Charas-Project
Off-Topic => All of all! => Topic started by: Darkfox on January 08, 2010, 09:39:24 PM
-
_JeT_ and Deathreaper have been getting viral warnings while visiting Charas Forums. Various security warnings. I have not YET but they have. Anyone else getting viral warnings/infections while browsing Charas Forums? Since two people have already gotten this I think I should bring it up with all of you in case it is actually an infection that originates here.
-
Well though answering "no" might seems unnecessary, it's good to have positive answer. Or so I think.
Maybe just a coincidence?
-
Maybe it is, but also one that repeated itself. So now I'm curious about it and if there is something going on. It is a coincidence when it happens once, but twice is when I start scratching my head.
-
I've been getting viral warnings too! I just installed a new anti-virus today though, so at first I thought it was just my anti-virus acting stupid. But it's only been occuring while visiting this site. Not sure what the problem is, but it's been really annoying...
Something keeps popping up and saying that an unknown file is trying to access my computer. I just keep saying "no" but it always pops up whenever I refresh or go to a new page.
-
Really? That makes three people now. A bit beyond mere coincidence. What is your scanner? Norton?
-
Just scanned just to make sure. Nothing.
If it's being done by an ad, I wouldn't know, I have adblock on.
-
getting this all the time
(http://i278.photobucket.com/albums/kk86/loneywolf/this.png)
-
I don't have that, but I tried to log in and all I got was a blank screen. Happens every time I post, too.
Fixed it by fiddling with the URL, but it's annoying.
-
I've just gotten the blank page as well. Maybe all this could be related to that hack that prevent us from using attachments. Maybe not, though...
-
I blame the Gorram Reavers.
That's just my opinion, though.
-
Do the people getting viral warnings have popups blocked? It might be an ad.
adblock+Sophos; no warnings.
-
I'm getting blank pages for posting and editing profile. Might have something to do with some people's avatars disappearing.
I'm not getting virus warnings, and I installed anti-malware programs yesterday because I got some nasty malware for some reason (probably not related, but can someone look into it?)
-
Not sure if this is related, but just now, I couldn't log in for a while. Even though it said I was logged in, it kept treating me like a guest and asking me to log in. Now, I logged in and every now and then it'll treat me like a guest again. Sometimes I can check my messages but when I click a forum or thread, there's that box at the top asking me to type in my user info and log in. If I refresh or go back to the main forum page, it returns to normal and I'm logged in.
Also, I get the white blank page when I post or log in.
I don't have any viruses. I'll scan tonight however. Maybe it's just the site acting screwy?
EDIT: Also when I delete posts or edit them.
-
I get a blank page when I don't put the "www" in the URL.
Test post:
http://charas-project.net/forum
http://www.charas-project.net/forum
Edit - It went blank when I posted this, even though there was www in the URL. Hmm.
Edit 2 - My avatar vanished. And so did some other people's. Might not be related though.
-
Woah... that is a lot of crap happening, people's avatars disappearing, pages without www turning up blank, and now this.
-
Is charas just getting old? Does that happen? Do sites age?
...Does charas have alzheimers? 0_o
-
Ah I was wondering about this Avast was telling me the viral warning everytime I came here every like 7 seconds Avast would freak out its doing it not anymore though.
My avatar has also just dissapeared and as soon as posting it goes to a white screen.
It also won't let me put my avatar back up.
Crazy
-
Adobe reader kept opening today. It stopped now, but it kep on opening giving me errors.
-
I haven't got any problems yet, but I'm starting to get worried...
Also, who are the Gorram Reavers?
[EDIT:] I just got the blank screen thing.
-
Hm.. I'm a little nervous. I started up my computer today and it gave me a list of programs that stopped working properly. Also, it was really sluggish for a bit and kept glitching. It's fine now, but it was weird. Not sure if it's connected, just figured I'd let you all know.
-
Wow, disappearing avatars, blank pages, virus warnings, and various bugs and glitches...
-
Uh, it seems no one updated you...
Well, let's do it now.
Yes, there was a code injection in charas. The code tried to open a malicious PDF document into an invisible 1x1 iframe.
