Jump to content
Jays Centre
  • Create Account

Recommended Posts

Posted
Just posting this to let the admin know to fix the problem. There is an exploit through v-bull where the user gets re-directed to myfilestore after searching through and clicking on a google search of bluejaysmessageboard.com
Posted

He is correct, the site is redirecting from a google search to the following link (which I provide for reference, there is no reason to click on it.):

 

http://myfilestore.com/download.php?id=f7b0f43d

 

It looks as though the file that it was trying to push has been deleted by myfilestore.com, but it also tries to pop up an ad, and you can't get here. I don't know this platform enough to suggest a fix, but I imagine there is one out there...

Posted
How exactly are you bringing it up? I've tried firefox/ie/chrome, cleared cookies, searched for bluejaysmessageboard.com in google and can click through no problem on each, can also sign in.
Posted
Working on it. Happened with another forum of mine, it's a pain. Vbulletin who created the forum software never wants to admit it's their problem.
Posted

Can you see if you can get it to do it again?

I disabled the chatbox thinking that might be the issue. I can't seem to get the problem to happen to me even when I clear cookies.

Posted
Can you see if you can get it to do it again?

I disabled the chatbox thinking that might be the issue. I can't seem to get the problem to happen to me even when I clear cookies.

 

Aw man. The chatbox is my favourite part of this site.

 

 

...said no one ever.

Posted
Can you see if you can get it to do it again?

I disabled the chatbox thinking that might be the issue. I can't seem to get the problem to happen to me even when I clear cookies.

 

I tried a bunch of stuff on my android tablet and desktop and the re-direct doesn't seem to occur anymore on either. The forum seems very slow today though.

Posted

The issue is described here as it appears to relate to a vulnerability in vbulletin

 

http://club.myce.com/f20/vbulletin-myfilestore-hack-find-traces-remove-them-332219/ <-- possible solution within first post

http://www.vbulletin.com/forum/forum/vbulletin-4/vbulletin-4-questions-problems-and-troubleshooting/389819-vbulletin-3-x-and-4-x-redirect-security-exploit

 

I didn't look in detail but appears there's an injection (SQL?) in the database and/or pluggins.... this one looks like a royal pain

Posted
The issue is described here as it appears to relate to a vulnerability in vbulletin

 

http://club.myce.com/f20/vbulletin-myfilestore-hack-find-traces-remove-them-332219/ <-- possible solution within first post

http://www.vbulletin.com/forum/forum/vbulletin-4/vbulletin-4-questions-problems-and-troubleshooting/389819-vbulletin-3-x-and-4-x-redirect-security-exploit

 

I didn't look in detail but appears there's an injection (SQL?) in the database and/or pluggins.... this one looks like a royal pain

 

That's some good sleuthing, the first link looks like a good resource...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
The Jays Centre Caretaker Fund
The Jays Centre Caretaker Fund

You all care about this site. The next step is caring for it. We’re asking you to caretake this site so it can remain the premier Blue Jays community on the internet.

×
×
  • Create New...