Page 1 of 1

Yotblog & Google Chrome

Posted: Fri Mar 20, 2009 3:58 pm
by craggy_steve
Hi Nick, just visited yotblog today and chrome threw me out with the following message:


Warning: Visiting this site may harm your computer!
The website at http://www.yotblog.com" onclick="window.open(this.href);return false; contains elements from the site g00gle-analyze.com, which appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
For detailed information about the problems with these elements, visit the Google Safe Browsing diagnostic page for g00gle-analyze.com.
Learn more about how to protect yourself from harmful software online.

Cheers, Steve

Re: Yotblog & Google Chrome

Posted: Fri Mar 20, 2009 6:19 pm
by Nick
Yes, it had been hacked - not seriously, but it is very iritating.

Can you try again and let me know if the problem recurs?

Re: Yotblog & Google Chrome

Posted: Fri Mar 20, 2009 6:21 pm
by Silkie
This is absolutely correct. Just logging on gives Nick immediate access to your bank details. I wouldn't, if I were you.

Re: Yotblog & Google Chrome

Posted: Fri Mar 20, 2009 7:38 pm
by craggy_steve
Hmmm.

Now whinging about sexbases.cn. Have you been I-framed? Is it running on IIS? Pain if so :(


Warning: Visiting this site may harm your computer!
The website at http://www.yotblog.com" onclick="window.open(this.href);return false; contains elements from the site sexbases.cn, which appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
For detailed information about the problems with these elements, visit the Google Safe Browsing diagnostic page for sexbases.cn.
Learn more about how to protect yourself from harmful software online.

Re: Yotblog & Google Chrome

Posted: Fri Mar 20, 2009 10:31 pm
by Nick
.
Have you been I-framed? Is it running on IIS?
Yes, it was an i-frame, and it was being generated by a dodgy javascript - but the site is running on a Linux Apache server so not IIS related. The platform is an old shared hosting system though and this is not the first security glitch in recent weeks.

First fix was a cursory glance and iframe rremoval omw out to the pub. Have now removed the javascript from the relevant pages as well as the (re-written) iframe and Chrome is not sending any warnings now. If anyone notices it re-appearing please get straight back to me.