MALWARE on zerotohundred

^pomen_GTR^

7,000 RPM
Senior Member
May 13, 2010
7,509
1,690
1,713
The Mines
my newly installed chrome detected malware again on all zth...today...
 

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
hi everyone, thanks for replies,

we've been attacked yet again. the files are scanned and removed at this time.

If your antivirus prompts a mesage, I would appreciate it greatly if you could post the messages here

thanks!
 

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
hi shaolin tiger,

thanks for the recommendation, we'll be upgrading soon to the latest patch.
though the affected areas were in fact not vbulletin this time but the openX adserver

Thanks!
Tom
 

ShaolinTiger

Known Member
Senior Member
Nov 13, 2009
57
308
1,553
Kuala Lumpur
www.shaolintiger.com
Ah, no worries. Best to keep everything up to date just to be safe.

You might wanna implement some more security measures on the server side too as I presume you're on a dedicated servers. Things to check out:

SuPHP - http://www.suphp.org/Home.html
Suhosin - http://www.hardened-php.net/suhosin/
mod_security - http://www.modsecurity.org/
CSF - http://www.configserver.com/cp/csf.html

All make sure all the permissions are correct (not 777) and scan the machine with chrootkit or similar.

There's also some tips here regarding OpenX specifically:

http://www.openx.org/fr/docs/2.8/adminguide/Securing+OpenX

You probably got this too:

http://www.thewebhostinghero.com/articles/openx-vulnerability-this-site-may-harm-your-computer.html
 
Last edited:

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
hi kian27

would you by any chance have the report with you?
this would help us detect the infected files better

Thanks!
 

kian27

Known Member
Senior Member
Sep 28, 2008
62
5
1,508
Petaling Jaya


this 1? if nt mayb other avast user can tell me where/how to find it, i will try my best. Those at july 1 is zth affect by malware period also. That time i thought was my pc problem so i just ignore it until other forumer file a report at here i just realize.

last time when here is affected by malware when i log to zth page then avast will warn me & something about java will pop up (i didn't read it just close the pop up). hope it helps.
 

Attachments

Last edited:

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
hi Kian

thanks for the reply
do continue to update us if you find any future notices

There was in fact a suspicious JavaScript file earlier which we've fixed.

It's now 100% safe. Your anti-virus shouldn't show any more pop-ups

thanks!
Tom
 

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
hi ppgoines, thanks

To everyone, I'd to apologize for the inconvenience caused (yet again).
Again, despite the various methods taken to secure Zerotohundred.com since the last 2 attacks, the attack yesterday came from one of the advertising network we work with.

here is a full explanantion from Innity:

Further to our earlier email, we have managed to rectify the issue of our ad server displaying a malware warning issue on your site. In summary, a portion of our domain; innity.net, which operates as a content delivery network focused on delivering static banner files to our end user, was affected in Indonesia and this led to Google classifying our domain as being infected by malware. While we have quickly resolved the issue and are now back to normal operation, Google’s aggressive malware prevention policy may result in users continuing to see warnings until Google completes its re-review process. As a result, the entire innity.net domain has been blacklisted. Websites that are embedded with the Innity tag have been affected by this problem and this has caused a warning message to be displayed when a user visits the websites when they are using either Google Chrome or Firefox.

We have excluded the affected delivery network from our advertising network until the service provider rectifies the issue from their side. We have also initiated the Google review process, and requested Google to recheck the site and declassify it as malware. The process could take up to 48 hours as the situation is complicated due to the fact that there is no detailed report as to why Google has classified us as a malware distributor.

We have also taken short-term steps to lock down our domain in Indonesia completely while we determine the true technical root cause of the initial malicious files.

We take the integrity of our infrastructure extremely seriously, and will post a detailed follow-up as the investigation completes. We sincerely apologize for any inconvenience caused to you and your visitors, and you have our assurance that part of the investigation also includes reviewing our early-detection mechanism for this type of glitch specifically.

You can temporarily remove the Innity tag from your site, and sign up for Google Webmaster Tools for a review. Details can be found on the site below: http://www.google.com/support/webmasters/bin/answer.py?answer=168328

Additionally, we would appreciate your help in sharing with us the information that is being displayed on your Google Webmaster Tools under the malware section to [email protected] .

Please refer to this page- http://www.innity.com/announcement/ for further updates on this issue. You can also write to us at [email protected] or call +603 78805611 for further questions.



Regards,
Innity Marketing Team

T: +(60)3 7880 5611 F: +(60)3 7880 5622
 

TitanRev

You think I print money?
Helmet Clan
Moderator
Mar 3, 2005
8,180
3,678
5,213
Hope everything is back to normal now..
 

papagoines

Orang Tua
Senior Member
Feb 6, 2006
2,024
376
1,683
Rawang/Selangor

Tom

TIMETOATTACK
Helmet Clan
Jul 6, 2000
5,562
3,229
5,213
Kuala Lumpur
thanks for the link, it's comforting in a way to know there are many other site who were affected
 

Random Post Every 5 Minutes

Pemilik:Pian @ Raver
Jenis Kenderaan: Satria Gti
Nombor Kenderaan: WKV 7769
Marking : Full stc sticker di semua cermin, antenna panjang radio amatur,
Tempat Hilang: Lukut Port Dickson

Minta bantuan sesiapa terjumpa, ternampak kenderaan ini, sila hubungi owner dengan segera di 0122222370 - Pian. or am 012-3103793

car pict
pic on sepang track day on 13/12/2009


latest pic - rim change...
Ask a question, start a discussion or post something for sale!
Post thread

Online now

Enjoying Zerotohundred?

Log-in for an ad-less experience