Log in

View Full Version : Malicious software notification, blocking access to forum...



Mrs-M
2-6-13, 1:31am
Advisory provided by Google
Safe Browsing
Diagnostic page for simplelivingforum.net

What is the current listing status for simplelivingforum.net?

Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 2 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 12 pages we tested on the site over the past 90 days, 3 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-02-04, and the last time suspicious content was found on this site was on 2013-02-04.

Malicious software is hosted on 1 domain(s), including nexttimetravel.com/.

This site was hosted on 1 network(s) including AS54020 (ADMONET).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, simplelivingforum.net did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

How did this happen?

In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:

Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.

Updated 6 hours ago

©2008 Google - Google Home

lhamo
2-6-13, 5:01am
Alan -- what is the status on this? I have just noticed several threads I posted on in the past few days have been radically edited. I hope I wasn't the channel for this latest intrusion. Please post an update when you can. I'll try to avoid posting in the meantime (with the exception of this request) in case my computers are somehow involved.

lhamo

Wildflower
2-6-13, 5:05am
lhamo, there are several posts/threads missing now. I was on here much earlier posting and now those threads/posts are nowhere to be found. Very strange!

Alan
2-6-13, 7:44am
Our hosting provider determined that we suffered a malicious hack on Feb 4th. The purpose of the attack was to inject scripts into some of the forum's core files for the purpose of re-directing users to spam sites. The most efficient means of eliminating the scripts was to restore the core files from a previous backup.

At about midnight, eastern time, we completed the restoration from the Feb 3rd backup. We will continue today looking for traces of malicious code and deal with them as/if they are found.

Mrs-M
2-6-13, 8:22am
Thank you for the information, Alan.

Such a shame, as a number of newly started threads and an even larger number of post entries, where scrubbed from the forum during the restoration process.

I also lost a number of private message notifications, too.

Mrs-M
2-6-13, 10:59am
To add... I wonder just how many other members are being blocked from gaining access to the site, account Google, and it's review and labeling of this forum.

ToomuchStuff
2-6-13, 11:49am
To add... I wonder just how many other members are being blocked from gaining access to the site, account Google, and it's review and labeling of this forum.


Every post I open, has at least three extra clicks to get to it. Yesterday, I was somewhere where they use Windows computers and it wouldn't even go here, and all google's searches (finding specific threads) were marked as banned as malicious.

Mrs-M
2-6-13, 11:54am
Every post I open, has at least three extra clicks to get to it. Yesterday, I was somewhere where they use Windows computers and it wouldn't even go here, and all google's searches (finding specific threads) were marked as banned as malicious.That's a shame... I hope, Alan, can get to the bottom of things and get the forum back to it's old self.

SteveinMN
2-6-13, 12:23pm
I find myself clicking multiple times to get things done as well (Macintosh, OS X 10.7, Firefox 17.x). Bummer. But at least it works.

My thanks to Alan for responding to this so quickly!

Mrs-M
2-6-13, 12:31pm
Ahhh... bells and whistles now going off. Now that a couple of you have mentioned multiple clicks needed to navigate the forum, I, too, prior to when Google planted the red balloon stating, "this site may harm your computer", was finding I needed to click certain commands several times to prompt them to load. Then I was blocked for over 24 hours. No access whatsoever.

Additionally, everything was much slower loading...

gimmethesimplelife
2-6-13, 1:05pm
Ahhh... bells and whistles now going off. Now that a couple of you have mentioned multiple clicks needed to navigate the forum, I, too, prior to when Google planted the red balloon stating, "this site may harm your computer", was finding I needed to click certain commands several times to prompt them to load. Then I was blocked for over 24 hours. No access whatsoever.

Additionally, everything was much slower loading...I am back from my time in Austin and then a bad cold that knocked me down for awhile and finally logged on yesterday only to find Google Chrome blocking me. Aaaaayyyyyy Carumba, technology has an upside, I will agree with this, but it can also drive one nuts IMHO.....Rob

gimmethesimplelife
2-6-13, 1:07pm
Just wanted to say thanks Alan for your computer skills and your willingness to work on this......I'm sure all here would agree. Rob

Mrs-M
2-6-13, 1:07pm
So happy to see you back again, Rob! Glad you're feeling better, too! :)

Here's hoping the problem will be solved ASAP.

