Your website has been compromised...

For any questions/comments/suggestions regarding using and/or contributing to ComicBookDB.com

Moderators: DarthSkeptical, Fnord Serious, Chris, spid, Skyhawke, Darth Kramer, mikebo

Comicsnut
 
Posts: 15
Joined: Sun Nov 27, 2011 1:00 am

Your website has been compromised...

Postby Comicsnut » Sat Aug 04, 2012 5:32 pm

Avast is currently flagging http://www.comicbookdb.com/collection_m ... atings.php.

It's using a javascript redirect to a trojan outlet.

Not sure if it's a false positive, so I ran it through my work's (IT Desktop Administrator) firewall and there is, in fact, a redirect in place.
--
RIP Rob

Uthor
 
Posts: 132
Joined: Fri Jun 03, 2011 1:15 am

Re: Your website has been compromised...

Postby Uthor » Sat Aug 04, 2012 8:11 pm

Could it explain this problem on the "user's end"?
viewtopic.php?f=2&t=7672

User avatar
Chris
Cosmic Donor
Cosmic Donor
 
Posts: 959
Joined: Sun Nov 13, 2005 4:48 am
Location: Toronto

Re: Your website has been compromised...

Postby Chris » Sun Aug 05, 2012 6:56 pm

I run Avast and am not getting any warnings on that page. Can you provide more details?

Caliban
 
Posts: 4
Joined: Tue Sep 13, 2011 8:20 am

Re: Your website has been compromised...

Postby Caliban » Mon Aug 06, 2012 11:28 am

Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
2012-08-06 12:26:24,High,An intrusion attempt by 208.76.81.137 was blocked.,Blocked,No Action Required,Web Attack: Mass Injection Website,No Action Required,No Action Required,"208.76.81.137, 80",www.comicbookdb.com/ajax_errorcheck.js?,"PC (******)",208.76.81.137,"TCP, www-http"
Network traffic from <b>www.comicbookdb.com/ajax_errorcheck.js?</b> matches the signature of a known attack. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.
Last edited by Caliban on Tue Aug 07, 2012 11:54 am, edited 1 time in total.

Quildra
 
Posts: 2
Joined: Tue Aug 07, 2012 11:43 am

Re: Your website has been compromised...

Postby Quildra » Tue Aug 07, 2012 11:49 am

NOD32 is picking up the same thing from comicbook.com/js/browserdetect.js? and comicbook.com/ajax_errorcheck.js? indicating a threat for JS/Kryptik.SX.trojan
Last edited by Quildra on Tue Aug 07, 2012 2:43 pm, edited 1 time in total.

User avatar
Chris
Cosmic Donor
Cosmic Donor
 
Posts: 959
Joined: Sun Nov 13, 2005 4:48 am
Location: Toronto

Re: Your website has been compromised...

Postby Chris » Tue Aug 07, 2012 2:04 pm

We've tracked down the bad code in these files and they should be fixed. Please let me know if you find any other problems.

Quildra
 
Posts: 2
Joined: Tue Aug 07, 2012 11:43 am

Re: Your website has been compromised...

Postby Quildra » Tue Aug 07, 2012 2:44 pm

NOD 32 is not longer reporting and issue :)

Caliban
 
Posts: 4
Joined: Tue Sep 13, 2011 8:20 am

Re: Your website has been compromised...

Postby Caliban » Wed Aug 08, 2012 8:26 am

Likewise NAV is now showing nothing.
Thanks for fixing it.
Reassuring

Caliban
 
Posts: 4
Joined: Tue Sep 13, 2011 8:20 am

Re: Your website has been compromised...

Postby Caliban » Sun Aug 12, 2012 9:19 am

NAV is showing the Mass Injection message as back again this morning

pnova
 
Posts: 67
Joined: Thu Oct 27, 2011 11:00 am

Re: Your website has been compromised...

Postby pnova » Sun Aug 12, 2012 1:58 pm

http://spyware-experts.com/need-to-remo ... tAod9S8AYw

Follow this is you had this software force it self to down load, you need to use safe mode or reinstall everything on your laptop - it blocks you from using the internet or opening any files or control panel. It downloaded from this site & disables your own security & doesn't let you do anything - takes you to page trying to get you to pay for the software.

jaxstrawww
 
Posts: 1
Joined: Sun Aug 12, 2012 8:02 pm

Re: Your website has been compromised...

Postby jaxstrawww » Sun Aug 12, 2012 8:04 pm

AVG is popping up blocked threat messages left and right.

Also, my original forum name was disabled by an admin? Any idea what that was about?

pnova
 
Posts: 67
Joined: Thu Oct 27, 2011 11:00 am

Re: Your website has been compromised...

Postby pnova » Mon Aug 13, 2012 8:05 am

Unable to add anything on the website - site must be blocked by spyware programs trying to download. Can the admin sort out the pop-up?

User avatar
Chris
Cosmic Donor
Cosmic Donor
 
Posts: 959
Joined: Sun Nov 13, 2005 4:48 am
Location: Toronto

Re: Your website has been compromised...

Postby Chris » Mon Aug 13, 2012 2:40 pm

I found the problem, I think. Can you guys check again?

pnova
 
Posts: 67
Joined: Thu Oct 27, 2011 11:00 am

Re: Your website has been compromised...

Postby pnova » Tue Aug 14, 2012 6:42 am

I've got another problem - don't know if related. When entering Red Alert (Transformers)(Armada) into an issue it come up without the character name but says something else.

Caliban
 
Posts: 4
Joined: Tue Sep 13, 2011 8:20 am

Re: Your website has been compromised...

Postby Caliban » Wed Aug 15, 2012 12:56 pm

Seems ok again now

Next

Return to Site Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron