Forum Home

Master Index of Archived Threads


Go Phish

John Cougar Lunchbucket
May 10 2012 04:37 PM

My Kaspersky picked up a phishing site warning when I surfed to CPF this evening. Anyone else get the same warning?

themetfairy
May 10 2012 06:10 PM
Re: Go Phish

I just got a warning on McAfee about a risky site when I came here.

John Cougar Lunchbucket
May 10 2012 06:15 PM
Re: Go Phish

weayvuav (dot) igg (dot) biz etc.

d'Kong76
May 10 2012 08:15 PM
Re: Go Phish

Getting blocked attack messages too.

John Cougar Lunchbucket
May 10 2012 08:46 PM
Re: Go Phish

different url now but still happening

batmagadanleadoff
May 10 2012 09:14 PM
Re: Go Phish

John Cougar Lunchbucket wrote:
My Kaspersky picked up a phishing site warning when I surfed to CPF this evening. Anyone else get the same warning?


Me too, even though I dunno what's a Kaspersky. Also, my board index is now suddenly giant sized.

Ceetar
May 10 2012 09:21 PM
Re: Go Phish

batmagadanleadoff wrote:
John Cougar Lunchbucket wrote:
My Kaspersky picked up a phishing site warning when I surfed to CPF this evening. Anyone else get the same warning?


Me too, even though I dunno what's a Kaspersky. Also, my board index is now suddenly giant sized.


seeing the giant sized thing, no phishy warning though.

Edgy MD
May 10 2012 09:45 PM
Re: Go Phish

I gots the giant board index, but no warnings.

Edgy MD
May 10 2012 09:48 PM
Re: Go Phish

Yeah, I take it back. Norton's warning me of maliciousness coming from iweayvuav.igg.biz.

Think it could have something to do with me uploading a picture as an attachment earlier today?

batmagadanleadoff
May 10 2012 09:54 PM
Re: Go Phish

I can't prove it, but I know that this is somehow connected to Soupy's creepy see-through middle finger.

Benjamin Grimm
May 11 2012 03:52 AM
Re: Go Phish

Edgy DC wrote:
Yeah, I take it back. Norton's warning me of maliciousness coming from iweayvuav.igg.biz.

Think it could have something to do with me uploading a picture as an attachment earlier today?


I'm seeing the warning and the giant text too. I wouldn't think it was from a photo attachment, but I suppose it's possible. What was the source of the photo?

I started seeing the warning late yesterday afternoon. Maybe around 4 p.m.?

Edgy MD
May 11 2012 05:09 AM
Re: Go Phish

The giant text and warnings seem gone now. I'm the best administrator ever!

TransMonk
May 11 2012 06:28 AM
Re: Go Phish

I still have big screen-ness but no warnings.

Benjamin Grimm
May 11 2012 06:45 AM
Re: Go Phish

I'm still seeing both effects.

Edgy MD
May 11 2012 07:06 AM
Re: Go Phish

So any suggestions? Should we re-boot it all?

Ceetar
May 11 2012 07:08 AM
Re: Go Phish

I saw the big text at home and work yesterday, but don't see it now. I wonder if i even have phishing software.

Benjamin Grimm
May 11 2012 07:11 AM
Re: Go Phish

I think we should ask KC to open a ticket with the company that hosts the site.

Did anyone upload any attachments late yesterday afternoon that were something other than photos taken with their own camera?

I don't know if attachments are the cause of this, but I'm a little leery of them nonetheless.

Benjamin Grimm
May 11 2012 07:32 AM
Re: Go Phish

http://www.symantec.com/security_respon ... asid=23928

MFS62
May 11 2012 08:06 AM
Re: Go Phish

TransMonk wrote:
I still have big screen-ness but no warnings.

This.
Later

d'Kong76
May 11 2012 01:07 PM
Re: Go Phish

I reported the issue to the hosting company. Will keep everyone
posted when I hear something back.

d'Kong76
May 11 2012 07:02 PM
Re: Go Phish

Email from forum host:

There has been a zero day security vulnerability announced when running php as cgi. It appears that this is an issue in most versions of PHP.
Here is the announcement from php.net
http://www.php.net/archive/2012.php#id2012-05-03-1
We are patching all shared hosting servers. All dedicated servers should also be patched if they run php as cgi.
Please contact (link remove by Kong76) technical support at:
(link removed by Kong76) if you have any questions.

Thanks
(Sig removed by Kong76) Admin Team

d'Kong76
May 12 2012 05:26 AM
Re: Go Phish

I'm still getting big font on index page but .....

Email from forum host:

The PHP community still does not have a official fix for the security vulnerability. We have though applied the 2 recommended fixes.
Lastly to ensure that there was not any rogue files uploaded by hackers, We restored the web content from May 5ths backup.
There is only one known issue with the applied patches. One of the patches required that we rebuild all the configuration files for each of your hosted domains. When these files are rebuilt, the system re-populated the system default index.html file for each hosted domain. By restoring the backup most of these default index.html files were put back to the backup from May 5th.
From there, We have applied the industry accepted temporary fix while the PHP community determines how to permanently close the security hole.
Please review announcement number 1, 2, 3, and Final for additional information.
Please direct all questions to the service ticket system at: (link removed by Kong76)

Sincerely,
(Sig removed by Kong76) Senior Engineering Team