.

I had to use Firefox to access the forum to disable the malicious script as Internet Explorer kept crashing. I don't think the code that was embedded on the forum actually had any effect on Firefox.
=Jak=
GR8.. thumbsup.gif
Paranoid Android
QUOTE(SaRuMaN @ May 5 2006, 08:30 PM) [snapback]1175471[/snapback]

He did actually request a name change, so he's nothing to do with it.
Ah, thanks.
Lottie
SaRu, You were incredibly quick at sorting this out. From now on I am calling you Super'S' grin2.gif
Thankyou for your hard work and quick response and its not your fault so don't worry.

((((Big Hugs))))
Chokmah
I use firefox, so would I still be infected? or am i safe?

EDIT

forget that, Saru already mentioned something on it 3 posts up >_<
Lottie
I don't think its anything to do with the browser you use. The virus could effect anyone who doesn't have the appropriate security and anti-virus features on windows.
Chokmah
QUOTE(Lottie @ May 5 2006, 01:52 PM) [snapback]1175591[/snapback]

I don't think its anything to do with the browser you use. The virus could effect anyone who doesn't have the appropriate security and anti-virus features on windows.


aye, but Firefox is better protected than IE. you get less spyware, viruses ect than if you were to use IE.
Saru
It's not that Firefox is better protected, it's that most viruses etc. are designed to work with IE, since most people use it.
DR. YO
QUOTE(Reincarnated @ May 5 2006, 04:02 AM) [snapback]1175384[/snapback]

i have a question for the people who got infected; what browser were you using at that time? i wonder if it could have been avoided by using firefox. for anyone still using IE i suggest to switch anyways, its more secure. and how exactly did it infect your computers? though the browser and through email?


My cpu would freeze and the UM site would close, followed by a message from my virus scanner stating I had infected files.

This happened 5 times in 35 min. Each and every time I logged on the infected files would change, on one occasion I had 5 infected files and on another I had 18.

What concerns me the most is that I log on to UM when I’m at work. I was afraid the virus would spread throughout my entire office and spread via email.

All the computers here seem to be working properly, so far nobody has complained about an unsuspecting virus.

Thanks again SaRu. thumbsup.gif

*Bleap* those people who infected UM angry.gif
epicstorm
Yea, i just found one of those in my inbox , to bad they dont have the brains to compose a more convincing mail .. laugh.gif

CODE
Please, take a part in our new cup.
Just register in the programm below:


Edited to remove malicious link- Dot
isis-999
I'm still getting a pop up window on here..I didn't know what the deal was until i read this..It happen once a few hour's ago...Do i need to run a virus scan or is the pop-up's safe..Just a pain to deal with.... hmm.gif
Saru
What section of the site do you see a popup, and whats on it ?
Mr. Fahrenheit
I'm especially angry about this type of thing because I just got infected with spyware (luckily Raptor X7 helped me). I can see if you're a hacker in the way of modding a game to add a level and practice coding, but what kind of lowly urchin sits around creating traps for people's computers? Grr.
ZEeSh@n (Is) Back
Thanks For Informing Saru....
U r the Best Admin!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.