Home
we had subs it was crazy

Primary links

  • About
    • $upport (lol)
    • Ethics
    • FAQ
    • Privacy Policy
  • Contact
  • MGoStore
  • MGoBoard
    • MGoBoard FAQ
    • Ticket spreadsheet
    • Michigan bar locator
    • Moderator Action Sticky
  • Useful Stuff
    • Depth Chart By Class
    • Unofficial Two Deep
    • 2013 Offer Board
    • Crude Bug Tracking System
    • Third Down Stats
    • Diaries, Windows Live Writer, And You
    • Michigan Future Schedules
    • User-Curated HOF
    • 2013 Recruiting Board
    • Where To Eat In Ann Arbor
Home

Navigation

  • Forums
  • Recent posts

User login

  • Create new account
  • Request new password

MGoElsewhere

  • @MGoBlog (Brian)
  • @aceanbender
  • @TomVH (Tom)
  • RSS Feed
  • iPhone App
  • Facebook profile
  • MGoKindle Store
  • mgo.licio.us
  • Brian @ TSB [Archive]
  • Brian @ AOL [Archive]
  • Sour Salty Bitter Sweet

Michigan Blogs

  • Big House Blog
  • Burgeoning Wolverine Star
  • Genuinely Sarcastic
  • Go Blue Michigan Wolverine
  • Holdin' The Rope
  • MGoFootball
  • MVictors
  • Maize 'n' Blue Nation
  • Maize 'n' Brew
  • Maize And Go Blue
  • Michigan Hockey Net
  • The Blog That Yost Built
  • The Hoover Street Rag
  • The M Block
  • The M Zone
  • The Wolverine Blog
  • Touch The Banner
  • UMGoBlog
  • UMHoops
  • UMTailgate
  • Wolverine Liberation Army

M On The Net

  • mgovideo
  • MGoBlue.com
  • Mike DeSimone
  • Recruiting Planet
  • The Wolverine
  • Go Blue Wolverine
  • Winged Helmet
  • UMGoBlue.com
  • MaizeRage.org
  • Puckhead
  • The M Den
  • True Blue Fan Forum

Big Ten Blogs

  • Illinois
    • A Lion Eye
    • Hail To The Orange
    • Illinois Baseball Report
    • Illinois Loyalty
  • Indiana
    • Inside The Hall
    • The Crimson Quarry
  • Iowa
    • Black Heart, Gold Pants
    • Fight For Iowa
  • Michigan State
    • The Only Colors
  • Minnesota
    • GopherHole.com
    • The Daily Gopher
    • I'm In Love With A Fringe Bowl Team
    • TNABACG
  • Nebraska
    • Big Red Network
    • Corn Nation
    • Husker Mike's Blasphemy
    • Husker Gameday
  • Northwestern
    • Sippin' On Purple
    • Lake The Posts
  • Notre Dame
    • The House Rock Built
    • One Foot Down
  • Ohio State
    • Eleven Warriors
    • Buckeye Commentary
    • Men of the Scarlet and Gray
    • Our Honor Defend
    • The Buckeye Nine
  • Penn State
    • Slow States
    • Black Shoe Diaries
    • Happy Valley Hardball
    • Penn State Clips
    • Linebacker U
    • Nittany White Out
  • Purdue
    • Boiled Sports
    • Hammer and Rails
  • Wisconsin
    • Bruce Ciskie

Links of Note

  • Baseball
    • Big Ten Hardball
    • College Baseball Today
    • The Baseball Zealot
    • The College Baseball Blog
  • Basketball
    • Ken Pomeroy
    • Basketball Prospectus
    • Midmajority
  • College Hockey
    • Chris Heisenberg
    • College Hockey Stats
    • Inside College Hockey
    • Michigan College Hockey
    • Hockey's Future
    • Sioux Sports
    • USCHO
    • Western College Hockey
    • CCHA
      • LSSU Hockey
      • Bronco Hockey Blog
  • Football
    • Smart Football
    • Every Day Should Be Saturday
    • Doctor Saturday
    • CFB Stats
    • Harold Stassen
    • NCAA D-I Stats Page
    • The Wizard Of Odds
  • General
    • Sports Central
  • Local Interest
    • The Ann Arbor Chronicle
    • Arborwiki
    • Arbor Update
    • Teeter Talk
    • Vacuum
  • Teams Of The D
    • Lions
      • Pride of Detroit
      • Fire Millen
    • Pistons
      • Detroit Bad Boys
      • Need4Sheed
    • Tigers
      • Roar Of The Tigers
      • The Detroit Tigers Weblog
      • The Daily Fungo
    • Red Wings
      • On The Wings
      • Behind The Jersey
      • Winging It In Motown
    • Michigan Sports Forum

Archive

  • May 2013 (53)
  • April 2013 (94)
  • March 2013 (104)
  • February 2013 (81)
  • January 2013 (93)
  • December 2012 (74)
  • November 2012 (142)
  • October 2012 (143)
  • September 2012 (107)
  • August 2012 (103)
  •  
  • 1 of 11
  • ››

Get Yer Tickets

Football Display Case

NFL Watches

Follow your favorite team with localtv-satellite.com: Click Here.

Site Search

Diaries

  • New
  • Popular
  • Hot
  • Does Expansion Actually Lead to More Recruits From a Certain Region?
    maizeonblueaction - 1 hour ago
  • Raiding the B1G-er Big Ten: Recruiting Prospects in Maryland and Rutgers Territory
    The Mathlete - 1 day ago
  • A Cynical Take on Why Expansion May be Dead for the Forseeable Future
    maizeonblueaction - 2 days ago
  • LIGHT IT UP, AGAIN. WALLPAPER
    jonvalk - 2 days ago
  • Using Rivals' Star Ratings To Look At Big Ten Football Recruiting: 2002-2013
    LSAClassOf2000 - 3 days ago
  •  
  • 1 of 4
  • ››
more
  • Using Rivals' Star Ratings To Look At Big Ten Football Recruiting: 2002-2013
    LSAClassOf2000 - 857 views
  • More Milford Men Than Michigan Men: Comparing the 11-12 and 12-13 Hockey Teams
    MGoBlueline - 774 views
  • UMich NFL draft history, Part III
    blueheron - 748 views
  • LIGHT IT UP, AGAIN. WALLPAPER
    jonvalk - 666 views
  • A Cynical Take on Why Expansion May be Dead for the Forseeable Future
    maizeonblueaction - 552 views
  •  
  • 1 of 2
  • ››
more
  • Big Ten Recruiting Rankings 4-30-13
    Ace - 81 comments
  • Using Rivals' Star Ratings To Look At Big Ten Football Recruiting: 2002-2013
    LSAClassOf2000 - 19 comments
  • A Cynical Take on Why Expansion May be Dead for the Forseeable Future
    maizeonblueaction - 17 comments
  • LIGHT IT UP, AGAIN. WALLPAPER
    jonvalk - 17 comments
  • Raiding the B1G-er Big Ten: Recruiting Prospects in Maryland and Rutgers Territory
    The Mathlete - 12 comments
  •  
  • 1 of 2
  • ››
more

MGoBoard

  • New
  • Recent
  • Hot
  • OT - ND paid Charlie more than Brian Kelly in 2012
    0 replies
  • Softball SuperRegionals Open Thread
    17 replies
  • OT: ESPN hires Paul Finebaum
    27 replies
  • OT: Red Wings vs Hawks Game 4 Open Thread
    171 replies
  • Mark May Trolls Ohio State Again, Buckeyes Fans Let Him Have It On Twitter
    30 replies
  • Who should replace ND in a long-term series?
    123 replies
  • Baseball Eliminated from B1G
    19 replies
  • Denard, other rookies discuss Star Trek
    52 replies
  • Urbs and his obsession with butts
    48 replies
  • Very OT: The Hangover 3 *Thread May Contain Spoilers*
    56 replies
  • Scouting Report: Jabrill Peppers
    145 replies
  • Awesome Uniform Timeline on MVictors
    39 replies
  • Baby’s life saved with 3D printed device at C.S. Mott
    36 replies
  • OT: Mott Takeover
    15 replies
  • Jersey Name Patches
    24 replies
  •  
  • 1 of 7
  • ››
  • OT: ESPN hires Paul Finebaum
    26 replies
  • OT: Red Wings vs Hawks Game 4 Open Thread
    171 replies
  • OT - ND paid Charlie more than Brian Kelly in 2012
    0 replies
  • Softball SuperRegionals Open Thread
    17 replies
  • Mark May Trolls Ohio State Again, Buckeyes Fans Let Him Have It On Twitter
    30 replies
  • Very OT: The Hangover 3 *Thread May Contain Spoilers*
    56 replies
  • Who should replace ND in a long-term series?
    123 replies
  • 5 star 2013 DT may not be enrolling at Notre Dame
    91 replies
  • Scouting Report: Jabrill Peppers
    145 replies
  • Awesome Uniform Timeline on MVictors
    39 replies
  • ESPN's Luginbill Predicts Top 5 Impact Freshmen, includes Derrick Green
    71 replies
  • OT - Official MGoBaby Thread (you got 'em, we want to see 'em)
    148 replies
  • Baby’s life saved with 3D printed device at C.S. Mott
    36 replies
  • Denard, other rookies discuss Star Trek
    52 replies
  • Baseball Eliminated from B1G
    19 replies
  •  
  • 1 of 7
  • ››
  • OT: Red Wings vs Hawks Game 3 Open Thread
    203 replies
  • OT: Red Wings vs Hawks Game 4 Open Thread
    170 replies
  • OT - Official MGoBaby Thread (you got 'em, we want to see 'em)
    148 replies
  • How much do you really hate ohio?
    145 replies
  • Scouting Report: Jabrill Peppers
    145 replies
  • OT? Graduatin' Season. Who had the Worst Commencement Speaker?
    139 replies
  • Who should replace ND in a long-term series?
    123 replies
  • Speight and TomVH on Peppers
    116 replies
  • OT: Red Wings @ Hawks Game 2 Open Thread
    114 replies
  • Prayers for Moore, Oklahoma
    112 replies
  • Alex Bars to Notre Dame
    96 replies
  • 5 star 2013 DT may not be enrolling at Notre Dame
    91 replies
  • OT: NBA Draft Lottery
    78 replies
  • ESPN 30 for 30 on the Bad Boys
    77 replies
  • Michigan Softball vs. Cal Open Thread
    75 replies
  •  
  • 1 of 7
  • ››

