ForumUp English Language Support Forum Index ForumUp English Language Support
Before asking for support:

*Check the FAQ, Guides and Tutorials
*Use a title in posts that describes your question
*Include your forum's URL
*No PM or Email support!
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Welcome!

**ALWAYS include the URL to your forum in every post.**
You cannot register with a web.de or mail.ru email address at this time, due to a massive spam registering attack.
* Read the rules for signatures and avatars
* If you did not get your activation email, look here

* Click here for fast help for your questions.
Trojan Reported on .US Forum [fixed]
Goto page Previous  1, 2, 3, 4, 5  Next
 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    ForumUp English Language Support Forum Index -> Archives of Urgent Problems
View previous topic :: View next topic  
Author Message
LVCF
Member


Joined: 16 Jun 2007
Posts: 68

PostPosted: Fri Aug 03, 2007 1:26 am    Post subject: Reply with quote

riosmom wrote:
Where is Raulkin? Has he made any mention of fixing this problem soon? I am not as technical as some of the other posters on this board but I have done all you have told me to do and that did not help me much today Evil or Very Mad
After reading LVCFs post I am more concerned than I was before.

I really feel if the ads are the problem the fair thing to do (in the event that it would even help) is to at least remove the ads for free until it gets fixed, particularly if it is compromising our computers as it did my co-admins. Perhaps you could run that by Raulkin?

I see you made mention of other free sites having these problems. That is not the case at all, I belong to several free sites and they have ads, I have never gotten a virus from any of them. They do not have the same type of ads that we do..the ads on our forum are much, much different.

Thanks for your help, I understand that you are not able to fix it yourself but it might be time to push the issue before you lose all of your forums on US.
Dawn


Only registered users can see links on this forum!
Register or Login on forum!




I've paid for the ads to be removed from day one, so the removal part isn't the issue.

There is no way this is emanating from an ad company. They would not purposely bother doing something like this that is largely blocked by anti-viral programs.

This is a server infection.

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
riosmom
Member


Joined: 21 Jul 2007
Posts: 18

PostPosted: Fri Aug 03, 2007 1:32 am    Post subject: Reply with quote

LVCF,
I do not know what this means "server infection"?
Can it even be fixed?
Thanks,
Dawn



Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
Danman
Member


Joined: 31 May 2007
Posts: 31

PostPosted: Fri Aug 03, 2007 2:23 am    Post subject: Reply with quote

riosmom wrote:
LVCF,
I do not know what this means "server infection"?
Can it even be fixed?
Thanks,
Dawn



Only registered users can see links on this forum!
Register or Login on forum!



The server, which is the equipment Mr. Raulken uses to allow these forums to exist, and the code in which the forums are based in (phpbb) are infected with a virus. One of them seems to be the quicktime virus, a very malicious virus that can ruin one's computer.

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
scooter999
Member


Joined: 02 Aug 2007
Posts: 14

PostPosted: Fri Aug 03, 2007 2:27 am    Post subject: Reply with quote

Forum URL:
Only registered users can see links on this forum!
Register or Login on forum!



I have disabled my forum until this problem is fixed.

When I set up my forum, I created a subdirectory called buzz.deaconlight.com so I could create user-friendly names to direct users to the different music forums via an .htaccess file. Therefore, I am able to redirect anyone trying to access my forum via the subdomain URLs to an advisory page as to why the site is down.

Don't know if this will work for anyone else. Just thought I'd pass it on in case it's something someone can use.

Scooter999
Back to top
View user's profile Send private message
scooter999
Member


Joined: 02 Aug 2007
Posts: 14

PostPosted: Fri Aug 03, 2007 2:41 am    Post subject: Reply with quote

Forum URL:
Only registered users can see links on this forum!
Register or Login on forum!



Apparently the configuration panel will NOT let me disable the forum. I have tried several times setting disable to Yes but it always defaults back to No.

Why can I not disable the forum?

Scooter999
Back to top
View user's profile Send private message
LVCF
Member


Joined: 16 Jun 2007
Posts: 68

PostPosted: Fri Aug 03, 2007 2:43 am    Post subject: Reply with quote

I'm trying to understand how the disable feature works. I've clicked the switch in admin, submitted, it said it took the change. I logged out, reentered, and it looked open as usual. Is it live to me because they recognize me as admin through IP or cookies?

what does a user get when he enters a disabled forum? If it is the regular forum index, I'm not sure that would stop the virus. It seems to kick in a soon as you open the page.

