Fri 03 September 2010. at 13:17
: SMF - Just Installed!

+  Eastleigh FC
|-+  General Category
| |-+  Eastleigh FC (: Big Stu, RobMDT)
| | |-+  web site and forum -PLEASE READ THIS
: 1 [2]
: web site and forum -PLEASE READ THIS  ( 3674 )
Paul Satts
International Superstar
****


: 834



« #20 : Wed 10 March 2010. at 17:30 »

I'm getting Trojan attacks on a daily basis and as this is one site i visit everyday, i suspect they are coming from here.
Others may not have good firewall defences, so are vulnerable and may not even realise they have a trojan on their system.
andy
Administrator
International Superstar
*****


: 901



« #21 : Wed 10 March 2010. at 17:41 »

Hi Paul

Depending on you AV software, you should be able to tell what site it's coming from.  I run AVG here and until yesterday I was getting warnings on there about the site.  I just checked again 1 minutes ago and I don't get any warnings.  Also, Google checks the site pretty much on a daily basis and when I looked this morning it was saying that no malicious code had been detected since the 6th March.  I never say never but I'm confident that the site is clean now.  I'm hoping that it stays that way but I'm monitoring things regularly and have the resources in place to act if we get more problems.

Best regards

Andy

WARNING: The consumption of alcohol is a major factor in dancing like a retard
fairoakspitfire
Squad Member
**


: 181


« #22 : Tue 16 March 2010. at 23:01 »

it came up saying its got something again this evening at around 10:40 ive had to use a proxy to get on here

We may not have gone up this year, but we will next year!!
MichaelEFC
Legend
*****


: 1032


« #23 : Wed 17 March 2010. at 09:01 »

The forum has gone bad again.
ryanjpage
Hot Prospect for the Future
*


: 71


« #24 : Mon 22 March 2010. at 19:07 »

does anyone know how the website got a virus ?
glad its all fixed now though.

COME ON EASTLEIGH
andy
Administrator
International Superstar
*****


: 901



« #25 : Mon 22 March 2010. at 19:20 »

does anyone know how the website got a virus ?
glad its all fixed now though.

Don't speak too soon!  The site has actually been attacked again.

It's a common exploit that has been used on the site, it's not a virus, it's some script that hijacks the site to get you to go somewhere else.  You type in www.eastleigh-fc.co.uk, you get www.buy-viagra.com where you'll get infected with spyware.  Google keeps a database of when this happens.  Most browsers use those databases to protect people which is why you might get a message to say that the site has been blocked or your anti-virus software will block the site.

We've put in so many measure on this site to stop this happening but every time we shut one door they find another way in.  The initial attack came through the forum which is quite old.  They use weaknesses in the forum to crow bar their way in.  Once they're in then they run round opening other doors wherever they can.  So we shut the door on the forum, not realising that they've opened a door somewhere else.

I've got 2 developers working full time this week to rebuild the whole site on a new system with a new forum.  There's LOTS of content to copy over and this will take time.  Once it's done though we'll have a much better system generally and we should all be nice and secure again.  What I need to do is devote my time to getting the new system built.  Devoting time to fixing the hack each time is just chasing our tails.

All I need at the moment is your patience.  This is not something that me or the club has brought on ourselves, this is the result of some very persistent and unscrupulous hackers in somewhere like China or Russia. Even if we could find them, these are countries who have little or no interest in prosecuting such people.  Personally, I'd like 5 minutes alone with one of them... just 5 minutes.

I'll keep you all posted but, fingers crossed, all will be well again in a week!

Best regards

Andy

WARNING: The consumption of alcohol is a major factor in dancing like a retard
ryanjpage
Hot Prospect for the Future
*


: 71


« #26 : Mon 22 March 2010. at 19:24 »

why would anyone want to target a football forum what sick person is this !!!!

COME ON EASTLEIGH
andy
Administrator
International Superstar
*****


: 901



« #27 : Mon 22 March 2010. at 19:45 »

That's the trouble.  They're not targeting anyone.  They'll go for any site where they find a vulnerability.  It doesn't matter to them whether you're a large multi national company or a charity.  They run highly complex programs that search the web and find the slightest chink the armour that they can use.  Most of this is done automatically.  They just set a program going and leave it to do all the dirty work.  This is often done by hijacking personal computers owned by individuals all over the world and putting viruses on them that the user doesn't know about.  While they're sitting at home in any part of the world surfing the net, writing documents and anything else, they're computer is being used to do someone's dirty work.  They'll hijack thousands of computers which create a botnet which is just a network of computers used to do tasks.  These are then used for things like sending spam.  One campaign using a botnet like this sent 350 million e-mails and they'll do this many times.  One security guy said that even a response rate of 0.00001% would yield millions of dollars a year.

I get the bounce backs when these bots try and register through the forum and since the 21st Feb 2010 I've probably seen 500 on this site.  99% of these will be people trying to register fake accounts on the forum with e-mail addresses like kjsgafjkgsdj@mail.ru.  The forum then sends an e-mail back for the person to verify their address.  The address doesn't exist so it bounces back to me.

Andy

WARNING: The consumption of alcohol is a major factor in dancing like a retard
ryanjpage
Hot Prospect for the Future
*


: 71


« #28 : Mon 19 April 2010. at 11:55 »

Is it all sorted now been a couple of months ?

COME ON EASTLEIGH
ade
Squad Member
**


: 172


« #29 : Sun 20 June 2010. at 19:22 »

sideways badger....
: 1 [2]  
:  



Sorry, the copyright must be in the template.
Please notify this forum's administrator that this site is missing the copyright message for SMF so they can rectify the situation. Display of copyright is a legal requirement. For more information on this please visit the Simple Machines website.