![]() |
|
|
||||||||
| Forum Suggestions, Feedback, and Bug Reports Please use this forum to post feedback and suggestions related to the Forums. Find a bug? Post it here. |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
![]() |
![]() |
|
| Level: 8 | HP: 36 / 198 |
|
EXP: 94% |
|
![]() |
#1 (permalink) | ||
|
|
It's happened again. Google's listed TFF as an attack site again for Firefox users. And once again the culprit seems to be google's adsense ads!
Now I'm unhappy!
__________________
My TFF Family My Chocolate and Theory lovin' Niece -- Unknown Entity
My CRAZY NUTTY Aussie sisters -- Tiger Lily and superjj ![]() |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 66 | HP: 1502 / 1629 |
|
EXP: 19% |
|
![]() |
#2 (permalink) | ||
|
The Old Skool Warrior
|
Okay, I know that AdSense brings in most of the funds required to run this place, but damnit this is just ridiculous now. Fuzz, we have to do something, whether it's in the form of finding an alternative or whatever...
__________________
![]() NOTABLE QUOTABLES; Last.fm recent tracks list: |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 65 | HP: 1174 / 1621 |
|
EXP: 87% |
|
![]() |
#4 (permalink) | ||
|
Magically Delicous
|
Has Fuzz actually scanned all the files on the server to see if there is a link to google-analytize.com? That isn't Google, it's a malware site with a similar name. It's possible the forums or the site has a link to it somewhere and Google is picking it up. Either that or someone hi-jacked the ads on Google's search engine itself, which is a known issue they aren't doing anything about. Never click sponsered links... ^_^
__________________
![]() New banner finally! |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 65 | HP: 1174 / 1621 |
|
EXP: 87% |
|
![]() |
#6 (permalink) | ||
|
Magically Delicous
|
Then it's a good possibility something is screwed up in the forums settings. I'm not sure where he put the ad shit in the forum code at but I can look at it later.
I'm working on scanning all the site files by hand to see if any of those are contaminated.
__________________
![]() New banner finally! |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 34 | HP: 113 / 846 |
|
EXP: 86% |
|
![]() |
#7 (permalink) | ||||
|
Born Again Atheist
|
I looked at the source code for this page, out of curiousity, to see what I could find. It just confirms our problems, but here it is.
Quote:
Quote:
__________________
![]() More to read here: |
||||||||||
|
|
|
||||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 65 | HP: 1174 / 1621 |
|
EXP: 87% |
|
![]() |
#8 (permalink) | ||
|
Magically Delicous
|
That didn't pinpoint anything... all sites that have Google's adSense use that same block of code, just with a different client id.
I couldn't find any botched code in the forums or in the files. All of them use that same block of code. The phrase google-analytize.com isn't located in any of the files or templates either. EDIT: There ARE viruses on the server. I was skipping images since I was focusing on code, but I'm going to do a more thorough search of every file when I get home. Here are some that I found and deleted: /picturepost/final_fantasy_iii/1408.2007.iTALiAN.AC3.DVDRip.XviD-GOLD.cd1.avi /picturepost/final_fantasy_iii/La.Bussola.D.Oro.2007.iTALiAN.MD.CAM.XviD-DSi.avi /picturepost/final_fantasy_iii/xh I have deleted these files off the server. It looks like someone was using PicturePost to store porn on TFF and the files have viruses. |
||||||||
|
|
|
||||||||
![]() |
![]() |
| Sponsored Links |
![]() |
![]() |
|
| Level: 65 | HP: 1174 / 1621 |
|
EXP: 87% |
|
![]() |
#9 (permalink) | ||
|
Magically Delicous
|
This needs a separate post, due to its importance:
The following people are BANNED for using vB-exploiting code in their sigs: Death Sentence maxpower Please smoke up The use of JavaScript of any sort is not allowed on TFF and you have no chances with this. If such code is used in an exploitive manner, you will be banned upon discovery. If you re-register I will ban you again. Keep your script-kiddy shit on your own site and leave it off TFF. ~~~~ I will continue to search for problems when I get home from college. Sarah, you were actually right... just not how you think. I was doing research on a vB exploit one of the above people were using and the site I went to was flagged by my virus software: ![]() Notice who it's from? This IS NOT a knockoff site... the virus is coming straight from Google. Now, this isn't our only problem here at TFF, but it is part of it. Note: The line thing is a cursor when I was copy+pasting the text... its not a L. |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 33 | HP: 67 / 803 |
|
EXP: 15% |
|
![]() |
#10 (permalink) | ||
|
|
I was so mad when we got flagged again by Google. It is just getting beyond annoying at this point. Thanks Merlin for taking the time to scan the files and look over the VB settings. I have also searched all files on TFF for google-analytize and b1izzard and have found nothing. In addition, I have also search the raw forum database and found nothing either.
We have had problems with the picturepost directory having suspicious files being uploaded to it. I just went into the server and made sure all directories were protected again, and yes, there was a loop-hole in there. Merlin did you check all the sub-directories? thanks again for finding those. Also, for the vb exploits you found... can we disable javascript or lock down the signatures to any extent? I wasn't aware of these exploits. IT is a shame if this is Google Adsense. I know it has been the case a few times in the past, but there is no way we can control that. I have made several attempts to let Google aware of this 3rd party ad problem... I am isntalling ClamAV to the server for more thorough virus protection. Hopefully this warning will be removed promptly and soon.
__________________
Webmaster @ <a href="http://www.thefinalfantasy.com">thefinalfantasy.com</a> <a href="mailto:fuzz@thefinalfantasy.com">webmaster@t hefinalfantasy.com</a><br /> |
||||||||
|
|
|
||||||||
![]() |
![]() |
![]() |
![]() |
|
| Level: 65 | HP: 1174 / 1621 |
|
EXP: 87% |
|
![]() |
#11 (permalink) | ||
|
Magically Delicous
|
Make sure you go through the hosts file in etc/hosts to see if there are any references to pagead2.googlesyndication.com or any other Google stuff and delete them. It's still a possibility that it really isn't Google doing it, but a third-party site which redirects back to Google after it installs shit on your comp unbeknownced to you. Might as well eliminate any possibility it's the box. If it's not the box, then well... we at least know with certainty WE aren't the ones dumping trojans on people.
![]() You still need to scan the entire disk for any more viruses because I didn't want to download every single file off the server and check by hand unless I had to. I can, but it will take a while to dl it all. Oh and feel free to email that pic to Google and tell them to shove it up their ass. Here is the log of it: Quote:
In case you're interested in the infection on our server, here it is: Quote:
![]() |
||||||||
|
|
|||||||||