Home
we had subs it was crazy

Primary links

  • About
    • $upport (lol)
    • Ethics
    • FAQ
    • Privacy Policy
  • Contact
  • MGoStore
  • MGoBoard
    • MGoBoard FAQ
    • Ticket spreadsheet
    • Michigan bar locator
    • Moderator Action Sticky
  • Useful Stuff
    • Depth Chart By Class
    • Unofficial Two Deep
    • 2013 Offer Board
    • Crude Bug Tracking System
    • Third Down Stats
    • Diaries, Windows Live Writer, And You
    • Michigan Future Schedules
    • User-Curated HOF
    • 2013 Recruiting Board
    • Where To Eat In Ann Arbor
Home

Navigation

  • Forums
  • Recent posts

User login

  • Create new account
  • Request new password

MGoElsewhere

  • @MGoBlog (Brian)
  • @aceanbender
  • @TomVH (Tom)
  • RSS Feed
  • iPhone App
  • Facebook profile
  • MGoKindle Store
  • mgo.licio.us
  • Brian @ TSB [Archive]
  • Brian @ AOL [Archive]
  • Sour Salty Bitter Sweet

Michigan Blogs

  • Big House Blog
  • Burgeoning Wolverine Star
  • Genuinely Sarcastic
  • Go Blue Michigan Wolverine
  • Holdin' The Rope
  • MGoFootball
  • MVictors
  • Maize 'n' Blue Nation
  • Maize 'n' Brew
  • Maize And Go Blue
  • Michigan Hockey Net
  • The Blog That Yost Built
  • The Hoover Street Rag
  • The M Block
  • The M Zone
  • The Wolverine Blog
  • Touch The Banner
  • UMGoBlog
  • UMHoops
  • UMTailgate
  • Wolverine Liberation Army

M On The Net

  • mgovideo
  • MGoBlue.com
  • Mike DeSimone
  • Recruiting Planet
  • The Wolverine
  • Go Blue Wolverine
  • Winged Helmet
  • UMGoBlue.com
  • MaizeRage.org
  • Puckhead
  • The M Den
  • True Blue Fan Forum

Big Ten Blogs

  • Illinois
    • A Lion Eye
    • Hail To The Orange
    • Illinois Baseball Report
    • Illinois Loyalty
  • Indiana
    • Inside The Hall
    • The Crimson Quarry
  • Iowa
    • Black Heart, Gold Pants
    • Fight For Iowa
  • Michigan State
    • The Only Colors
  • Minnesota
    • GopherHole.com
    • The Daily Gopher
    • I'm In Love With A Fringe Bowl Team
    • TNABACG
  • Nebraska
    • Big Red Network
    • Corn Nation
    • Husker Mike's Blasphemy
    • Husker Gameday
  • Northwestern
    • Sippin' On Purple
    • Lake The Posts
  • Notre Dame
    • The House Rock Built
    • One Foot Down
  • Ohio State
    • Eleven Warriors
    • Buckeye Commentary
    • Men of the Scarlet and Gray
    • Our Honor Defend
    • The Buckeye Nine
  • Penn State
    • Slow States
    • Black Shoe Diaries
    • Happy Valley Hardball
    • Penn State Clips
    • Linebacker U
    • Nittany White Out
  • Purdue
    • Boiled Sports
    • Hammer and Rails
  • Wisconsin
    • Bruce Ciskie

Links of Note

  • Baseball
    • Big Ten Hardball
    • College Baseball Today
    • The Baseball Zealot
    • The College Baseball Blog
  • Basketball
    • Ken Pomeroy
    • Basketball Prospectus
    • Midmajority
  • College Hockey
    • Chris Heisenberg
    • College Hockey Stats
    • Inside College Hockey
    • Michigan College Hockey
    • Hockey's Future
    • Sioux Sports
    • USCHO
    • Western College Hockey
    • CCHA
      • LSSU Hockey
      • Bronco Hockey Blog
  • Football
    • Smart Football
    • Every Day Should Be Saturday
    • Doctor Saturday
    • CFB Stats
    • Harold Stassen
    • NCAA D-I Stats Page
    • The Wizard Of Odds
  • General
    • Sports Central
  • Local Interest
    • The Ann Arbor Chronicle
    • Arborwiki
    • Arbor Update
    • Teeter Talk
    • Vacuum
  • Teams Of The D
    • Lions
      • Pride of Detroit
      • Fire Millen
    • Pistons
      • Detroit Bad Boys
      • Need4Sheed
    • Tigers
      • Roar Of The Tigers
      • The Detroit Tigers Weblog
      • The Daily Fungo
    • Red Wings
      • On The Wings
      • Behind The Jersey
      • Winging It In Motown
    • Michigan Sports Forum

Archive

  • May 2013 (42)
  • April 2013 (94)
  • March 2013 (104)
  • February 2013 (81)
  • January 2013 (93)
  • December 2012 (74)
  • November 2012 (142)
  • October 2012 (143)
  • September 2012 (107)
  • August 2012 (103)
  •  
  • 1 of 11
  • ››

Get Yer Tickets

Football Display Case

NFL Watches

Follow your favorite team with localtv-satellite.com: Click Here.

Site Search

Diaries

  • New
  • Popular
  • Hot
  • More Milford Men Than Michigan Men: Comparing the 11-12 and 12-13 Hockey Teams
    MGoBlueline - 6 hours ago
  • Future Non-Conference Opponent Recruiting Watch
    EGD - 2 days ago
  • Way Too Late B1G Men's Basketball Scheduling Idea
    BeileinBuddy - 3 days ago
  • The Blockhams in "HOCKEY HANGOVER"
    Six Zero - 1 week ago
  • MGoAcceptance: Another MGoAnecdote
    LSAClassOf2000 - 1 week ago
  •  
  • 1 of 4
  • ››
more
  • Big Ten Recruiting Rankings 5-15-13
    Ace - 1,341 views
  • Future Non-Conference Opponent Recruiting Watch
    EGD - 493 views
  • Way Too Late B1G Men's Basketball Scheduling Idea
    BeileinBuddy - 356 views
  • More Milford Men Than Michigan Men: Comparing the 11-12 and 12-13 Hockey Teams
    MGoBlueline - 33 views
  • Big Ten Recruiting Rankings 5-15-13
    Ace - 50 comments
  • MGoAcceptance: Another MGoAnecdote
    LSAClassOf2000 - 19 comments
  • The Blockhams in "HOCKEY HANGOVER"
    Six Zero - 13 comments
  • Future Non-Conference Opponent Recruiting Watch
    EGD - 13 comments
  • Way Too Late B1G Men's Basketball Scheduling Idea
    BeileinBuddy - 2 comments
  •  
  • 1 of 2
  • ››
more

MGoBoard

  • New
  • Recent
  • Hot
  • OT: ESPN Mag/Insider special $5/Year
    0 replies
  • BBall year in review Deleted...
    7 replies
  • OT: RIP Dick Trickle and Ken Venturi
    12 replies
  • Siva Admits Trey Burke's Title Game Block Was Clean
    43 replies
  • Softball Open Thread 7pm vs Valpo ESPN3
    33 replies
  • OT Staee shutout by Penn St 9-0 in baseball
    20 replies
  • Alex Bars to Notre Dame
    89 replies
  • OT - The Friday Night Alcoholics - Early Edition Thread
    59 replies
  • Trey Burke current on ESPN2 at NBA Combine
    28 replies
  • OT: End of Drew and Mike on 101WRIF
    37 replies
  • Michigan has #1 recruiting class on ESPN now.
    72 replies
  • The Talented Shallmans
    41 replies
  • OT: Advice on moving to Ann Arbor
    71 replies
  • Speight to compete in Oakland Elite 11 camp
    45 replies
  • Nice Article on Michigan Baseball Signee Hector Gutierrez
    7 replies
  •  
  • 1 of 7
  • ››
  • OT: The Office series finale thread (may contain spoilers)
    43 replies
  • OT: Former ASU shooting guard Evan Gordon transfers to Indiana
    22 replies
  • Softball Open Thread 7pm vs Valpo ESPN3
    33 replies
  • The Talented Shallmans
    41 replies
  • OT: Explore Ann Arbor (YouTube)
    11 replies
  • Michigan Baseball Wins Big Game at Nebraska
    19 replies
  • Brady Hoke Calls Notre Dame A Chicken
    162 replies
  • CBS Article: FBS Conferences To Split To New Division?
    29 replies
  • OT: Tigers-Rangers (Verlander v Darvish)
    20 replies
  • Sam Webb on LB Recruiting
    47 replies
  • Nice Article on Michigan Baseball Signee Hector Gutierrez
    7 replies
  • Regents approve baseball & softball Turf fields, massive field hockey renovations
    21 replies
  • Tim Hardaway Jr. Impressing in Early Workouts
    59 replies
  • ESPN's Fraschilla has Trey Burke as Top PG in Draft
    26 replies
  • Brandon on Uniformzzz
    119 replies
  • ‹‹
  • 2 of 7
  • ››
  • OT: Red Wings @ Ducks Game 7 Open Thread
    229 replies
  • OT: Red Wings vs. Blackhawks Open Thread
    201 replies
  • Shane Morris to wear the famed #7 jersey, J.J. McGrath #46
    175 replies
  • Jabrill Peppers Announcement Date Set
    169 replies
  • Brady Hoke Calls Notre Dame A Chicken
    162 replies
  • Hello: Lawrence Marshall
    124 replies
  • UM 2014 Conf schedule football
    123 replies
  • Saturday night drinking thread
    121 replies
  • Brandon on Uniformzzz
    119 replies
  • Notre Dame's Nix fires back at Coach Hoke
    110 replies
  • GoBlueWolverine's Dre Barthwell: Marvin Robinson to leave Michigan
    96 replies
  • Sparty losing recruits to the rap game
    95 replies
  • Wading in the waters of tRCMB, post Marshall
    95 replies
  • Alex Bars to Notre Dame
    89 replies
  • PSU about to get blasted again by SI investigative report
    88 replies
  •  
  • 1 of 7
  • ››

mgo.licio.us

  • Big Ten football procrastinates on parity-based scheduling, and nothing ever changes

    the just released schedules were a flat-out statement that the B10 doesn't believe SOS will matter in playoff selection

    1 comments
  • Michigan's Glenn Robinson III, Mitch McGary ranked inside top 20 on ESPN's 2014 draft board

    but I thought that draft was supposed to be incredibly loaded?

    0 comments
  • Tim Hardaway Jr. turning heads, viewed as a first-rounder by some teams, analyst says

    If you're gonna go please be in the first round.

    0 comments
  • Michigan-Ohio State once, Indiana-Purdue once? The Big Ten has to protect its hoops rivalries

    another delightful side effect of a 14 team conference

    0 comments
  • Beilein on transfers: All should have to sit a year, regardless of situation

    I disagree.

    0 comments
  • Julie Hermann takes over as Rutgers AD, won't try to spend like Michigan

    GOOD PLAN

    1 comments
  • Jay Harris says no to Michigan State, decides to become a rapper

    hahahahaha

    0 comments
  • The Difference Between A Good Fan And A Bad Fan

    thoughtful piece from Jacobi on middle finger lady

    3 comments
  • Michigan's rising recruiting profile exciting John Beilein, who remains true to his scouting form

    Their high school coaches and AAU coaches have probably a better appreciation of Michigan than maybe they had before," Beilein said. "It's a tough balance right now. Tim Hardaway and Trey Burke weren't really high-profile players, nor was Darius Morris, and all were high-profile players. "We're still looking at 'who is the best fit.' "

    0 comments
  • Charles Barkley discusses Michael Jordan, Dream Team and more - NBA - Jack McCallum - SI.com

    "When I call somebody a midget, clearly I'm not trying to insult f---ing midgets. I'm just using basketball terminology."

    0 comments
  • Why does the NFL make for such bad media?

    robots

    0 comments
  • Pictured: Detroit's Robocop Statue nears completion date

    elsewhere in awesome things kickstarter made happen

    0 comments
  • Spectacular images of the madness that was the first FA Cup final

    And you think you're crowded at Michigan Stadium

    0 comments
  • Bear Vs. Monkey Bicycle Race Ends With Bear Eating Monkey

    IMPORTANT: Ondre Pipkins not involved.

    11 comments
  • Damon Bullock Has the Greatest Vine Account of All Time

    this is amazing

    7 comments

Lessons From The Great Malware Disaster Of 2011

By Brian — January 27th, 2011 at 1:38 PM — 63 comments
Filed under:
  • burning dwarves
  • great malware disaster of 2011
  • meta

[Note: iPhone app is currently broken; that is the #1 priority in terms of fixes. Hope to have it up by Monday.]

This has nothing to do with Michigan football but the least I can do to help the greater health of the internet is to offer some measure of advice for people who find themselves hacked in the face.

I'm not an expert. Please read the comments for people disagreeing with me, as they may/are better at this than I am. But I just went through this and if you're in the same boat here's what happened with me and what I took from it.

all-bird

Boatmurdered. BURN. ALL BURN.

"Last known good" may not be as good as you think. We have a backup. That backup overwrites itself on a nightly basis. Correction: that backup overwrote itself on a nightly basis. Going forward we wanted to be able to roll back up to a week.