Then, by using a known adobe vulnerability, the javascript code tried to use the malicious PDF in order to do... something (i don't know what).
Everyone with javascript disabled for PDF reader should be safe (i never understood why in hell PDF docs needed javascript support).
However, yesterday we found and removed that code, so now all should be fine.
Charas was "exposed" to this from January 7th to yesterday: so, if you do have javascript allowed for Reader and you have an outdated version of Reader itself, a full scan is surely recommended.
I'm just sorry i can't tell you more about what that PDF was supposed to do... but considering today's trends, i think to transform your PC into a part of a botnet of something similar
-
Ok... So what the heck do we do? There's clearly still some problems on site;
The site returns a white screen whenever I make a post or try to log on. In fact, it probably will return one as I post this message. Hell, there was a period I couldn't even post OR logon because it told me some **** like my session had timed out or something.
Your session timed out while posting. Please try to re-submit your message.
Thank god I was even able to get this post out. Still got a white screen, but at least the message was laid down.
ED: I also seem to be logging out randomly. Fix this.
ED2: And I can't quote.
-
Uh, it seems no one updated you...
Well, let's do it now.
Yes, there was a code injection in charas. The code tried to open a malicious PDF document into an invisible 1x1 iframe.
Then, by using a known adobe vulnerability, the javascript code tried to use the malicious PDF in order to do... something (i don't know what).
Everyone with javascript disabled for PDF reader should be safe (i never understood why in hell PDF docs needed javascript support).
However, yesterday we found and removed that code, so now all should be fine.
Charas was "exposed" to this from January 7th to yesterday: so, if you do have javascript allowed for Reader and you have an outdated version of Reader itself, a full scan is surely recommended.
I'm just sorry i can't tell you more about what that PDF was supposed to do... but considering today's trends, i think to transform your PC into a part of a botnet of something similar
Oh wow. This explains why I kept getting Reader error messages even though I hadn't been looking at PDF. Might have explained where I got that malware from, too. Cheers.
I recommend everyone download MalwareByte's Anti-Malware and Spyware Doctor. Both are great for getting rid of viruses. AVG hasn't really done anything for me lately.
EDIT: lucas_irineu still can't post. Getting timeout errors. And I'm still getting the white screen.
-
White screens and being unable to post or quote or logon are not results of the virus. This seems to be a problem on the server side.
If it was the virus, my antivirus program would be complaining right now.
Tell Lucas Irineu to clear his cookies and logon again. And make sure he's clicking on the actual text of the link, not on the general blue area of forum links. It's the only way to preserve session ID for some messed up reason.
-
Tell Lucas Irineu to clear his cookies and logon again. And make sure he's clicking on the actual text of the link, not on the general blue area of forum links. It's the only way to preserve session ID for some messed up reason.
Wow, it worked!
EDIT: Lucas says he wants PUB back.
-
Asploding I tell you. Asploding.
There's is something definitely going wrong here. But nothing to worry. Like Earthlings in the future will migrate to new horizons
I AM LIKE KING OF THE WORLD.
Seriously someone else post, I feel lonely.
-
Okay well, I found out how to post, as well as log in, when I receive the blank screen.
Of course, it may not work for others, but it worked for me.
So yeah, here's how it goes.
1- Post something or try lo log in
2- Blank screen appears. Don't panic.
3- Erase the "2" at the far end of the URL then press enter. If the last character isn't "2", try erasing it anyway. And then press enter. It should say it didn't work or something like that, but it actually did.
4- If it didn't work, then you're doomed. So now you can panic.
Edit: If the reason you can't post or do anything is because your session "timed out", just delete your cookies, then when you'll try to log back in, you should receive the blank screen. Again, of course, it might not work for you, but it did for me.
Edit2: Okay so when you edit, it isn't the last character you must delete, but that damn "2" again. Somewhere in the URL you should see like "post2" when you post or edit. For me, it appears at the end of the URL when I post, but somewhere in the middle when I edit a post.
When you edit a post, again when on the blank screen, just erase the "2" end press enter. It should bring you back to editing your post. However, your post will already be edit.
