Feb 17 2011, 04:08 PM
So, this site (and every other site that I host) was hacked in the past twelve hours. It might be a good idea to run a virus check on your machine.

Sorry about this - my site became hosted by a new company about six months ago and there seem to be a lot more breaches since this new company took over.

The telltale sign of a hack is often a tiny square, just a few pixels wide and tall, usually at the very top or the very bottom of the screen. If you see one of these then please let me know immediately.

Feb 19 2011, 01:21 AM
I would suggest you look into changing ALL your site passwords with very strong ones (14+ characters including upper and lower case, numbers, and symbols). And I would update every bit of software on the server. After that, it would seem that it is a server issue and then you would have to move to a different host. If you want help with this, let me know.

Feb 19 2011, 10:10 PM
QUOTE (moooooooooooooooooooooooooop @ Feb 18 2011, 12:39 AM) *
QUOTE (MataTeachesMeLudology @ Feb 17 2011, 09:54 PM) *
Fun-fact: Computers can't get viruses from websites unless you download something like an executable, or batch file (exe or bat).

The message you probably received was the one that said that the website you are visiting is unsafe. This could basically mean the site would provide child pornography, viruses, or offer other stuff that can be regarded as unsafe.

This is why it has been reported.

This is how you fix this. Read some stuff about it.

Worst-case scenario: Someone actually hacked your site and puts scripts on it for advertisement purposes. In this case you should deny ALL downloads coming from this website, close pop-ups and press cancel to everything it offers you. Don't use anything that requires input, which unfortunately includes the donate button (You would possibly donate to a random person in Nigeria all of the sudden). Mata, I suggest that you check if everything still links to where you want it to link, and possibly, get someone that does the technical stuff on this website for you.

Even if it can't download executables and run them (though I'm sure there are problems in older browsers that would allow that) they've clearly injected data into the page and from there it's a trivial step to scripting vulnerabilities that could give access to someone's MZ password and email, and from there access to their email if they've not been careful and used the same password for both. That's pretty bad.

My points is, it's best not to be complacent about security. Being condescending to people for worrying about such things is just going to discourage them from sensible computer security habits. It's a lot less harmful to just let them run the virus scan!
Up-to-date browser USUALLY (as in, almost always, but there are small exceptions) does not allow applications to be stored on your computer under any circumstance without properly notifying the user about this. Next to that, the latest versions of Windows automatically detect whenever an application that is downloaded from the internet or is coming from a questionable source and notifies the user whenever that application is trying to run. This means basically that the user can deny the launch of any unwanted applications as well.

Java could do stuff to your computer, but you're properly notified of the fact that it's trying to do that by the Java application itself. Exploits could still happen, but is rather unlikely.

My point is, you're pretty safe as long as you know what you're doing. I've been running without a virus-scanner for quite some time now and I am doing fine, because I know what I can download and what not. But, as long as you're unsure about what to download, keep your virus-scanner on.

And next to that, injecting data into a page is useless, as it's stored on your own computer. You'd be doing nothing at all. You'd have to send something to the server.
QUOTE (SPEAKERfortheLOST @ Feb 19 2011, 02:21 AM) *
I would suggest you look into changing ALL your site passwords with very strong ones (14+ characters including upper and lower case, numbers, and symbols). And I would update every bit of software on the server. After that, it would seem that it is a server issue and then you would have to move to a different host. If you want help with this, let me know.
I'd only do this if Mata keeps your passwords stored without an hash. Which, by standards, he'll probably do. (I don't see him changing the source code of IPS, no offence)
