Solas wrote:I was using Google to search aegidian.org as results point to page,
and came accross a jsp that looked out of place, Google lists 240+
http//www.google.com/search?num=40&hl=en&q=js ... lr=lang_en
another thing ..
http//www.phpbb.com/index.php itself is down. ( vulnerability in an outdated PHPList )
http//community.mybboard.net/thread-44513.html advises on this.
hope this helps
Solas
Reporting spam
Moderators: winston, another_commander, Cody
- DaddyHoggy
- Intergalactic Spam Assassin
- Posts: 8515
- Joined: Tue Dec 05, 2006 9:43 pm
- Location: Newbury, UK
- Contact:
Oolite Life is now revealed hereSelezen wrote:Apparently I was having a DaddyHoggy moment.
- JensAyton
- Grand Admiral Emeritus
- Posts: 6657
- Joined: Sat Apr 02, 2005 2:43 pm
- Location: Sweden
- Contact:
Well, that was interesting.DaddyHoggy wrote:Solas wrote:I was using Google to search aegidian.org as results point to page,
and came accross a jsp that looked out of place, Google lists 240+
http//www.google.com/search?num=40&hl=en&q=js ... lr=lang_en
another thing ..
http//www.phpbb.com/index.php itself is down. ( vulnerability in an outdated PHPList )
http//community.mybboard.net/thread-44513.html advises on this.
hope this helps
Solas
It appears that part of a distributed warez network had been hidden in our images/avatars/ directory. Until I have a good explanation for how that happened, uploading of avatars is disabled again. As far as I’m aware we don’t use PHPList for anything Oolite-related, but Giles may have it installed for some other part of aegidian.org, possibly something that’s no longer used. I’ve e-mailed him about it.
Out of interest, the following out-of-place files were in images/avatars/ (modification dates in parens):
- index.htm (modified from original blank page; 2005-10-05 00:00)
- time.php (2005-10-05 00:00)
- date.php (2005-10-05 00:00)
- 13923715934416f3d4e57ff.php (2005-10-05 00:00)
- .htaccess (2005-10-05 00:00)
- ferrometer91/ (2008-11-01 08:21)
- ferrometer91/.htaccess (2008-11-01 08:21)
- ferrometer91/guest.php (2008-12-16 12:14)
- ferrometer91/messages.php (2008-12-16 12:13)
I know a couple of our users manage phpBBs of their own; I suggest taking a look in your avatars directory. There should be no .htaccess file, no php files, no subdirectories other than gallery, and index.htm should be a blank page containing no JavaScript. (Note: these details may not be correct for phpBB 3.)
E-mail: [email protected]
- Commander McLane
- ---- E L I T E ----
- Posts: 9520
- Joined: Thu Dec 14, 2006 9:08 am
- Location: a Hacker Outpost in a moderately remote area
- Contact:
- Captain Hesperus
- Grand High Clock-Tower Poobah
- Posts: 2310
- Joined: Tue Sep 19, 2006 1:10 pm
- Location: Anywhere I can sell Trumbles.....
https://bb.oolite.space/viewtopic.php?p=70187#70187
<ka-chik> BOOOOOOOOOOOOOOOOOOOOOOMMM!!!!
Captain Hesperus
<ka-chik> BOOOOOOOOOOOOOOOOOOOOOOMMM!!!!
Captain Hesperus
The truth, revealed!!
- Commander McLane
- ---- E L I T E ----
- Posts: 9520
- Joined: Thu Dec 14, 2006 9:08 am
- Location: a Hacker Outpost in a moderately remote area
- Contact:
- Captain Hesperus
- Grand High Clock-Tower Poobah
- Posts: 2310
- Joined: Tue Sep 19, 2006 1:10 pm
- Location: Anywhere I can sell Trumbles.....
- Disembodied
- Jedi Spam Assassin
- Posts: 6885
- Joined: Thu Jul 12, 2007 10:54 pm
- Location: Carter's Snort
- Disembodied
- Jedi Spam Assassin
- Posts: 6885
- Joined: Thu Jul 12, 2007 10:54 pm
- Location: Carter's Snort
-
- Quite Grand Sub-Admiral
- Posts: 6682
- Joined: Wed Feb 28, 2007 7:54 am
*
This one is definitely spamming and has posted the same message all over the Internet. I just deleted it from Outworld, so would one of our esteemed Spam Assassins do the honors and terminate the bot?
This one is definitely spamming and has posted the same message all over the Internet. I just deleted it from Outworld, so would one of our esteemed Spam Assassins do the honors and terminate the bot?
- Disembodied
- Jedi Spam Assassin
- Posts: 6885
- Joined: Thu Jul 12, 2007 10:54 pm
- Location: Carter's Snort
- Disembodied
- Jedi Spam Assassin
- Posts: 6885
- Joined: Thu Jul 12, 2007 10:54 pm
- Location: Carter's Snort
- Disembodied
- Jedi Spam Assassin
- Posts: 6885
- Joined: Thu Jul 12, 2007 10:54 pm
- Location: Carter's Snort
- DaddyHoggy
- Intergalactic Spam Assassin
- Posts: 8515
- Joined: Tue Dec 05, 2006 9:43 pm
- Location: Newbury, UK
- Contact:
Is anybody actually killing these off? All the ones identified so far are still present and correct
[unpacks Silent Death and watches the door as new members shuffles in]
[unpacks Silent Death and watches the door as new members shuffles in]
Oolite Life is now revealed hereSelezen wrote:Apparently I was having a DaddyHoggy moment.
-
- Quite Grand Sub-Admiral
- Posts: 6682
- Joined: Wed Feb 28, 2007 7:54 am
I was under the impression that members tagged as Spam Assassins had the power to do this. Unfortunately moderators cannot interfere with user status, otherwise these spam instances would have been already sanitized. If the SAs cannot do anything, then I guess it's up to one of the forum admins.DaddyHoggy wrote:Is anybody actually killing these off? All the ones identified so far are still present and correct