Jump to content


Latest Posts

My Channel Logos XL!
Forum: Windows Media Center Plugins & Addons
Last Reply: skypilot (May 23 2013 11:17 PM)
I'm Sick of Updates
Forum: The Ettamogah Pub
Last Reply: skypilot (May 23 2013 05:38 PM)
ALL: MCEWebView
Forum: Windows Media Center Plugins & Addons
Last Reply: corylee20121970 (May 23 2013 01:46 AM)
Simple process for retuning?
Forum: Windows 7: Media Center & OS
Last Reply: aanda6 (May 22 2013 09:51 PM)

Recent Topics


Photo
- - - - -

Site Downtime


  • Please log in to reply
10 replies to this topic

#1 Mike

Mike

    Founding Member

  • Administrators
  • 9151 posts

Posted 17 September 2011 - 02:30 PM

I had to close the site on Friday afternoon following browser warnings that we were serving malware.

Because this site runs on a dedicated server, I'm responsible for all maintenance so to be sure I'd fixed the problem I had to employ a third party to run scans and identify where the "security hole" was, identify which part of the system or file structure had allowed the exploit to occur - and of course be 100% sure it was fixed. It turns out that it was the old xpmediacentre site which appears to have been the target and not this one.

Back in January when I switched over to Invision form software, I had to leave the old site in place on the server to enable individual thread and post redirects to send visitors who followed the all the old backlinks out there to find the corresponding content here. Even though I had believed that nobody could access the old site, it seems under certain circumstances it was still possible, and because I hadn't upgraded it in over 8 months it was a soft target.

The first job was to completely remove the old site to avoid any possibility of a repeat incident, after that new server software was installed and new scans run which all came up clean. I finally got it sorted out late yesterday afternoon, then it was off to Google and others to lodge a request for a security review to be able to get rid of those horrible red warning screens - and here we are.

I'm still scratching my head about why the wankers that do this stuff even bother with a small, under-the-radar website like this one, and according to the security experts I hired, there was nothing to be concerned about anyhow, no virus or malicious script was found - they believe it was an uploaded image file which had triggered the warning - so at least we can all feel good that our browsers are working well and taking care of us.

My apologies for any inconvenience or alarm this incident may have caused.

Mike

#2 hutchley

hutchley

    MC Apprentice

  • Members
  • PipPipPip
  • 105 posts

Posted 17 September 2011 - 05:55 PM

Mike - thanks for all the hard work in getting things straightened out.

#3 DDH

DDH

    Grand Poobah

  • Members
  • PipPipPipPipPipPipPipPipPipPip
  • 3950 posts

Posted 17 September 2011 - 06:25 PM

Mike, thanks, as always, for keeping one of the sources of my addiction alive. :D

#4 morphjk

morphjk

    MC Guru

  • Members
  • PipPipPipPipPipPipPip
  • 1559 posts
  • LocationHobart, Tasmania

Posted 17 September 2011 - 06:25 PM

Mike seeing you had to pay for a security expert and I know that you normally don't except donations but if you were willing to on this occasion then I would be very happy to make a donation to assist with the costs

Sent from my Galaxy S

#5 morphjk

morphjk

    MC Guru

  • Members
  • PipPipPipPipPipPipPip
  • 1559 posts
  • LocationHobart, Tasmania

Posted 17 September 2011 - 08:33 PM

Mike just so you know I just got the warning again. This was after clicking on a link to an old post.

#6 bill24

bill24

    MC Mentor

  • Members
  • PipPipPipPipPip
  • 711 posts

Posted 17 September 2011 - 08:57 PM

< snip >

Thanks Bill but I'd rather not advertise bogus login information from BugMeNot - I'm sure you understand why.

As for what they have over there - it was wrong anyway however I've now banned the account and submitted a block request to BugMeNot.

Thanks for the heads up but perhaps a PM might be a better idea in future. ;) - Mike


#7 Mike

Mike

    Founding Member

  • Administrators
  • 9151 posts

Posted 17 September 2011 - 09:07 PM

@morphjk - thank you sincerely for the kind offer of a donation, but I'll have to decline I'm afraid. The crappy advertising covers the cost pretty well these days, and even though revenue has been down since the change of domain name, it still pretty much covers all costs and as long as that continues I've said I won't accept donations. If however circumstances change, I'll be sure to let everyone know. ;)

As for the warning appearing again, I haven't seen it so it's a bit difficult to know where to look. As part of my housekeeping yesterday I removed lots and lots of files & old directories and 5 scans since that clean-out have produced nothing.

I'm not sure how Google runs its checks but as I write, it's showing as clear in all my browsers and MSSE is quiet as well. Hopefully it was just something in the cache showing up - if not I'm in trouble since I wouldn't know where to start looking next.

Fingers crossed... :blush:

#8 morphjk

morphjk

    MC Guru

  • Members
  • PipPipPipPipPipPipPip
  • 1559 posts
  • LocationHobart, Tasmania

Posted 17 September 2011 - 09:55 PM

No worries at all Mike.

It was the link in this post but I just tried it again and didn't get the error.

When I got the error before it was in Firefox. Trying Internet Explorer it didn't do it but now it is fine other than url not being found.

#9 debo

debo

    MC Graduate

  • Members
  • PipPipPip
  • 173 posts

Posted 18 September 2011 - 06:10 PM

thanks Mike for sorting the issue

#10 Tak

Tak

    MC Specialist

  • Members
  • PipPipPipPip
  • 374 posts

Posted 18 September 2011 - 07:23 PM

Thanks from me too Mike, I'm just glad I wasn't suffering from a media centre problem at the time as I wouldn't have known where else to go :)

At least it's forced me to update my bookmark to the pcmediacentre site, my old favourite was still pointed at the xpmediacentre site that's still getting a warning screen.

#11 Mike

Mike

    Founding Member

  • Administrators
  • 9151 posts

Posted 18 September 2011 - 09:14 PM

my old favourite was still pointed at the xpmediacentre site that's still getting a warning screen.


You gotta love the internet cache.

I completely removed that account & DNS from my server yesterday and still it shows a warning! B)