We were hacked overnight
Moderator: Moderators
-
The Robman
- Site Owner
- Posts: 22031
- Joined: Fri Aug 01, 2003 9:37 am
- Location: Chicago, IL
- Contact:
We were hacked overnight
So some of you might have had your Spam Blocker software get tripped earlier when the forum tried to re-direct you somewhere else, but I have fixed it now. Hopefully I found all the places where they put their code.
Rob
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
-
vickyg2003
- Site Admin
- Posts: 7109
- Joined: Sat Mar 20, 2004 12:19 pm
- Location: Florida
- Contact:
Thanks for fixing this Rob, the sight that they sent me to was a little frightening.
I wish the hacker/spammers would just leave us alone!
I wish the hacker/spammers would just leave us alone!
Remember to provide feedback to let us know how the problem was solved and share your upgrades.
Tip: When creating an upgrade, always include ALL functions from the oem remote, even if you never plan on assigning them to a button. Complete function lists makes an upgrade more helpful to others.
Tip: When creating an upgrade, always include ALL functions from the oem remote, even if you never plan on assigning them to a button. Complete function lists makes an upgrade more helpful to others.
-
vickyg2003
- Site Admin
- Posts: 7109
- Joined: Sat Mar 20, 2004 12:19 pm
- Location: Florida
- Contact:
Re: We were hacked overnight
Actually my SPAM blocker didn't catch that since it wasn't an email. Though, the AVAST Web Shield blocked the site "www2.simplegjcleaner.rr.nu" due to the trojan named, "JS:FakeAV-HZ" on the page it was trying to connect.The Robman wrote:So some of you might have had your Spam Blocker software get tripped earlier when the forum tried to re-direct you somewhere else, but I have fixed it now. Hopefully I found all the places where they put their code.
Remotes; JP1.2: Comcast URC-1067, JP1.3: Insignia NS-RC02U-10A, JP1.4 OARI06G, JP2.1: Cox URC-8820-MOTO (still trying to figure out how to make them self-aware.)
-
vickyg2003
- Site Admin
- Posts: 7109
- Joined: Sat Mar 20, 2004 12:19 pm
- Location: Florida
- Contact:
Try Avast, I'm using the free version and once it detects the trojan it will block the destination link permanently allowing you to freely navigate through the wiki worry free.vickyg2003 wrote:They have hacked the wiki too. Can't get anywhere without seeing things I'd rather not see.
Remotes; JP1.2: Comcast URC-1067, JP1.3: Insignia NS-RC02U-10A, JP1.4 OARI06G, JP2.1: Cox URC-8820-MOTO (still trying to figure out how to make them self-aware.)
-
The Robman
- Site Owner
- Posts: 22031
- Joined: Fri Aug 01, 2003 9:37 am
- Location: Chicago, IL
- Contact:
I've spent all day cleaning the wiki and I've got most of the stuff out, but obviously not all of it because when I go to the wiki page, I see it reference sweepstakesandcontestsinfo.com which is part of the hacked code.
Rob
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
-
vickyg2003
- Site Admin
- Posts: 7109
- Joined: Sat Mar 20, 2004 12:19 pm
- Location: Florida
- Contact:
I am using Norton 360 version 5, which identified the hack and blocked my access to the JP1 site, telling me that it was trying to access Fake AV Website 24. Indeed, because of the time difference between here (UK) and the US, I discovered the hack while Rob was still asleep and drew his attention to it.
Whatever is left of the hack in the Wiki is still enough to activate Norton 360. I cannot access the Wiki link at all. I get the same message from Norton and the browser shows I have been redirected to:
http:/ /www3.bustdy.in/?v2d3atte=mqfNl56pqZyYm%2BPdyLapWNinzbGnlpmqqKaUrqdmmlc%3D
(I've put a space between the two /'s so that it doesn't show as a hyperlink) So some users, like me, will be unable to use the Wiki until it has been fully cleaned.
Whatever is left of the hack in the Wiki is still enough to activate Norton 360. I cannot access the Wiki link at all. I get the same message from Norton and the browser shows I have been redirected to:
http:/ /www3.bustdy.in/?v2d3atte=mqfNl56pqZyYm%2BPdyLapWNinzbGnlpmqqKaUrqdmmlc%3D
(I've put a space between the two /'s so that it doesn't show as a hyperlink) So some users, like me, will be unable to use the Wiki until it has been fully cleaned.
Graham
-
The Robman
- Site Owner
- Posts: 22031
- Joined: Fri Aug 01, 2003 9:37 am
- Location: Chicago, IL
- Contact:
Can you guys try the wiki now and tell me if it's working for you. I don't see the tell-tale sign of the hacker's URL anymore when I try it.
Rob
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!