-
Alternatively:
1: Logon normally. A white screen will show up...
2: Press the back button on the browser window.
3: Press the "HOME" link on the top bar of the forum nav. page. It should work if the bottom bar of your browser shows a long string of characters for the Session ID. If that's there, then this method should work.
... I don't know why it works, but thank god it does.
-
Indeed, just tried as well. Seems like it's simpler this way.
-
Cool, Cerebus's method worked for me.
EDIT - Oops, I keep forgetting to click on the actual links instead of the blue areas near it. Oh well, at least I can post.
-
What does it actually do? Doesn't seem to make a difference to me.
-
Clicking on the blue area instead of the text logs me out.
-
Hooray, I can post and stuff. Abnormally, but still posting.
-
It's happening to me as well.
The generators also seem to have problems. None of the resources are currently showing up at all.
-
God, this is a nightmare.
I've never had any problems in the 6 years I've been here.
-
Yeah, it's quite annoying indeed. But I won't let this hack or something prevent me to go on Charas. No!
But I sure hope it'll get fixed soon. Until then, I'll just erase the 2s.
-
Yes. Not now though. It was right around the time that the I'm not able to post in the news topic thing started.
Okay. Nevermind. I can't post anywhere it seems. Bum.
Will it work!?!!?
EDIT: IT DID. =DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
I don't seem to have the "2" problem now. I'm doing normal replies. But I have to be careful where I click. =P
-
Post about white-screen fix: http://www.charas-project.net/forum/index.php?topic=26436.0
I'm curious if people are still having trouble clicking the boxes rather than the forum link.
-
Nope, I'm all good here. =D
-
Post about white-screen fix: http://www.charas-project.net/forum/index.php?topic=26436.0
I'm curious if people are still having trouble clicking the boxes rather than the forum link.
Yeah, you even fixed that.
Oh, and quoting works again, too!
-
POST
EDIT: YES
-
I went back to charas default skin without complying to that choice.
HAX
-
Well, good to see things are fixed up, and it seems there really was a virus but got fixed too. Hmmm... funny that we got issues only after that "hack".
-
Well, good to see things are fixed up, and it seems there really was a virus but got fixed too. Hmmm... funny that we got issues only after that "hack".
Track down the sonnuavabitch somehow.
-
I highly doubt a troll would still care after a few years.
Oh wait, a joke.
Oops.
-
I doubt he had anything to do about it, though if he'd learn about it, he would probably claim he was behind it.
Because yes, some people would still care even after years. Some people are stupid, you know.
But anyway. Joy!
-
Well, everything seems to be working for me again too, sooo yay! :w00t:
-
Yepp, everything seems to be back to normal now.
-
I've missed you all so much!
-
I've missed you all so much!
AAAAAAAAAAAAGHHHH!!! Nah, yeah, it is good to be back. ^_^
-
Oh, so good to be back. For a minute there, I was afraid that I'd never break into a five digit post count! That would be a real shame, huh?
-
I can finally change my avatar.
Oh yeah, and I'm back I guess. Not that any of you care.
-
I would say "you're right" but that'd be mean.
-
Oh, so good to be back. For a minute there, I was afraid that I'd never break into a five digit post count! That would be a real shame, huh?
Real shame. >_>
<_<
-
Yup, back now too...
-
I've just been reading this thread all week! Can finally post!! ^____________^
-
Wewt!
-
(http://img42.imageshack.us/img42/7934/internethighfiver.jpg)
-
Now my screen has fingerprints on it.
Thanks a lot, Archem.
-
Jesus, you have a fat hand.
-
Now my screen has fingerprints on it.
Thanks a lot, Archem.
One step closer to stolen identity... Yes...
Jesus, you have a fat hand.
Not my hand. I'm sure it's one of those one-size-fits-all thingies.
-
Now if only those generat... nevermind, those fixed too, we're good!
-
Strangely enough, that fit perfectly.
I think I went a little too overzealous though, because now my screen has some weird colours on it.
-
We all did, but now I need to replace my monitor, this one has a big crack in it for some reason.
-
Clearly, I'm doing my job around here.