Help, anyone?

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
LVCF
Member


Joined: 16 Jun 2007
Posts: 68

PostPosted: Fri Aug 03, 2007 2:43 am    Post subject: Reply with quote

scooter999 wrote:
Forum URL:
Only registered users can see links on this forum!
Register or Login on forum!



Apparently the configuration panel will NOT let me disable the forum. I have tried several times setting disable to Yes but it always defaults back to No.

Why can I not disable the forum?

Scooter999



Yeah. What he said.

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
Danman
Member


Joined: 31 May 2007
Posts: 31

PostPosted: Fri Aug 03, 2007 2:54 am    Post subject: Reply with quote

LVCF wrote:
scooter999 wrote:
Forum URL:
Only registered users can see links on this forum!
Register or Login on forum!



Apparently the configuration panel will NOT let me disable the forum. I have tried several times setting disable to Yes but it always defaults back to No.

Why can I not disable the forum?

Scooter999



Yeah. What he said.


Agreed, same here. What's the deal...features are promised but cannot be used? And no, the "pay for ads" line cannot be used here, as L has paid for ads and it does not work for him.

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
gg'ssimon
ForumUp World-Wide Admin
<b>ForumUp World-Wide Admin</b>


Joined: 13 Nov 2005
Posts: 11137
Location: USA (ForumUp World-wide Admin )

PostPosted: Fri Aug 03, 2007 3:31 am    Post subject: Reply with quote

That "forum disable" feature does not work on ForumUp forums. It never has. That information has been in our FAQ post since July 2005 at
Only registered users can see links on this forum!
Register or Login on forum!



The link to it is there because it comes like that with the phpBB forum making program.

LVCF wrote:
One of them seems to be the quicktime virus, a very malicious virus that can ruin one's computer.


No one has reported anything of the sort having happened. No one's computer will be "ruined". It's not like the harddrives melt or explode or something. I would think someone would have mentioned it if it happened, since there are thousands of users between ForumUp.us and .be.

Anyway, I am sure our Webmaster Raulken is working on the problem.

LVCF wrote:
The server, which is the equipment Mr. Raulken uses to allow these forums to exist, and the code in which the forums are based in (phpbb) are infected with a virus.


We do not know exactly, specifically what is infected.

riosmom wrote:
I do not know what this means "server infection"?
Can it even be fixed?


Yes, eventually, when the problem is discovered and then the way to remove it is found and implemented.

I understand all the frustration and anger. No more needs to be expressed on this forum. The moderators try not to take things personally, but it is hard not to with some of these venting posts.

Please post only helpful evidence or information from now on.

_________________
Margaret /gg'ssimon~ForumUp World-Wide Administrator

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message Send e-mail Visit poster's website
Penguin
Member


Joined: 27 Nov 2006
Posts: 41

PostPosted: Fri Aug 03, 2007 3:55 am    Post subject: Reply with quote

gg'ssimon wrote:

Anyway, I am sure our Webmaster Raulken is working on the problem.


Can you confirm that????
If you don't have his number I have.
If you call him you will notice he is all but working on it.

His own words: "I'm not in the office and can reply only every 2 or 3 days"

Call him (There is no excuse not to do so!!), and ask him to post some explanations regarding the problems (VIRUS AND BACKUP) and what his current and panned actions are.

Then, and only then the words of you and your colleague admins (Blind slaves) have some value !!!!

For now I'm sure no one is believing you admins and are taking your words as hold off's

_________________

Only registered users can see links on this forum!
Register or Login on forum!


Only registered users can see links on this forum!
Register or Login on forum!


Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
LVCF
Member


Joined: 16 Jun 2007
Posts: 68

PostPosted: Fri Aug 03, 2007 11:10 am    Post subject: Reply with quote

gg'ssimon wrote:
No one has reported anything of the sort having happened. No one's computer will be "ruined". It's not like the harddrives melt or explode or something. I would think someone would have mentioned it if it happened, since there are thousands of users between ForumUp.us and .be.


