• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Virus Warning Accessing This Forum

Status
Not open for further replies.

Ivo

Established Member
Joined
8 Jan 2010
Messages
7,307
Location
Bath (or Southend)
See below for the message I got. As with the Google problem though, it only came up the first time!

Running an emergency scan at present. 1.22 million objects so far and nothing - I'll update when done...

Scan complete. 1,302,005 objects, and nothing - not even any tracking software.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Schnellzug

Established Member
Joined
22 Aug 2011
Messages
2,926
Location
Evercreech Junction
yes, i got a couple of messages saying that Norton had blocked something or other. It might have been helpful if I'd remembered what they were.
 

Ivo

Established Member
Joined
8 Jan 2010
Messages
7,307
Location
Bath (or Southend)
Here's a surprise: I'm now getting adverts for anti-virus software :roll:

Still, more useful than what I had last month!
 

Xenophon PCDGS

Veteran Member
Joined
17 Apr 2011
Messages
34,176
Location
A typical commuter-belt part of north-west England
I ran a full deep scan with the Norton 360 Anti-Virus (1,743,746 entries checked) and logged back on line.

I now keep receiving pop-up notes saying "Your browser blocked this website from displaying content with security certificate errors" every time that I try to make a posting entry. This did not happen before I caused the deep scan to take effect.
 
Last edited:

Eccles

Member
Joined
16 Dec 2011
Messages
23
Location
York
I use a bookmark to get here so I can't comment on the Google issue, but I have noticed Opera getting twitchy with this site recently - keeps warning me about clickjacking.

watching my proxy logs I can see requests made to these two URLs each time a page is loaded:

http://javascript-collection.in/jquery.compatibility.js
http://gamessilver.in/in.cgi?

(wouldn't recommend following either of those!)

only seems to affect thread contents pages rather than topic lists...

a quick search through the php code for those two URLs might shed a bit of light?

Googling those two URLs doesn't turn up much, except the javascript one gives a result in Russian, which is rarely a good sign...!
 

StoneRoad

Member
Joined
6 Jan 2010
Messages
341
Location
Haltwhistle
when coming here just now to sign in, my firewall/antivirus told me that a trojan or something called 'blackhole' (I think it was) had been blocked.
 

jopsuk

Veteran Member
Joined
13 May 2008
Messages
12,773
In Opera, I'm finding that as the page finishes loading (and it does quickly) unless I hit "Stop" fast enough, I'm redirected to Google with a pop-up blocked.
 

Statto

Established Member
Joined
8 Feb 2011
Messages
3,582
Location
At home or at the pub
See below for the message I got. As with the Google problem though, it only came up the first time!

Running an emergency scan at present. 1.25 million objects so far and nothing - I'll update when done...

That's the message i got, but i did a full scan which gave the all clear, no Viruses.
 

MidnightFlyer

Veteran Member
Joined
16 May 2010
Messages
12,856
Is it a good or bad sign that I've noticed absolutely no difference and everything is running smoothly at my end?
 

Ivo

Established Member
Joined
8 Jan 2010
Messages
7,307
Location
Bath (or Southend)
Given the two Virus threads have been merged, this post is now worthless.
 
Last edited:

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
16,392
Location
Epsom
My anti virus* is giving the blocked content with security certificate errors message in the form of a yellow bar across the top of the page, time 22.23. So whatever it is must still be present.


*Computer Associates, updates itself automatically every hour.
 

Xenophon PCDGS

Veteran Member
Joined
17 Apr 2011
Messages
34,176
Location
A typical commuter-belt part of north-west England
My anti virus* is giving the blocked content with security certificate errors message in the form of a yellow bar across the top of the page, time 22.23. So whatever it is must still be present.


*Computer Associates, updates itself automatically every hour.

Peter, see my posting # 35. This appears to be quite similar to what you describe here. Norton 360 ultra-deep scan found THREE "Blackhole" attempts to ingress my HP Pavilion desktop.
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
29,527
Location
UK
As this forum runs vBulletin, I know that the forum I ran for a magazine (I've now left the company) was hacked.

My understanding is that it's rogue code put in an ad slot. And it's clever enough to divert the first time, and then (presumably using cookies or the IP address) working the next. So, most people would be redirected to a dodgy site (and invited to buy some scareware or something) but not the second time - making it incredibly hard for someone to spot. Especially when so many ad slots are dynamic, and based on the content of the page or other factors (cookies on machine showing what sites a visitor has been to recently).

