dagsky

0
Registered
Joined
Aug 27, 2011
Messages
27
Just coming on to the forum and i'm greeted by this site is a malicious site!!! Someone messing about with the site? This message is recieved on firefox and google search......

From google

What is the current listing status for mattersofsize.com?

Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 1522 pages we tested on the site over the past 90 days, 28 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2012-04-03, and the last time suspicious content was found on this site was on 2012-04-02.

Malicious software includes 29 trojan(s), 29 exploit(s). Successful infection resulted in an average of 10 new process(es) on the target machine.

Malicious software is hosted on 1 domain(s), including 62.109.0.0/.

This site was hosted on 1 network(s) including AS36351 (SOFTLAYER).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, mattersofsize.com did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

How did this happen?

In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:

Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google WeBathmateaster Tools. More information about the review process is available in Google's WeBathmateaster Help Center.

If you need some help dld let me know....
 
I think DLD does need help as this happened before. Some nasty piece of work keeps attacking us and wants the site down so anyone here with technology background and can help us PLEASE pm someone like Maxameys, kooky or supra to sort this.
 
One has to remember that members post a lot of links in here. I have not noticed now, nor the last time this "problem" cropped up, any additional processes or tasks added to my machine due to visiting this site. This is why I think it has to do with links within the site, most probably within the forum, posted by members here and not the "site" itself. Just my .02 :D Just be aware of "links" that go outside of this site is what I am getting at Brothers.

Tom
 
irspow;478239 said:
One has to remember that members post a lot of links in here. I have not noticed now, nor the last time this "problem" cropped up, any additional processes or tasks added to my machine due to visiting this site. This is why I think it has to do with links within the site, most probably within the forum, posted by members here and not the "site" itself. Just my .02 :D Just be aware of "links" that go outside of this site is what I am getting at Brothers.

Tom

Starting to see this too. We may need to start moderating all links.
 
I've seen where an "Ad Server" is infected, and as web page visitors load a web page, and its ads, they get a "drive by" drop in Trojan, as the Advertisements are read off the Ad server, and loaded onto the users web page.
 
i like the fact that there is alot of freedom on this page. usually links to alot of things and there isnt any censorship. i love this.

however i had to completely shut off my browsers security to get to the page now.

this blows :(

hope you guys get it fixed. and please inform us when you do.

cheers
 
We normally have 4.5-5k new visitors daily here! one heck of allot but currently with all this going on its down to 500 new visitors daily. This malicious code has been placed by a nasty piece of work who wants to harm MOS and especially DLD's empire. It is to ruin his reputation, integrity and bring the place to a standstill.
 
Idiots never realize that good men may be able to be destoyed, but that good ideas are immortal :)
 
irspow;478239 said:
One has to remember that members post a lot of links in here. I have not noticed now, nor the last time this "problem" cropped up, any additional processes or tasks added to my machine due to visiting this site. This is why I think it has to do with links within the site, most probably within the forum, posted by members here and not the "site" itself. Just my .02 :D Just be aware of "links" that go outside of this site is what I am getting at Brothers.

Tom

Would that cause Safari to go nuts on the main page as well? I can not even log into the forums when I am using Safari (Private Browsing).
 
I'm experiancing the same thing fellas. I'm unable to get to mos through google. I can only get it through bing.com. What the hell is going on??
 
kingsnake;478327 said:
I'm experiancing the same thing fellas. I'm unable to get to mos through google. I can only get it through bing.com. What the hell is going on??
Have you tried typing the address directly into your address bar?
 
Ok did some digging and heres my conclusion.
The message referencing to ,,62.109.0.0'' also ties in 2 other forums that were infested. As I suspected they share common forum software.
It's not usual that if some idiot finds a sploit for forum engine they will try to reap on as many as they can.
Speaking of witch there seem to be forum about vbulletin issues: https://www.vbulletin.com/forum/sho...erabilities-Found-in-Popular-vBulletin-Addons
Where exactly the attack originated I cannot tell from my side.
The google error message is not very useful for troubleshooting.
AS for forum vulnreability my suggestion would be try to keep the software as latest as you can, in case any addons check vbulletin forum for info, tighten the new user creation methods for the forum and perhaps (if its not toomutch admin overhead) moderate links and stuff in posts.

EDIT: Woha, while checking those other forums they seem to be still affected! My useless symantec actually cauth something :p Dont worry about me guys, I'm using virtual environment to sandbox my browsing until this crap is clear.

K.
 
irspow;478239 said:
One has to remember that members post a lot of links in here. I have not noticed now, nor the last time this "problem" cropped up, any additional processes or tasks added to my machine due to visiting this site. This is why I think it has to do with links within the site, most probably within the forum, posted by members here and not the "site" itself. Just my .02 :D Just be aware of "links" that go outside of this site is what I am getting at Brothers.

Tom

i got this too... what if people started coding their links? would that stop it? example:
Code:
mattersofsize.com
 
Kraken;478332 said:
Ok did some digging and heres my conclusion.
The message referencing to ,,62.109.0.0'' also ties in 2 other forums that were infested. As I suspected they share common forum software.
It's not usual that if some idiot finds a sploit for forum engine they will try to reap on as many as they can.
Speaking of witch there seem to be forum about vbulletin issues: https://www.vbulletin.com/forum/sho...erabilities-Found-in-Popular-vBulletin-Addons
Where exactly the attack originated I cannot tell from my side.
The google error message is not very useful for troubleshooting.
AS for forum vulnreability my suggestion would be try to keep the software as latest as you can, in case any addons check vbulletin forum for info, tighten the new user creation methods for the forum and perhaps (if its not toomutch admin overhead) moderate links and stuff in posts.

EDIT: Woha, while checking those other forums they seem to be still affected! My useless symantec actually cauth something :p Dont worry about me guys, I'm using virtual environment to sandbox my browsing until this crap is clear.

K.

Thank you for the suggestion. These vulnerabilities are a pain in the ass cheeks tbh. Also thumbs up on the virtual environment and I'm a big fan of it incl sandbox. Have you tried Shadow Defender? not officially supported now since the developer went AWOL but its imho and many other users the best virtual environment for a system. Kick ass.
 
Back
Top Bottom