Author Topic: [solved] Forum Infected With Malware  (Read 12841 times)

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« on: February 24, 2016, 11:33:31 am »
Hi,

this is a long standing issue here, but so far no-one has ever fixed it.  

Every time I try to access the forum, the first time it always redirects to a malicious website (url123.info). When I reload the page, it correctly redirects me to the forum.

This seems to be the issue (thanks Tomoe for the hint):

https://revisium.com/en/kbe/infected_ipb_and_vbulletin.html

I hope that the DB (with the usernames/passwords) hasn't been compromised too

Varti
« Last Edit: April 18, 2017, 08:29:42 pm by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #1 on: March 21, 2016, 09:17:42 am »
I have now sent a PM to InSearchOf, he seems to still come here from time to time. I wonder if he's the only remaining admin here or if there are others who are still active...

Varti
« Last Edit: April 18, 2017, 08:26:17 pm by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

sdjf

  • Sr. Member
  • ****
  • Posts: 447
    • View Profile
    • http://www.sdjf.wordpress.com and http://www.sdjf.esmartdesign.com
[solved] Forum Infected With Malware
« Reply #2 on: September 28, 2016, 11:28:09 pm »
I wonder if the malware had anything to do with triggering the last 6 months or so of outage?

Looking at his profile, it looks like InSearchOf has not been here (at this point) since July 2015.  Several moderators have privatized the dates of their last visits, so it is hard to say if there are any active moderators at all!
http://www.sdjf.esmartdesign.com
http://www.sdjf.wordpress.com
-----------------
sl5500 running Sharp ROM 2.38 (dead batteries)
sl6000L running Sharp ROM 1.12 (still working)
Opera 7.25 and 7.30
Socket CF 56k modem
3Com USB Ethernet Adapter
Toshiba, Lexar and Kingston SD cards
Lexar, Kingston and Transcend CF cards

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #3 on: September 29, 2016, 04:57:00 am »
Quote from: sdjf
I wonder if the malware had anything to do with triggering the last 6 months or so of outage?
No idea. The malware was anyway here since at least a couple of years, I believe it might have been some server update on the host which might have required to fix the configuration files of the forum. I'm anyway glad that the malware has been removed, there's no redirection anymore when opening www.oesf.org, just a blank page is opened. IMHO it would be better that it would link to the main OESF page, or redirect to www.oesf.org/forum.

Quote
Looking at his profile, it looks like InSearchOf has not been here (at this point) since July 2015.  Several moderators have privatized the dates of their last visits, so it is hard to say if there are any active moderators at all!
I guess that the moderators' list requires a cleanup and new moderators should be found, among the users who are more active lately here.

Varti
« Last Edit: April 18, 2017, 08:26:03 pm by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #4 on: September 29, 2016, 05:11:14 am »
Hi,

the main page redirection malware has been thankfully removed, but there are still at least two present, you can see them by searching oesf.org with Google:

- one adds the following text to each found page on Google, and it seems there's a link hidden there redirecting to a phishing site: "Call of Duty: Black Ops 3" and "Call of Duty: Black Ops 3 is my most anticipated title of the year. Developer Treyarch and publisher Activision recently let players across the globe beta test some..."

https://www.google.com/search?q=site%3Awww....-8&oe=utf-8


- it seems that www.oesf.org/images/diag contains lots of harmful php scripts (e.g. sitemap51.php, sitemap92.php, art-924073.php...), with text in cyrillic (in russian?):

https://www.google.it/search?q=%22Call+of+D...te:www.oesf.org


Varti
« Last Edit: April 18, 2017, 08:25:51 pm by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

sdjf

  • Sr. Member
  • ****
  • Posts: 447
    • View Profile
    • http://www.sdjf.wordpress.com and http://www.sdjf.esmartdesign.com
[solved] Forum Infected With Malware
« Reply #5 on: September 29, 2016, 11:26:50 am »
Those pages are not in the forum, whose working url is https://www.oesf.org/forum, they are in the home page link https://www.oesf.org.

In a browser, I cannot even get to https://www.oesf.org, only the forum when I go directly.

