Is there malware on the site?

Discussion in 'Suggestion Box' started by judobrian, Sep 11, 2013.

  1. judobrian

    judobrian New Member

    Country:
    United States
    Joined:
    Sep 8, 2012
    Messages:
    69
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    Colorado
    Map
    Often when I try to go to VFRWorld I get redirected to this URL: http:// myfilestore.com/download.php?id=a8cdee57 (<-- Added the space to make the URL show without a link to it)

    No idea what is going on, but it seems like there is something trying to hijack the browser. Does anyone else see this?
     
  2. PawnBoy

    PawnBoy New Member

    Country:
    Canada
    Joined:
    Jun 23, 2013
    Messages:
    286
    Likes Received:
    24
    Trophy Points:
    18
    Location:
    Waterloo, ON
    Map
    Yeah...I get that when I try to access the forums from a search engine link...
     
  3. TOE CUTTER

    TOE CUTTER Mullet Man

    Country:
    United States
    Joined:
    Nov 30, 2008
    Messages:
    6,731
    Likes Received:
    85
    Trophy Points:
    78
    Location:
    Sacramento
    Map
    Been like that for a long time.
     
  4. 34468 Randy

    34468 Randy Secret Insider

    Country:
    Canada
    Joined:
    Dec 18, 2007
    Messages:
    13,743
    Likes Received:
    1,558
    Trophy Points:
    158
    Location:
    Chilliwack, BC Canada
    Map
    I just started getting this "VisualBee" header on any VFRWorld page that I access through a link from and email. When I try to navigate back and forth using the "Back" and "Forward" arrows, I end up with a blank light blue page. Did a bit of reading on this VisualBee thing and it appears it is hidden as an add on from some other program you may have downloaded. I have tried everything to get rid of it, and have gotten rid of most of it, but it seems to be parked on VFRW when you access VFRW through a link in the mail. I don't have this problem when I go to VFRW using their homepage addy. I thought I may have picked this up when I downloaded one of Garmin's Map reading plugins but now I don't know. Going to call in my techy to figure this out cause I just get all pissed off at computers when I try to fix the fuggers. Just makes me wann, ah, i dunno, drink or something you know.
     
  5. skimad4x4

    skimad4x4 "Official" VFRWorld Greeter

    Country:
    France
    Joined:
    Jul 5, 2009
    Messages:
    2,273
    Likes Received:
    370
    Trophy Points:
    113
    Location:
    French Alps & London
    Map
    I am really disappointed this hack has not been removed months ago by the Admin on VFRW!

    This is due to a well known hack into vBulletin based forum software (the software used by VFRW and thousands of other forums). Most worrying it means the core forum software is currently compromised and critical files with things like real user names, emails, passwords, PM messages etc could all be at risk. If you want to get techy then its all explained here along with how to fix it...

    Vbulletin myfilestore hack - Find the traces and remove them - Club Myce

    So come on folks - I am happy to financially support the site - so please do your bit - follow the advice and it should be history and the forum software should be safe again.





    SkiMad
     
  6. signal

    signal Definitely Not New Member

    Country:
    United States
    Joined:
    Jun 29, 2013
    Messages:
    292
    Likes Received:
    15
    Trophy Points:
    18
    Very annoying, hopefully this gets fixed soon
     
  7. mello dude

    mello dude Administrator

    Country:
    Romania
    Joined:
    Jan 3, 2006
    Messages:
    4,135
    Likes Received:
    321
    Trophy Points:
    113
    Location:
    Southwest Ohio
    Map
  8. michael

    michael Administrator Staff Member

    Country:
    United States
    Joined:
    Dec 18, 2005
    Messages:
    1,253
    Likes Received:
    44
    Trophy Points:
    83
    Location:
    Kihei, Maui, Hawaii
    Map
    While it may appear that this issue is as straight-forward as the link you posted, I'm afraid that is not the case. That article you posted lists many suggestions for preventing this issue from occurring, and although the suggestions on that page were previously implemented (as well as countless others), the redirect keeps coming back. This is a very common issue not only for sites running vBulletin, but other types of forum software as well. There are many theories out there on how to the hackers are gaining access, but there hasn't been one obvious solution to the problem. We have spent countless hours researching potential solutions and implementing security enhancements over the past 3 years since this issue first started happening. For the most part, we've been successful in removing the hack and preventing it, but unfortunately it has reappeared on VFRworld 4 or 5 times over the years. In this most recent case, it also caused Google to automatically flag the site as "malware", which causes some users to receive a warning page when they go to VFRworld.

    For the record, it is not true that this hack exposes private information from within VFRworld. What this hack does is inserts a redirect, such that when you attempt to load certain pages, it automatically takes you to an external site. I suppose it's possible that external site could install malware on your computer, but I wanted to make sure there wasn't confusion that the VFRworld member information has been compromised.