mgo.licio.us

  • This college baseball team is the best at postgame interviews

    national champs baby

    0 comments
  • Rounding up the latest in NCAA absurdities.

    Patrick Hruby is doing God's work.

    0 comments
  • Cornell wrestler tops Michigan's Trey Burke for Sports Illustrated award | The Detroit News | detroitnews.com

    first comment: "EVERY ATHLETE HAS ASPIRATIONS OF WINNING AND WE HAVE OUR FAVORITES BUT IT IS ALWAYS A PLEASURE TO OTHER STUDENTS ACHIEVE THEIR GOALS, TOO!"

    0 comments
  • Burke hearing he'll go two through six in NBA draft

    stupid Pistons and their refusal to tank properly

    0 comments
  • 2013 NHL Draft Prospect: Andrew Copp

    rundown of Michigan's riser

    0 comments
  • Michigan's key returnee: Glenn Robinson

    needs moar usage

    0 comments
  • Former Arkansas QB Brandon Mitchell transferring to NC State

    so much for that

    0 comments
  • The B1G List: Ranking the State Fossils of the Big Ten

    This list is completely arbitrary and not a genuine analysis of the relative merits of state fossils.

    0 comments
  • Trey Burke turns to inner circle to prepare for NBA draft

    will be michigan's highest pick in a while

    2 comments
  • B1G assistant coach salaries on the rise

    money has to go somewhere

    0 comments
  • Tim Hardaway Jr. is motivated by his critics and doubters, and supremely confident in his ability

    I am only motivated by people who have no opinion about me.

    0 comments
  • Big Ten football procrastinates on parity-based scheduling, and nothing ever changes

    the just released schedules were a flat-out statement that the B10 doesn't believe SOS will matter in playoff selection

    1 comments
  • Michigan's Glenn Robinson III, Mitch McGary ranked inside top 20 on ESPN's 2014 draft board

    but I thought that draft was supposed to be incredibly loaded?

    1 comments
  • Tim Hardaway Jr. turning heads, viewed as a first-rounder by some teams, analyst says

    If you're gonna go please be in the first round.

    0 comments
  • Michigan-Ohio State once, Indiana-Purdue once? The Big Ten has to protect its hoops rivalries

    another delightful side effect of a 14 team conference

    0 comments
  •  
  • 1 of 2
  • ››
more

Lessons From The Great Malware Disaster Of 2011

By Brian — January 27th, 2011 at 1:38 PM — 63 comments
Filed under:
  • burning dwarves
  • great malware disaster of 2011
  • meta

[Note: iPhone app is currently broken; that is the #1 priority in terms of fixes. Hope to have it up by Monday.]

This has nothing to do with Michigan football but the least I can do to help the greater health of the internet is to offer some measure of advice for people who find themselves hacked in the face.

I'm not an expert. Please read the comments for people disagreeing with me, as they may/are better at this than I am. But I just went through this and if you're in the same boat here's what happened with me and what I took from it.

all-bird

Boatmurdered. BURN. ALL BURN.

"Last known good" may not be as good as you think. We have a backup. That backup overwrites itself on a nightly basis. Correction: that backup overwrote itself on a nightly basis. Going forward we wanted to be able to roll back up to a week.

However, we found out that would not have helped us here. Some of our infected files were last modified in early January. A "last known good" configuration from last weekend would have still featured multiple scripts with backdoors that Eastern European hackers could jump in.

We're still going to change our backup system so that it has more snapshots—an injection attack would be more susceptible to a DB rollback, I think—and we are going to have a billion and two backups of the actual code so that if, God forbid, something like this happens again we can have a reference point to pull forward stuff we customized and don't want to lose.

But…

BURN. ALL BURN. I'm not pulling anything forward except select bits and pieces I can hand-inspect. The rest of it dies in a fire. I thought we were destroyed until my brother asked "how long would it take to recreate it from scratch?" This was the moment in the movie when the camera zooms out and the city becomes transparent. It would take… um… maybe a couple hours. The defining feature of a CMS is that everything is in the database. So if you're confident the database isn't the issue you can pick that out, raze the world, download and install all your crap, and not have to worry about finding every last piece of corrupted code. You're going to break a few things when the new versions of your modules don't work exactly as expected but it's way better than the alternative.

