Go to Post Frank is frank, and I like that. - rsisk [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications > Website Design/Showcase
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 25-06-2009, 02:46
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
ATTENTENTION Webmasters - possible security vulnerability on school networks

This post is mainly intended as a warning, but also to see if anyone else has been affected.

Our school used to run Moodle, a sort of CMS / Online class software, and recently, the school newspaper's website (which i maintain along with our robotics site) got hacked.

curiously though, the result of the hack was the addition of a div marked display:none (thankfully) that contained links to pages on a ton of moodle sites. however, when we investigated a coupple of the sites, they seemed fishy. the pages had been added maliciously to the websites, and contained no relevance to the host.

it see if your website has a similar problem, put some comments like this around your "BODY" tag:

Code:
<!--The ghost div starts IMMEDIATELY after the open body tag.-->
<body><!--end ghost spam div-->
when you render the website in a browser, right click and hit "view source" if your site has been affected, there will be a huge ghost div in between the body tag and the second comment.

try viewing the source of this page (our newspaper site)

so far, we've been lucky and haven't had the div turn visible, but want to spread the word that this is happening to see if anyone knows how to stop it.

we have tried virus-scans, spyware scans... etc... and nothing has turned up. hopefully, not many people have this kind of problem, but if you do, please post here so that we can all check out each others sites. the way i see it, the more people we have looking, the better.

if you have any ideas on how to fix this type of problem, Please post! it would be much appreciated.

-Z
__________________
[center]
  #2   Spotlight this post!  
Unread 25-06-2009, 11:17
SushaK's Avatar
SushaK SushaK is offline
Registered User
AKA: Susha The Russian
FRC #0461 (Westside Boiler Invasion)
Team Role: Mechanical
 
Join Date: Jan 2009
Rookie Year: 2007
Location: West Lafayette, IN
Posts: 49
SushaK has a spectacular aura aboutSushaK has a spectacular aura about
Send a message via AIM to SushaK
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

my school uses moodle for some classes but just as a way to post practice quizzes and assignments and as a way to chat with teachers or as an easier way to get ahold of the teachers. we don't actually use it much though and i personally havent used it since last year... but thanks for the warning, i'll make sure to ckeck it out and warn our tech advisor. good luck with your problem and hopefully it'll go away!
__________________
BOILER UP!

  #3   Spotlight this post!  
Unread 25-06-2009, 16:23
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

curiously enough though (i forgot to mention this earlier) the list of links doesn't appear in the moodle system, it's currently appearing on a sepparate system, the newspaper, which was hand-coded by myself and a friend.

the reason we're pointing the finger toards moodle is because the links ALL go to sites using moodle!

also, if you look at the rendered source of the site (loaded in a browser) every page (categories etc...) has a different list of links, and the whole set changes every coupple days! but, without fail, they are all moodle!!!

if i were you, i'd have the tech person check every website and page on the domain.

-Z
__________________
[center]
  #4   Spotlight this post!  
Unread 28-06-2009, 13:29
Andrew Schreiber Andrew Schreiber is offline
Joining the 900 Meme Team
FRC #0079
 
Join Date: Jan 2005
Rookie Year: 2000
Location: Misplaced Michigander
Posts: 4,060
Andrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond repute
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

That is strange.

Have you filed a report with the makers of Moodle?

Have you checked through all of the javascript on the page? A virus scan won't find AJAX calls to external pages. If the content is changing it has to have a source, if a virus scan found nothing chances are it isn't local to you. ( I did a quick scan through of it but being unfamiliar with the system I would have missed it)

Does that appear on every page or just certain ones?

A quick google search didn't return results for the phrases other than your newspaper site.
__________________




.
  #5   Spotlight this post!  
Unread 28-06-2009, 15:07
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

unfortunatley, the only person with contact info for moodle (other than the non-responsive online suport email) is the tech coord at our school, and he's on vacation.

my friend and i hand-coded the pages (there are several, but all are "included" by index.php)i've looked through every script, and none of them reference external files; whenever i get a new script or such that does, i download the source (if it's creative commons) and tweak it, removing any external references.

oddly, the only place that the code shows up is the "rendered" source. the files on our server are clean.

we'll be contacting moodle as soon as our tech gets back.

