Lefora Free Forum
Loading
125 views

Spammers on my forum?

Page 1 · 2
(items) 1–20 of 23 Newer >
Regular - member
122 posts

OK, so we just got our first spam attack last night, with some members being attacked by various worm viruses (whilst not opening any links from suspect posters or anything like that)...

We're a small private forum, yet somehow got hacked into and made into a public one with automatic membership approval and no membership required to post... I fixed it all as soon as I could and things are OK now, but I'mwondering if any of the rest of you could share info/experiences for the benefit of myself and others on Lefora...???

My action plan was as follows:

(1) Change forum settings back to private with membership approval required.

(2) Delete spammers' various identities.

(3) Delete various spammers' posts (some containing erroneous virus-ridden links).

I'm new to all this, and so would very much appreciate any help, tips, or suggestions for what to do next time...

Many thanks!

Gethin :-D :-D :-D

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Regular - member
122 posts

Actually, I forgot to add a few other things I did..

* Changed forum title and description to warn members to scan PC for viruses.

* Spammed all members warning of recent attack.

Anything else I should do next time...???

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Fanatic - moderator
1396 posts

Have to say that changing your forum name looks ridiculous. wink If you want to warn your members then there's the group email option....

Either one of your admins had their password hacked (so that the forum rules could be changed) or they did it themselves.

Have all your admins change their passwords, just to be sure.

__________________
hackyour.lefora.com/ for customizing your forum.
Rookie - member
7 posts

I would like to know why and how my anti virus alerted me to the worms when I did not click a link.?

Any ideas?

__________________
Chairman of the bored. President of the state i'm in.
Regular - member
122 posts

Have to say that changing your forum name looks ridiculous.

-coloneljack

We do that on an almost daily basis anyway, just to reflect the mood/humour of the forum... ;-D

Have all your admins change their passwords, just to be sure.

-coloneljack

I thinks so. Warnings were posted to that effect, so I hope everyone has had the sense to do so...

I would like to know why and how my anti virus alerted me to the worms when I did not click a link.?
Any ideas?

-rockhopper

Quite right, mate! That's really got me confused as well. Still can't work out if it just targetted you, or if your antivirus detection is better than others. I'm hoping everyone else did the recommended scan just in case...

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Regular - member
122 posts

One more question - and please excuse me if the answer is obvious, as I'm no IT God... But, is it possible that a random image link off the internet posted on our forum could have been a backdoor for the spammers to get in...???

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Superstar - member
580 posts

Not in regards to the Spam attack, but long time ago, with one of the Lefora upgrades, some of the private Forums had been changed to public by mistake. Not sure if something similar may have happened to you that does not involve your Forum being Hacked.

As for the virus scan, recently the New York Times and other prominent websites was hit with a phony advertisement the purports to be a virus scan that says your computer was hosting a worm/virus. This was done to get unaware people to click on it and d/l a real virus. I am not sure if Windows has improved but it did have enough vulnerabilities that you could be compromised with out any action on your part. IE was/is a really insecure Browser and most computer professionals use others that are standard compliant.

__________________
Learn Linux in your spare time! Start now on a exciting future where the pay and prestige is unlimited. suseunbound.lefora.com/
Fanatic - moderator
1396 posts

Congratulations Matt - you managed not to mention Linux in a post. devil

__________________
hackyour.lefora.com/ for customizing your forum.
Superstar - member
580 posts

angel Mwaa? grin

__________________
Learn Linux in your spare time! Start now on a exciting future where the pay and prestige is unlimited. suseunbound.lefora.com/
Regular - member
122 posts

lol :-D

Have tried to encourage more of our members to run on Firefox, but in some cases the reply hs been "What's a web browser...?" D'oh!!

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Fanatic - moderator
1396 posts

lol :-D
Have tried to encourage more of our members to run on Firefox, but in some cases the reply hs been "What's a web browser...?" D'oh!!

-fossilmagnet

I feel your pain....

__________________
hackyour.lefora.com/ for customizing your forum.
Fanatic - founder
3758 posts

hi fossilmagnet, i'd be surprised if this could happen on your forum just from a spammer posting.  If anti-virus messages are popping up on your forum, it's possible that you, as the admin, added a third-party widget on the sidebar of your forum that has a something malicious in it.  This may not be the case, it's only an assumption.

I see your forum, luckypants.lefora.com, is set to fully private now. You can switch the forum to public, but restrict posting only to members you approve - Public is the security setting we recommend to take advantage of all the promotion features we offer (they only work on public forums).

__________________
find me answering questions at support.lefora.com or interviewing forum admins on blog.lefora.com
Regular - member
122 posts


I feel your pain....

-coloneljack

ROFL^ ;-D

hi fossilmagnet, i'd be surprised if this could happen on your forum just from a spammer posting.  If anti-virus messages are popping up on your forum, it's possible that you, as the admin, added a third-party widget on the sidebar of your forum that has a something malicious in it.  This may not be the case, it's only an assumption.

I see your forum, luckypants.lefora.com, is set to fully private now. You can switch the forum to public, but restrict posting only to members you approve - Public is the security setting we recommend to take advantage of all the promotion features we offer (they only work on public forums).

-chief

Tbh, I know very little about this kind of stuff, but what I can say for sure is we have no 3rd party widgets on there. I added a chatbox (as per threads on here) a while back, yet felt like the privacy of the forum was being compromised as a result, and so removed it. Other than that, nothing else has been added in the last 4+ months...

I'm more inclined to think that an admin with a "weak" password got hacked. Could well be wrong, naturally, and am always open to other suggestions...

As I see it, both Lefora and Firefox are pretty tight security-wise, so I'm inclined to look elsewhere in terms of trying to figure out how they got in...

Do you think a mod/admin with a "weak" password would be a likely suspect...?

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Fanatic - moderator
1396 posts


Do you think a mod/admin with a "weak" password would be a likely suspect...?

-fossilmagnet

Yes.

__________________
hackyour.lefora.com/ for customizing your forum.
Regular - member
122 posts

Yeah, I thought as much... Have already reduced the number of mods/admins and advised them to reset to stronger passwords. Hopefully that should do it... ;-D

Cheers!!!

__________________
The Lucky Pants Fossil Forum - luckypants.lefora.com/
Fanatic - founder
3758 posts

installing malicious software on the forum could come from an admin (with a compromised password), not so much a mod.  So I'd keep a close eye on the admin accounts and change the password.

__________________
find me answering questions at support.lefora.com or interviewing forum admins on blog.lefora.com
Rookie - member
7 posts

Not in regards to the Spam attack, but long time ago, with one of the Lefora upgrades, some of the private Forums had been changed to public by mistake. Not sure if something similar may have happened to you that does not involve your Forum being Hacked.
As for the virus scan, recently the New York Times and other prominent websites was hit with a phony advertisement the purports to be a virus scan that says your computer was hosting a worm/virus. This was done to get unaware people to click on it and d/l a real virus. I am not sure if Windows has improved but it did have enough vulnerabilities that you could be compromised with out any action on your part. IE was/is a really insecure Browser and most computer professionals use others that are standard compliant.

-mattb4

Hi mattb4

I am very aware of fake antivirus pop ups, I have schooled a number of people (older relations mainly) in how to spot the difference! LOL  no mean feat!!

I don't use IE ( strictly firefox - sometimes Chrome if the FF beta isnt working  lol)

I am 99% sure I did not click on a link or a picture on the particular thread , this concerns me.
 I have never experienced an attack when I have not been active in letting myself get attacked!!

I'm even beginning to doubt myself.  The only thing I can think of, is that I quoted the spammer to give him some abuse (I know, I know......  ignore them!!)

If you quote a message which contains a link to a virus are you in effect opening the link in some way??

This is the only thing that makes sense, as a direct attack through lefora  to my pc seems highly unlikely!?

Thanks for the responses guys :D

Great site by the way  :D

__________________
Chairman of the bored. President of the state i'm in.
Rookie - member
7 posts


"Hey Teal'c, what's with the hair?"

-coloneljack

The finest SCFI character ever to grace our screens!  lol

__________________
Chairman of the bored. President of the state i'm in.
Superstar - member
580 posts

I have not used Windows since 98SE so I have not kept up with the exploits of or means of securing from online attacks. Some of the best are to have a hardware based Firewall (routers have these) and not to open too many services. A site I have used in the past and I see is still active, will check to see what ports you have open and perhaps vulnerable to attack. Shields UP! — Internet Vulnerability Profiling  It also contains a lot of good material on setups to protect a PC from getting hacked. I have posted a screen shot of their beginning Statement. I also posted a results shot of my computer (I run openSUSE Linux and am not surprised that the results are unusual for a Windows computer). Note: this does not require you to install anything!

__________________
Learn Linux in your spare time! Start now on a exciting future where the pay and prestige is unlimited. suseunbound.lefora.com/
Rookie - member
7 posts

. A site I have used in the past and I see is still active, will check to see what ports you have open and perhaps vulnerable to attack. Shields UP!

-mattb4

I have disabled all of my "remote access" services.

Thanks for the link to the site:

I gave it a whirl.

I do run windows ...  lol     But I am still very,very tempted by linux



__________________
Chairman of the bored. President of the state i'm in.
Page 1 · 2
(items) 1–20 of 23 Newer >

Locked Topic


You must be a member to post in this forum