The Final Fantasy Forums  

Go Back   The Final Fantasy Forums > TFF Lobby > Forum Suggestions, Feedback, and Bug Reports

Forum Suggestions, Feedback, and Bug Reports Please use this forum to post feedback and suggestions related to the Forums. Find a bug? Post it here.

Reply
 
LinkBack Thread Tools Display Modes
 
Old 10-02-2008, 06:19 PM Level: 65  HP: 1174 / 1621
Merlin's HP
EXP: 87%
Merlin's XP
  #16 (permalink)
Magically Delicous
 
Merlin's Avatar
 

Join Date: Jan 2001
Location: Quel'thalas

   Posts    10,429
        
Provided Answers: 2

Send a message via AIM to Merlin


I don't remember if I got the most updated vB licensce info, but I can upgrade the forums to the latest update, etc once I do... which would include nuking all the files. That is unless you want to go ahead and do that now, since I won't have time to do it until Saturday.

And yes, I deleted all traces of vB exploits I found. I have backups of what they did on my computer. What they were doing didn't actually work, from what I could see, but even attempting it is good enough in my book to ban your ass.
Merlin is offline


 
Reply With Quote
 
 
Old 10-02-2008, 06:50 PM Level: 33  HP: 67 / 803
Fuzz's HP
EXP: 15%
Fuzz's XP
  #17 (permalink)
 
Fuzz's Avatar
 

Join Date: Feb 1999
Location: Columbia, M-O-O

   Posts    1,513
        
Provided Answers: 1

Send a message via ICQ to Fuzz Send a message via AIM to Fuzz Send a message via MSN to Fuzz Send a message via Skype™ to Fuzz


I'll e-mail you the updated VB info. I did update the forums earlier today to 3.7.3 Patch Level 1, which is the latest version. THANK YOU for handling the vb exploits and doing what you gotta do You the man.

Oh and good news, I think this is all resolved, apparently that Javascript file with the URL injection was the culprit. Here is the latest message from Google (about 2 hours ago)

"Status of the latest badware review for this site: A review for this site has finished. The site was found clean. The badware warnings from web search are being removed. Please note that it can take some time for this change to propagate."

YAY!

I am currently working on securing the server even more to ensure this type of thing will not happen again... wow, how annoying... Again thanks.
__________________
Webmaster @ <a href="http://www.thefinalfantasy.com">thefinalfantasy.com</a>
<a href="mailto:fuzz@thefinalfantasy.com">webmaster@t hefinalfantasy.com</a><br />
Fuzz is offline


 
Reply With Quote
 
Sponsored Links
 
Old 10-06-2008, 03:00 PM Level: 21  HP: 69 / 506
Kaiser Dragoon's HP
EXP: 25%
Kaiser Dragoon's XP
  #18 (permalink)
Definitely not 6:10:50
 
Kaiser Dragoon's Avatar
 

Join Date: Oct 2006
Location: On the Veldt

   Posts    532
        

Send a message via AIM to Kaiser Dragoon Send a message via MSN to Kaiser Dragoon Send a message via Yahoo to Kaiser Dragoon


Ehh, just a little FYI, you should update the rules and regulations if you're gonna ban people for something. *nods* I did I search in the Rules and Regulations and the word "javascript" is nowhere to be found.

Now, I only did a "CTRL+F" and typed in Java (I didn't need to type anything else, because it told me it didn't even find that), so, it may be worded different and all. Either way, not to be a prick, which it may seem like I am doing, just saying, it should probably be added so someone doesn't add script they think might be harmless and get banned for it.

~Kaiser Dragoon
__________________
<a href="http://profile.xfire.com/thedarkdragoon"><img src="http://miniprofile.xfire.com/bg/wow/type/0/thedarkdragoon.png" width="440" height="111" /></a>

Haha, I am a WoW nerd now >.>;;

Part of Crimson Moon
Kaiser Dragoon is offline


 
Reply With Quote
 
 
Old 10-07-2008, 09:04 AM Level: 65  HP: 1174 / 1621
Merlin's HP
EXP: 87%
Merlin's XP
  #19 (permalink)
Magically Delicous
 
Merlin's Avatar
 

Join Date: Jan 2001
Location: Quel'thalas

   Posts    10,429
        
Provided Answers: 2

Send a message via AIM to Merlin


Ignorance, ie: "I didn't know the gun was loaded", is not an excuse. You are responsible for what you put in your profile. It goes without saying that anything that interferes with the functionality/behavior of the site/forums is considered hacking and will be dealt with appropriately. Also, the discussion of, linking to, or actual use of hacking on the forums used to be a rule. It was modified outside of my control, but Site Security trumps those rules anyways.

Keep in mind, upon registering you sign a waiver stating that the staff can enforce standards whether they are listed or not. If you have any questions or concerns on a particular banning or decision or are unsure whether the code in your signature is acceptable, please address them to the staff through the Private Message system, not in a topic.
Merlin is offline


 
Reply With Quote
 
 
Old 10-14-2008, 12:56 PM Level: 66  HP: 1502 / 1629
LocoColt04's HP
EXP: 19%
LocoColt04's XP
  #20 (permalink)
The Old Skool Warrior
 
LocoColt04's Avatar
 

Join Date: Aug 2002
Location: Mount Olympus

   Posts    10,587
        
Provided Answers: 3

Send a message via ICQ to LocoColt04 Send a message via AIM to LocoColt04 Send a message via MSN to LocoColt04 Send a message via Yahoo to LocoColt04


We need to get rid of AdSense. I just pulled seven trojans off of my laptop; first infection I've ever had since I got this laptop nearly three years ago. I only visit a very limited number of websites, and this is the only one that's having security issues.

