Lazy Peon Tavern
https://forum.lazypeontavern.com/

The viruswarnings on the webpage
https://forum.lazypeontavern.com/viewtopic.php?t=2597
Page 1 of 2

Author:  Luria [ 21 Sep 2015, 17:23 ]
Post subject:  The viruswarnings on the webpage

Two weeks ago we had an issue with the forum where we kept getting strange php warnings on the forum and the layout of the forum kept looking strange. Saerdon posted this post.
Saerdon wrote:There is currently some sort of malicious "virus"-like script that keeps deleting the header in our wordpress-theme. Which is why all the layout and so on is gone at the moment. I'm keeping an eye on a fairly new thread on the wordpress forums about this to see if anyone figures out how to remove it completely.

I don't think there's been much malicious code infecting our computers or anything; from what I can tell the script tried to create a javascript that was supposed to do something, but the php-files that were overwritten were changed in such a way that they crashed before they actually reached that part in the code.
The next day I asked Milen (our website friend) to look at it as well, and he found some strange code that he deleted and then he put the forum back. Since then the forum appears to have been fixed. Instead there's been something weird with the webpage, where some people are getting warnings from their firewalls or antivirus-programs about our page. It appears to be the same script that has put malicious code both places.

Yesterday I asked Milen to look into it; and today he is saying:
"What the malware did was to inject malicious code into the webpage files. I have purged that code and in theory the site is now clean. If any warnings of malware is detected again, report it to Luria copying the whole message and also indicating, if possible, which files are infected so I can look at it, as the webpage consist of more of 10000 files."

So please post in this thread if you're getting warnings on the website again, or tell me in game; and we can try and get this sorted. :o

Author:  Saerdon [ 21 Sep 2015, 21:06 ]
Post subject:  Re: The viruswarnings on the webpage

In other news I also did a virus scan and removed some cached files that also contained traces of this yesterday evening.

Author:  Luria [ 21 Sep 2015, 21:59 ]
Post subject:  Re: The viruswarnings on the webpage

Yes i think i made you both double work then :o Probably both of you did the same thing at the same time :o Sorry!

Author:  Luria [ 21 Sep 2015, 22:29 ]
Post subject:  Re: The viruswarnings on the webpage

Or did you find more stuff after Milen took stuff away? I will make him talk to you about it so you can check if you did different things and like learn from eachother :o

Edit: Nvm, i asked Milen and he said you did different things. :o

Author:  Saerdon [ 22 Sep 2015, 07:03 ]
Post subject:  Re: The viruswarnings on the webpage

Luria wrote:Nvm, i asked Milen and he said you did different things. :o
I did the copypaste thing that Daeryn said you suggested 8)

Actually I removed quite a few themes that were also infected because we're not using them anyway, which should hopefully make it less of a hassle if this security hole hasn't been fixed yet.

Author:  Begemmot [ 22 Sep 2015, 08:02 ]
Post subject:  Re: The viruswarnings on the webpage

Since yesterday my Norton-protection quite happy again :)
The website doesn't get blocked and I don't get any warnings.

Author:  Rattie [ 27 Sep 2015, 12:51 ]
Post subject:  Re: The viruswarnings on the webpage

I just received the "This is an attack page" warning for the first time, I've had no bother up to now :o

Author:  Begemmot [ 27 Sep 2015, 15:10 ]
Post subject:  Re: The viruswarnings on the webpage

Got it too since yesturday

Author:  Rvp [ 27 Sep 2015, 15:58 ]
Post subject:  Re: The viruswarnings on the webpage

Same as Tassle, got it for the first time earlier today. But it seems to have disappeared now.

Author:  Milen [ 27 Sep 2015, 17:09 ]
Post subject:  Re: Site updates and requests

Hi,

If you tried to log into any of the webpages under the lazypeontavern.com domain (homepage, forum, lootlist, etc) you might have notice a warning. The same malware as we had a few weeks ago, has infected again the files. This time Google safescan detected this issue and put the webpage in its blacklist.

Saerdon and I have worked today to clean up the site and install some features to prevent this happening again. Once we were done, we reported Google to review our page and we passed it. So the webpage is back fully operational, clean and removed from the blacklist of Google.

Google also provided information about other sites in the same network as ours. It seems a lot of this sites have been infected as well. We will study the posibility of moving the site from this network in case we are affected again.

If you want to know more about what is happening to our webpage, you can read up in this link for more details.

Page 1 of 2 All times are UTC+01:00
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/