Chatroom
 

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Bad Astronomy and Universe Today Forum > General > Off-Topic Babbling
Register FAQ Members List Calendar Mark Forums Read

   

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 21-November-2004, 01:15 PM
ignorant_ape ignorant_ape is offline
Senior Member
 
Join Date: Oct 2002
Posts: 117
Default has the BA main page been hacked ?

sorry for the intrusion - but out of 150+ book marks it is only badastronomy.com that fires a porn redirect when i try to open the page

in my mind this suggests that phils server has been nixied , not my puter

help / ideas etc ?

how did i get here - using the history cache to bring up each section header then i can navigate all but the main board page - that gives a 404 error

YRS - APE
Reply With Quote
  #2 (permalink)  
Old 21-November-2004, 01:30 PM
R.A.F.'s Avatar
R.A.F. R.A.F. is offline
Banned
 
Join Date: Jun 2002
Posts: 7,081
Default Re: has the BA main page been hacked ?

Quote:
Originally Posted by ignorant_ape
...in my mind this suggests that phils server has been nixied , not my puter
I believe you are correct.

Quote:
help / ideas etc ?
I don't know if it's such a good idea using a regular computer to come here...I'm using my WebTV, which isn't effected by virus', so I don't have a problem.

Quote:
how did i get here - using the history cache to bring up each section header then i can navigate all but the main board page - that gives a 404 error.
I "got on" by using the email notification link to log on...then the "drop down" at the bottom to go to each individual forum...I can't get on the main index either.

The BA's last "aussie speech" was on saturday, so I assume he'll be winging his way "home" soon...hopefully he can take care of this problem.
Reply With Quote
  #3 (permalink)  
Old 21-November-2004, 01:32 PM
kucharek's Avatar
kucharek kucharek is offline
Senior Member
 
Join Date: Feb 2002
Location: Karlsruhe, Germany, Old Europe
Posts: 4,052
Default

I'm sure it had been hacked. Many weird things and, an applet wants to start on the index page and an iframe to a porn site.
And Phil is out of house.
__________________
"Flying in space is risky business, but just staying on this planet is risky business too." - John Young, astronaut
Reply With Quote
  #4 (permalink)  
Old 21-November-2004, 01:40 PM
zebo-the-fat's Avatar
zebo-the-fat zebo-the-fat is offline
Senior Member
 
Join Date: Sep 2003
Location: South Yorkshire, U.K.
Posts: 1,776
Default

Same problem here, main page hacked and Norton AV stomps on a possible virus as soon as the "new" page opens. I VERY strongly recomend that everyone runs a full virus check asap.

It must be creationist hackers!
__________________


The meek will inherit the earth ... the rest of us will go to the stars.
Reply With Quote
  #5 (permalink)  
Old 21-November-2004, 04:16 PM
AT AT is offline
Member
 
Join Date: Nov 2004
Posts: 47
Default yes

Yes, this page has been hacked; INCLUDING THIS ONE. If you have Java and/or Javascript enabled (odds are you do), and arn't using FireFox (wow, QED on that other thread) and/or have a very up to date antivirus you are infected.
In other words, if you went to the main page, and weren't informed that it was attempting to install a trojan, it got you.
If you came to this page, and weren't informed AGAIN, it got you.

Either way, disabling java/script for this URL should prevent its install, but I also don't recomend frequenting a hacked site until it is fixed.

Perhaps topic title should be edited to something attention getting like 'READ THIS FOR THE SAKE OF YOUR SANITY!'
Reply With Quote
  #6 (permalink)  
Old 21-November-2004, 04:55 PM
patrick patrick is offline
Senior Member
 
Join Date: May 2004
Location: Antwerp, Belgium
Posts: 138
Default

Time to consider Linux on the destop... =D>
Reply With Quote
  #7 (permalink)  
Old 21-November-2004, 05:43 PM
Sammy Sammy is offline
Senior Member
 
Join Date: May 2003
Location: Washington DC Metro Area (MD)
Posts: 1,654
Default

I got on OK (tho slowly) but my Norton Firewall and Antivirus went wild with alerts. There are still attempts to download stuff as I type this. Something evil may have taken up residence on the BA server, or it's random hits.
__________________
Standing on the shoulders of giants...
Reply With Quote
  #8 (permalink)  
Old 21-November-2004, 05:44 PM
zebo-the-fat's Avatar
zebo-the-fat zebo-the-fat is offline
Senior Member
 
Join Date: Sep 2003
Location: South Yorkshire, U.K.
Posts: 1,776
Default

The bad astro website is also infecte not just the bulleten board
__________________


The meek will inherit the earth ... the rest of us will go to the stars.
Reply With Quote
  #9 (permalink)  
Old 21-November-2004, 07:47 PM
kylenano's Avatar
kylenano kylenano is offline
Senior Member
 
Join Date: Sep 2003
Location: 100 miles N of London, UK
Posts: 221
Default

I'm using Mozilla in Linux, and it's coming up with the message at the bottom of the window 'Applet BlackBox started'. There's a tiny black square by 'Powered by phpBB 2...' at the bottom of this web page, with this in the source code:
Quote:
<script>document.write(unescape('%u003C%u0069%u .........
My partner, saying that the code looked dodgy, tracked down this: Virus Name: ByteVerify.exploit
Quote:
Description:

This is not a virus, but rather a method to exploit a security vulnerability in the Microsoft Virtual Machine. This vulnerability arises as the ByteCode verifier in the Microsoft Virtual machine does not correctly check for the presence of certain malformed code when a Java applet is loaded. Attackers could exploit this vulnerability by creating malicious Java applets and inserting them into web pages. These web pages could be hosted on a site by a malicious web master, or could be sent to users as an attachment. To read more about this issue, and to download the necessary patches, please visit:

http://www.microsoft.com/technet/sec.../MS03-011.mspx
Not my area of expertise, but it might help explain what's happening.

(Got here after reading FWIS posts and using a bookmark to an old thread!)
__________________
Carolyn

"All the screens are filled with heroes and losers, but the sky's still filled with stars"
...Midnight Oil - 'Golden Age'
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 05:01 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0
©  2006 Bad Astronomy and Universe Today