They showed up on boot and were killed immediately.
__________________
NOTABLE QUOTABLES; Last.fm recent tracks list:
Quote:
[01:04:30] maximo828: and holy crap dude, youre a mess
[01:04:48] LocoColt04: Correction: I am AWESOME.
[01:04:59] LocoColt04: I live in a third floor apartment. There is no handicap access.
[01:05:00] maximo828: an awesome mess
Quote:
Originally Posted by IRC, #CAD channel
InvaderZIM> i just remembered why i don't really like debates
InvaderZIM> neither of them have to have sources
Panda> kinda like wikipedia
InvaderZIM> mccain could say obama drinks the blood of infants and no one can say otherwise
Panda> please
Panda> McCain drinks baby blood
Panda> thats how he survived being a POW
LocoColt04 is offline


 
Reply With Quote
 
 
Old 10-14-2008, 01:18 PM Level: 33  HP: 67 / 803
Fuzz's HP
EXP: 15%
Fuzz's XP
  #21 (permalink)
 
Fuzz's Avatar
 

Join Date: Feb 1999
Location: Columbia, M-O-O

   Posts    1,513
        
Provided Answers: 1

Send a message via ICQ to Fuzz Send a message via AIM to Fuzz Send a message via MSN to Fuzz Send a message via Skype™ to Fuzz


Not Adsense this time. a mySQL injection on the forum index. The main site is fine... just the forums this time. I searched the DB and found an 'unescape' javascript with a hidden google-analytize URL on there with a link to malware.

I have updated the security patches and this should resolve the issue yet again

Sorry for the trouble guys, i mean it... I HATE when this happens.
__________________
Webmaster @ <a href="http://www.thefinalfantasy.com">thefinalfantasy.com</a>
<a href="mailto:fuzz@thefinalfantasy.com">webmaster@t hefinalfantasy.com</a><br />
Fuzz is offline


 
Reply With Quote
 
 
Old 10-15-2008, 09:35 AM Level: 11  HP: 9 / 269
IRANianCha0s's HP
EXP: 78%
IRANianCha0s's XP
  #22 (permalink)
TFF'S RESIDENT DOOM GOD
 
IRANianCha0s's Avatar
 

Join Date: Jun 2006
Location: Arlington, TX

   Posts    162
        

Send a message via AIM to IRANianCha0s Send a message via MSN to IRANianCha0s Send a message via Yahoo to IRANianCha0s

This is so lol...



Google: Here you go, use some of our proprietary Adsense advertisements to make money towards hosting your site!

TFF: HOKAY! (uses Adsense)

Google: OMFG The Final Fantasy: Exclusive Final Fantasy Coverage and Community IS NOW A REPORTED ATTACK SITE!!! NO ONE GO THERE LOL

TFF: :'(

IRANianCha0s:
__________________
#include stdio.h
int main () {
printf("http://www.youtube.com/watch?v=HsqqtgxdKkY");
return 0; }


IRANianCha0s is offline


 
Reply With Quote
 
 
Old 10-15-2008, 10:05 AM Level: 65  HP: 1174 / 1621
Merlin's HP
EXP: 87%
Merlin's XP
  #23 (permalink)
Magically Delicous
 
Merlin's Avatar
 

Join Date: Jan 2001
Location: Quel'thalas

   Posts    10,429
        
Provided Answers: 2

Send a message via AIM to Merlin


Is MySQL and Apache up-to-date, or is that what you are refering to? O.o

Also, why the hell is vB so vunerable to XSS all of a sudden... they are supposed to be filtering everything for that shit.

The only other thing I can think of is because you have the site and forums interconnected in a mishmash fashion, so someone is hijacking the DB through the site somehow. The DB has been steadily getting more and more buildup over the years from old hacks, whatever... plus all the crap running now. Last ditch effort might be to back-up the "useful" parts of the db, ie: only the fields that are used by vB 3.7.3 standard, and nuke the whole damned thing, DB, directory, everything. Reinstall everything from the ground up and only add the features we actually need. It'd be a big mess and the forums would be down a few days, but it might be worth looking into. I'd work on it, but I have no clue how to access the DB atm.
Merlin is offline


 
Reply With Quote
 
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Final Fantasy IX Trivia (POSSIBLE SPOILERS) LocoColt04 Final Fantasy IX 822 11-18-2008 07:21 PM
Google has listed TFF as an attack site Sean Forum Suggestions, Feedback, and Bug Reports 16 09-20-2008 02:09 AM
ok... this is really gonna flare up.... miggyboi Cleft of Dimension 15 02-07-2006 08:52 PM


All times are GMT -8. The time now is 01:52 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
Forum Answers by - Gio~Logist - Vbulletin Solutions & Services
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
© 2008 - The Final Fantasy
Page generated in 0.30049 seconds with 15 queries