Originally posted by OwlHoot
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: Forum Virus
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Forum Virus"
Collapse
-
-
Originally posted by administrator View Posttulipe, sorry TimberWolf Did mbam clean it OK? Hope you didn't have to reinstall or anything.
Yes, this was the same iframe kind of hack that is being used on the Wordpress sites but it was calling a page from an Indian site and I am certain this was just a page that would trigger the Trojan payload that would check the browser etc on your machine to see if it could be hacked at all. Very easy to hit on a site that has been hacked and get infected. As others in this thread said - try Avast, it was the only AV that detected it.
Leave a comment:
-
shit:e, sorry TimberWolf Did mbam clean it OK? Hope you didn't have to reinstall or anything.
Yes, this was the same iframe kind of hack that is being used on the Wordpress sites but it was calling a page from an Indian site and I am certain this was just a page that would trigger the Trojan payload that would check the browser etc on your machine to see if it could be hacked at all. Very easy to hit on a site that has been hacked and get infected. As others in this thread said - try Avast, it was the only AV that detected it.
Leave a comment:
-
Who got infected? I did. And when I ran the anti malware software admin recommended, that was the only malware found. So in all my years of browsing on this PC and all the dodgy sites that I must have accidentally strayed across, seemingly CUK was the only one to infect me. How odd.
I'm a bit disappointed that it's still so easy to become infected, just by viewing a webpage.
Leave a comment:
-
Originally posted by NickFitz View PostInteresting article:
"Cyber criminals have opened an online store offering website operators increased traffic by hijacking other websites.
"The Russia-based web shop injects hidden iframes into pages of legitimate, unsuspecting websites to redirect visitors to a buyer's URL."
It's the e-equivalent of being grabbed in the street konked on the head and hustled half stunned into a crappy junk shop, where they then release you and expect you to start looking around and buying things.
Leave a comment:
-
According to El Reg, there's a virus using iFrames to attack out of date Wordpress sites
The link points to a page on compromised WordPress sites (the sites appear legitimate to spam filters) that includes a hidden iFrame, which loads the Phoenix exploit kit from a Russian-hosted server.
Arriving at the page puts surfers in the firing line of a page that attempts exploit multiple vulnerabilities in Microsoft Internet Explorer, Adobe PDF, Flash and Oracle Java. The attack is ultimately designed to distribute a information-harvesting Trojan, dubbed Cridex-B.
From the comments on the El Reg article
I'm totally down with you on the plug-ins and widgets, though. There's a number of blogs out there whose content I really enjoy -- some WordPress-powered, some on Blogger -- but which I hardly ever visit because they're so heavily infested with plug-ins and widgets that they take forever to load and often cause my browser to totally gag, crap its drawers and fall over.
Leave a comment:
-
Originally posted by Sysman View PostGood catch.
The Wordpress readme.html is accessible to the outside world and mine was announcing 3.3 until I applied the latest update.
3.3.1 came out in early January and did contain some security fixes.
I also installed Sucuri Scanner which was what warned me about the readme.html file.
Of course, doing a Google search for *.php~ is a good one, which reveals some interesting ways to get into websites.
Leave a comment:
-
Originally posted by TheFaQQer View PostIf you are on Wordpress, make sure that you remove the readme file as well. Wonder if vBulletin has the same kind of thing.
The Wordpress readme.html is accessible to the outside world and mine was announcing 3.3 until I applied the latest update.
3.3.1 came out in early January and did contain some security fixes.
Leave a comment:
-
Originally posted by Sysman View PostI once Googled for a something like "Wordpress x.y" and came up with gazillions of hits. The "perps" probably have that sort of thing automated.
Leave a comment:
-
Originally posted by administrator View PostI now know about the VBulletin patch system as well so fingers crossed we won't get a VB specific again.
Originally posted by administrator View PostWe don't output the VB version at the bottom of the site like a lot of forums do to try and make life difficult for people who do take advantage of these exploits. This is the first time in the almost sever years that I have been running the forum that we have had it hit. I won't tempt fate by saying any more
Leave a comment:
-
Hmmm: http://dictionary.reference.com/browse/virus
"3. a corrupting influence on morals or the intellect; poison."
Leave a comment:
-
Originally posted by cojak View PostYou're on twitter?!?
I'm not sure about the facebook page I know there's a Facebook group, but that's just for CUK evening photo's and the only people allowed on that need to be in the photos or have taken them...
God only knows who looks after them these days - used to be me. Maybe RH and Gonzo???
I created the CUK photos one, but I'm not a member of the group any more, so don't know who looks after it.
I think Zara created the LinkedIn page, but again I'm not sure.
Leave a comment:
-
Originally posted by cojak View PostYou're on twitter?!?
Leave a comment:
-
Originally posted by cojak View PostYou're on twitter?!?
I'm not sure about the facebook page I know there's a Facebook group, but that's just for CUK evening photo's and the only people allowed on that need to be in the photos or have taken them...
Will look at setting up a FB fan page or whatever it is. Although I don't even have time to look at what friends and relatives get up to on FB so don't hold your breath on that one...
Leave a comment:
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Secondary NI threshold sinking to £5,000: a limited company director’s explainer Dec 24 09:51
- Reeves sets Spring Statement 2025 for March 26th Dec 23 09:18
- Spot the hidden contractor Dec 20 10:43
- Accounting for Contractors Dec 19 15:30
- Chartered Accountants with MarchMutual Dec 19 15:05
- Chartered Accountants with March Mutual Dec 19 15:05
- Chartered Accountants Dec 19 15:05
- Unfairly barred from contracting? Petrofac just paid the price Dec 19 09:43
- An IR35 case law look back: contractor must-knows for 2025-26 Dec 18 09:30
- A contractor’s Autumn Budget financial review Dec 17 10:59
Leave a comment: