• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Forum Virus

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #41
    Originally posted by chef View Post
    what's the facebook CUK group for when things like this happen again?
    That is a good point. I should have tweeted about it as well to make sure people did not come here and risk infection until I was sure it was clean. Who owns the CUK facebook page? Happy to get listed on there or have an admin account or whatever so I can post if things like this happen. I don't do FB much at all so not got too much of a clue about how it works...

    I have now patched the software. I did not realise that VBulletin were now releasing patches instead of forcing upgrades to was pretty easy to do and I will make sure it is patched whenever new releases are made to hopefully make sure that this doesn't happen again.

    Apologies if anyone got hit with anything but hope we did enough to prevent damage to too many.

    Comment


      #42
      Originally posted by fullyautomatix View Post
      Did this same thing not happen a year or so ago ?

      Virus being injected via Java runtime bug using a IFrame embedded in the Ad server ?

      I dont think a forum post was used for this but the buggy ad server.

      This being a IT forum i thought it would be prevented from happening again.
      Yes, was the adserver last time and that was my first point of call when we got the alert this morning of infection. I spotted a new patch for that only a few weeks ago and upgraded immediately as did not want the same thing to happen again. I don't even think the adserver is "buggy", simply that all applications have the potential to contain programming flaws which some people like to exploit if they can. All we can do is patch and upgrade the software when we see new releases come out and make sure our backup plans cover the potential of sites getting hit in this way.

      I now know about the VBulletin patch system as well so fingers crossed we won't get a VB specific again.

      We don't output the VB version at the bottom of the site like a lot of forums do to try and make life difficult for people who do take advantage of these exploits. This is the first time in the almost sever years that I have been running the forum that we have had it hit. I won't tempt fate by saying any more

      Yes, this is an IT company so we should be on top of these things but it is hard to cover everything, and as Nick pointed out, sometimes the time between the exploit being identified and you getting hit by them can be very small. I have come to learn that this is part of the joy of running websites

      Comment


        #43
        Originally posted by administrator View Post
        That is a good point. I should have tweeted about it as well to make sure people did not come here and risk infection until I was sure it was clean.
        You're on twitter?!?

        I'm not sure about the facebook page I know there's a Facebook group, but that's just for CUK evening photo's and the only people allowed on that need to be in the photos or have taken them...
        "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
        - Voltaire/Benjamin Franklin/Anne Frank...

        Comment


          #44
          There's a LinkedIn group, I'd no idea there was a FB page.
          Originally posted by MaryPoppins
          I'd still not breastfeed a nazi
          Originally posted by vetran
          Urine is quite nourishing

          Comment


            #45
            Originally posted by cojak View Post
            You're on twitter?!?

            I'm not sure about the facebook page I know there's a Facebook group, but that's just for CUK evening photo's and the only people allowed on that need to be in the photos or have taken them...
            Yeah have been for a while but don't really do much on there apart from tweet the news as it comes out. Trying to do more but I don't tend to have time to put any real effort in to it

            Will look at setting up a FB fan page or whatever it is. Although I don't even have time to look at what friends and relatives get up to on FB so don't hold your breath on that one...

            Comment


              #46
              Originally posted by cojak View Post
              You're on twitter?!?
              https://twitter.com/itcontracting

              Comment


                #47
                Originally posted by cojak View Post
                You're on twitter?!?

                I'm not sure about the facebook page I know there's a Facebook group, but that's just for CUK evening photo's and the only people allowed on that need to be in the photos or have taken them...
                There's two FB groups - CUK and CUK photos.

                God only knows who looks after them these days - used to be me. Maybe RH and Gonzo???

                I created the CUK photos one, but I'm not a member of the group any more, so don't know who looks after it.

                I think Zara created the LinkedIn page, but again I'm not sure.
                Best Forum Advisor 2014
                Work in the public sector? You can read my FAQ here
                Click here to get 15% off your first year's IPSE membership

                Comment


                  #48
                  Hmmm: http://dictionary.reference.com/browse/virus

                  "3. a corrupting influence on morals or the intellect; poison."

                  Comment


                    #49
                    Originally posted by administrator View Post
                    I now know about the VBulletin patch system as well so fingers crossed we won't get a VB specific again.
                    Do VBulletin offer patch notifications or security alerts by mail or RSS? I find this sort of thing from other vendors pretty useful for making you jump when you should.

                    Originally posted by administrator View Post
                    We don't output the VB version at the bottom of the site like a lot of forums do to try and make life difficult for people who do take advantage of these exploits. This is the first time in the almost sever years that I have been running the forum that we have had it hit. I won't tempt fate by saying any more
                    I once Googled for a something like "Wordpress x.y" and came up with gazillions of hits. The "perps" probably have that sort of thing automated.
                    Behold the warranty -- the bold print giveth and the fine print taketh away.

                    Comment


                      #50
                      Originally posted by Sysman View Post
                      I once Googled for a something like "Wordpress x.y" and came up with gazillions of hits. The "perps" probably have that sort of thing automated.
                      If you are on Wordpress, make sure that you remove the readme file as well. Wonder if vBulletin has the same kind of thing.
                      Best Forum Advisor 2014
                      Work in the public sector? You can read my FAQ here
                      Click here to get 15% off your first year's IPSE membership

                      Comment

                      Working...
                      X