Then change your FTP password over SSH. And then, if you're paranoid (ie: us now), turn FTP off entirely for a while. We had to use plain FTP, which is not very secure, because for some reason enabling encryption turned directory listing into a cripplingly slow process. A reader had related an experience in which a corrupted local computer had been giving away FTP passwords, giving hackers direct access to the server. We're not taking any chances despite my incessant scanning.

Burn, all burn exception: we pulled the "files" folder forward despite it being too massive to check because it's all data and those folders are locked down by server permissions so they can't execute anything. Everything else was pored over.

Why we thought it wasn't the database. Well, one, we found plenty of stuff indicating the server had taken a direct hit in the form of scripts that included helpful comments like "webshell by oRb." We brought those shells up and didn't find any database functionality.

Also, injection attacks usually don't affect the entire site—they're more likely to be hostile code submitted by users (something Drupal is good about) that affect only the pages they're submitted on. The malware was being delivered via the CSS and JS files, which are amongst the few bits of the page you're reading that don't come from the DB. While the server corruption could have in turn hit the DB, we didn't see obvious avenues for that and all of the problems were segregated from said DB.

We're now watching it closely just in case, but the evidence pointed to something other than an SQL injection.

What to search for. This article is fairly comprehensive but I'd also suggest looking for "unescape" or the string "%3C%69%66%72%61%6D%65." If you run that through the unescape function you get "<iframe". What are the chances that's helpful code? Not so good.

Don't waste your time with "StopBadware." This is the site you get funneled to if you click the I'm-so-screwed button on the Google warning page. Their extremely awesome advice is to look for the bad things and remove them. They list scripts, redirects, and iframes as the main ways you transmit the bad things—okay, probably helpful—and then offer this up:

There exist several free and paid website scanning services on the Internet that can help you zero in on specific badware on your site. There are also tools that you can use on your web server and/or on a downloaded copy of the files from your website to search for specific text.

Awesome! Where are they? Which are the best ones?

StopBadware does not list or recommend such services, but the volunteers in our online community will be glad to point you to their favorites.

Fu. The "online community" at "badwarebusters" mostly consists of people screaming about erroneous hits. About four threads pop up per day and they can go days without a response. If you're looking to do something quickly it's useless.

That's annoying. This is the worst advice possible:

Once you have located the code that is causing the badware behavior, removing it is often as simple as deleting the offending code from all files in which it appears. Sometimes, it is easier, if you have a clean backup of your site’s contents, to re-upload all of the site’s files, though be careful about overwriting files that may have changed since your last backup.

They've just glossed over the difference between the offending iframe and the code that generated it. Backdoors are not mentioned. This section needs to be replaced with:

BURN. ALL BURN.

Whoever wrote it should be horsewhipped. The next section is about "preventing future infection" when the previous section has essentially advised a n00b who needs to be informed that scripts and iframes are bad, mmmmkay, that "removing the offending code" "often" solves the problem. False. Burn. All burn. 

If you aren't already, sign up with Google's Webmaster tools. We first found out the aggregated JS file was an issue from them, and they periodically updated their findings to let us know we still hadn't killed the problems. Tip: if you're aggregating js and css you may want to stop for more precise identification of the end destinations.

These are not the sources. You have to find those, or just burn everything to the ground.

Don't get notifications other than security notifications. This site is now running dozens of Drupal modules, some of which actually have release changelists that read, in their entirety, "fixed typo X." After a while you stop checking just to see that some random module has done some stuff you don't care about, and then you don't know when certain modules are out of date. We're still not sure what the attack vector was but one of the main candidates was known, patched holes in Drupal. I went from weekly updates about everything to daily updates about security. Drupal shouldn't have other options.

Status. We're not entirely out of the woods yet but it's looking promising, and we have installed various alarms in the system to blare at us whenever anything unexpected (a file getting updated outside of the areas that's supposed to happen) goes down. Hopefully if there is another breach we will catch it long before anything starts getting delivered.

  • Login or register to post comments

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
January 27th, 2011 at 1:43 PM | Why on firefox (Score:1)
somewittyname
Joined: 05/15/2009
MGoPoints: 1030

is it still saying it's an attack page? I can access fine on my phone and Safari.

  • Login or register to post comments
January 27th, 2011 at 1:47 PM | Is it safe to come out yet? (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

I feel like I am taking those first steps right out of the nuclear bunker to navigate the damage right now. Did we get our missles off at those Reds from tsio?

  • Login or register to post comments
January 27th, 2011 at 3:03 PM | Seriously (Score:1)
Eyebrowse
Eyebrowse's picture
Joined: 07/06/2009
MGoPoints: 1388

It's like I don't even know where I am anymore.  

On a more serious note, this whole malware disaster has really shown me the depths of my own addiction.  I can say I am both proud and saddened by the state of my inner self since then.  

Let's also not talk about how I haven't shaved or showered in days (okay weeks, but that's nothing out of the ordinary).  