One part of the attack of this Trojan Horse is it steals passwords and then personal information and credit card info, etc.

So, whether or not it ca blowup my users computers, it can blow up their lives. Thanks for making the distinction.

Quote:
Anyway, I am sure our Webmaster Raulken is working on the problem.


With what evidence? He has not posted here in three weeks, and has not responded to my PMs.

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
riosmom
Member


Joined: 21 Jul 2007
Posts: 18

PostPosted: Fri Aug 03, 2007 11:37 am    Post subject: Reply with quote

[quote="LVCF
With what evidence? He has not posted here in three weeks, and has not responded to my PMs.[/quote]

LVCF,
Has he picked up your PMs? That would at least be a step in the right direction..
I had another member this AM call me at home and tell me their computer is down and won't come back up.
Back to top
View user's profile Send private message
Penguin
Member


Joined: 27 Nov 2006
Posts: 41

PostPosted: Fri Aug 03, 2007 12:08 pm    Post subject: Reply with quote

From my outbox:
"Payed for backup, read all, but got no file or download opt Raulken Mon Jul 23, 2007 8:57 am"

Proof enough !

_________________

Only registered users can see links on this forum!
Register or Login on forum!


Only registered users can see links on this forum!
Register or Login on forum!


Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
scooter999
Member


Joined: 02 Aug 2007
Posts: 14

PostPosted: Fri Aug 03, 2007 1:42 pm    Post subject: Reply with quote

Forum URL: http://deaconlight.forumup.us

My primary concern now is the liability issue that could arise from this vulnerability on Forumup.us. Subscriber admins need to have the ability to disable our forums in a crisis situation to protect us from possible litigation.

Excerpt from Symantec:

HTTP Quicktime RTSP URI BO
Severity: High


This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

DescriptionThis signature detects attempts to exploit a vulnerability in Apple QuickTime that allows an attacker to execute arbitrary code.

Additional Information

Apple QuickTime is prone to a remote buffer-overflow vulnerability. This issue is due to a failure of the application to properly bounds-check user-supplied input prior to copying it to an insufficiently sized stack-based memory buffer.

Specifically, URIs with the 'RTSP' scheme containing specifically formatted excessive data will result in a memory buffer being overrun with attacker-supplied data.n n This issue allows remote attackers to execute arbitrary machine code in the context of the affected application, facilitating the remote compromise of affected computers.

Attackers exploit this issue by coercing targeted users to access malicious HTML or QTL files, or by executing malicious JavaScript code. Any of these methods allow attackers to launch an excessively long RTSP URI, triggering the issue.n n QuickTime version 7.1.3 is vulnerable to this issue; other versions may also be affected.

Possible False Positives
There are no known false positives associated with this signature.
Back to top
View user's profile Send private message
Danman
Member


Joined: 31 May 2007
Posts: 31

PostPosted: Fri Aug 03, 2007 3:03 pm    Post subject: Reply with quote

I know it is not common to see a video player above my forum banner on the top left of the screen on my homepage. Every once and awhile I see that. I am pretty certain that is the Quicktime Virus, a very malicious virus. Like Scooter said, I will not be subject to any litigation, so I will close my forum tomorrow or the day after after consulting with my co-admin. Any damages to any one's computer may fall onto the Webmaster, so he might want to check on this little problem that we have been experiencing. Here is a blurb written from someone on this subject:

Quote:
damages for putting viruses and adware into our computers.

they should be aware of the content on their site.

negligence or perhaps something more intentional... trespass to chattel....


Quote:

our computers.

the adware and virus's infect our computers.. take control of it.

if its unintentional - its negligence.

if its intentional - its trespass to chattel

_________________

Only registered users can see links on this forum!
Register or Login on forum!

Back to top
View user's profile Send private message
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    ForumUp English Language Support Forum Index -> Archives of Urgent Problems All times are GMT
Goto page Previous  1, 2, 3, 4, 5  Next
Page 3 of 5

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


View posts since last visit / View your posts


Powered by phpBB © 2001, 2005 phpBB Group

Powered by forumup.com free forum, create your free forum!
Created by Raulken of Hyarbor S.r.l.
TOS & Privacy.

Page generation time: 0.114