It needs to be fixed, however, as sooner or later, Google will start flagging it on search results as a dodgy site - and then the traffic will fall hugely. It may even result in pages being removed entirely from Google (although you can apply to be rescanned once you can confirm the problem has been fixed).

I clicked the link as detailed at the start and did get a redirect, although Opera then picked up on it as being dodgy so I never proceeded. Upon clicking again later, it worked fine. Let me stress again; the admins on here must take it seriously! The page linked may have subject matter that is getting certain ads to appear, which are infected. If it's Google AdSense, there may well be a case of reporting the code to Google to fix. For the record, we also used AdSense.

Finally, in case anyone is worried - I think that the hack is simply to get you to go to another site to buy something, rather than something to infect your machine.
 

Ivo

Established Member
Joined
8 Jan 2010
Messages
7,307
Location
Bath (or Southend)
Progress is definitely being made on the forum's part, so kudos for that. For those that haven't noticed, there is now a Global Announcement relating to this issue.

For future reference: This is only valid until 10/03/2012.
 

MikeWh

Established Member
Associate Staff
Senior Fares Advisor
Joined
15 Jun 2010
Messages
8,116
Location
Crayford
I've noticed that McAfee sometimes displays a warning bar at the top of the page saying that it has blocked content. The content must be ad related though, because the page always looks the way it should. I've never thought much about it as I get it on other sites too, some much bigger than RailUK.
 

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
73,867
Location
Yorkshire
We are working to get this removed. I apologise for the delay.

The offending URLs are hosted on the following domains:

javascript-collection.in
gamessilver.in


(do not attempt to go to either of these sites)

They will of course re-direct to many other URLs.

Adding these URLs to your "black list" (depending on what software you use) or in a host-file to redirect to 127.0.0.1 will prevent the sites it redirects to being attempted to load on your computer. This attack is affecting other forums as well (I found a music forum with the exact same issue).

I recommend ensuring your operating system is up to date (all latest updates/patches etc installed), an up to date browser, and anti-virus software or equivalent installed and up to date.

I also run No script for added security, however it can be a bit of a pain at times (I personally think it's worth it; I add the sites I use to the trusted list when I visit them for the first time).

If you have an insecure OS/browser and/or no anti-virus software or have any concerns then do not visit this forum until around 1pm tomorrow by which time I hope we will have it fixed (at the latest I would hope)
 
Last edited:

headshot119

Established Member
Joined
31 Dec 2010
Messages
2,051
Location
Dubai
Just to advise the forum staff that Google Chrome and Firefox now give an attack site warning when trying use the forum.
 

Ivo

Established Member
Joined
8 Jan 2010
Messages
7,307
Location
Bath (or Southend)
When accessing the site directly, I had an unknown configuration-related error message appear (see attachment). Google also resulted in the same response as mentioned by headshot119. Further to this, Hotmail SmartScreen (or whatever if it is called) is blocking all attachments and hyperlinks in forum e-mails as "suspicious". Using such a link however is how I finally accessed the site this morning...!

Regarding the attachment though, note how the "domain" is noted as railouk.
 

Attachments

  • RUK Config Error.png
    RUK Config Error.png
    15.9 KB · Views: 34

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
73,867
Location
Yorkshire
We are replacing infected files on the server today so you will get some configuration errors from time to time.

If anyone is not able to block javascript-collection.in and gamessilver.in then I would advise against using accessing the forum until we have resolved the issues.

I have both of these domains blocked using a hosts file, which I would strongly recommend.
 

DXMachina

Member
Joined
24 Oct 2011
Messages
652
confirmed, Google Chrome sees the site as hosting malware and puts up a warning - since I'm a linux user this is a matter of very little concern.... Glad to see the mod team is on the job.
 

First class

Established Member
Joined
9 Aug 2008
Messages
2,731
The site wouldn't even load for the last hour for me. Got some weird code message. Imagine it's to do with the fix being applied.

rfnew.jpg
 

Badger

Member
Joined
17 Oct 2011
Messages
617
Location
Wolverhampton
I use noscript and was still effected by the initial redirect - which means it must have been done with something like PHP header('url'), rather than javascript. However due to noscript the redirected site itself (in theory) couldn't harm my PC.

Noscript shows javascript-collection.in is still trying to run scripts though.

The site wouldn't even load for the last hour for me. Got some weird code message. Imagine it's to do with the fix being applied.

You'll get this while files are down for editing to fix them. All that message really means is "config.php is missing".
 
Status
Not open for further replies.

Top