Mrs-M
2-6-13, 1:19pm
One thing I am still noticing, is I bookmark, Simple Living Forum, and yesterday, up until late last night, there was a small red circle beside the bookmark, with a red horizontal dash through it. Today the red circle/w dash is gone, replaced with the normal black and white V.

However, when I log-out and log back in again, I have to click "ignore warning"? on the red balloon box, before I can visit the site. Hopefully that, too, will be a thing of the past in short order.

Alan
2-6-13, 1:51pm
FYI everyone, I believe we've solved the majority of the problems. This issue now is getting rid of Googles warning. It seems they're only too happy to crawl the web, looking for and reporting problems. It's another thing alltogether to get them to re-evaluate, which must be done before the warnings can be removed. Sheesh!

Another oddity: Other than what has been shared here and in one email, I still haven't seen the warnings everyone else has reported, after visiting the site from multiple machines, multiple locations and several different browsers.

Mrs-M
2-6-13, 2:02pm
That's great, Alan. Could the oddity be, depending on the level and variations of each members computer security settings, why only a select few are being prevented from obtaining access to SLF, and/or being plagued by the big red balloon warning?

Alan
2-6-13, 2:27pm
That's great, Alan. Could the oddity be, depending on the level and variations of each members computer security settings, why only a select few are being prevented from obtaining access to SLF, and/or being plagued by the big red balloon warning?
I'm not sure, I think there's too many variables for me to wrap my head around.

Mrs-M
2-6-13, 2:35pm
Originally posted by Alan.
I think there's too many variables for me to wrap my head around.LOL! Me, too... Stop 'em dead in their tracks, Simpleton!

Mrs-M
2-6-13, 2:59pm
Alan. One thing I have been noticing all morning, is script, popping up when transferring from forum to forum, topic to topic. It only displays briefly (not nearly long enough to decipher), then disappears.

Alan
2-6-13, 3:24pm
Alan. One thing I have been noticing all morning, is script, popping up when transferring from forum to forum, topic to topic. It only displays briefly (not nearly long enough to decipher), then disappears.
I haven't a clue. Just spent a few minutes going from forum to forum, topic to topic and didn't see anything like that.

If you can get a long enough look at it, or better yet a screen capture of it, send it to me.

Mrs-M
2-6-13, 3:28pm
Will do, Alan.

CathyA
2-6-13, 3:40pm
I've been quickly popping my head in here for short periods of time, in spite of the red alert and huge sirens still going off (not really...well, big red signs, but no sirens).......but I feel better about staying around a little longer. I think I'm going to need to re-post a couple posts that didn't get posted for some reason.
Thanks Alan. I'm glad you didn't have anything else to do for the last few days! >8)

awakenedsoul
2-6-13, 7:08pm
I wasn't able to get on the site yesterday, (with Internet Explorer.) Now it seems to be fine.

Mrs-M
2-6-13, 7:10pm
So happy you are now able to join us, Awakenedsoul!

rosarugosa
2-6-13, 7:57pm
I never saw any of the warnings or had any of the problems, so I'm just checking in. Thanks Alan for getting it fixed and thanks Mrs. M for the updates!

Mrs-M
2-6-13, 8:00pm
So glad to see you here, Rosarugosa!

Alan
2-6-13, 8:58pm
Finally, virtually every file on the site has been replaced with fresh versions from vBulletin. Those few that remain have been opened, inspected and scrubbed if necessary. The database was replaced with a backup version, which accounts for the loss of a few posts/threads, and every member with elevated privileges (admins & mods) has been asked to change their login credentials on the off chance that they were compromised.

Now, the process of getting Google to re-evaluate the site and remove their warnings begins, which could take a few days.

Thanks to everyone for their patience.

Mrs-M
2-6-13, 9:01pm
Just did a quick test, where I logged-out, cleared the cache/cookies, then tried logging in again. Verdict, no luck.

Reported Attack Page!

This web page at www.simplelivingforum.net has been reported as an attack page and has been blocked based on your security preferences.

Attack pages try to install programs that steal private information, use your computer to attack others, or damage your system.Some attack pages intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.

