Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 3 1 2 3 >
Topic Options
#247384 - 12/22/11 11:29 AM JS/IFrame.AS trojan found in ubbthreads.php
DennyP Offline
member
Registered: 04/12/04
Posts: 154
Loc: Phoenix, AZ
A user reported the above message generated by their corporate security system. I am running 7.5.3.

The security system is ESET NOD32 V4 Business Edition.


Edited by DennyP (12/22/11 11:39 AM)
_________________________
DennyP - www.dennyp.com
DennyP Travel
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#247385 - 12/22/11 11:55 AM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
driv Offline

Pooh-Bah
Registered: 01/10/04
Posts: 2377
Just before my browser crashed, I got this alert...


Attachments
alert.jpg (73 downloads)

_________________________
Using version :: 7.5.6
Top
#247387 - 12/22/11 01:56 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Yep. corporate firewalls are tough to deal with.
You never know what they have instituted.
I deal with them all of the time.
Most times with no success.

But anyway for starters v7.5.3 has been patched with a security update which it appears you are not using.
So even if you upgrade right now. it will not correct prior hacking to your board, if that is the case.
_________________________
Blue Man Group
Top
#247389 - 12/22/11 02:20 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
If you where hacked you'll need to patch your forums, make sure you're using stock files (and that they haven't been altered by a hacker), and make sure your webspace doesn't have malicious files lingering around which would allow a remote hacker to continue compromising your system.

I actually just did a cleanup of a really nasty hack last week, they aren't pretty and you as the owner are really responsible for hosting these files; after a while Google and antivirus people will start flagging your site as malicious and users will start getting warnings about your site hosting malicious content if you allow it to just sit there.

You should look into either hiring someone to fix your site, or if you think you can do it yourself (which I highly advise against as with disaster recovery is easy to miss something) you'll need to use a utility like beyond compare to compare your forum files to that of the stock files and compare differences, then you'll need to use ssh and grep to look for any suspicious edits to files and you'll need to look at recently edited/new files on the server.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#247392 - 12/22/11 03:35 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
DennyP Offline
member
Registered: 04/12/04
Posts: 154
Loc: Phoenix, AZ
Which of the two initial messages in this topic does the above reference? It appears that "driv" hijacked my topic with a different subject so I'm not sure to which one the comments refer.
_________________________
DennyP - www.dennyp.com
DennyP Travel
Top
#247393 - 12/22/11 03:47 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
I have no idea where Driv got his info for his post image.
You edited your post and where your error message came from is not displayed.
Possibly you had posted a url and he tested it.

I went by that the latest security patch addressed a very very serious security hole. Where someone could edit your scripts.
In fact it delayed progress on the next version release.
Not so much the patch itself but finding the actual hack in the scripts before the patch.

So if you are getting nagged with security risks then that could possibly be the culprit.
_________________________
Blue Man Group
Top
#247394 - 12/22/11 03:48 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
SD Offline
Registered: 04/19/07
Posts: 4056
Loc: SoCal, USA
driv reported what his browser said, when he went to your site, so he didn't hijaack it

he was confirming that you prolly have an issue with your board security.

then we get to Giz who noticed that you aren't patched and his reply.

sooo.. the thread is still about your initial post wink

but maybe i'm wrong too laugh
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#247395 - 12/22/11 03:54 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
DennyP Offline
member
Registered: 04/12/04
Posts: 154
Loc: Phoenix, AZ
I see thanks. I thought driv was just posting something they got someplace on their system.

When I go to the download area I see the full version files and I see the patch files. Which do I need? Thanks.
_________________________
DennyP - www.dennyp.com
DennyP Travel
Top
#247397 - 12/22/11 03:59 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
Since your running 7.5.3 you need to full version to upgrade to 7.5.6. The patch is if you were running 7.5.6 already
Top
#247398 - 12/22/11 04:03 PM Re: JS/IFrame.AS trojan found in ubbthreads.php [Re: DennyP]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Well it is suggested to upgrade. there is a security patch for your version in the right side of the member area.
But if you were hacked already. The patch will only stop future attacks not repair past issues.
_________________________
Blue Man Group
Top
Page 1 of 3 1 2 3 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image