SydLexia.com Forum Index
"Stay awhile. Stay... FOREVER!"

  [Edit Profile]  [Search]  [Memberlist]  [Usergroups]  [FAQ]  [Register]
[Who's Online]  [Log in to check your private messages]  [Log in]
Need help checking the site!


Reply to topic
Author Message
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 09 2009 04:02 pm Reply with quote Back to top

So the site's primary FTP account, which contains Haddox, the Wiki, the main site, GAR, Lemon Party, Live Snake Insertions, and a few other random subdomains was hacked last night. Someone injected a script redirect to fake virus scan (scanner-free.com) into the main pages of all subdomains on the FTP, as well as many popular pages on the main site.

This is the second time this has happened. Last time, only index.htm and index.php pages were target.

To help prevent this from I have moved all the non-updating subdomains to other FTP accounts, and changed all my FTP passwords.

However, I still need help. Last time this happened, it was easy to find all the modified pages. I simply went into the FTP, and looked for pages that had been modified in the last few hours, and changed them back. This time, it's not that simple. Whatever they did, they did it in such a way that the pages don't show up as being recently modified. So I am not sure I got every page. Also, my full back-up of the site is 6 months old, so simply copying over the site isn't an option either.

All the main articles are fixed. However, I may have missed some pages. My site structure is a fucking mess. I have some random subpages hidden away in image folders for the articles they accompanied and pages made to go with the news section are all in a giant folder called /blogstuff alomg with a shitload of images.

If any of you have some free time, please go through the articles (making sure you allow pop-ups for this site) and click every link within them. With a few exceptions, they should all bring up either internal images or internal pages. If they bring up a fake virus scan, I need to fix it.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
Rydog
Title: Dragon Slayer
Joined: Aug 11 2009
Location: Massachusetts
PostPosted: Nov 09 2009 04:14 pm Reply with quote Back to top

Fuck that explains it. I thought it was my computer. I just ran all my checks and it was okay after that so you must have been fixing it at the same time.

I'll run through a few items.

EDIT: Syd Lexia on Revolution X through Poison Your Mind seem clean.
View user's profileSend private messageSend e-mail
username
Title: owner of a lonely heart
Joined: Jul 06 2007
Location: phoenix, az usa
PostPosted: Nov 09 2009 04:30 pm Reply with quote Back to top

i got the same thing this morning when i went to the main page (sydlexia.com) but i thought it was just chrome being stupid.

ill check after work


Klimbatize wrote:
I'll eat a turkey sandwich while blowing my load

 
View user's profileSend private messageAIM AddressYahoo MessengerMSN Messenger
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 09 2009 04:34 pm Reply with quote Back to top

I thought the same thing this morning, that it was a problem with my computer. Wasted 90 minutes on a virus scan, then realized the truth.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
IceWarm
Joined: Dec 22 2008
Location: Breckenridge, Colorado
PostPosted: Nov 09 2009 04:41 pm Reply with quote Back to top

I thought it was on my end too. I got up to go to work and wanted to check some sites and the main page was blocked by Firefox as an attack site. I ran a spywware scanner and nothing came up.


"Anybody who ever built an empire, or changed the world, sat where you are now. And it’s because they sat there that they were able to do it."

"Fighting in a basement offers a lot of difficulties, number one being, you're fighting in a basement."

"You're Not So Tough Without Your Veggie!"
 
View user's profileSend private messageVisit poster's website
Slayer1
Title: ,,!,, for you know who
Joined: Sep 23 2008
PostPosted: Nov 09 2009 05:10 pm Reply with quote Back to top

Same thing happened to me as well. AVG Suspected it was threat so I had to goto the forums link from a saved BM...

Well I checked all the articles and the links inside each of the first page from AYAOTD part six to mega man 3 and they appear to be fine
View user's profileSend private message
username
Title: owner of a lonely heart
Joined: Jul 06 2007
Location: phoenix, az usa
PostPosted: Nov 09 2009 07:42 pm Reply with quote Back to top

Slayer1 wrote:
Same thing happened to me as well. AVG Suspected it was threat so I had to goto the forums link from a saved BM...

Well I checked all the articles and the links inside each of the first page from AYAOTD part six to mega man 3 and they appear to be fine

i had to google 'sydlexia forums' in order to access those


Klimbatize wrote:
I'll eat a turkey sandwich while blowing my load

 
View user's profileSend private messageAIM AddressYahoo MessengerMSN Messenger
Slayer1
Title: ,,!,, for you know who
Joined: Sep 23 2008
PostPosted: Nov 09 2009 08:37 pm Reply with quote Back to top

From Alex Kid to Legend of Zelda seems to be all clear...
View user's profileSend private message
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Nov 09 2009 10:54 pm Reply with quote Back to top

The maniac mansion article seems fine
View user's profileSend private message
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 09 2009 10:57 pm Reply with quote Back to top

I believe we are in the clear.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Nov 09 2009 11:12 pm Reply with quote Back to top

Syd,

Dreamhost has SFTP or FTPS right?

Time to start looking at a more secure option for uploading/editing.



 
View user's profileSend private messageVisit poster's website
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 09 2009 11:16 pm Reply with quote Back to top

No idea what those are, but probably.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Nov 09 2009 11:21 pm Reply with quote Back to top

Syd Lexia wrote:
No idea what those are, but probably.

It lets you transfer files with an encrypted connection.



 
View user's profileSend private messageVisit poster's website
Blackout
Title: Captain Oblivious
Joined: Sep 01 2007
Location: That Rainy State
PostPosted: Nov 09 2009 11:55 pm Reply with quote Back to top

Is there any way to get back at the culprit?



 
View user's profileSend private messageAIM AddressYahoo MessengerMSN Messenger
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 10 2009 12:06 am Reply with quote Back to top

I don't know.

The site was redirected to scanner-free.com, so they're the ones in need of punishment.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
Slayer1
Title: ,,!,, for you know who
Joined: Sep 23 2008
PostPosted: Nov 18 2009 08:59 pm Reply with quote Back to top

I don't know if this is relevent, but the comparison between NA Monster Party and Japan's Monster Party doesn't load
View user's profileSend private message
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Nov 30 2009 08:59 pm Reply with quote Back to top

Slayer1 wrote:
I don't know if this is relevent, but the comparison between NA Monster Party and Japan's Monster Party doesn't load

The page that originally had the screenshots is apparently dead: http://dbz.icequake.net/share/afs/pub/emu/nesnew/64.53.95.207/ujap/mp/mp.html

Luckily, I saved them to my hard drive. I have replaced the old link with this: http://www.sydlexia.com/monsterpartyjapan.htm
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
Display posts from previous:      
Reply to topic

 
 Jump to: