NAM Site Blocked as "ATTACK PAGE"

Discussion in 'MINI' started by goaljnky, Oct 10, 2010.

  1. Metalman

    Metalman Well-Known Member
    Lifetime Supporter

    Sep 29, 2009
    12,714
    7,659
    113
    Ex-Owner (Retired) of a custom metal fab company.
    Columbus, Ohio
    Ratings:
    +7,916 / 1 / -0
    Hi ya CmLaUnB, welcome to M/A:D
     
  2. OldBlue

    OldBlue New Member

    Sep 7, 2010
    115
    11
    0
    Die Shop Coordinator
    Cleveburb, OH
    Ratings:
    +11 / 0 / -0
    That's exactly how I'm feeling,and I'm still a MINI newbie!
     
  3. Nathan

    Nathan Founder

    Mar 30, 2009
    25,144
    10,052
    113
    Writer
    Short North
    Ratings:
    +10,069 / 0 / -0
    #103 Nathan, Oct 13, 2010
    Last edited: Oct 13, 2010
    I need to get something off my chest here...

    I just read a post on NAM by a moderator that the cause of the issue they have been suffering from according to that persons understanding is that someone had posted a photo hosted on a site that was blacklisted by Google. Guilt by association one could say.

    I gotta call BS on that.

    Why...

    1) This site, motoring|underground, MINI2, and a whole lot of Club sites would also be on Google's blacklist by now too. There were isolated reports that some people did get a warning on this and other sites. For this site I scoured the page that one member reported they saw the blocked message.

    2) Google reported that the issue was on 9 different pages. An image would be on one page, if quoted a few times it might span over 2-3 pages. But 9 pages, even on a site with as many pages as NAM has it would be very rare that the same bad image would be in that many locations.

    3) These same exploits were used on a LOT of other sites that use vBulletin. Want to read about it, I did...all 21 pages Security issue - vBulletin SEO Forums BTW, NAM updated the vBSEO product since Sunday. I checked the version they were running there Sunday AM when I first saw "the troubles" and then checked a few times over the past few days. Now I see the latest version that addresses certain security issues has been installed. If you scroll to the bottom of the page there you will see "Search Engine Friendly URLs by vBSEO 3.5.2" As of Sunday morning they were on 3.2. As IB does about nothing to update that site, they still are on vB 3.6.1 when 3.8.6 is out, and they OWN vBulletin.

    4) The moderator also stated that no one was at risk. I visited the site on Monday. My A/V tool, Esat, reported this. Direct from quarantine log.

    10/11/2010 4:18:15 PM HTTP filter file http:/(broken)/2304.in/ep.php?i=1 a variant of Win32/Kryptik.AJD trojan connection terminated - quarantined Speedy\Nathan Threat was detected upon access to web by the application: C:\Program Files (x86)\Java\jre6\bin\java.exe.

    We have the time, the scanner type (HTTP filter), object (file) Name of linked source were I broke the URL above, the threat and action, computer name/logged in user and some information about where the nasty was found to trying to gain access.

    What we have here is yet another example of a big corp owned site that is spinning "the trouble" to make themselves look better. This stuff happens to us all. It happened here. See this post. It's happened to some of the biggest forums out there, and people wonder why I left there to start M/A.

    So why are they still listed on Google's Blacklist at this time if it has been cleaned? Looks to me that Google is taking it own sweet time in de-listing the site.
     
  4. ke4sfq

    ke4sfq Member

    Aug 3, 2009
    85
    21
    8
    Technology Coordinator for a School District
    Florence, AL
    Ratings:
    +21 / 0 / -0
    Too bad the error doesn't show a list of other similar sites you could visit instead and have this one first! :lol:
     
  5. goaljnky

    goaljnky New Member

    Apr 7, 2009
    3,105
    394
    0
    LaLaLand, Left Coast, Overpopulated and Underfunde
    Ratings:
    +394 / 0 / -0
    And to add to Nate's post. If you read a detail of the threat:


    That would make it one popular picture someone posted. BS indeed.
     
  6. Johngo

    Johngo New Member
    Supporting Member

    May 18, 2010
    1,671
    200
    0
    Art Director
    Sugar Hill, GA
    Ratings:
    +200 / 0 / -0
    We already know they do a lot of truth bending over there... Now we know it even more.

    The longer they are down, the better MA looks. Here's to hoping they are down for a bit, not that MA needs the help.
     
  7. CmLaUnB

    CmLaUnB New Member

    Oct 10, 2010
    4
    0
    0
    Software Engineer
    Bay Area, CA
    Ratings:
    +0 / 0 / -0
    Thank you, sir! I'm have a pretty good time :beer
     
  8. lotsie

    lotsie Club Coordinator

    May 5, 2009
    3,922
    401
    83
    stagehand/part time detailer
    Right here
    Ratings:
    +401 / 0 / -0
     
  9. futuremini

    futuremini New Member

    Jun 11, 2010
    60
    0
    0
    Oklahoma
    Ratings:
    +0 / 0 / -0
    And we thank you for starting M/A Nathan!:Thumbsup::Thumbsup:

     
  10. OldBlue

    OldBlue New Member

    Sep 7, 2010
    115
    11
    0
    Die Shop Coordinator
    Cleveburb, OH
    Ratings:
    +11 / 0 / -0
    +2!! Here's to you! :beer
     
  11. Justa Jim

    Justa Jim Well-Known Member
    Lifetime Supporter

    May 6, 2009
    7,422
    1,685
    113
    Ratings:
    +1,685 / 0 / -0
    I'll drink to that. :cool:

    Jim
     
  12. maacodale

    maacodale Club Coordinator

    May 7, 2009
    546
    255
    63
    Maaco Collision Repair & Auto Painting Center owne
    Poquoson, VA
    Ratings:
    +265 / 0 / -0
    Oh Lordy! This could turn into a praise Nathan thread.

    (Not that we don't already, right?)

    Yeah, M/A!
     
  13. Nathan

    Nathan Founder

    Mar 30, 2009
    25,144
    10,052
    113
    Writer
    Short North
    Ratings:
    +10,069 / 0 / -0
    Wow...going on Day 5.

    From the Google Safe Browsing Diagnostic Page today...I added the bold.

    In the bottom right corner of the report as of 8:13 AM CT

    A bad image...yeah right.

    For those interested in more about how Google does all this please see About malware and hacked sites - Webmaster Tools Help
     
  14. Justa Jim

    Justa Jim Well-Known Member
    Lifetime Supporter

    May 6, 2009
    7,422
    1,685
    113
    Ratings:
    +1,685 / 0 / -0
    I need some info here. I use google now, but when I made some of my "favorites" I believe it was while searching with "Bing". I get no warning, so is that because I did not save them using "Google"?

    Jim
     
  15. Nathan

    Nathan Founder

    Mar 30, 2009
    25,144
    10,052
    113
    Writer
    Short North
    Ratings:
    +10,069 / 0 / -0
    The warning being displayed or not is browser dependent. Chrome, Opera, Firefox and Safari all check the Google Blacklist before sending you off to the site. Internet Explorer does not. You can get to the site via IE with no warnings and being that over all IE has 49% of the total browser market according to wikipedia then about 1/2 the people are wondering...what message.
     
  16. ScottinBend

    ScottinBend Space Cowboy
    Supporting Member

    May 4, 2009
    8,767
    2,547
    113
    Bend, OR USA
    Ratings:
    +2,678 / 1 / -0
    .....wondering what happened to their computer afterwards.

    :D
     
  17. TGS91

    TGS91 New Member

    May 8, 2009
    1,593
    18
    0
    Sales Dude
    St. Louis, MO
    Ratings:
    +18 / 0 / -0
    IE would not want to be bothered with their end users getting malware installed using their software, how so very inconvenient

    Another ringing endorsement for Chrome, Firefox, Safari, etc
     
  18. Justa Jim

    Justa Jim Well-Known Member
    Lifetime Supporter

    May 6, 2009
    7,422
    1,685
    113
    Ratings:
    +1,685 / 0 / -0
    On the top corner of the Google page it asks if I want to download Chrome. Can I do that and not mess up anything already on my computer?

    Jim
     
  19. Nathan

    Nathan Founder

    Mar 30, 2009
    25,144
    10,052
    113
    Writer
    Short North
    Ratings:
    +10,069 / 0 / -0
    Yes.

    Any of the above mentioned browser can be added with no ill effects.

    I use them all with Firefox being the workhorse.
     
  20. TGS91

    TGS91 New Member

    May 8, 2009
    1,593
    18
    0
    Sales Dude
    St. Louis, MO
    Ratings:
    +18 / 0 / -0
    Get ready for a most pleasurable internet experience

    Only reason I mainly use Chrome over Firefox is I *understand* that Chrome is a bit more secure than Firefox. That may have been some Microsoft FUD
     

Share This Page