Malware? - Bodyartforms
in

Malware?

Last post 10-29-2009 1:26 PM by bodyartforms. 22 replies.
Page 2 of 2 (23 items) < Previous 1 2
Sort Posts: Previous Next
  • 10-28-2009 7:31 PM In reply to

    Re: Malware?

    My computer keeps telling me that something is wrong with the site.
    nosce te ipsum
  • 10-28-2009 8:21 PM In reply to

    Re: Malware?

     Scripts got inserted into our database AGAIN.

     To be honest, I don't know how much more of this I can take... this will be the 3rd time in a week and no matter how much I do.. it doesn't seem to solve the issue.

    Back to work... Website will be down until further notice.

    Bodyartforms CEO & internet junkie
  • 10-29-2009 1:01 AM In reply to

    • Rodger
    • Top 150 Contributor
    • Joined on 05-20-2009
    • Canberra, Aus
    • Posts 560

    Re: Malware?

     Mum's business website had a few attacks like this recently too, people adding little scripts to the ends of pages... We ended up changing ISPs because the one we were with didn't even bother changing the password for us to try stop them... They didn't even seem that concerned that their servers had been compromised!

    If you can get your ISP to change your account password maybe try something like a password form this site... That's as secure as a password can be, so unless they somehow don't need to guess the password, it will stop em I hope...

    2g lobes, 2g conches, 6g septum, 8g labret, 12g left tragus, 14g right tragus, 14g right eyebrow, 10g 'halfadravya'

    One day: 1/2" lobes, 0g conches, 12g right tragus... maybe more

    IAM: rodger
    "Rodger has great eyelashes." - rat
    jesskaface: i fart a *lot*
    "A plug is an item of jewelry made to fit stretched ears and comes in a variety of gauges." - Jessamine
    Itty Bitty Plug Committee - token large gauger :P
    Wishlist!
  • 10-29-2009 2:28 AM In reply to

    Re: Malware?

    I'm pulling a late night tonight recoding many of the pages to be MUCH more secure so these scripts can't be inserted into our database. I do have a feeling that this won't happen after I do this. Plus we have access to our own database and I'm having a few new securities added there as well.

    It'll take a couple of days to work it all out, but I'm slowing plowing through it. I have 55 pages to recode at this point :( And probably half of them are very complex ... taking up to 1 hour each.

    I'm really sorry for the trouble... please bear with us. I feel very confident after the site is back online that we won't see this happen again.

    Bodyartforms CEO & internet junkie
  • 10-29-2009 3:26 AM In reply to

    Re: Malware?

     Good luck getting everything straightened out. My bank account will be waiting for you!  Going to nab something off my wishlist as soon as the site is back up.  GODSPEED 2 YA

    1/2 lobes
    4g punched helixes (helices?)
  • 10-29-2009 4:27 AM In reply to

    Re: Malware?

    laaaaaaame. on one hand, I'm glad to know they're only inserting, instead of removing information. on the other hand it makes me even more annoyed since it's not like whoever is doing this is getting anything out of it, other than pissing off a bunch of people and giving some people headaches. ::sigh::

    anyways. there's a pair of hangies in my wishlist that are calling my name, so I'll be keeping an eye out for when the site gets back up again. good luck, and I hope everyone who has had to pull long hours this week at BAF has a relaxing and fun halloween weekend. : )

    ---------------------------
    8g lobes (6g goal size)
    8g right conch
    right nostril
    bunny tattoos! : D
  • 10-29-2009 12:15 PM In reply to

    Re: Malware?

     Hey...It seems the big security holeshave been abused.

    If you need some help finding and fixing them, I would help you out (btw i was also emailing you about those security issues).

    Mostly the site wasn't protected for simple XSS attacks..Seems like SQL Injection was possible aswell..So you haven't validated and sanitised the users input and the GETs and POSTs.

     

    If you need some help, let me know (xxxfanta@googlemail.com).

    Hope the site will be fine soon..Need some jewelery for Christmas ^^


    Greetz,
    FaNtA

  • 10-29-2009 1:26 PM In reply to

    Re: Malware?

    xxxfanta:

     Hey...It seems the big security holeshave been abused.

    If you need some help finding and fixing them, I would help you out (btw i was also emailing you about those security issues).

    Mostly the site wasn't protected for simple XSS attacks..Seems like SQL Injection was possible aswell..So you haven't validated and sanitised the users input and the GETs and POSTs.

     

    If you need some help, let me know (xxxfanta@googlemail.com).

    Hope the site will be fine soon..Need some jewelery for Christmas ^^


    Greetz,
    FaNtA

     

    Can you PM me? Even though much of the information was sanitized the problem was InLine SQL. I'm in the process of converting all pages to use Stored Procedures :/ FUN FUN 

    This should solve the issue... but if you have anything else to add.. lemme know ;)

    Bodyartforms CEO & internet junkie
Page 2 of 2 (23 items) < Previous 1 2
Powered by Community Server (Commercial Edition), by Telligent Systems