RedsZone.com - Cincinnati Reds Fans' Home for Baseball Discussion  

Go Back   RedsZone.com - Cincinnati Reds Fans' Home for Baseball Discussion > Miscellaneous > Introductions and Site Feedback

Reply
 
Thread Tools Display Modes
Old 01-19-2012, 12:42 AM   #136
Ravenlord
Into de Halls of Valhalla
 
Ravenlord's Avatar
 
Join Date: Mar 2003
Location: mostly Williamsburg....occassionaly the rest of the several state region.
Posts: 8,909
Re: RedsZone Malware Attack Discussion

Quote:
Originally Posted by Boss-Hog View Post
Anyone else having this? I think this rules out the ads as the root cause.
first time i've posted in God-knows-when, and i had a worm alert pop on my Norton anti-virus on the Stubbs as #8 hitter thread i posted.
__________________
the store for all your blade, costuming (in any regard), leather (also in any regard), and steel craft needs.www.facebook.com/tdhshop


yes, this really is how we make our living.
Ravenlord is offline   Reply With Quote
Turn Off Ads?
Old 01-19-2012, 06:44 AM   #137
Boss-Hog
Administrator
 
Boss-Hog's Avatar
 
Join Date: Apr 2000
Location: Cincinnati, OH
Posts: 6,007
Re: RedsZone Malware Attack Discussion

All,

We need URLs from the site where the attacks are coming from; otherwise, there's nothing to connect the two. Thanks for your help.
Boss-Hog is online now   Reply With Quote
Old 01-19-2012, 11:05 AM   #138
Boss-Hog
Administrator
 
Boss-Hog's Avatar
 
Join Date: Apr 2000
Location: Cincinnati, OH
Posts: 6,007
Re: RedsZone Malware Attack Discussion

Quote:
Originally Posted by Ravenlord View Post
first time i've posted in God-knows-when, and i had a worm alert pop on my Norton anti-virus on the Stubbs as #8 hitter thread i posted.
Ravenlord, here's what our host had to say about this - if you (or anyone else affected) could supply the bolded information, we would greatly appreciate it. Thanks in advance.

Quote:
Hello,

I have checked the server in detail. I could find that the URL "http://www.redszone.com/forums/showthread.php?t=93571" is being served by accessing the database.

I have checked the tables corresponding to the thread 93571. But I could not find any attachments or suspicious files that are linked to it. Please see the corresponding table pasted below.

--
mysql> select * from thread where threadid=93571;
+----------+---------------------------------------+------------+---------+--------+------+------------+--------------+------------+------------+------------+------------+-------+--------+-------+---------+--------+---------+-----------+--------+-------------+-------------+-----------------------------------+----------+----------+-------------+--------------+------------+--------+----------+----------------+
| threadid | title | lastpost | forumid | pollid | open | replycount | postusername | postuserid | lastposter | dateline | lastedit | views | iconid | notes | visible | sticky | votenum | votetotal | attach | closereason | firstpostid | similar | rss_feed | rss_date | hiddencount | deletedcount | lastpostid |wrdate | prefixid | taglist |
+----------+---------------------------------------+------------+---------+--------+------+------------+--------------+------------+------------+------------+------------+-------+--------+-------+---------+--------+---------+-----------+--------+-------------+-------------+-----------------------------------+----------+----------+-------------+--------------+------------+--------+----------+----------------+
| 93571 | Drew Stubbs is the perfect #8 hitter. | 1326948915 | 7 | 0 | 1 | 17 | WebScorpion | 28 | Ravenlord | 1326849525 | 1326860498 | 749 | 0 | | 1 | 0 | 0 | 0 | 0 | | 2526149 | 87133, 80390, 68946, 78719, 48675 | 0 | | 0 | 0 | 2526762 | | | lineup, stubbs |
+----------+---------------------------------------+------------+---------+--------+------+------------+--------------+------------+------------+------------+------------+-------+--------+-------+---------+--------+---------+-----------+--------+-------------+-------------+-----------------------------------+----------+----------+-------------+--------------+------------+--------+----------+----------------+
--

But I am still not sure about some of the values in the table. Can you please get back to us with the details of the malware that was detected by the antivirus ? This data would be available with the detection report of the antivirus.
Also please discuss this issue with a database programmer as the issue goes deeper in to the codes, we are facing more limitations.

