Forums


Go Back   The TrekEarth Forums > TrekEarth Forum Home > Forum Feedback and Support

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-25-2012, 10:46 AM
mkamionka's Avatar
mkamionka mkamionka is offline
TE Senior Member
 
Join Date: Jan 2008
Location: Middlesbrough, UK
Posts: 925
Default Is there a VIRUS on TE website?

Every time I click TE website today, regardless where, is it my profile or forum, I get the following message from Norton Antivirus:

Norton blocked an attack by: Web Attack: Blackhole Toolkit Website 12

If I click for more details it says:

Severity: HIGH
An intrusion attempt by 98.158.194.23 was blocked
Attacker URL: www.trekearth.com/js/nav.js

Does anybody know if it is serious?
M
Reply With Quote
  #2  
Old 01-25-2012, 11:34 AM
jlbrthnn jlbrthnn is offline
TE Expert
 
Join Date: Jan 2007
Posts: 1,336
Default Intrusion attempt from www.trekearth.com

Hello,

I have the same problem, pubished today with details, on Forum General

Joël Berthonneau

Hello,

I NEED URGENT EXPLANATION.

Today Wednesday, January 25, 2012: CONTINUING INTRUSION ATTEMPT FROM WWW.TREKEARTH.COM for any action on my account TrekEarth with Internet Explorer.

Alert example:
_ NORTON SECURITY REPORT
An intrusion attempt by 98.158.194.23 was blocked Wednesday, January 25, 2012 10:49
Name of the alert IPS Web Web Attack Blackhole Toolkit Website 12
Attacking computer 98.158.194.23, 80
URL of origin of the attack fr.trekearth.com/js/nav.js

SEARCH post alert:
_ IP Tracing and IP 98.158.194.23 FOR TRACKING
Server IP 98.158.194.23
Server Host Name www.trekearth.com
Internet Service Provider Internet Brands Inc.
Country United States
California Region
El Segundo City
Address 909 N. Sepulveda Blvd 11th Floor

Joel Berthonneau


Bonjour,

J'AI BESOIN D'EXPLICATIONS URGENTES.

Aujourd'hui Mercredi 25 janvier 2012: TENTATIVE D'INTRUSION PERMANENTE VENANT DE WWW.TREKEARTH.COM, pour toute action sur mon compte Trekearth avec Internet Explorer.

Alerte:
_ NORTON SECURITY REPORT
Une tentative d'intrusion par 98.158.194.23 a été bloquée le mercredi 25 janvier 2012 10:49
Nom de l'alerte IPS Web Attack Blackhole Toolkit Website 12
Ordinateur attaquant 98.158.194.23, 80
URL d'origine de l'attaque fr.trekearth.com/js/nav.js

RECHERCHE après alerte:
_ IP TRACING AND IP TRACKING FOR 98.158.194.23
Server IP 98.158.194.23
Server Host Name www.trekearth.com
Internet Service Provider Internet Brands Inc
Country United States
Region California
City El Segundo
Address 909 N.Sepulveda Blvd 11th Floor

Joël Berthonneau

Last edited by jlbrthnn; 01-25-2012 at 11:40 AM.
Reply With Quote
  #3  
Old 01-25-2012, 12:22 PM
Porteplume's Avatar
Porteplume Porteplume is offline
Moderator
 
Join Date: Feb 2003
Location: Tholen - Holland
Posts: 5,873
Send a message via Skype™ to Porteplume
Default

Hi Marius & Joël,

Nothing serious here but Paul O'Brien / IBobi will explain this better this evening (morning for them)

Community Notice: January 25th-26th, AM hours.

What: One of our tech service providers will be performing maintenance on their servers during the mentioned window.

Impact: Users could report "general weirdness" on our sites manifested as - CSS load failure, image load failure, general broken html, javascript issues, etc.

Everything will automatically go back to "normal" upon maintenance window completion.
__________________
Amicalement...
Reply With Quote
  #4  
Old 01-25-2012, 04:41 PM
Keitht Keitht is offline
Moderator
 
Join Date: Jul 2003
Location: Gloucester, England
Posts: 3,679
Default

Quote:
Originally Posted by Porteplume View Post

Impact: Users could report "general weirdness" on our sites

Everything will automatically go back to "normal" upon maintenance window completion.[/I][/COLOR]
Great description but how do we differentiate between new 'general weirdness' and the usual glitches?? Just kidding techies.
Reply With Quote
  #5  
Old 01-25-2012, 09:40 PM
mkamionka's Avatar
mkamionka mkamionka is offline
TE Senior Member
 
Join Date: Jan 2008
Location: Middlesbrough, UK
Posts: 925
Default

I just hope that tech guys know what they are talking about. Notification about a severe attack does not seem like something comparable to load failure, image load failure etc. It has to be an ACTIVE attack.
But so far my antivirus says it knows how to deal with it.

I am just curious: If there was a virus attacking everybody who clicks something on TE web page, would the tech guys tell us about it or rather they would keep it quiet so that nobody gets scared and everybody stays clicking on TE?
In the end solving simple issues takes sometimes forever so how can we trust they know what they are talking about?

M

Last edited by mkamionka; 01-25-2012 at 09:46 PM.
Reply With Quote
  #6  
Old 01-25-2012, 10:15 PM
JRushen JRushen is offline
TE Newbie
 
Join Date: Jan 2005
Posts: 21
Default Attack

We had this on the Modaco site some time ago and I think they traced it back to an advert.
Reply With Quote
  #7  
Old 01-26-2012, 07:09 PM
patdeph patdeph is offline
TE Senior Member
 
Join Date: Feb 2007
Posts: 606
Default

J'écris de la part de Marine Rebillout, eversmile, qui après avoir subi l'attaque du virus hier matin, a perdu toutes ses photos sur son PC et aussi sur son disque dur qui était branché à ce moment là.Elle ne peut plus se connecter sur internet non plus.Attention, l'attaque semble sérieuse, il serait bien de prévenir tous les membres. En ce qui me concerne, le virus est bloqué par "norton".

I write for Marine Rebillout, eversmile, who having undergone the attack of the virus yesterday morning, lost all her photos on her Pc and also on its hard disk which was connected at this moment there.Now , she can't either connect to internet any more. Attention, the attack seems serious, it would be good to prevent all the members. As for me, the virus is blocked by "norton".
Reply With Quote
  #8  
Old 01-26-2012, 07:22 PM
IBobi IBobi is offline
Administrator
 
Join Date: Mar 2011
Posts: 284
Default

Our technicians are looking into this, thank you for your reports!
Reply With Quote
  #9  
Old 01-26-2012, 09:38 PM
IBobi IBobi is offline
Administrator
 
Join Date: Mar 2011
Posts: 284
Default

This has been resolved; please report if any further instances occur!


Thank you,

Paul
Reply With Quote
  #10  
Old 01-26-2012, 10:08 PM
patdeph patdeph is offline
TE Senior Member
 
Join Date: Feb 2007
Posts: 606
Default

thank you,it seems to be OK, now.
Reply With Quote
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:37 AM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.


explore TREKEARTH