Page 1 of 1

Site infected?

Posted: Sat Sep 06, 2008 7:00 pm
by Alanthus
Getting "Remote Data Services Data Control" activeX message on front page of warcraftrealms, in my experience this suggests malicious content.

Posted: Sat Sep 06, 2008 9:40 pm
by zekzor
I too am getting that. Becoming very worried about visiting here any more :(

Posted: Sun Sep 07, 2008 4:52 pm
by Rollie
It's the forums. I located the offender, looking into how it happened now.

Posted: Mon Sep 08, 2008 12:48 pm
by xpolockx
Rollie to the rescue!

Posted: Mon Sep 08, 2008 7:34 pm
by Rollie
I eliminated the problem, went ahead and changed all passwords. I can't help but wonder if it's not a phpbb security hole. I went through all my log files and did not find any suspicious activity.

Unfortunately it is impossible to know exactly how it happened without intensive SQL logging, which just isn't feasible. I can rack up a 1gig log file in less than 24 hours =x

Posted: Wed Sep 10, 2008 2:13 pm
by DM.
zekzor wrote:I too am getting that. Becoming very worried about visiting here any more :(
Popular sites just like warcraftrealms.com can be targets for attacks, we've seen it many times with keyloggers in ads at Thottbot and other Zam.com sites, and even the popular Wowace Updater program had keyloggers in their ads at sometime. Rollie is always on top of things and does his best to make it very secure and safe for everyone who visits.