another funny thing, making me think that this has nothing to do with the code, is that when we renamed index.php to index1.php, the problem went away, for a couple days, but, so did our site (index1 will not get auto-called like index)

thanks for the ideas,

-Z
__________________
[center]
  #6   Spotlight this post!  
Unread 28-06-2009, 17:38
Andrew Schreiber Andrew Schreiber is offline
Joining the 900 Meme Team
FRC #0079
 
Join Date: Jan 2005
Rookie Year: 2000
Location: Misplaced Michigander
Posts: 4,060
Andrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond reputeAndrew Schreiber has a reputation beyond repute
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

Try renaming the page then having index.php redirect to index1.php. Odd problem.
__________________




.
  #7   Spotlight this post!  
Unread 28-06-2009, 18:51
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

we tried that, but it seems that the redirect connects the files just enough to cause the divs to keep appearing!

once the tech gets back, we'll try migrating the entire site to a different location on the server, then moving the DNS reference...

hopefully, that'll help.

-Z
__________________
[center]
  #8   Spotlight this post!  
Unread 29-06-2009, 16:15
OScubed's Avatar
OScubed OScubed is offline
Lee Drake, CEO, OS-Cubed Inc.
AKA: Lee Drake
FRC #1511 (Rolling Thunder)
Team Role: Parent
 
Join Date: Mar 2008
Rookie Year: 2006
Location: Rochester, NY
Posts: 156
OScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond reputeOScubed has a reputation beyond repute
Send a message via ICQ to OScubed Send a message via AIM to OScubed Send a message via MSN to OScubed
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

It looks like link generating spam. This is placed into remote sites to point back at other sites for advertising SEO. Many spiders won't notice that they are in a hidden div, so the links back to the original sites increase (in a black hat kind of way) the linkscore of the target.

Have you commented out the following JS to be sure they're not injecting the div:

Colourloverscolorpicker.js
print.js
ddaccordion.js
lnews.js

Check this link on the moodle site for additional info:
http://moodle.org/mod/forum/discuss.php?d=116103

If your webmaster downloaded a template from a "free site" the linkspam js may be embedded in the moodle skin.
__________________
Lee Drake, CEO, OS-Cubed, Inc.
Business Mentor - team 1511
Rochester, NY

Building optimal, stable, secure solutions to your business challenges.


Last edited by OScubed : 29-06-2009 at 16:24.
  #9   Spotlight this post!  
Unread 29-06-2009, 16:41
ZInventor's Avatar
ZInventor ZInventor is offline
Registered User
AKA: Zeno Le Héricy
FRC #2915 (Riverdale Robotics Pandamonium)
Team Role: Alumni
 
Join Date: Feb 2008
Rookie Year: 2000
Location: Portland Oregon USA
Posts: 247
ZInventor is just really niceZInventor is just really niceZInventor is just really niceZInventor is just really nice
Re: ATTENTENTION Webmasters - possible security vulnerability on school networks

Quote:
Originally Posted by OScubed View Post
Have you commented out the following JS to be sure they're not injecting the div:

Colourloverscolorpicker.js
print.js
ddaccordion.js
lnews.js
lnews.js and print.js are scripts we've written, and both of the other scripts have been heavily modified, and do not reference any other files, unless i missed something... (after all, i was working late at night)

now that you mention it,i've re-checked the scripts, and they are all clean...

the only scipt i haven't modified is http://ajax.googleapis.com/ajax/libs.../jquery.min.js, but i use that on several other sites without any issues...

looking at the pages referenced in the ghost div, it doesn't seem to be for advertizing... all the pages seem to be located on sites they have no relation to, most of which are schools and universities, and all of which run moodle

i wasn't able to get to the moodle discussuion board, as i do not have an account... however, i will talk with the tech coordinator at school to see if he has one.

thanks for the thought though,

-Z
__________________
[center]
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireless Networks(A/B/G/N) kiettyyyy Rules/Strategy 4 11-02-2009 15:04
Attention all Webmasters out there.... Meyer_Shuky Website Design/Showcase 46 12-01-2004 16:53
Webmasters...its here! blueWarrior Website Design/Showcase 0 25-12-2003 10:10
Exchange of Picture/Ideas for Webmasters Next Year archiver 2000 3 23-06-2002 23:21
Team Webmasters robophent Chit-Chat 6 06-03-2002 21:32


All times are GMT -5. The time now is 15:48.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi