win a ball from Bowling.com

Author Topic: Issues On Sunday & Monday Afternoon-Evening (Aka WHERE DID MY STUFF FROM SUNDAY GO!)  (Read 4610 times)

BallReviews-TECH

  • Administrator
  • Sr. Member
  • *****
  • Posts: 480
There was an attempted security breach against our SQL database on Sunday afternoon that caused issues with our site until the evening. This attempt was unsuccessful at retrieving any information from our systems (so all emails, passwords, etc were kept secure) but some dynamic aspects of the site were changed during this period. Because of this, I suggest all users virus-scan and spyware-scan their systems if you visited the site on Sunday. If you do not have av or spyware scanning software installed I would suggest:
http://www.free-av.com/ <-Avira AntiVir
or
http://free.grisoft.com/ww.download-avg-anti-virus-free-edition <-AVG Free Edition
for av scanning and
http://www.safer-networking.org/en/index.html <-SpyBot S&D
for spyware scanning.

To ensure that no traces of any site changes remained we have reverted to our backup from Saturday night which means all posts, pm''s, etc... made after the backup were removed.

Update: As some of you noticed. There was another breach Monday afternoon that used a different vector than the initial breach. Because we saw multiple vectors in use, we made the decision to pull down the site Monday in the early evening and have been testing and reworking the logic for all pages on the site. We have also removed some older pages that we were seeing attempts against. In order to clean up after Monday we did have to revert our user table back to a the Monday at midnight backup. This means that the users who signed on Monday were lost along with their posts and pm''s however, all posts and pm''s made by existing users were retained. Please note that we are continuing to do everything possible to ensure the integrity of this site and your security.

-BR-Tech

Edited on 5/11/2008 10:19 PM

Edited on 5/13/2008 2:19 AM
-BR-Tech

 

charlest

  • Hero Member
  • *****
  • Posts: 24526
Thank you, BR-Tech, for the rapid response and for re-securing our treasured web site.

My virus ware protected my PC; I hope everyone had some virus scan software on theirs.

Why the low life pond scum keep trying this crap is beyond me. May Kharma pay them back for the damage they intend to cause.
--------------------
"None are so blind as those who will not see."
Unofficial Ballreviews.com FAQ
"None are so blind as those who will not see."

Debina

  • Sr. Member
  • ****
  • Posts: 345
My software found and destroyed the VBS/Psyme Trojan when I tried to log in earlier today.  If your computer seems to be acting oddly since being on this site today, I'd suggest doing a search for this specific file and getting rid of it ASAP.

Deb
--------------------
Do you want to play.net?

Joe Jr

  • Hero Member
  • *****
  • Posts: 2776
Should we be worried that whoever got onto the site got our passwords?
--------------------
My Vid
Formerly Brunswick Lefty & Richard Cranium


BallReviews-TECH

  • Administrator
  • Sr. Member
  • *****
  • Posts: 480
There has been no indication that the user information area of our db was breached. That being said, if you do run a virus scan and find some of the little buggers on your machine, they could expose your passwords from your local machine. So you may want to change some passwords if you find an infection.

-BR-Tech
-BR-Tech

ThongPrincess

  • Hero Member
  • *****
  • Posts: 3179
quote:
My software found and destroyed the VBS/Psyme Trojan when I tried to log in earlier today.  


Same here.  It said it was in a temporary internet file.  In addition to the virus protection software finding and destroying it, I also ran disc cleanup and deleted all temporary internet files.
--------------------
USBC Bronze Coach

"I cannot change the direction of the wind but I can adjust my sails to reach my destination." Jimmy Dean
Quaker 10/93 - 4/07
Quaker
USBC Bronze Coach

"I cannot change the direction of the wind but I can adjust my sails to reach my destination." Jimmy Dean
Quaker 10/93 - 4/07

I am a proud member of BallReviews.com and  Bowling Boards.com forums

Quaker

Lillen

  • Hero Member
  • *****
  • Posts: 1287
I use this:

http://www.filehippo.com/download_ccleaner/

I've also got ad-aware, spybot and tweak reg cleaner..

Monster Pike

  • Hero Member
  • *****
  • Posts: 19904
  • Be careful what you wish for...;)
quote:
How could you let this happen BR TECH? Do you know nothing about securing websites. You should be fired!
--------------------
It is not the ball it is the BOWLER!


Hey bowling eh, maybe it was an inside job, just like you think 9/11 was.
--------------------
"The last time I saw a face like that, it had a hook in it's mouth." Rodney Dangerfield

bowlingnut2008

  • Full Member
  • ***
  • Posts: 105
Yea, my computer blocked and removed like 5-8 trojans once I restarted my computer later sunday night.

MI 2 AZ

  • Hero Member
  • *****
  • Posts: 8156
Is there a problem with the private message system?  I get an error when I try to send one.

Edited to add:

This is the error message I am getting.  Tried to send one to BR-TECH also as a test.

ADODB.Recordset error '800a0e78'

Operation is not allowed when the object is closed.

/Messaging/ComposeMessage.asp, line 110
--------------------

I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________

New to BR? - Please check this:  BR FAQ

Edited on 5/13/2008 2:52 AM
_________________________________________
Six decades of league bowling and still learning.

ABC/USBC Lifetime Member since Aug 1995.

BallReviews-TECH

  • Administrator
  • Sr. Member
  • *****
  • Posts: 480
Working on it now. Not related to any security breaches (in case anyone is worried) but rather the new code we put in place to help prevent the breaches.
-BR-Tech
-BR-Tech

BallReviews-TECH

  • Administrator
  • Sr. Member
  • *****
  • Posts: 480
Messaging should be running now.
-BR-Tech
-BR-Tech

MI 2 AZ

  • Hero Member
  • *****
  • Posts: 8156
I'll check it in a minute.  If you get the chance to, I left a post under the topic 'Site Under Attack AGAIN' for you.
--------------------

I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________

New to BR? - Please check this:  BR FAQ
_________________________________________
Six decades of league bowling and still learning.

ABC/USBC Lifetime Member since Aug 1995.

charlest

  • Hero Member
  • *****
  • Posts: 24526
I had trouble accessing Messages last night, Monday, 5/12, around 10 PM.
Today, Tuesday morning, 6 AM Eastern time, all seems fine.
--------------------
"None are so blind as those who will not see."
Unofficial Ballreviews.com FAQ
"None are so blind as those who will not see."

pnj1967

  • Hero Member
  • *****
  • Posts: 3633
My Avast caught every thing (I hope).

 And its free too.

http://www.avast.com/eng/free_software.html
--------------------
Enjoy the people on the ballreview.com forum. Like to help when I can.

http://www.visionarybowling.com/TESTpullout2.html

Users,  I wont deal with,  CBB and Bingham's Bowling Supply Online Bowling Store and read my profile.