Search






Jeff's Amazon.com Wish List

Archive Calendar

November 2024
M T W T F S S
 123
45678910
11121314151617
18192021222324
252627282930  

Archives

Site hack

Looks like pw was hacked and some bad code placed (again) in the site footer. I’ve removed it and requested a re-evaluation of the site, but Google tells me that can take “several weeks” — and I still have no idea how to stop the insertion of this bad code.

Personally, I can’t reach the site on Firefox; I am able to reach it on Safari and Internet Explorer.

I’ve contacted my host to see what he can do, but I haven’t heard back from him. Evidently, this just happened. My site is not even yet listed on badware.

Also, I’ve tried responding to several emails and I’m getting error messages. My domain appears to be blocked on att.net, so if you’ve emailed me and didn’t get a response, that’s likely why.

I have no idea what to do going forward. This is where we are.

*****
update: you can safely bypass any warning you receive. Until this is resolved, I’ve changed my browser security settings to allow me to get to the site.

39 Replies to “Site hack”

  1. sdferr says:

    There don’t appear to be any untoward consequences to bypassing the warning page. On the other hand, Sparty is down 10 pts to Nebraska in the early going, so. . .

  2. ThomasD says:

    I’m using Firefox right now, and also not seeing any warning (running Trend Micro.)

  3. apotheosis says:

    Was the site itself hacked, or was it in the banner ad rotation?

    Whatever the code was meant to do, it failed pretty miserably on my system. Ran a full scan right after I saw the warning the first time and it came up with nothing.

    So basically it’s just an inconvenience.

  4. dicentra says:

    Got the warning from Google, then bypassed it.

  5. Benedick says:

    I was able to bypass the warnings on Firefox (took a few tries though).

  6. Jeff G. says:

    It was that crap that was inserted in the footer. This happened before. But I caught it before the site got placed “on the list”.

  7. Jeff G. says:

    THose of you who use Twitter, or follow me there, please re-tweet my latest Tweet that tells people to ignore security warnings.

    Too bad, too. PW was enjoying a kind of resurgence, now that I’ve been able to sell it on Twitter and bypass the linky linky gatekeepers somewhat.

  8. geoffb says:

    For now I went into options/security in Firefox and unchecked the “block all reported attack sites” option.

  9. sdferr says:

    Same thing happened to the country in an administration hack. Didn’t catch it in time.

  10. Jeff G. says:

    If you trust the site, and you don’t frequent a lot of potentially skeevy sites, you can do this: go to options/security on Firefox and tell it not block reported attack sites for the time being.

  11. bh says:

    I just hit ignore or whatever it said and I’m not having any problems.

  12. Topsecretk9 says:

    I saw no problems coming here on Firefox. No warnings, nothing. Everything’s fine for me.

  13. sdferr says:

    With the espn football talking heads all insistent that the Eagles must win tomorrow night, I’m feeling better than ever the Pokes are gonna beat ’em like a drum.

    Kinda like I do with the cw on Mitt Romney. The man is toast.

  14. Jeff G. says:

    TSK9 —

    Can you go to your security settings and see if you have your browser set to check for attack sites? It’s under preferences and then security.

  15. Patrick Chester says:

    I guess you can take this as meaning someone’s finding your writings to be a threat. A rather dubious blessing, unfortunately.

    (Finally got in, but had to exit and leave to get the warnings to stop.)

  16. BBHunter says:

    Jeff, since I can’t access your email at the moment Im posting this here for redact once you’ve read it.

    – There are only so many ways a hacker can access your site source code or ftp files. Check with your host. Hackers either have to gain access to your admin log-in or utilize server-side cgi apps. Those are the only two direct ways to access your account and make changes (bad code over-writes) that could trigger security protect scripts.

    – They can get indirect access through RSS/Newline/AD Banner feeds.

    – Best guess is it was a server wide attack, not a single site attack, but your provider will know if that’s tha case.

  17. In other, vaguely related news, this is what democracy looks like:

    Anonymous plans to take down the Fox News Web site on November 5, according to a new video apparently released by the hacker group. The group said it is targeting the network for what it called biased news coverage of the Occupy Wall Street protests occurring in cities across the country. The network’s “continued right-wing, conservative propaganda against the occupations” is the group’s catalyst for its intention of “destroying the Fox News Web site,” a digitally generated voice on the video explains. “Since they will not stop belittling the occupiers, we will simply shut them down.”

