• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

CUK May have yet another virus

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #11
    Confirmed, only on the Capital Umbrella ad it appears; but it's exactly the same as the previous one. Maybe something to do with the control panel for the ad system, as it's only on the new ad. I'll let admin know

    Comment


      #12
      Originally posted by Zippy View Post
      Haven't seen anything but am using AdBlocker.
      Nice to see this place is full of CUK supporters.

      Comment


        #13
        Originally posted by AtW View Post
        Nice to see this place is full of CUK supporters.

        The advertisers said they didn't want her as a client anyway

        Comment


          #14
          Originally posted by AtW View Post
          Nice to see this place is full of CUK supporters.

          I have to use it or the Daily Wail site becomes unuseable. Honest guv.
          +50 Xeno Geek Points
          Come back Toolpusher, scotspine, Voodooflux. Pogle
          As for the rest of you - DILLIGAF

          Purveyor of fine quality smut since 2005

          CUK Olympic University Challenge Champions 2010/2012

          Comment


            #15
            Cheers guys, yes looks to be the same beasty as last week. OpenX (ad manager) released a new patch yesterday:
            OpenX Blog » OpenX Source 2.8.9 Security Release

            Last time there was an upgrade released they emailed me on the three different addresses I have signed up to their mailing list, but this time nothing. Couple that with the source of the infection last week being a hack on their own site (OpenX CSRF Vulnerability Being Actively Exploited | InfosecStuff) then it does not leave me overly impressed with them but there is nothing else out there that I can find that gives me the functionality I would like (and no, dropping Trojans on you all is not the functionality I am looking for).

            Yes we did also have another hack a month or so ago but this was not the ad manager, it was vBulletin (the forum software) to blame...

            Can't remember the time before that but was about a year ago I think and I was able to catch that one pretty quickly but this year there does seem to be a raft of them.

            Do shoot me a PM if you spot anything like this as that goes to my email as well as the forum pop up so will spot things much quicker.

            I have cleaned up the source of the infection (JavaScript injection into the prepend field of all rows in the banner table, so not just the new banner that was infected) and then upgraded to the new version. That will have stopped the point of infection and should also stop us being open to the same attack again. Will be voicing my annoyance with OpenX for not emailing their users but as the system is Open Source and they want us to use their paid service then I doubt they will have much sympathy...

            Comment


              #16
              It's like ******* amateur hour on here. Come on Ad, sort your tulip out.
              What happens in General, stays in General.
              You know what they say about assumptions!

              Comment


                #17
                I thought I'd go take a look at openx to see how expensive the non-opensource version is.

                I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.
                The proud owner of 125 Xeno Geek Points

                Comment


                  #18
                  Originally posted by chef View Post
                  I thought I'd go take a look at openx to see how expensive the non-opensource version is.

                  I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.
                  It's a bit of an moment trying to look at their site with Javascript disabled

                  And no, I don't feel inclined to switch JS on to see them, just in case there is still a nasty lurking.
                  Behold the warranty -- the bold print giveth and the fine print taketh away.

                  Comment


                    #19
                    Originally posted by chef View Post
                    I thought I'd go take a look at openx to see how expensive the non-opensource version is.

                    I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.
                    It's not the price but that it is hosted by them and as you said, they haven't been too hot in protecting themselves. Also this isn't a huge site and the hosted solution would be overkill for us. I am quite capable of hosting the thing, backing it up and working the interface without some grinning permie explaining to me how to use it. I just need the thing to be secure and to be told if / when there are patches or updates that need applying.

                    Comment


                      #20
                      Originally posted by MarillionFan View Post
                      It's like ******* amateur hour on here. Come on Ad, sort your tulip out.
                      I do hope Admin ups their rep power ang gives that -ve.

                      On the other hand only a few more days of putting up with MF.

                      Comment

                      Working...
                      X