    I assure you that the admins of VFRworld are working as hard as possible to always stay up to take with potential security vulnerabilities, and that's why we occasionally must be down for upgrades, etc.

    We are implementing additional safeguards this week, including another version upgrade, to hopefully reduce our risk. It may take some time for Google to officially scan the site to remove the malware warning, so don't be surprised if that doesn't happen immediately.

    As always, I appreciate the feedback, and the support of the VFRworld community. We are doing our best to ensure the safety of the site, and our users privacy and experience are the number one priority, besides keeping our bikes shiny and maintained.

    :drinker:
     
  9. michael

    michael Administrator Staff Member

    Country:
    United States
    Joined:
    Dec 18, 2005
    Messages:
    1,253
    Likes Received:
    44
    Trophy Points:
    83
    Location:
    Kihei, Maui, Hawaii
    Map
    Can you post a screenshot of this issue? This does not sound like it's related to the other issue mentioned in this thread, and doesn't sound like a VFRworld issue, but a screenshot would help (or if anyone else has experienced this issue, please let us know also).
     
  10. squirrelman

    squirrelman Member

    Country:
    United States
    Joined:
    Jul 27, 2006
    Messages:
    9,865
    Likes Received:
    753
    Trophy Points:
    128
    Location:
    Buffalo, NY
    Map
    YES !! And it's infueriating

    "Warning: Attack Page" is what i saw + this.........

    Diagnostic page for vfrworld.com/forums

    What is the current listing status for vfrworld.com/forums?

    Site is listed as suspicious - visiting this web site may harm your computer.

    What happened when Google visited this site?

    Of the 241 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-09-12, and the last time suspicious content was found on this site was on 2013-09-12.

    Malicious software is hosted on 1 domain(s), including myfilestore.com/.

    This site was hosted on 1 network(s) including AS11051 (CYBERVERSE).

    Has this site acted as an intermediary resulting in further distribution of malware?

    Over the past 90 days, vfrworld.com/forums did not appear to function as an intermediary for the infection of any sites.

    Has this site hosted malware?

    No, this site has not hosted malicious software over the past 90 days.

    How did this happen?

    In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

    Next steps:

    Return to the previous page.
    If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.

    Updated 5 hours ago

    ©2008 Goog
     
  11. michael

    michael Administrator Staff Member

    Country:
    United States
    Joined:
    Dec 18, 2005
    Messages:
    1,253
    Likes Received:
    44
    Trophy Points:
    83
    Location:
    Kihei, Maui, Hawaii
    Map
    Yes, this is the "Google Malware" warning that I was referring to. Basically, Google is currently doing an automated scan to verify that the issue has been resolved, and then they will remove that message. Like, I said, it may take some time. Everything with Google tends to take time.
     
  12. 34468 Randy

    34468 Randy Secret Insider

    Country:
    Canada
    Joined:
    Dec 18, 2007
    Messages:
    13,743
    Likes Received:
    1,558
    Trophy Points:
    158
    Location:
    Chilliwack, BC Canada
    Map
    I am not having any luck with this Michael. When I try to import a screen shot, it wont accept the image. I really don[t know what is going wrong here. I have my lap top next to me and using microsoft help to do a print screen to no avail.

    I don't think it is related though. If I access VFRW through Firefox, then there is no issue other than the Google warning which I have ignored. It is only when I access VFRW by clicking on a notification of subscribed thread link i get in my e-mail, that I get this header.

    The header is VisualBee (on the top left banner) and several link icons across the banner. This happens on my PC and not my notebook. Seems this showed up after I tried to download updates to my Garmin Products which was done on the PC. It showed up even when I went to VFRW right from my Firefox browser but I was able to get rid of that by uninstalling it. However, it still showed up when I hit a link in the email message from VFRW.

    I have a tech coming early next weeks and I will tell him about VFRW's problems and see what he thinks if my issue is associated with yours. Meantime, if I manage to accomplish this screenshot, I will send it along. I don't understand why I cannot get the screenshot. Maybe my keyboard is TU.
     
  13. NormK

    NormK New Member

    Joined:
    Jul 12, 2012
    Messages:
    1,821
    Likes Received:
    3
    Trophy Points:
    0
    At least I feel better now, I thought it was just me
     
  14. tinkerinWstuff

    tinkerinWstuff Administrator Staff Member

    Country:
    United States
    Joined:
    Oct 5, 2009
    Messages:
    7,831
    Likes Received:
    91
    Trophy Points:
    78
    Location:
    Colorado Front Range
    Map

    :gossip: Inside job.

    That Jason character has always been a bit shady IMO. :peep:
     
  15. TOE CUTTER

    TOE CUTTER Mullet Man

    Country:
    United States
    Joined:
    Nov 30, 2008
    Messages:
    6,731
    Likes Received:
    85
    Trophy Points:
    78
    Location:
    Sacramento
    Map
    Jason is from Iran?
     
Related Topics

Share This Page