Malware Malware where are thou malware?

19

On Wednesday we starting to receive  a flood of complaints about some sort of malware/issue warning on the site. Apparently from Google’s own Safe Browsing tool. You can see what our site looks like on the issue right over here and you can look at what Google’s site looks like too. There was bad code that was installed on the site in the deep public back-end. How was it installed? Our ad server was targeted from out of date code that was vulnerable to attack.   The strange thing was the malware didn’t appear to be working at least not for a while and that is why it took so long to track down the problem. Regardless, the ad server has been completely removed and installed with a different secure ad  system. This has been one of the more sophisticated attacks I’ve seen, and its been reported by the media.

Reef Builders has grown tremendously over the past year. As a result evil bots/persons were scanning the site looking for vulnerabilities as they wanted to leverage the amount of traffic we get for their own use. Because of this we’ve added a very powerful hardware firewall to the site which blocks about 99% of the attacks we were getting subjected to. We should have added this sooner and I’ll take the blame on this one. This was my fault.

Special thanks to all who emailed, called, tweeted, and blogged about this. We wouldn’t be around if it weren’t for you.


 



Top Related Stories:

  • No Related
  • http://www.advancedaquarist.com/ Shane Graber

    What version of OpenX were you guys running anyhow?

  • http://www.advancedaquarist.com/ Shane Graber

    What version of OpenX were you guys running anyhow?

  • Ryan Gripp

    2.8.3

  • Ryan Gripp

    2.8.3

  • http://www.advancedaquarist.com/ Shane Graber

    Interesting. We are currently updating our ancient ad software (Adcycle) and are looking at OpenX. It seems as though the exploit is supposed to affect only 2.8.2. So 2.8.3 was affected as well. Any idea if 2.8.4 (latest release) is vulnerable? I couldn’t find info about it on their site.

  • http://www.advancedaquarist.com/ Shane Graber

    Interesting. We are currently updating our ancient ad software (Adcycle) and are looking at OpenX. It seems as though the exploit is supposed to affect only 2.8.2. So 2.8.3 was affected as well. Any idea if 2.8.4 (latest release) is vulnerable? I couldn’t find info about it on their site.

  • Tim Morrissey

    Yeah ever since I watched that video of the Japanese tank, now my computer is acting weird with pop ups saying it is being attacked…

  • Tim Morrissey

    Yeah ever since I watched that video of the Japanese tank, now my computer is acting weird with pop ups saying it is being attacked…

  • http://www.oceansmotions.com Paul

    Japanese? Pearl Harbor, please say it isn’t happening again.

  • http://www.oceansmotions.com Paul

    Japanese? Pearl Harbor, please say it isn’t happening again.

  • mthomp

    its a shame. i love your forums. but now everytime i try to visit them i get that screen.

  • mthomp

    its a shame. i love your forums. but now everytime i try to visit them i get that screen.

  • Pingback: Free Malware Removal Hands-down Approach « PC Rescue Reviews

  • pickle

    I saw that warning too. glad to hear you got if figured out.

  • pickle

    I saw that warning too. glad to hear you got if figured out.

  • Marc

    What firewall software/appliance did you end up with?

  • Marc

    What firewall software/appliance did you end up with?

  • http://www.computersecurityarticles.info Computer Security Articles

    I wanted to thank you for this great read!! I definitely enjoying every little bit of it I have you bookmarked to check out new stuff you post! Visit my site: Computer Security Articles.

  • http://www.computersecurityarticles.info Computer Security Articles

    I wanted to thank you for this great read!! I definitely enjoying every little bit of it I have you bookmarked to check out new stuff you post! Visit my site: Computer Security Articles.