The google search of oesf.org (not forum) turns up the feed, which is alive and well (yay!), and a bunch of pages which should get removed if they are still there, but who can do that?

 https://www.google.com/search?q=site%3Awww....amp;btnG=Search

The only place in the forum where "call of duty" now appears is in one user's profile, as far as I can tell???

Okay, I see those pages are still on the web, and accessible via google, although not in the forum itself.  Is offroadgeek the only person now with admin rights?  I PM'd speculatrix (or emailed, I forget which) to see if he is still reachable, although not about the malware.

sdjf
« Last Edit: September 29, 2016, 11:30:36 am by sdjf »
http://www.sdjf.esmartdesign.com
http://www.sdjf.wordpress.com
-----------------
sl5500 running Sharp ROM 2.38 (dead batteries)
sl6000L running Sharp ROM 1.12 (still working)
Opera 7.25 and 7.30
Socket CF 56k modem
3Com USB Ethernet Adapter
Toshiba, Lexar and Kingston SD cards
Lexar, Kingston and Transcend CF cards

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #6 on: September 29, 2016, 12:11:44 pm »
Well, it has happened once, with one of the search results with the "Call of Duty" tag, that I was redirected on a phishing site instead of the forum's thread, so I believe that this malware can be harmful when searching the forum via Google (I do that sometimes).

Varti
« Last Edit: April 18, 2017, 08:25:36 pm by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

sdjf

  • Sr. Member
  • ****
  • Posts: 447
    • View Profile
    • http://www.sdjf.wordpress.com and http://www.sdjf.esmartdesign.com
[solved] Forum Infected With Malware
« Reply #7 on: September 30, 2016, 10:54:32 am »
Quote from: Varti
Well, it has happened once, with one of the search results with the "Call of Duty" tag, that I was redirected on a phishing site instead of the forum's thread, so I believe that this malware can be harmful when searching the forum via Google (I do that sometimes).

Varti

I see what you mean, they are in the oesf domain although not in the forum itself.  But, who has admin rights who can remove those pages?  Do moderators or does it have to be someone at a higher level?
« Last Edit: April 18, 2017, 08:25:22 pm by Varti »
http://www.sdjf.esmartdesign.com
http://www.sdjf.wordpress.com
-----------------
sl5500 running Sharp ROM 2.38 (dead batteries)
sl6000L running Sharp ROM 1.12 (still working)
Opera 7.25 and 7.30
Socket CF 56k modem
3Com USB Ethernet Adapter
Toshiba, Lexar and Kingston SD cards
Lexar, Kingston and Transcend CF cards

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #8 on: September 30, 2016, 11:21:56 am »
Quote from: sdjf
Quote from: Varti
Well, it has happened once, with one of the search results with the "Call of Duty" tag, that I was redirected on a phishing site instead of the forum's thread, so I believe that this malware can be harmful when searching the forum via Google (I do that sometimes).

Varti

I see what you mean, they are in the oesf domain although not in the forum itself.  But, who has admin rights who can remove those pages?  Do moderators or does it have to be someone at a higher level?
EDIT: I have talked with speculatrix about the matter, unfortunately neither moderators nor admins (like him) have access to the file structure, except offroadgeek.

Varti
« Last Edit: April 19, 2017, 03:01:07 am by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #9 on: April 18, 2017, 08:23:53 pm »
(Note: I have merged the two "malware" threads, since this post will answer both of them).

It has taken quite some time and effort, but at last I can now announce that I have removed all the malware which was pestering the forum all these years, or at least I have not managed to find any more of them.

I have registered the forum on the Google Search Console, and asked them for a security review. They have now answered me that the review has been successful and that no more malware have been found, they will now remove all the security warnings related to the forum. I have also activated all the available security options in the admin's control panel, although we'll need to switch to a newer CMS to be safer from similar attacks in the future.

For those curious to know what type of malware was infecting the board:

- by searching for the "Call of Duty" text in a dump of the database, I have found that it was injected in the Borderline-Blue skin, which is an alternative skin to the default one we use here. For some reason, Google cached all the pages using this skin, and sometimes a redirection URL was triggered when opening a page from a Google search. Google will probably still keep the cached pages with the injected text for some months, as it doesn't refresh them often, but at least all the pages which will be cached from now on will not have that text anymore.

- the images/diag directory was full of harmful scripts; the images directory is actually part of the (still offline, I'm working on that) Wiki, so all those files have been added though the Wiki, rather than the forum. The owner of all the files was "apache" and not the OESF shell's account user, since the were added via the HTTP protocol, and only that "user" (and ibiblio's root) could remove them or change the permissions. I solved the problem by temporarily installing a PHP web file manager with an internal web shell, and by manually removing the files using that shell. There was also a malware file called wso2.php inside images/thumb which has been removed, too.

- when searching for write-protected files (i.e. set as 700 and similar), I found out that the lang_global.php and lang_javascript.js files in the forum's cache had the malicious code described here: https://peter.upfold.org.uk/blog/2013/01/15...url4short-mess/

I'll check Google's Search Console in the future for any security issue, since the admin's board is unfortunately unable to detect such threats.

Varti
« Last Edit: April 19, 2017, 03:54:17 am by Varti »
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

HoloVector

  • Hero Member
  • *****
  • Posts: 533
    • View Profile
    • http://
[solved] Forum Infected With Malware
« Reply #10 on: April 19, 2017, 07:17:06 pm »
Thanks for all your hard work on this.  I can't wait to have wiki back.
I think I'm coming down with what kahm's got!  I now have 3 Zaurii in house!  ;)
Current: Zaurus SL-C3200 -  Bobby (Configuring pdaXii13 Akita with Full 5.4.9 upgrade running IceWM)
Zaurus SL-C1000 - Hachiko (Configuring Cacko 1.23 with evilJazz's new kernel)
Zaurus SL-C860 - Fett (Customized Cacko 1.23 with handmade Boba Fett Theme)
Symbol WiFi CF card|Buffalo WiFi CF Card|Buffalo Ethernet CF Card|Red Piel Frama Case|PDAir Case|Black Pelican 1020 Case|Pentopia Stylii|SaruTek Protectors|Transcend SDs (4GB 150X, 1GB 80X, 256MB 45X, 128MB 45X)|2GB PNY SD|2GB SanDisk SD|Transcend CFs (1GB 80X, 512MB 80X)|Sandisk CFs (4GB, 512MB, 256MB)|256MB Netac USB-CF|RH-1 Remote
Check out the ScummVM@tyrannozaurus page if you are an "adventurer" type of person.

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #11 on: April 20, 2017, 10:08:10 am »
Quote from: HoloVector
Thanks for all your hard work on this.  I can't wait to have wiki back.
Regarding the MediaWiki upgrade, I'm currently stuck with the upgrade of the wiki database: the web updater script is showing me a blank page every time I run it, and unfortunately I can't use the command line version of the updater since the php shell command is disabled  I'll try to find out what's blocking the updater.

Varti
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!

koan

  • Sr. Member
  • ****
  • Posts: 370
    • View Profile
    • http://www.lyndonhill.com
[solved] Forum Infected With Malware
« Reply #12 on: May 07, 2017, 01:31:01 pm »
Good work on fixing the infection.

Perhaps you can download a copy of the wiki database and run the update script locally to work out what is going on ?
Zocalo Feed Reader : Thai on Zaurus : Dictionaries for zbedic : Sharp ROM package feed
HELUX Handheld Embedded Linux Blog
SL-C3200 Multiboot : SL-C750  Sharp ROM

speculatrix

  • Administrator
  • Hero Member
  • *****
  • Posts: 3709
    • View Profile
[solved] Forum Infected With Malware
« Reply #13 on: May 07, 2017, 04:34:14 pm »
nice work!
Gemini 4G/Wi-Fi owner, formerly zaurus C3100 and 860 owner; also owner of an HTC Doubleshot, a Zaurus-like phone.

Varti

  • Administrator
  • Hero Member
  • *****
  • Posts: 1295
    • View Profile
[solved] Forum Infected With Malware
« Reply #14 on: May 09, 2017, 05:00:46 am »
Quote from: koan
Perhaps you can download a copy of the wiki database and run the update script locally to work out what is going on ?
Good idea, I'll try that too, thanks for the hint!

Varti
Planet Gemini PDA WiFi/LTE with Mediatek x27
SL-C1000 running Arch Linux ARM May2017, K30225 Wi-Fi CF Card, 64GB SDXC card
and many other Zauruses!