BallReviews
General Category => Miscellaneous => Topic started by: BallReviews-TECH on May 11, 2008, 02:06:27 PM
-
There was an attempted security breach against our SQL database on Sunday afternoon that caused issues with our site until the evening. This attempt was unsuccessful at retrieving any information from our systems (so all emails, passwords, etc were kept secure) but some dynamic aspects of the site were changed during this period. Because of this, I suggest all users virus-scan and spyware-scan their systems if you visited the site on Sunday. If you do not have av or spyware scanning software installed I would suggest:
http://www.free-av.com/ <-Avira AntiVir
or
http://free.grisoft.com/ww.download-avg-anti-virus-free-edition <-AVG Free Edition
for av scanning and
http://www.safer-networking.org/en/index.html <-SpyBot S&D
for spyware scanning.
To ensure that no traces of any site changes remained we have reverted to our backup from Saturday night which means all posts, pm''s, etc... made after the backup were removed.
Update: As some of you noticed. There was another breach Monday afternoon that used a different vector than the initial breach. Because we saw multiple vectors in use, we made the decision to pull down the site Monday in the early evening and have been testing and reworking the logic for all pages on the site. We have also removed some older pages that we were seeing attempts against. In order to clean up after Monday we did have to revert our user table back to a the Monday at midnight backup. This means that the users who signed on Monday were lost along with their posts and pm''s however, all posts and pm''s made by existing users were retained. Please note that we are continuing to do everything possible to ensure the integrity of this site and your security.
-BR-Tech
Edited on 5/11/2008 10:19 PM
Edited on 5/13/2008 2:19 AM
-
Thank you, BR-Tech, for the rapid response and for re-securing our treasured web site.
My virus ware protected my PC; I hope everyone had some virus scan software on theirs.
Why the low life pond scum keep trying this crap is beyond me. May Kharma pay them back for the damage they intend to cause.
--------------------
"None are so blind as those who will not see."
Unofficial Ballreviews.com FAQ (http://"http://home.mchsi.com/~s-cross-7-28-71/FAQ.htm")
-
My software found and destroyed the VBS/Psyme Trojan when I tried to log in earlier today. If your computer seems to be acting oddly since being on this site today, I'd suggest doing a search for this specific file and getting rid of it ASAP.
Deb
--------------------
Do you want to play.net (http://"http://www.play.net")?
-
Should we be worried that whoever got onto the site got our passwords?
--------------------
My Vid (http://"http://s37.photobucket.com/albums/e56/RevLefty/?action=view¤t=0415085.flv")
Formerly Brunswick Lefty & Richard Cranium
-
There has been no indication that the user information area of our db was breached. That being said, if you do run a virus scan and find some of the little buggers on your machine, they could expose your passwords from your local machine. So you may want to change some passwords if you find an infection.
-BR-Tech
-
quote:
My software found and destroyed the VBS/Psyme Trojan when I tried to log in earlier today.
Same here. It said it was in a temporary internet file. In addition to the virus protection software finding and destroying it, I also ran disc cleanup and deleted all temporary internet files.
--------------------
USBC Bronze Coach
"I cannot change the direction of the wind but I can adjust my sails to reach my destination." Jimmy Dean
Quaker 10/93 - 4/07
Quaker (http://"http://thongprincess.bowlspace.com/gallery/view_gallery.one?gal_id=1")
-
I use this:
http://www.filehippo.com/download_ccleaner/
I've also got ad-aware, spybot and tweak reg cleaner..
-
quote:
How could you let this happen BR TECH? Do you know nothing about securing websites. You should be fired!
--------------------
It is not the ball it is the BOWLER!
Hey bowling eh, maybe it was an inside job, just like you think 9/11 was.
--------------------
"The last time I saw a face like that, it had a hook in it's mouth." Rodney Dangerfield
-
Yea, my computer blocked and removed like 5-8 trojans once I restarted my computer later sunday night.
-
Is there a problem with the private message system? I get an error when I try to send one.
Edited to add:
This is the error message I am getting. Tried to send one to BR-TECH also as a test.
ADODB.Recordset error '800a0e78'
Operation is not allowed when the object is closed.
/Messaging/ComposeMessage.asp, line 110
--------------------
I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________
New to BR? - Please check this: BR FAQ (http://"http://www.ballreviews.com/Forum/Replies.asp?TopicID=74110&ForumID=16&CategoryID=5")
Edited on 5/13/2008 2:52 AM
-
Working on it now. Not related to any security breaches (in case anyone is worried) but rather the new code we put in place to help prevent the breaches.
-BR-Tech
-
Messaging should be running now.
-BR-Tech
-
I'll check it in a minute. If you get the chance to, I left a post under the topic 'Site Under Attack AGAIN' for you.
--------------------
I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________
New to BR? - Please check this: BR FAQ (http://"http://www.ballreviews.com/Forum/Replies.asp?TopicID=74110&ForumID=16&CategoryID=5")
-
I had trouble accessing Messages last night, Monday, 5/12, around 10 PM.
Today, Tuesday morning, 6 AM Eastern time, all seems fine.
--------------------
"None are so blind as those who will not see."
Unofficial Ballreviews.com FAQ (http://"http://home.mchsi.com/~s-cross-7-28-71/FAQ.htm")
-
My Avast caught every thing (I hope).
And its free too.
http://www.avast.com/eng/free_software.html
--------------------
Enjoy the people on the ballreview.com forum. Like to help when I can.
http://www.visionarybowling.com/TESTpullout2.html
Users, I wont deal with, CBB and Bingham's Bowling Supply Online Bowling Store and read my profile.
-
Awesome! Looks like I got infected too - good to know it was from here and not one of those pr0n sites!
I was wondering why my posts were gone.
--------------------
Unoffical Ballreviews.com FAQ (http://"http://www.ballreviews.com/Forum/Replies.asp?TopicID=74110&ForumID=16&CategoryID=5")
Search Ballreviews entire database here (http://"http://www.bowling-info.com/Search.html")
-
quote:
anyone who accessed the website in general
My AV program was tripping both logged in and not.
I had been logged in and reading several topics when the attack started. Logged out and just accessing this site set the AV off again.
--------------------
I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________
New to BR? - Please check this: BR FAQ (http://"http://www.ballreviews.com/Forum/Replies.asp?TopicID=74110&ForumID=16&CategoryID=5")
-
I have something weird going on with my home PC and this one only. When I connect to this site from my home PC using Internet Explorer, I am logged in on the home page.
When I click the link to go to the forum, I'm mysteriously not signed in anymore. When I login, it takes me back to the home page. Then when I try to go to the forum again, I'm logged out again..!!
So, I have to use another browser, which is Firefox to get in to the forums.
Is anyone else having this issue..? It's only happening with my home based PC. Weird... =:^D
This link http://www.ballreviews.com/Forum/Default.asp only shows posts up until 5/3/08. When I click into the Lane #1 forum... http://www.ballreviews.com/Forum/Topics.asp?ForumID=7&CategoryID=2 ...posts only come up until 5/10/08. When I click into any other forum, all the posts are current. Hmmmmm... =:^D
Edited on 5/16/2008 11:20 PM
-
Booling, I'm already in the forums. Right now, if I click on the links in my last post, using IE, it only shows posts up until 5/3/08 and 5/10/08 when I click into the Lane #1 forum. It only happens with my home PC and only when I'm using IE.
I can have another window open at the same time using a different browser, like Firefox, and the posts all come up to the current date. It is really weird. =:^D
-
T-God,
You might try restoring your computer to any day prior to 5-11 and see if that works. There are times when something happens and I can't get my computer to work right, so I click on the "restore" link and put in a date to a few days earlier and that usually does the trick, depending on what the problem was.
--------------------
"Whenever I feel the urge to exercise I lie down until the feeling passes away."
Brick
-
Brick, I'll give that a try. But to tel you the truth, every time I've tried to go back to a restore point, my computers have never reset back to that point. I think I have to create a restore point first, which I've never done, because the restore points/dates that look like you can go back to that are already set in the computer don't seem to work. I'll try it again. Thanks for the suggestion. =:^D
-
The restore worked, but it didn't cure the login problem. Oh well. =:^D
-
T-God, did you try clearing all your cookies in IE? You will probably have to log back in again after deleting the cookies.
Tools/Internet Options/Delete Cookies
--------------------
I am the Sgt Schultz of bowling.
"I know nothing! I see nothing! NOTHING!"
_________________________________________
New to BR? - Please check this: BR FAQ (http://"http://www.ballreviews.com/Forum/Replies.asp?TopicID=74110&ForumID=16&CategoryID=5")