Announcement

Collapse
No announcement yet.

And the trojan/virus infection story continues...

Collapse
X
Collapse
Who has read this thread:
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • And the trojan/virus infection story continues...

    One of our new members mentioned when they click on the Weekly Cruise Night Locator link that it takes them to an antivirus link. Sure enough, it did it to me too!

    Then, while researching what would cause this, I noticed that the people talking about it were talking about Google redirecting them to the malware site when they clicked legitimate search results.

    So, I went to Google and searched our site, clicked the link -- SON OF A *****! Got redirected to the malware site.

    Needless to say, I figured it out and all should be back to normal. It also explains why our bandwidth usage has plummetted the past few months -- ever since April 11th when the site got hacked they must have had that file on there that was redirecting to the malware site.
    - Brian Meissen
    Owner, MiFBody.com
    Administrator, LTxTech.com


    1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
    2022 Camaro LT1 - "Cherry Bomb 2"
    Michigan FBody Meet & Greet Car Show 2022
    June 4th, 2022 - 9am to 3pm!!!
    The HUB Stadium, Auburn Hills, MI

  • #2
    Good job!

    Comment


    • #3
      for B!!!!
      Gone but not forgotten: 1986 Chevrolet Camaro IROC-Z

      "You shall ride eternal. Shiny and chrome."

      Comment


      • #4
        Wow thats pretty dirty!

        Glad your figuring this out!

        Originally posted by meissen View Post
        One of our new members mentioned when they click on the Weekly Cruise Night Locator link that it takes them to an antivirus link. Sure enough, it did it to me too!

        Then, while researching what would cause this, I noticed that the people talking about it were talking about Google redirecting them to the malware site when they clicked legitimate search results.

        So, I went to Google and searched our site, clicked the link -- SON OF A *****! Got redirected to the malware site.

        Needless to say, I figured it out and all should be back to normal. It also explains why our bandwidth usage has plummetted the past few months -- ever since April 11th when the site got hacked they must have had that file on there that was redirecting to the malware site.

        Comment


        • #5
          For B



          VicePresident of West Michigan Firebird Club
          A.K.A The Maverick
          http://www.cardomain.com/ride/660128/1
          93 TA Currently Under Construction AGAIN
          2007 2500 Chevy Silverado Crew Cab w/ 6.0L & 3.73's

          Comment


          • #6
            Originally posted by BlackbirdWs6zzz View Post
            Wow thats pretty dirty!

            Glad your figuring this out!
            Yeah it was -- they had it set up so that every time someone clicked a link to MiFbody from a search engine, they'd get redirected to the malware site. They also had it set up so all 404's redirected to the malware site.

            Needless to say, I'm going to purchase a new server tonight and start transferring over files to a better machine.
            - Brian Meissen
            Owner, MiFBody.com
            Administrator, LTxTech.com


            1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
            2022 Camaro LT1 - "Cherry Bomb 2"
            Michigan FBody Meet & Greet Car Show 2022
            June 4th, 2022 - 9am to 3pm!!!
            The HUB Stadium, Auburn Hills, MI

            Comment


            • #7
              Oh wow. I can't believe the even cracked your password for your server. And it's not even like they got in thru an application on the board either.

              Thats like grabbing you by the BALLS. New server is costly isn't it??

              Originally posted by meissen View Post
              Yeah it was -- they had it set up so that every time someone clicked a link to MiFbody from a search engine, they'd get redirected to the malware site. They also had it set up so all 404's redirected to the malware site.

              Needless to say, I'm going to purchase a new server tonight and start transferring over files to a better machine.

              Comment


              • #8
                Originally posted by BlackbirdWs6zzz View Post
                Oh wow. I can't believe the even cracked your password for your server. And it's not even like they got in thru an application on the board either.

                Thats like grabbing you by the BALLS. New server is costly isn't it??
                Still trying to figure out exactly how they made it in, but with it being back in April it's hard to tell for sure. On 4/11, I got an e-mail that someone gained root access, but the hostname and IP address was blank -- and I've always seen it filled in when I or my server management team does an SSH into the server, so that right there should've been my red flag but I disregarded it.

                Once they had SSH access, they could do whatever they wanted.

                As for the new server -- yeah, it's a little more expensive... in comparison to what I'm paying now, it's only $15 more per month.... but it's also one sweet combo. Core2Quad, 8gb DDR, 750gb SATA hdd... No messing around.
                - Brian Meissen
                Owner, MiFBody.com
                Administrator, LTxTech.com


                1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                2022 Camaro LT1 - "Cherry Bomb 2"
                Michigan FBody Meet & Greet Car Show 2022
                June 4th, 2022 - 9am to 3pm!!!
                The HUB Stadium, Auburn Hills, MI

                Comment


                • #9
                  $15 more a month is pretty pricey, make sure you raise the donation goal on the main page to cover it. I noticed it hasn't been very full lately, we need to get our act together to help pay for this awesome site!
                  1999 Camaro - 6 liters of fury.....

                  Comment


                  • #10
                    Originally posted by sman View Post
                    $15 more a month is pretty pricey, make sure you raise the donation goal on the main page to cover it. I noticed it hasn't been very full lately, we need to get our act together to help pay for this awesome site!
                    I pay $120 right now for a dual core 2.2ghz with 2gb of ram, so $135 for quad core 2.8ghz with 8gb ram is a steal. It's actually normally $175 per month but on sale locked at $135 if you sign up while it's on sale.
                    - Brian Meissen
                    Owner, MiFBody.com
                    Administrator, LTxTech.com


                    1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                    2022 Camaro LT1 - "Cherry Bomb 2"
                    Michigan FBody Meet & Greet Car Show 2022
                    June 4th, 2022 - 9am to 3pm!!!
                    The HUB Stadium, Auburn Hills, MI

                    Comment


                    • #11
                      Those are great prices for a server! What hosting company you go thru?

                      Comment


                      • #12
                        I go through whatever I find on webhostingtalk.com This one is Limespot I think it's called.
                        - Brian Meissen
                        Owner, MiFBody.com
                        Administrator, LTxTech.com


                        1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                        2022 Camaro LT1 - "Cherry Bomb 2"
                        Michigan FBody Meet & Greet Car Show 2022
                        June 4th, 2022 - 9am to 3pm!!!
                        The HUB Stadium, Auburn Hills, MI

                        Comment


                        • #13
                          Limestonenetworks.com The Quad Core Q9300 with 8gb of ram (what I bought) is the fastest server they have
                          - Brian Meissen
                          Owner, MiFBody.com
                          Administrator, LTxTech.com


                          1994 Camaro LT1 Transplant - 357ci LT1, cammed, stalled, and driven.
                          2022 Camaro LT1 - "Cherry Bomb 2"
                          Michigan FBody Meet & Greet Car Show 2022
                          June 4th, 2022 - 9am to 3pm!!!
                          The HUB Stadium, Auburn Hills, MI

                          Comment


                          • #14
                            Dude, that's a bad ass server.

                            Still not like dual quad-core Xeons, but still, it's pretty damn good! It'll be just fine for what you'll use it for.

                            Gone but not forgotten: 1986 Chevrolet Camaro IROC-Z

                            "You shall ride eternal. Shiny and chrome."

                            Comment

                            Working...
                            X