telemark skiingbackcountry skiingPacific NorthwestWashington and Oregonweather linksThe Yuki AwardsMt. Rainier and Mt. Adams
Turns All Year
www.turns-all-year.com
  Help | Search | Login | Register
Turns All Year Trip Reports
Backcountry Skiing and Snowboarding

Welcome, Guest. Please login or register.
05/20/13, 05:01 AM

The Yuki Awards
 
Trip Reports Sponsor
Pro Ski Service
Pro Ski Service
Turns All Year Trip Reports
(1) Viewing these pages constitutes your acceptance of the Terms of Use.
(2) Disclaimer: the accuracy of information here is unknown, use at your own risk.
(3) Trip Report monthly boards: only actual trip report starts a new thread.
(4) Keep it civil and constructive - that is the norm here.
 
FOAC Snow
Info Exchange


NWAC Avalanche
Forecast
+  Turns All Year Trip Reports
|-+  Hot Air
| |-+  Random Tracks: posts that don't fit elsewhere
| | |-+  Malware Warnings on TRs
:
« previous next »
Pages: [1] | Go Down Print
Author Topic: Malware Warnings on TRs  (Read 1170 times)
Marcus
Administrator
Offline

Posts: 2237


WWW
Malware Warnings on TRs
« on: 02/21/12, 08:43 AM »

A couple of folks have sent me PMs/emails about some malware warnings they're getting when viewing the site in Google Chrome.  I'm not seeing the same thing in FireFox but there have been some global changes to some of the source files and I'm weeding them out now.

The malware seems to be trying to redirect folks to *.rr.nu websites.

Anyone with more experience here is free to chime in with advice.  I'm replacing the edited source files with backups, but I'm not clear yet on the extent of the problem.

Sorry for any hassle.  Browse cautiously, I guess.
Logged
mc
5Member
Offline

Posts: 24


Re: Malware Warnings on TRs
« Reply #1 on: 02/21/12, 08:54 AM »

morning-- i'm getting these now on IE7 at work.  i know our IT group has been clamping down lately so i thought it was just part of that.

-mc
Logged
Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #2 on: 02/21/12, 09:44 AM »

Okay I pulled the forum back out of maintenance mode after doing a ton of cleanup.  There may be more to root out -- if anyone is still having problems, please post here or PM/email me.

Thanks.
Logged
Charlie Hagedorn
Member
Offline

Posts: 1133


WWW
Re: Malware Warnings on TRs
« Reply #3 on: 02/21/12, 10:05 AM »

This page still has a script!
« Last Edit: 02/21/12, 10:42 AM by Charlie Hagedorn » Logged

Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #4 on: 02/21/12, 10:07 AM »

Thanks Charlie, tracking it down.
Logged
Amar Andalkar
Member
Offline

Posts: 898


WWW
Re: Malware Warnings on TRs
« Reply #5 on: 02/21/12, 10:48 AM »

Thanks for dealing with this quickly, Marcus.  Keeping a website running smoothly is not easy in the face of malicious intruders.

I first noticed the issue just after midnight, when the TAY website tried to redirect me to a *.rr.nu website -- this was on Safari on Mac OS X. But I immediately closed the window before it had finished loading the site. However, Safari gave me no warning, and the problem did not recur on a second (tentative) visit to TAY a minute later.

Then this morning at 9am, I got the following warning message when surfing from Chrome on Mac OS X, but Safari was still not warning me.




A few minutes later, you had the forum in maintenance mode, and then by 9:45am, Chrome was no longer giving the warning, and still isn't.

And yes, using the Developer tools in Safari, I can still see a php script from tomoti62veform.rr.nu too.

Logged

Charlie Hagedorn
Member
Offline

Posts: 1133


WWW
Re: Malware Warnings on TRs
« Reply #6 on: 02/21/12, 10:53 AM »

Chrome is only getting hits on a small fraction of the URLs. I'm not sure how the Google Safe Browsing servers decide that a site is a source for malware, but they surely have some latency.

Hope this isn't hitting your day job hard, Marcus! Any TAYers with some modern site admin experience may be of considerable help with rooting out the trouble....
Logged

Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #7 on: 02/21/12, 10:56 AM »

Good info, thanks -- I'm still trying to root out the pieces.  Hopefully I can get it all cleaned out.  I'm getting some help from TAY folks via email, thank you very much!
Logged
Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #8 on: 02/21/12, 12:08 PM »

Huge help from JF, TAY lurker extraordinaire -- I think we've cleaned out most of the malware for now, but we'll keep an eye on it to see if it resurfaces.
Logged
mc
5Member
Offline

Posts: 24


Re: Malware Warnings on TRs
« Reply #9 on: 02/21/12, 08:41 PM »

thanks for jumping on that so quick.  pretty soon after my initial post it was cleared up on IE7...
Logged
Amar Andalkar
Member
Offline

Posts: 898


WWW
Re: Malware Warnings on TRs
« Reply #10 on: 02/21/12, 11:32 PM »

It looks like the TAY clock-error problem has also been fixed -- the displayed time on each page had been over 8 minutes fast recently, but is now correct.

Did you do something to fix it while dealing with the malware? Or did it just fix itself?

Logged

Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #11 on: 02/22/12, 07:16 AM »

I noticed the clock corrected itself when I replaced one of the first php files that was infected -- I had thought that clock was server-side and I had no way to change it.  Still not sure if I do, but something fixed it.  Smiley I knew that would make you happy Amar!

TAY's hosting service was hacked and lost a bunch of SSH login/password info a few weeks ago.  They were pretty quick to force password resets, but I'm guessing that short window was when somebody got onto the TAY server and put this trojan in.  Seems plausible.
Logged
JibberD
Member
Offline

Posts: 533


Re: Malware Warnings on TRs
« Reply #12 on: 02/22/12, 08:42 PM »

About 30 minutes ago I was redirected to another site while choosing TAY from my favorites.

The site looked like youtube and included a message saying my machine needed to be scanned. Also wouldn't allow me to close the page. Used Task Mgr. to end ie process.

Anyone else seen this?
Logged

-Doug O
CMSkier
Member
Offline

Posts: 214


WWW
Re: Malware Warnings on TRs
« Reply #13 on: 02/22/12, 08:46 PM »

About 30 minutes ago I was redirected to another site while choosing TAY from my favorites.
Anyone else seen this?

Same issue about the same time. Tried again and it went to admin login screen.

Ken
Logged

Kkz
Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #14 on: 02/22/12, 09:08 PM »

Yeah, had a recurrence there while trying to sort out some database problems.  I'm hoping we're in the clear now.  I'm going to stop touching stuff for a little while.
Logged
flowing alpy
Member
Offline

Posts: 200


Re: Malware Warnings on TRs
« Reply #15 on: 02/23/12, 03:50 PM »

Same issue about the same time. Tried again and it went to admin login screen.

Ken
same here and was a nsfw site
Logged
Marcus
Administrator
Offline

Posts: 2237


WWW
Re: Malware Warnings on TRs
« Reply #16 on: 02/23/12, 03:53 PM »

I'm assuming no one's getting this anymore though, right?  Please let me know if you are.
Logged
JibberD
Member
Offline

Posts: 533


Re: Malware Warnings on TRs
« Reply #17 on: 02/23/12, 06:47 PM »

I'm assuming no one's getting this anymore though, right?  Please let me know if you are.

Just logged on. No issue to report.
Logged

-Doug O
Griff
Member
Offline

Posts: 165


Re: Malware Warnings on TRs
« Reply #18 on: 02/24/12, 08:59 PM »

I was re-directed to a quasi porn site either yesterday or the day before. Quickly shut down my machine as it froze. No problems since then, specifically today.
Logged
Pages: [1] | Go Up Print 
« previous next »
Jump to:  



Login with username, password and session length

Thank you to our sponsors!
click to visit our sponsor: Feathered Friends
Feathered Friends
click to visit our sponsor: Marmot Mountain Works
Marmot Mountain Works
click to visit our sponsor: Second Ascent
Second Ascent
click to visit our sponsor: American Alpine Institute
American Alpine Institute
click to visit our sponsor: Pro Guiding Service
Pro Guiding Service
Contact turns-all-year.com

Turns All Year Trip Reports ©2001-2010 Turns All Year LLC. All Rights Reserved

The opinions expressed in posts are those of the poster and do not necessarily
reflect the opinions of Trip Reports administrators or Turns All Year LLC


Turns All Year Trip Reports | Powered by SMF 1.0.6.
© 2001-2005, Lewis Media. All Rights Reserved.
Page created in 0.359 seconds with 20 queries.

home  |  trip reports  |  weather  |  access  |  year-round skiers  |  snow images  |  about
photo copyright  |  DMCA/copyright  |  other legal  |  contact  |  t-shirts  |  donate  |  Yuki Awards