Thank you for the understanding.
Boss-Hog is online now   Reply With Quote
Old 01-20-2012, 05:28 PM   #139
TRF
Vavasor
 
TRF's Avatar
 
Join Date: Apr 2000
Location: Amarillo, TX
Posts: 12,677
Re: RedsZone Malware Attack Discussion

I have a fresh install of windows 7, running symantec anti virus and have had no issues whatsoever. all my antivirus is up to date.
__________________
"don't end up with a grandson with a dog collar."
TRF is online now   Reply With Quote
Old 01-21-2012, 12:31 AM   #140
Ravenlord
Into de Halls of Valhalla
 
Ravenlord's Avatar
 
Join Date: Mar 2003
Location: mostly Williamsburg....occassionaly the rest of the several state region.
Posts: 8,909
Re: RedsZone Malware Attack Discussion

info sent, hope it works.
__________________
the store for all your blade, costuming (in any regard), leather (also in any regard), and steel craft needs.www.facebook.com/tdhshop


yes, this really is how we make our living.
Ravenlord is offline   Reply With Quote
Old 01-21-2012, 10:17 AM   #141
Boss-Hog
Administrator
 
Boss-Hog's Avatar
 
Join Date: Apr 2000
Location: Cincinnati, OH
Posts: 6,007
Re: RedsZone Malware Attack Discussion

Quote:
Originally Posted by Ravenlord View Post
info sent, hope it works.
Who did you send it to?
Boss-Hog is online now   Reply With Quote
Old 01-21-2012, 06:16 PM   #142
jojo
Five Tool Fool
 
jojo's Avatar
 
Join Date: Nov 2006
Posts: 16,569
Re: RedsZone Malware Attack Discussion

I don't know if this is actually much help but this is what sophos just just flagged:

Virus/spyware 'Mal/Iframe-X' has been detected in "http://www.redszone.com/forums/clientscript/vbulletin_menu.php".
__________________
"This isn’t stats vs scouts - this is stats and scouts working together, building an organization that blends the best of both worlds. This is the blueprint for how a baseball organization should be run. And, whether the baseball men of the 20th century like it or not, this is where baseball is going."---Dave Cameron, U.S.S. Mariner
jojo is online now   Reply With Quote
Old 01-21-2012, 07:30 PM   #143
Boss-Hog
Administrator
 
Boss-Hog's Avatar
 
Join Date: Apr 2000
Location: Cincinnati, OH
Posts: 6,007
Quote:
Originally Posted by jojo View Post
I don't know if this is actually much help but this is what sophos just just flagged:

Virus/spyware 'Mal/Iframe-X' has been detected in "http://www.redszone.com/forums/clientscript/vbulletin_menu.php".
That helps...I will look into it.
Boss-Hog is online now   Reply With Quote
Old 01-21-2012, 09:02 PM   #144
Boss-Hog
Administrator
 
Boss-Hog's Avatar
 
Join Date: Apr 2000
Location: Cincinnati, OH
Posts: 6,007
Re: RedsZone Malware Attack Discussion

I've confirmed that was a malicious file and it has been removed. Please let me know if this continues, and if so, the URL(s).
Boss-Hog is online now   Reply With Quote
Old 01-23-2012, 10:44 PM   #145
BLEEDS
Member
 
Join Date: Feb 2007
Location: Omaha, NE
Posts: 2,128
Re: RedsZone Malware Attack Discussion

I had one about a month ago - trojan got in and I have Windows 7 and McAfee - got the one where it takes over all your IE pages and asks you to install "Win7 security" or something, nasty little bugger.

Had to call McAfee and get it scrubbed, and they updated their database. Yikes.

Definitely had to do with ads. Ah well, yet another reason to pay the site fee - I figure I've broken even, given that I hadn't posted in awhile ;-)!

PEACE
-BLEEDS
__________________
I think that in a year or two, one of these guys - Frazier, Dorn, Valaika, Cumberland, Stubbs - will be ready to replace Dunn. They won't hit as many home runs as Dunn, but they should have similar OPS. - 757690, July 22, 2008

Alonso will be playing 1B for the REDS and batting 4th one year from today. - Kingspoint, July 9, 2009
BLEEDS is online now   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:56 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

Board Moderators may, at their discretion and judgment, delete and/or edit any messages that violate any of the following guidelines: 1. Explicit references to alleged illegal or unlawful acts. 2. Graphic sexual descriptions. 3. Racial or ethnic slurs. 4. Use of edgy language (including masked profanity). 5. Direct personal attacks, flames, fights, trolling, baiting, name-calling, general nuisance, excessive player criticism or anything along those lines. 6. Posting spam. 7. Each person may have only one user account. It is fine to be critical here - that's what this board is for. But let's not beat a subject or a player to death, please.

Thank you, and most importantly, enjoy yourselves!

RedsZone.com is a privately owned website and is not affiliated with the Cincinnati Reds or Major League Baseball

Contact us: Boss | GIK | dabvu2498 | GADawg | Gallen5862 | LexRedsFan | mattfeet | MBZags | Plus Plus | redsfan1995 | The Operator | Tommyjohn25