• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Reply to: We've been hacked!

Collapse

You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:

  • You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
  • You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
  • If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.

Previously on "We've been hacked!"

Collapse

  • eek
    replied
    Originally posted by Cliphead View Post
    I wanna be a pilchard again
    I was happy being ook. Be warned, however, that as in the books I'm comfortable with the new avatar and strapline.
    Last edited by eek; 3 April 2013, 20:35.

    Leave a comment:


  • NotAllThere
    replied
    Originally posted by doodab View Post
    I like being do bad, makes up for all the times I've been called a leftie dogooder.
    Originally posted by administrator View Post
    Can set it as your custom title seein' as you are Godlike. PM me if you want that or something else...
    Leftie Dogooder? Sounds perfect.

    Leave a comment:


  • Cliphead
    replied
    I wanna be a pilchard again

    Leave a comment:


  • KentPhilip
    replied
    I wonder when some of these name changes are going to be made permanent?
    I'm sure there are many here who would celebrate sasguru being turned into "cretin", and Atw into "SquirrelBotherer"..

    Leave a comment:


  • administrator
    replied
    Originally posted by doodab View Post
    I like being do bad, makes up for all the times I've been called a leftie dogooder.
    Can set it as your custom title seein' as you are Godlike. PM me if you want that or something else...

    Leave a comment:


  • doodab
    replied
    I like being do bad, makes up for all the times I've been called a leftie dogooder.

    Leave a comment:


  • administrator
    replied
    Originally posted by Zippy View Post
    I wanna be Bungle and have mates like ADHD and ArnoldLayne and vera.duckworth and lots of others and why can't I? Why?

    Disappointed. Very.
    Maybe you're not interesting enough?

    Leave a comment:


  • norrahe
    replied
    Originally posted by Zippy View Post
    I wanna be Bungle and have mates like ADHD and ArnoldLayne and vera.duckworth and lots of others and why can't I? Why?

    Disappointed. Very.
    I quite liked being Vera Duckworth.

    Leave a comment:


  • Zippy
    replied
    I wanna be Bungle and have mates like ADHD and ArnoldLayne and vera.duckworth and lots of others and why can't I? Why?

    Disappointed. Very.

    Leave a comment:


  • dmo
    replied
    Originally posted by administrator View Post
    Cheers dmo - this is an interesting one and could well be an artefact from an old exploit. I cannot find any reference to vbulletin_sitemap.js at all - Google and Bing draw blanks for the file name and that is unusual enough to get my attention.

    The datestamp on the file is Jan 30th 2012, and so are a lot of other files, so looks like this could be the remnant of a really old exploit.

    What I can't work out though is when is the script being called? I can't see it in source, have tried logged in and out in both FF and Chrome but cannot see this JS file being loaded at any point. I have now killed the contents of the file (have a back up just in case) but are you, or any one else, able to help me work out when that JS file is loaded so I can check the template logic and make sure that is clean too.

    Cheers,

    Admin
    It was being called whenever I loaded a new page; I think it was specifically a forum-page (that's my good guess anyway). Also, I don't see my AV kicking up a fuss anymore, so the change you made seems to have done the trick for now. I'll pm you more deets.

    Leave a comment:


  • administrator
    replied
    Cheers dmo - this is an interesting one and could well be an artefact from an old exploit. I cannot find any reference to vbulletin_sitemap.js at all - Google and Bing draw blanks for the file name and that is unusual enough to get my attention.

    The datestamp on the file is Jan 30th 2012, and so are a lot of other files, so looks like this could be the remnant of a really old exploit.

    What I can't work out though is when is the script being called? I can't see it in source, have tried logged in and out in both FF and Chrome but cannot see this JS file being loaded at any point. I have now killed the contents of the file (have a back up just in case) but are you, or any one else, able to help me work out when that JS file is loaded so I can check the template logic and make sure that is clean too.

    Cheers,

    Admin

    Leave a comment:


  • dmo
    replied
    Not much online about it, this so far: Encyclopedia entry: Trojan:JS/Iframe.CB - Learn more about malware - Microsoft Malware Protection Center

    Leave a comment:


  • dmo
    replied
    Still seeing the CB.trojan error in my AV when I visit cUK :/

    01/04/2013 17:09:54 HTTP filter file http://forums.contractoruk.com/clien...tin_sitemap.js JS/Iframe.CB trojan connection terminated - quarantined Studio-1558\Me Threat was detected upon access to web by the application: C:\Users\Me\AppData\Local\Google\Chrome\Applicatio n\chrome.exe.

    Leave a comment:


  • Freamon
    replied
    Is everything supposed to be back to normal now? Suity's posts are still garbled.

    Leave a comment:


  • KentPhilip
    replied
    Originally posted by administrator View Post
    Aye, just a couple more usernames to remove from the replacement variables and we should be back to reality. Cheers for taking the name change so well, I just caught glance of a comment you made a few days ago and when I saw you online last night I couldn't resist
    Ah yes that comment, which I <cough> deleted yesterday I think.

    I've been called worse sir!

    lol

    Leave a comment:

Working...
X