The above pops up by way of a large red warning balloon. See below.

http://www.codecolony.com/images/reported-attack-site.png

Mrs-M
2-6-13, 9:02pm
Thank you, Alan.

Alan
2-6-13, 9:15pm
Just did a quick test, where I logged-out, cleared the cache/cookies, then tried logging in again. Verdict, no luck.

Reported Attack Page!

This web page at www.simplelivingforum.net (http://www.simplelivingforum.net) has been reported as an attack page and has been blocked based on your security preferences.



Mrs M., you do understand that what you're seeing is the result of the Google report, not the current state of the forum?
If you'd feel more comfortable staying away while I work with Google to have the report rescinded, that would be fine.

Mrs-M
2-6-13, 9:18pm
Oh, heavens no, Alan, I'm right-at-home with staying active, just wish Google, would get on with it. I'm feeling the pinch of a lack of visiting members today. :)

Tussiemussies
2-6-13, 9:38pm
Mrs M., you do understand that what you're seeing is the result of the Google report, not the current state of the forum?
If you'd feel more comfortable staying away while I work with Google to have the report rescinded, that would be fine.

Yes, I just did a search on Safari and it warned against using the forums.....

goldensmom
2-6-13, 9:51pm
I'm still getting blocked on Firefox and Chrome but no problem with Explorer.

Mrs-M
2-6-13, 9:54pm
Good to see Tussiemussies and Goldensmom! I've been sitting on pins and needles all day long, thinking (overthinking) about all the members who haven't been able to access the forum.

Tradd
2-6-13, 10:00pm
I read (and post some, short stuff, anyway) on my phone. I've had no problems at all. So perhaps that might be an option for those with smartphones who are getting this message on their computers.

Alan
2-6-13, 10:01pm
Google advises it may take up to one week to remove the warnings. Please be patient.

Mrs-M
2-6-13, 10:03pm
Good to see you, Tradd!

Thanks for the info, Alan. What would we do without you...

Wildflower
2-7-13, 11:34pm
Thanks so much, Alan, for all the hard work you do here!

Alan
2-11-13, 7:50am
Topic Update:

Google has finally removed the forums from it's blacklist. Website scans from Google, Norton Safe Web, Phish Tank, Site Advisor, Sucuri, and Yandex have all returned a clean bill of health.

WooHoo!!

Mrs-M
2-11-13, 7:53am
Woo-Hoo!

Blackdog Lin
2-11-13, 7:56am
Ditto my thanks for getting the issue fixed.

It's been AWFUL! Just awful. I haven't been able to get on here for a solid week - my security program wouldn't let me on, and trying to go around it with Google wouldn't work either. I've been trying twice a day all week, and this morning all of a sudden.....hallelujia! Finally!

I didn't realize how much I'd miss y'all - you're my only online family. And now, off to get caught back up.....

CathyA
2-11-13, 9:19am
Glad you could get back in Blackdog Lin!
I have a large group of gardening forums (Gardenweb.com), and for some crazy reason, there are months at a time when I can't get in there, and I really miss it!
I'm still getting the red-alert-this-is-a-bad-forum message when I open up Simple Living, but I'm just ignoring it. I hope it goes away eventually.

danna
2-11-13, 11:07am
Good morning....I have been trying everyday too...first thing the morning I still could not get in and thought I would try again a few minutes ago
and low and behold. No RED Alert page and my nice blue tick mark is back on your page.
Thank you Alan for all your work.

gimmethesimplelife
2-11-13, 12:40pm
Just tried to get on and viola this time it worked! Thanks Alan for fixing this! Glad to have this up and running again. Rob

Mrs-M
2-11-13, 1:23pm
Blackdog Lin, Danna, and Gimmethesimplelife, so happy to have you back!

SiouzQ.
2-11-13, 8:12pm
I'm finally checking back in again too; I was too scared to do anything when I got that big warning last week. It's good to be back and on track with you all!

ToomuchStuff
2-12-13, 2:03am
I miss the triple clicking to get here.:laff:

Gregg
2-12-13, 10:19am
A shoutout to Alan for fixing the problem! Thank you Alan!!!!!!!!!

Tussiemussies
2-12-13, 2:57pm
Thanks Alan, really missed being on the board and glad to be back now....:)

redfox
2-12-13, 3:11pm
Ditto all the above.