Server Downtime... Hacked?

Do you use the "SPAM-O-MATIC"?
It really simplifies the process.

LoveHerDeeply;563072 said:
I'm sure its not the recommended method, but I spent Hours over the last 2 days hard deleting the ad spam. Hope it helped. I'm still finding some buried within the sub forums.

I Keeelll Them!
II KEEL THEM AAAALLLLL!!!
 
Well I was concerned about the live links lagging the site like some of our techy guts were posting in other threads... so I was clicking the boxes on the right, mod box, delete... password etc. But I can understand keeping the posts for Google ranking purposes... so ill try that button you're on about, NP.
 
Penis EnlargementGym has also been getting hit with DDOS attacks and script hijacking. It was really bad a few weeks ago, and it got hit again just yesterday :(
 
Big Al;563791 said:
???

The bottom of my post under the sig is showing the following (replace { & } with < & >):

{a href="http://www.nkll.com/hpot.php?name=51099" style="display: none;"}fey{/a}

I'm seeing links to that site on some other member's sigs. It's also coming up on google: see https://www.google.com/#q=http://www.nkll.com/hpot.php?name=51099

Is that now embedded in your sig? Goto your profile and check, delete it and report back... maybe another creative spam-hack?
 
LoveHerDeeply;563848 said:
Is that now embedded in your sig? Goto your profile and check, delete it and report back... maybe another creative spam-hack?

Thanks!

It was embedded in my sig- now removed. I had to go into the MOS moderator site to do it, though.

Some other members are showing that URL in their sigs. The links were like mine or read "jail-brick". The text is telling, and it definitely appears malicious.
 
Last edited:
About half the mods have a code string hacked into their sig. I noticed it while reading a thread in mod forum. Uht. Ohh.
 
At the pegym:
Today I discovered "new applicants" who had adjusted their IP address to be that of our mail server.
Hoping to avoid being caught.
In about 2 hours, there were ~ 600 new applicants, most were stopped by a plug in used by the site.
 
I have signatures disabled, so not sure how long it's been like that.

Damn dangler. I haven't been in pegyms since early august.
Do you have a captcha in the signup system? Recaptcha is the better one, but I think the main forum bot(xrumer) might solve this already.
 
LIGHTNING;564085 said:
We removed all the hacks in the mod signatures

Thanks Lightning. Been frustrating times with all the spammers alone. Now we figure out we got hacks into our sigs that's just scary bro. Thanks for housecleaning g for us.
 
Thanks for pointing that out!
I didn't even know shit like that was possible...
I HATE hackers!!

I've been offsite for awhile, now I'll keep a much closer watch on my own stuff to keep it clean too.
Looks like Lightning removed it...but if you hadn't pointed it out to me (and others, of course) I'd never think of looking at my own sig.

Damn...I feel kinda raped.
And it sucks.

smerc;563948 said:
Found this in "MAXAMEYES" signature.
View attachment 27743


Seems you and Big are not the only incident. Look here: https://www.google.com/search?clien...m+nkll.com&oq=site:mattersofsize.com+nkll.com
 
Thanks again brother.
Cavemen like me rely on tech wizards like you to keep our heads from disappearing up our own asses.


LIGHTNING;564085 said:
We removed all the hacks in the mod signatures
 
MAXAMEYES;564138 said:
Thanks for pointing that out!
I didn't even know shit like that was possible...
I HATE hackers!!

I've been offsite for awhile, now I'll keep a much closer watch on my own stuff to keep it clean too.
Looks like Lightning removed it...but if you hadn't pointed it out to me (and others, of course) I'd never think of looking at my own sig.

Damn...I feel kinda raped.
And it sucks.

What's interesting is how user-targeted this attack was.
 
Nobody really questions mod/admin links, so it may have went untalked about.


Here is a good talk if anyone is interested in this stuff in regards to malware/adware/trojans: http://www.youtube.com/watch?v=fSErHToV8IU (unrelated to server hacking/injections unless someone gets a backdoor to an admins pc)
 
Back
Top Bottom