  • Login or register to post comments
January 27th, 2011 at 3:11 PM | Addicted?! Who is addicted?! (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

Addicted?! Who is addicted?! I'm not addicted!

 

All I want to know is if that malware has any offers? TomVH? I think MGoMalware was great breakaway speed and punishing hits over the middle. He has to at least have 4 stars.

  • Login or register to post comments
January 27th, 2011 at 3:21 PM | Seriously (Score:1)
JeepinBen
JeepinBen's picture
Joined: 01/22/2010
MGoPoints: 9542

I have gotten record amounts of work done this week... At least my boss doesn't read MGoBlog and therefore doesn't know that my uptick in production was due to a lack of time on here...

"Over? Did you say, over? Nothing is over until we decide it is!"

  • Login or register to post comments
January 27th, 2011 at 3:28 PM | Emerging from Vault 13 (Score:1)
I Bleed Maize N Blue
I Bleed Maize N Blue's picture
Joined: 09/27/2008
MGoPoints: 4884

Michigan Resurgent?  Michigan Resurgent!

The beatings will continue until the uniforms improve!

  • Login or register to post comments
January 27th, 2011 at 1:47 PM | to arms! (Score:1)
Moe Greene
Moe Greene's picture
Joined: 08/01/2008
MGoPoints: 2133

When do we launch the MGoCounterattack?

Even the noobs that get negged into the stratosphere know that we must defend this house....

Lock and load!

No radio. Nothing of value.

  • Login or register to post comments
January 27th, 2011 at 1:49 PM | WOLVERINES!!!!!11!!1! (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

  • Login or register to post comments
January 27th, 2011 at 1:52 PM | My guess is that Scout needed traffic numbers and sent this over (Score:1)
iawolve
iawolve's picture
Joined: 11/03/2008
MGoPoints: 2488

They had insight on all the future pending commits that we had not even heard of or had contemplated a michigan offer. s\ 

  • Login or register to post comments
January 27th, 2011 at 1:56 PM | I'm still inclined to blame (Score:1)
wlubd
wlubd's picture
Joined: 02/26/2009
MGoPoints: 4971

I'm still inclined to blame Danny Hope. Next Purdue commit we take, he might just kill someone...

Twitter

  • Login or register to post comments
January 27th, 2011 at 1:52 PM | Did you find any Baxter (Score:1)
TrppWlbrnID
TrppWlbrnID's picture
Joined: 10/29/2009
MGoPoints: 7897

Did you find any Baxter Updates?

2013 resolution - make it onto the 2014 favorite MGoPosters post, not ironically
  • Login or register to post comments
January 27th, 2011 at 1:52 PM | Fingers crossed.  Knock on (Score:1)
Tauro
Tauro's picture
Joined: 06/30/2008
MGoPoints: 656

Fingers crossed.  Knock on wood.  Rabbits foot purchased.  Anything else that helps!

  • Login or register to post comments
January 27th, 2011 at 1:54 PM | Um, does this mean Demetrius (Score:1)
Zone Left
Zone Left's picture
Joined: 07/03/2008
MGoPoints: 13967

Um, does this mean Demetrius Hart isn't coming?  I don't know what the hell else that could have been about.

It's all John Navarre's fault.

 

  • Login or register to post comments
January 27th, 2011 at 1:56 PM | I don't understand (Score:1)
wolverine1987
wolverine1987's picture
Joined: 07/07/2008
MGoPoints: 2928

a single thing you wrote Brian. Sounds like some stuff is happening though, so good luck.

"Everyone gets dumped Gabe. Let me give you some advice: a little coverup on your Adams Apple will make it appear smaller. Which will make you appear less like a transvestite." 

  • Login or register to post comments
January 27th, 2011 at 2:00 PM | Hacker or Bot? (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

Brian,

Do you think this was done by a person or done by a bot?  It doesn't really matter, I was just curious.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:02 PM | Good luck Brian, hope you get (Score:1)
dennisblundon
dennisblundon's picture
Joined: 02/23/2010
MGoPoints: 6631

Good luck Brian, hope you get this back up and running again soon. For those of you eagerly awaiting my ability to post again I have a couple of gems ready on deck. One is a projected depth chart for 2011, complete with win/loss predictions for next years schedule. The other is why aren't we recruiting Cardale Jones with more tenacity. It will be glorious.

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | . (Score:1)
MGoShoe
MGoShoe's picture
Joined: 04/23/2009
MGoPoints: 19236

LSA '89 - MBB Natl Champions, Big 10/Rose Bowl Champions | @MGoShoe

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | I know nothing (Score:1)
Blue-Chip
Blue-Chip's picture
Joined: 01/06/2010
MGoPoints: 2950

about computer viruses.  Was there some goal in mind with this malware, or was it specifically designed to be a pain in Brian's proverbial backside?

Your friendly neighborhood contrarian.

  • Login or register to post comments
January 27th, 2011 at 5:34 PM | Get in. Stay In. (Score:1)
ottomatic
Joined: 01/12/2011
MGoPoints: 142

The goal of most modern malware is to operate quietly. Get in, stay in, and exfiltrate data, or gain control of additional systems. The malware that infected the MGOBLOG site attempted (for some not all) to download  a payload of a known spyware, there's a good chance it would have redirected to additional malware as well. The ultimate aim being that criminal syndicate want to steal your shit and control your computer.

Worldwide there are close to 7 million computers still infected with conficker. Those infected systems can be thought of as a zombie army ready to take commands and participate in distributed denial of service attacks (DDOS). The criminal syndicates that control these assets will even rent them out. In some of the shadier corners of the internet you can bid-on or buy a zombie contingent to launch your attack.

Sort of like paying Scam Newton to win the BCS.

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | We're HEEEERRREEEE! (Score:1)
MGoBlueForLife
MGoBlueForLife's picture
Joined: 10/15/2010
MGoPoints: 174

They can't stop us, they can only hope to Malware us! Which they did, but were STILL HERE!
YEAH!

Can't see the line, can you Russ?
-Clark W. Griswold

  • Login or register to post comments
January 27th, 2011 at 2:05 PM | (No subject) (Score:1)
Laser Wolf
Joined: 07/09/2008
MGoPoints: 1693

  • Login or register to post comments
January 27th, 2011 at 2:06 PM | I am still not taking any (Score:1)
a non emu
Joined: 06/30/2008
MGoPoints: 683

I am still not taking any chances on my work computer. I am running firefox with AdBlock, and NoScript set to everything, including iFrames, disabled. One promising thing is that the site no longer shows up as an attack site on Firefox, so looks like you are more or less out of the woods. But, good luck! My MGoWithdrawal symptoms have been terrible recently.

Need. Moar. Mgo. Less. Malware.

  • Login or register to post comments
January 27th, 2011 at 2:06 PM | I am clueless (Score:1)
Hugh Jass
Hugh Jass's picture
Joined: 01/03/2011
MGoPoints: 719

to this kind of technology psycho babble.  You were talking a foreign language to me.  I have faith that a Blog about Michigan football will rise from the ashes and be bigger and better than ever!  Also thanks for saving all my mgopoints that I have wasted several hours of potentially productive time to earn -  You Rock!

If someone ever invented a low fat vitamin - filled vegetable that tasted like fudge covered Rice Krispies treats - I'd probably eat better

 

 

  • Login or register to post comments
January 27th, 2011 at 2:31 PM | Me too (Score:1)
michgoblue
michgoblue's picture
Joined: 11/16/2009
MGoPoints: 11210

I know nothing other than that the Board is screwed up and I can't respond to anything other than the main page.

  • Login or register to post comments
January 27th, 2011 at 2:07 PM | This post equals (Score:1)
Laser Wolf
Joined: 07/09/2008
MGoPoints: 1693

But it sounds like good things are afoot. Huzzah!

  • Login or register to post comments
January 27th, 2011 at 2:07 PM | Still getting the warning on FF (Score:1)
Don
Don's picture
Joined: 06/30/2008
MGoPoints: 19220

FWIW.

We need to get a complete record of phone calls and emails going back and forth from Eastern Europe/Russia to:

• West Lafayette

• Columbus

• East Lansing

• Rivals


  • Login or register to post comments
January 27th, 2011 at 2:10 PM | LOL @ "how long would it take (Score:1)
bryemye
Joined: 09/14/2009
MGoPoints: 2374

LOL @ "how long would it take to start over"

"a couple hours."

The BURN philosophy to dealing with this stuff is usually best.

My Blog

  • Login or register to post comments
January 27th, 2011 at 2:14 PM | For anyone infected (Score:1)
CRex
CRex's picture
Joined: 09/28/2009
MGoPoints: 8737

For anyone infected and running a version of Windows I suggest: Windows Defender.

Yes it is a Microsoft product, but it is free and good at what it does. I started using it back when Vundo hit the scene and was blowing by things like McAfee and Norton. I'd have machines come in with McAfee flashing "OMG VUNDO DETECTED! DOOM! DOOM! DOOM!" but unable to clean it. However installed Windows Defender resulted in Vundo being blown away in under an hour. Basically it looks like MS is tired of being a bad joke in the security arena and is out for blood. It updates daily and does a major Rev at least 2 or 3 times a year.

Should you be a Michigan student and using McAfee 8.0/8.1/8.5/9.0 or whatever version is currently up on itd.umich.edu/bluedisc get rid of it and get something better. Sometime around 8.0 McAfee lost its mojo in terms of virus detect and their spyware detection is a freaking joke. Plus they do things like decide system32.exe is a virus and delete it. System32.exe is a key Windows system file and deleting it basically bricks your computer. Get rid of it and avoid Virus Busters (the UMich group) like the plague. They have no clue what they're doing (assuming they do anything, given their page hasn't been updated since 2004).

As a side note, don't run multiple virus scanners at one. They end up trying to scan the same chunk of memory from time to time and bad things happen. So if you get a new one, be sure to remove the old one.

  • Login or register to post comments
January 27th, 2011 at 2:35 PM | MS Security Center (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

If MS Security Center is part of Windows Defender (or vice-versa), it didn't do it's job on my Dad's computer.  It was infected and he had MS Security Center installed.  It didn't even bat an eye at the malware propogated thru this site.  My brother-in-law does workstation support for a Fortune 100 company and recommends the current version of Norton.  Say what you will about Norton (or any of the other anti-virus software products) but I have it installed and was not infected.

My Dad decided to go with something called Viper that's supposed to work well on Windows 7 (all of the PCs I use are Win XP).  I'm not saying CRex doesn't know what he's talking about, I'm just trying to add more information since most of the comments here indicate this subject is beyond a lot of folks comprehension (no offense to anyone).

Unfortunately, there are people out there that want to ruin other's internet experience.  A lot of you use your computers for work, home finance, personal archives, etc.  Please don't let something like this ruin all of your hard work.  Get some sort of anti-virus protection.  If you decide to go the freebie route, do some reasearch first to see what it can and cannot do.  Don't be cheap just for the sake of being cheap.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:56 PM | What on earth is MS Security (Score:1)
CRex
CRex's picture
Joined: 09/28/2009
MGoPoints: 8737

What on earth is MS Security Center beyond a generic webpage that provides updates and links to various tools.  It's not some kind of program you can install, just a links of removal tools and links to updates, post infection removal tools and scanners.  Thus I have no idea what parts of that system your dad had installed or didn't have installed.  

Windows Defender (spyware only) and Microsoft Security Essentials (spyware + virus) both do realtime and benchmark in 95+% for detection rating.  Security Essentials actually benchmarked hirer than AVG (the most popular free antivirus) during the 2010 tests by SpywareTools.  

As it stands right now I think SE is pushing about a 95% in latest tests and normally is in the 95-98% range for detection (above average in rootkit detection and repair, below average in zero threat handling*).  I like it better because its idiot proof and updates via normal Windows mechanisms which I feel is better for less savvy folks.     Security Essentials is known for its fast boots and good realtime protection, with actual scanners taking a bit longer (but you can do those at 2 am when you're asleep).  

I'll avoid any kind of flamewar over who likes what, no tool is perfect.  Rather just be an intelligent consumer and Google likes like "Microsoft Security Essentials detection rating" and "Microsoft Security Essentials review".  Don't rely on single accounts or "he said/she said" stuff.  av-tests.org, icsalabs.com/ and virusbtn.com/ are all good places to go for reviews beside just general Googling.  

*For non techies, zero day means the exploit hits without any warning.  Normally you see hackers talking on their forums about exploits and people have time to patch or prepare.  A zero day is a sucker punch out of nowhere.

  • Login or register to post comments
January 27th, 2011 at 2:13 PM | I can't believe I read all that !! (Score:1)
Catahoulajak
Catahoulajak's picture
Joined: 02/25/2009
MGoPoints: 72

 I don't comment a whole lot, but damn it feels good to be able to if I want now !! It's been a long time since I had a comment box.

PUNCH EM IN THE MOUTH!!

  • Login or register to post comments
January 27th, 2011 at 2:17 PM | Also I just noticed (Score:1)
Catahoulajak
Catahoulajak's picture
Joined: 02/25/2009
MGoPoints: 72

 My profile info just updated, it was stuck at 50 weeks for almost a year. I felt like such a newbie !!

PUNCH EM IN THE MOUTH!!

  • Login or register to post comments
January 27th, 2011 at 2:14 PM | I thought we were destroyed (Score:1)
MGoBSam
MGoBSam's picture
Joined: 10/18/2010
MGoPoints: 521

I thought we were destroyed until my brother asked "how long would it take to recreate it from scratch?"

 

Someone buy Brian's brother a drink.

  • Login or register to post comments
January 27th, 2011 at 2:16 PM | Kaspersky (Score:1)
scblue
scblue's picture
Joined: 06/20/2009
MGoPoints: 14

My home computer was infected by the malware.  I downloaded and created a Kaspersky rescue disk - http://support.kaspersky.com/viruses/rescuedisk and it removed all the bad stuff.  Just burn the ISO on a cd and boot from that cd.  Computer works fine now and the download is free.  It's worth a try!

 

  • Login or register to post comments
January 27th, 2011 at 2:23 PM | "Their extremely awesome (Score:3 Normal)
Go Blue Eyes
Go Blue Eyes's picture
Joined: 12/05/2010
MGoPoints: 574

"Their extremely awesome advice is to look for the bad things and remove them."

I guess that's like calling the fire department and they say, "Put water only on the spots that are on fire."

  • Login or register to post comments
January 27th, 2011 at 2:55 PM | If points come back into existence (Score:1)
WolverBean
Joined: 06/30/2008
MGoPoints: 851

remind me to +1 you for this.

