• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Collapse

You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:

  • You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
  • You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
  • If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.

Previously on "Virus Threat AGAIN!!!"

Collapse

  • fullyautomatix
    replied
    Originally posted by SupremeSpod View Post
    You're fired!

    None of this namby-pamby "And we all learned a lesson from that and we've tightened up procedures" bollocks, that's it, security are on the way to escort you from the building.

    :

    What Spod Said.

    Leave a comment:


  • SupremeSpod
    replied
    Originally posted by BrilloPad View Post
    Wont HMRC query your return when they notice 20 invoices from the same company?
    ftfy

    Leave a comment:


  • BrilloPad
    replied
    Originally posted by MarillionFan View Post
    Yes. The invoice will be made out from Arse Tickler's Faggots Fan Club though, to ensure you're not embarrassed by membership of CUK.
    Wont HMRC query your return when they notice 2 invoices from the same company?

    Leave a comment:


  • MarillionFan
    replied
    Originally posted by SimonMac View Post
    I will be the first to ask, are CUK fees deductible?
    Yes. The invoice will be made out from Arse Tickler's Faggots Fan Club though, to ensure you're not embarrassed by membership of CUK.

    Leave a comment:


  • BrilloPad
    replied
    Originally posted by MarillionFan View Post
    It'll keep the dross out.
    Exactly. Personally I would like to see different categories of membership. There are a few here who would pay ALOT more to be platinum members - without them realising that the rest of us are not impressed and merely see them as kn0bs.

    Leave a comment:


  • SimonMac
    replied
    Originally posted by MarillionFan View Post
    I've heard rumours that it's a ploy so Admin can start to charge for user accounts to CUK.

    £20 per user, so that's AtW and Suity a couple of grand out of pocket each.
    I will be the first to ask, are CUK fees deductible?

    Leave a comment:


  • MarillionFan
    replied
    Originally posted by BrilloPad View Post
    A good move IMO
    It'll keep the dross out.

    Leave a comment:


  • BrilloPad
    replied
    Originally posted by MarillionFan View Post
    Admin can start to charge for user accounts to CUK.
    A good move IMO

    Leave a comment:


  • MarillionFan
    replied


    Cojak for Admin!

    Leave a comment:


  • SupremeSpod
    replied
    Originally posted by administrator View Post
    Yes, I am a pillock and should not be in charge of a smart phone, let alone a server if the truth be known.

    As I said before, the banner ad system got hacked due to the provider (OpenX) getting hacked. This initial hack created a new user account on the system and the hacker logged in to the account via the control panel and added the JavaScript code to the database for each banner entry in a field that can be used to append or prepend the code to the banners.

    So cleaned this out, removed the new admin account and changed the password on the main account.

    They must have left some sort of backdoor on the file system though as the JavaScript calls were re-inserted into the database for each banner prepend field last Friday. I deleted them out again and saw that OpenX had an upgrade so ran through this as well. This was a complete change of all files on the file system bar the config file. The DB content was not touched though.

    This morning I tracked the code down to append and prepend fields in the zone table - the zones are the blocks which you serve ads in. I have checked backups over the last week and these were added to the DB at the same time as the banner ones (Friday) but I missed these when I cleaned the others out and patched the software - these don't appear to have become activate until yesterday for some reason or other.

    So with these cleaned out as well I really do hope this is the last of it. If not just raise another forum thread, or if you are feeling really generous send me a PM so I get to see it a bit quicker. I have added a couple of other checks - the prepend and append fields from the banner and zone tables to be emailed to me 4 times a day just in case there is still a route into the server and will also basic auth the admin area later so even if new admin accounts can be injected or passwords revealed somehow they shouldn't be able to get past that to do any damage.
    You're fired!

    None of this namby-pamby "And we all learned a lesson from that and we've tightened up procedures" bollocks, that's it, security are on the way to escort you from the building.

    Leave a comment:


  • administrator
    replied
    Yes, I am a pillock and should not be in charge of a smart phone, let alone a server if the truth be known.

    As I said before, the banner ad system got hacked due to the provider (OpenX) getting hacked. This initial hack created a new user account on the system and the hacker logged in to the account via the control panel and added the JavaScript code to the database for each banner entry in a field that can be used to append or prepend the code to the banners.

    So cleaned this out, removed the new admin account and changed the password on the main account.

    They must have left some sort of backdoor on the file system though as the JavaScript calls were re-inserted into the database for each banner prepend field last Friday. I deleted them out again and saw that OpenX had an upgrade so ran through this as well. This was a complete change of all files on the file system bar the config file. The DB content was not touched though.

    This morning I tracked the code down to append and prepend fields in the zone table - the zones are the blocks which you serve ads in. I have checked backups over the last week and these were added to the DB at the same time as the banner ones (Friday) but I missed these when I cleaned the others out and patched the software - these don't appear to have become activate until yesterday for some reason or other.

    So with these cleaned out as well I really do hope this is the last of it. If not just raise another forum thread, or if you are feeling really generous send me a PM so I get to see it a bit quicker. I have added a couple of other checks - the prepend and append fields from the banner and zone tables to be emailed to me 4 times a day just in case there is still a route into the server and will also basic auth the admin area later so even if new admin accounts can be injected or passwords revealed somehow they shouldn't be able to get past that to do any damage.

    Leave a comment:


  • MarillionFan
    replied
    Originally posted by fullyautomatix View Post
    If nothing, these pesky virii have managed to get Ads removed off the CUk forums. It can only be good news.
    Originally posted by SupremeSpod View Post
    Until Admin decides to stop paying the server fees...
    I've heard rumours that it's a ploy so Admin can start to charge for user accounts to CUK.

    £20 per user, so that's AtW and Suity a couple of grand out of pocket each.

    Leave a comment:


  • SupremeSpod
    replied
    Originally posted by fullyautomatix View Post
    If nothing, these pesky virii have managed to get Ads removed off the CUk forums. It can only be good news.
    Until Admin decides to stop paying the server fees...

    Leave a comment:


  • fullyautomatix
    replied
    If nothing, these pesky virii have managed to get Ads removed off the CUk forums. It can only be good news.

    Leave a comment:


  • SupremeSpod
    replied
    Originally posted by SimonMac View Post
    Does this mean that the subs are going up as you no longer have ad revenue? Can I be official CUK Bailiff?
    I doubt you've the cojones! Oi MaryPoppins, We've got a job for you!

    Leave a comment:

Working...
X