    Or, “See the world how we see it or we will hurt you.”

  18. Jeff G. says:

    Thanks BBH.

    My host hasn’t yet responded to any of my emails. He’s in Australia, so likely he’s sleeping.

  19. Jeff G. says:

    Or, “See the world how we see it or we will hurt you.”

    That could be the motto of the entire left.

  20. serr8d says:

    No warnings on Droid’s Opera.

    Check the Pub, Jeff. It’s eaten up with spammers, and is a subdomain.of pw. Could be that’s the entry port.

  21. John Bradley says:

    “Since they will not stop belittling the occupiers, we will simply shut them down.”

    “We’ve got handcuffs, and we know how to use them. You have 24 hours to respond.”

  22. serr8d says:

    Vanderbilt is beating No. 10 Arkansas 28-17. This is a BFD.

  23. serr8d says:

    Disregard that previous comment; the Football Gods were just having a chuckle.

  24. sdferr says:

    One of those Husker kids is named Epaminondas.

  25. sdferr says:

    They don’t have our interest at heart,” she said.

    Hell, she could as easily say it against the public sector unions, as an electricity utility company standing apart from government.

  26. apotheosis says:

    cleared cache & cookies, restarted the browser, no warning this time.

  27. David Block says:

    Apple MacBook Pro. No problems in Firefox. No problems in Safari.

  28. newrouter says:

    maybe related. i couldn’t log in using the log in function at the bottom of post. it gives a 404 error. i had to use the log in on the side bar.

  29. David Block says:

    newrouter, I had the same problem, but no warnings about the site.

  30. McGehee says:

    What newrouter and David Block reported: me too.

  31. serr8d says:

    No malware warnings! The site’s clean again. Stupid hackers.

    Login problems too, as noted above.

  32. serr8d says:

    OT.. I lit up the range with my new hand-toy, a Kel-Tec PMR-30. Sweet; 30 rounds of .22 WMR in under 10 seconds. A veritable ‘fountain of hot lead’.

  33. Carin says:

    Yea, Thanks for the heads up on using the log-in on the sidebar. I had considered that, but figured “why would that work”? and hadn’t tried.

  34. guinspen says:

    i had to use the log in on the side bar

    Likewise.

  35. Pablo says:

    Aha! That works. Pity that I forgot what I was going to say.

  36. Jeff G. says:

    Serr8d —

    I was looking at that pistol, and also the RFB. Reviews?

  37. serr8d says:

    The most amazing thing about the PMR-30 (besides the magazine capacity) is it’s light weight, being a polymer-framed pistol. I put only a couple mags through it today; one issue I noted is the difficulty in getting the last 2-3 rounds loaded in the magazines. I may not have the ‘hang’ of it yet, because I actually dented the brass cases of several already-loaded rounds, having to compress the magazine spring with additional rounds. Kel-Tec should’ve added a thinger to help compress the magazine spring, other than simply relying on pressure from additional rounds against already-loaded rounds. But 25 rounds (half a box) are easy enough to load.

    Offhand accuracy is good enough to plug small game, out to whatever range your eyes will allow with ‘iron’ sights. The sights are easy to pick up, bright red – green optic cables concentrate any available light. I haven’t installed a laser on the built-in rail system yet; probably won’t, as this tool is intended as a target – small game device, not as a self-defense weapon (although with 30 rounds per mag, with two loaded mags, one could certainly use it as such if the .40+’s were out of reach or out of ammo).

    Cheap to shoot (50 CCI Maxi-Mags can be had at Wal-Mart for $15), easy to carry, an attention-getter at the range. Kel-Tec can’t keep up with demand (I had to wait 6 weeks after ordering mine for it to come in). For the price, around $400 MSRP, I’m happy.

    The RFB is another trick pony entirely. A .308, bullpup-class, roughly three times the cost to own and to shoot as the PMR-30. My .308 has a target bbl and is on a traditional ‘black rifle’ frame, with a ‘target’ scope, as befitting the round’s capabilities. Seems a shame to dump those out of a bullpup, really.

  38. Seth says:

    @BBH #16:

    Don’t forget SQL injection.

  39. Seth says:

    Jeff, you’ve probably already seen this, but in case you haven’t…these are probably all good steps to take to avoid a future hack:
    http://codex.wordpress.org/FAQ_My_site_was_hacked

Comments are closed.