  • Login or register to post comments
January 27th, 2011 at 5:26 PM | Seconded! (Score:1)
Benoit Balls
Benoit Balls's picture
Joined: 11/27/2010
MGoPoints: 860

Seconded!

ALWAYS remember the golden rule: He who has the gold, makes the rules

 

  • Login or register to post comments
January 27th, 2011 at 2:24 PM | How do we know if we are affected? (Score:1)
profitgoblue
Joined: 09/01/2009
MGoPoints: 19415

Is it blantantly obvious if our home/work computer is affected by this virus thing?  I am about as computer savvy as my 3-year old son . . .

Disgruntled former moderator.  I got a lot of problems with you people!

  • Login or register to post comments
January 27th, 2011 at 2:39 PM | Pop-Up (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

You'll have a pop-up that won't go away.  If you try to close it, it will tell you you need to buy some sort of product and ask for a credit card number.  This is what my Dad experienced.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:50 PM | So... (Score:1)
modaddy21
modaddy21's picture
Joined: 11/09/2009
MGoPoints: 1313

if we never got the pop-up we are good?  I have McAfee Security Center through my internet provider (Cox) and it says no virus or spyware.

  • Login or register to post comments
January 27th, 2011 at 2:57 PM | Thanks Bronco (Score:1)
profitgoblue
Joined: 09/01/2009
MGoPoints: 19415

No pop-up here (knock on wood!).

Disgruntled former moderator.  I got a lot of problems with you people!

  • Login or register to post comments
January 27th, 2011 at 2:25 PM | uggh, malware (Score:1)
sharkhunter
Joined: 01/29/2009
MGoPoints: 2247

Photobucket

  • Login or register to post comments
January 27th, 2011 at 2:29 PM | I'm not trying to get ahead (Score:1)
SanFrancisco_Wo...
SanFrancisco_Wolverine's picture
Joined: 11/16/2009
MGoPoints: 2078

I'm not trying to get ahead of you Brian, I am really just curious.  How long do you think it will take before we get points and voting back up and running as well as the ability to view our account and recent posts?  This change in formatting is making me muy nerviouso.

Formerly akron_wolverine and columbus_wolverine.  New home, new name.  A year in Columbus was enough.

  • Login or register to post comments
January 27th, 2011 at 2:33 PM | hard lesson (Score:1)
entirely reasonable
entirely reasonable's picture
Joined: 07/24/2008
MGoPoints: 2515

Memo:

Do not renew the GERG Robinson Antivirus.

That is all.

"Play hard and with great effort"

  • Login or register to post comments
January 27th, 2011 at 2:38 PM | Is this going to get rid of (Score:1)
His Dudeness
His Dudeness's picture
Joined: 11/24/2008
MGoPoints: 13558

Is this going to get rid of all the retarded commenters who just post stupid pics all the time?

No?

KTHXBAI

or uh, Duder, or El Duderino if you're not into the whole brevity thing.

  • Login or register to post comments
January 27th, 2011 at 3:06 PM | (No subject) (Score:3 Normal)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

  • Login or register to post comments
January 27th, 2011 at 2:44 PM | I am just glad i have a (Score:1)
joelrodz
joelrodz's picture
Joined: 09/26/2009
MGoPoints: 372

I am just glad i have a MAC....disease free since 2005 (NTKOD)

  • Login or register to post comments
January 27th, 2011 at 3:03 PM | Amen (Score:1)
u_of_mfootball.com
u_of_mfootball.com's picture
Joined: 01/24/2011
MGoPoints: 17

brother ... me too ... since 2000 ... n lovin it

http://www.university-of-michiganfootball.com

  • Login or register to post comments
January 27th, 2011 at 4:44 PM | You noob (Score:1)
ottomatic
Joined: 01/12/2011
MGoPoints: 142

My first Mac was the Mac IIFX circa. 1990. 9000.00 USD without RAM or Video card. By 1997 my kids were using it as key-banger toddler toy.

As for infections on a Mac. Last year I clicked on a link on this site (I'm not blaming) to a bit torrent of a UM game. The destination had some  additional links regarding sound problems and the need to download an additional file, yada, yada, yada ... that additional link tried to download a  remote control app that would have executed on the Mac. So yeah, I love the security of Mac but I still run ClamXAV as well as other precautions.

  • Login or register to post comments
January 27th, 2011 at 2:52 PM | This partial site retro-ization (Score:1)
Sgt. Wolverine
Sgt. Wolverine's picture
Joined: 06/30/2008
MGoPoints: 3523

has made me realize how much I miss the boxes around each individual comment.  These particular boxes are sort of unwieldy and ugly, but I think it would be worth reconsidering the decision to remove the boxes from the comments.  I find the boxed comments easier to follow.

Sportscenter.com raves: Sgt. Wolverine, "Michigan's biggest fan"!

  • Login or register to post comments
  • 1
  • 2
  • next ›
  • last »
Powered by Pressflow, an open source content management system
Theme provided by Roopletheme; sidebars adapted from Chris Murphy.