NukeWorker Forum

Reference, Questions and Help => Site Q&A => Forum Help => Topic started by: JustinHEMI05 on Mar 12, 2011, 02:45

Title: Redirected
Post by: JustinHEMI05 on Mar 12, 2011, 02:45
Is anyone else getting redirected to yahoo.com when they come here? It just started today for me, and in once instance, I got a "warning... attack site" from the link I was being redirected to.

Title: Re: Redirected
Post by: HydroDave63 on Mar 12, 2011, 02:51
Is anyone else getting redirected to yahoo.com when they come here? It just started today for me, and in once instance, I got a "warning... attack site" from the link I was being redirected to.

looked like this:
Title: Re: Redirected
Post by: Pman52 on Mar 12, 2011, 03:34
It has happened to me atleast twice.  I also happened to notice my URL heading had been changed while still on the nukeworker page.  Hmm... ???
Title: Re: Redirected
Post by: desertdog on Mar 12, 2011, 03:53
Has been happening repeatedly to me today.
Title: Re: Redirected
Post by: JustinHEMI05 on Mar 12, 2011, 04:14
looked like this:

Yes exactly!

In fact, I was having trouble replying to this! I kept getting sent to yahoo.com!!!
Title: Re: Redirected
Post by: OldHP on Mar 12, 2011, 04:39
It started happening to me this AM (~ 10).  I haven't gotten the virus warning - but, until now (this thread) it only happened going to the thread on the problems in Japan!
Title: Re: Redirected
Post by: JustinHEMI05 on Mar 12, 2011, 06:13
Come to think of it, I agree, this started for me when all that stuff started being posted in the Japan thread. There must be something in one of those links that isn't good, but I am not a doctor. Hopefully Mike or Tom can sort this out soon.
Title: Re: Redirected
Post by: RDTroja on Mar 12, 2011, 06:30
I logged in at work and got redirected to a blocked site, so the network stopped it. Apparently something got into the system.
Title: Re: Redirected
Post by: RDTroja on Mar 12, 2011, 08:13
I thought it might be the upgrade to picture loading Mike R. has been working on,....

Then I read this,....

So then I went back to Firefox and selected Japan's Nukes Following Earthquake from the Most Visited Button and got the bad link warning followed by the Yahoo Homepage,....

Hmmmmmm,....

It happens (Yahoo Homepage) when selecting Recent Unread Topics too,....

I haven't gotten it from 'Recent Unread Topics.' (I used that to get here.)
Title: Re: Redirected
Post by: Marlin on Mar 12, 2011, 09:36
I am being redirected to YAHOO as well but my spell check does not seem to be working for me either.
Title: Re: Redirected
Post by: ski2313 on Mar 12, 2011, 09:40
NIMBY-hacked, no doubt..
Title: Re: Redirected
Post by: dad on Mar 12, 2011, 09:47
Yes. Once today.

I received a warning that I was being redirected to a dangerous site.

I use different malware detection software than Hydro Dave shows above, but the web site his software reported appears to match what I saw.

I hand typed the nukeworker hypertext address and it worked the second time without a problem.
Title: Re: Redirected
Post by: drayer54 on Mar 12, 2011, 10:16
Emoticons and and the rest of the toolbar buttons on the fritz too,....

OMG!!!!,...we're approaching a nukeworker.com meltdown!!!!! Somebody quick!!! Call MSNBC!!!!

Or maybe those fair and balanced guys, I need to know whAT'S GOING ON!?!?!?!?!?!?!?

:-P  ;-)  :-) B-)
It's probably an attack from those greenpeace a**holes...
Title: Re: Redirected
Post by: OldHP on Mar 12, 2011, 10:47
Open forum penalty, when you are bouncing around the fields posting like a demon you have to remember where the boundaries are;



Since "insert quote" will not work at this point - I'll say Amen to that!
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 04:05
Well... our home page file hasn't been altered, and I don't see anything weird here.  I read through the 4 pages of the Japan thread, and nothing happened to my.

If you have more information, let me know.

Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 04:28

I've tried logged in with Firefox, and loged out with Ie... nothing.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 04:29
I thought it might be the upgrade to picture loading Mike R. has been working on,....

Then I read this,....

So then I went back to Firefox and selected Japan's Nukes Following Earthquake from the Most Visited Button and got the bad link warning followed by the Yahoo Homepage,....

Hmmmmmm,....

It happens (Yahoo Homepage) when selecting Recent Unread Topics too,....

What "Most visited" button??
Title: Re: Redirected
Post by: JustinHEMI05 on Mar 13, 2011, 11:16
Yeah it seems to have stopped. Very strange.
Title: Re: Redirected
Post by: ski2313 on Mar 13, 2011, 11:17
Rennhack, it seemed to be a temporary problem for a few hours+ yesterday. I haven't had any issues since late afternoon.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 12:08
Firefox toolbar option,....

Oh, ok.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 12:08
Yeah it seems to have stopped. Very strange.

Oh, ok.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 02:40
Hmm, it finally happened to me today,the only code that is from outside our site is the "share" button on the top right corner of every page...
Title: Re: Redirected
Post by: HydroDave63 on Mar 13, 2011, 03:10
Hmm, it finally happened to me today,the only code that is from outside our site is the "share" button on the top right corner of every page...

Ever since the attack page/redirect, adding links for pics, youtube etc seems to be broke in firefox.
Title: Re: Redirected
Post by: Pman52 on Mar 13, 2011, 04:10
It has stopped for me as well.  I'll also say that I am using safari.  I'm not sure if that makes a difference or not regarding the situation.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 05:03
Apparently they hacked out .js files which control those buttons.  I have restored older versions.
Title: Re: Redirected
Post by: drayer54 on Mar 13, 2011, 05:09
How bout we get redirected to a NCAA tourney pool?
Title: Re: Redirected
Post by: Marlin on Mar 13, 2011, 05:12
Spell check seems to be working again and I have not been directed away from the site for a while.
Title: Re: Redirected
Post by: Rennhack on Mar 13, 2011, 05:29
I'm replacing some files that i suspect have been compromised, but I have not found the source of their ability to compromise them... so the investigation continues.

I also just deleted any attachments posted since 2/14/11, so don't freak out when all of your clever political satire is gone.  I'm just cleaning house, to try to stop this from getting worse.
Title: Re: Redirected
Post by: OldHP on Mar 13, 2011, 08:12
Since about noon today I keep getting dumped to windows media player!
Title: Re: Redirected
Post by: Rennhack on Mar 14, 2011, 01:42
This seems to be an active bunch of hackers.  As I 'fix' issues, they reinfect files.  They 'somehow' are appending a script onto the end of files that add the redirection.

I'm cleaning files as fast as I can, and looking for how they are doing it.  I had the forum software clean last night, and tonight its re-infected.

It's going to be a long week.
Title: Re: Redirected
Post by: JustinHEMI05 on Mar 14, 2011, 02:00
This seems to be an active bunch of hackers.  As I 'fix' issues, they reinfect files.  They 'somehow' are appending a script onto the end of files that add the redirection.

I'm cleaning files as fast as I can, and looking for how they are doing it.  I had the forum software clean last night, and tonight its re-infected.

It's going to be a long week.

I know you have attemtped to go to 2.0 RC before, but you might want to revisit that plan. I had to upgrade a gaming site I run to 2.0 RC4 because of a similar issue. We might have to give up some things for a while, but site security is a higher priority.
Title: Re: Redirected
Post by: Rennhack on Mar 14, 2011, 03:04
I know you have attemtped to go to 2.0 RC before, but you might want to revisit that plan. I had to upgrade a gaming site I run to 2.0 RC4 because of a similar issue. We might have to give up some things for a while, but site security is a higher priority.

If it wouldn't break the home page, the forum, the quiz section, the picture section, the facility rating section....
Title: Re: Redirected
Post by: Rennhack on Mar 14, 2011, 03:24
Every time it starts up again, let me know again....
Title: Re: Redirected
Post by: Rennhack on Mar 14, 2011, 04:40
It seems that there was a breach of security in the online store, I may close it down.

The photo gallery also seems to have had issues. -- It's currently deleted entirely, while I scrub it.

The forum software was compromised, using who knows what, replacing the .js files (controls the spell checker, and the BB code, etc)

I've uploaded an older version of  the forum, while I work on the rest of the site.

The job board seems untouched, it does not use open source like the others do.
Title: Re: Redirected
Post by: JustinHEMI05 on Mar 14, 2011, 04:41
If it wouldn't break the home page, the forum, the quiz section, the picture section, the facility rating section....

Yeah I hear ya, this site is much more complicated than the one I run. Good luck!
Title: Re: Redirected
Post by: OldHP on Mar 14, 2011, 06:24
The forum software was compromised, using who knows what, replacing the .js files (controls the spell checker, and the BB code, etc)
I've uploaded an older version of  the forum, while I work on the rest of the site.
The job board seems untouched, it us not open source like the others are.

Mike:

 [salute] [salute] [salute]
First time since this all started that I've been able to use the "Quote" function and have been able to use my back function.
Title: Re: Redirected
Post by: MacGyver on Mar 15, 2011, 10:33
It seems that there was a breach of security in the online store, I may close it down.

The photo gallery also seems to have had issues. -- It's currently deleted entirely, while I scrub it.

The forum software was compromised, using who knows what, replacing the .js files (controls the spell checker, and the BB code, etc)

I've uploaded an older version of  the forum, while I work on the rest of the site.

The job board seems untouched, it us not open source like the others are.

We appreciate the effort of you and your technical staff Mike  +K

(http://www.threadbombing.com/data/media/18/tech_cat.jpg) (http://www.threadbombing.com/details.php?image_id=204)
NukeWorker.com support tech at work  ;) :P
Title: Re: Redirected
Post by: Rennhack on Mar 15, 2011, 04:57
I've deleted the shop and photo gallery, The shop will likely stay gone, It's just not worth the risk.  The photo gallery will be back as soon as I can get all of the security updates in place.  I've finished manually scrubbing the site.  I think I've found all of the exploits.
Title: Re: Redirected
Post by: Rennhack on Mar 20, 2011, 08:25
Someone's been busy today (3/20/2011),...

What's up?!?!?! Not a college hoops fan?!?!?!?

I don't watch sports on TV, except the the super bowel, or Mike Tyson..

Yes, I've been busy... trying to get the site back to pre-FUBAR days.  It's getting better.

When we are (I am) done, the site should be better than ever.
Title: Re: Redirected
Post by: Rennhack on Mar 21, 2011, 01:21
And just so you know, I am aware that there are still some problems, like the "<img src=" title=" +K" /> <img src=" title=" -K" />" formatting issue.
Title: Re: Redirected
Post by: Rennhack on Mar 21, 2011, 03:11

I think I have the karma (description) log hack working again...

I also have registration working again... it was not working for a whole week!  That's around 300 people we turned away!

http://www.nukeworker.com/forum/index.php?action=stats;expand=201103#201103
Title: Re: Redirected
Post by: Rennhack on Mar 21, 2011, 07:14
I also have registration working again... it was not working for a whole week!  That's around 300 people we turned away!

It seems the registration isn't working again... ;(
Title: Re: Redirected
Post by: Rennhack on Mar 23, 2011, 02:51
It seems the registration isn't working again... ;(

And... now they are... I verified it this time.

I also noticed the karma buttons in the PM section was fubar, and fixed that.

We HAVE to be getting close to getting the forum working again.
Title: Re: Redirected
Post by: 01changeup on Mar 23, 2011, 10:11
And... now they are... I verified it this time.

I also noticed the karma buttons in the PM section was fubar, and fixed that.

We HAVE to be getting close to getting the forum working again.

Good luck my friend. I would offer my help, but I am afraid that I would be worse than useless! My advise would always be to just kick the darn thing! But in all seriousness, good luck.

V/R
01changeup
Title: Re: Redirected
Post by: Rennhack on Mar 24, 2011, 12:10
I've deleted the shop and photo gallery, The shop will likely stay gone, It's just not worth the risk.  The photo gallery will be back as soon as I can get all of the security updates in place.  I've finished manually scrubbing the site.  I think I've found all of the exploits.


The photo gallery is back online.  New and improved too!  Great new up-loader.

We are missing some pictures from the "cleaning" that occurred recently, but those files should be restored soon.

We were able to take this opportunity to update the software while it was down.  It has a new look, and a fantastic new picture up-loader.
Title: Re: Redirected
Post by: Rennhack on Mar 28, 2011, 01:50
We are missing some pictures from the "cleaning" that occurred recently, but those files should be restored soon.

The 'missing' pictures have been restored.  The photo gallery should be at 100% now.


The shop... something has to be done about that.
Title: Re: Redirected
Post by: Rennhack on May 21, 2013, 02:55
Woot, 2 months without an issue.  That's a lot better than two hours.
Title: Re: Redirected
Post by: RDTroja on May 21, 2013, 03:02
I guess that means you are not superstitious.
Title: Re: Redirected
Post by: cedugger on May 21, 2013, 03:44
I never saw this thread when it was still fresh.

About two months ago, nukeworker.com started getting blocked on my DoD computer. I get the "Website Blocked" from US Cyber Command. It was still blocked as of last week (I'm not at work this week). Not sure why it's being blocked.
Title: Re: Redirected
Post by: Rennhack on May 21, 2013, 05:10
I never saw this thread when it was still fresh.

About two months ago, nukeworker.com started getting blocked on my DoD computer. I get the "Website Blocked" from US Cyber Command. It was still blocked as of last week (I'm not at work this week). Not sure why it's being blocked.

Two months ago, there was some malicious code injected into the site.  As far as I know, it has been removed.  The DoD block, as well as any companies block isn't lifted automatically.  You have to request that it be re-evaluated.

If you ask them to re-evaluate it, please let me know of the outcome.