However, we found out that would not have helped us here. Some of our infected files were last modified in early January. A "last known good" configuration from last weekend would have still featured multiple scripts with backdoors that Eastern European hackers could jump in.

We're still going to change our backup system so that it has more snapshots—an injection attack would be more susceptible to a DB rollback, I think—and we are going to have a billion and two backups of the actual code so that if, God forbid, something like this happens again we can have a reference point to pull forward stuff we customized and don't want to lose.

But…

BURN. ALL BURN. I'm not pulling anything forward except select bits and pieces I can hand-inspect. The rest of it dies in a fire. I thought we were destroyed until my brother asked "how long would it take to recreate it from scratch?" This was the moment in the movie when the camera zooms out and the city becomes transparent. It would take… um… maybe a couple hours. The defining feature of a CMS is that everything is in the database. So if you're confident the database isn't the issue you can pick that out, raze the world, download and install all your crap, and not have to worry about finding every last piece of corrupted code. You're going to break a few things when the new versions of your modules don't work exactly as expected but it's way better than the alternative.

Then change your FTP password over SSH. And then, if you're paranoid (ie: us now), turn FTP off entirely for a while. We had to use plain FTP, which is not very secure, because for some reason enabling encryption turned directory listing into a cripplingly slow process. A reader had related an experience in which a corrupted local computer had been giving away FTP passwords, giving hackers direct access to the server. We're not taking any chances despite my incessant scanning.

Burn, all burn exception: we pulled the "files" folder forward despite it being too massive to check because it's all data and those folders are locked down by server permissions so they can't execute anything. Everything else was pored over.

Why we thought it wasn't the database. Well, one, we found plenty of stuff indicating the server had taken a direct hit in the form of scripts that included helpful comments like "webshell by oRb." We brought those shells up and didn't find any database functionality.

Also, injection attacks usually don't affect the entire site—they're more likely to be hostile code submitted by users (something Drupal is good about) that affect only the pages they're submitted on. The malware was being delivered via the CSS and JS files, which are amongst the few bits of the page you're reading that don't come from the DB. While the server corruption could have in turn hit the DB, we didn't see obvious avenues for that and all of the problems were segregated from said DB.

We're now watching it closely just in case, but the evidence pointed to something other than an SQL injection.

What to search for. This article is fairly comprehensive but I'd also suggest looking for "unescape" or the string "%3C%69%66%72%61%6D%65." If you run that through the unescape function you get "<iframe". What are the chances that's helpful code? Not so good.

Don't waste your time with "StopBadware." This is the site you get funneled to if you click the I'm-so-screwed button on the Google warning page. Their extremely awesome advice is to look for the bad things and remove them. They list scripts, redirects, and iframes as the main ways you transmit the bad things—okay, probably helpful—and then offer this up:

There exist several free and paid website scanning services on the Internet that can help you zero in on specific badware on your site. There are also tools that you can use on your web server and/or on a downloaded copy of the files from your website to search for specific text.

Awesome! Where are they? Which are the best ones?

StopBadware does not list or recommend such services, but the volunteers in our online community will be glad to point you to their favorites.

Fu. The "online community" at "badwarebusters" mostly consists of people screaming about erroneous hits. About four threads pop up per day and they can go days without a response. If you're looking to do something quickly it's useless.

That's annoying. This is the worst advice possible:

Once you have located the code that is causing the badware behavior, removing it is often as simple as deleting the offending code from all files in which it appears. Sometimes, it is easier, if you have a clean backup of your site’s contents, to re-upload all of the site’s files, though be careful about overwriting files that may have changed since your last backup.

They've just glossed over the difference between the offending iframe and the code that generated it. Backdoors are not mentioned. This section needs to be replaced with:

BURN. ALL BURN.

Whoever wrote it should be horsewhipped. The next section is about "preventing future infection" when the previous section has essentially advised a n00b who needs to be informed that scripts and iframes are bad, mmmmkay, that "removing the offending code" "often" solves the problem. False. Burn. All burn. 

If you aren't already, sign up with Google's Webmaster tools. We first found out the aggregated JS file was an issue from them, and they periodically updated their findings to let us know we still hadn't killed the problems. Tip: if you're aggregating js and css you may want to stop for more precise identification of the end destinations.

These are not the sources. You have to find those, or just burn everything to the ground.

Don't get notifications other than security notifications. This site is now running dozens of Drupal modules, some of which actually have release changelists that read, in their entirety, "fixed typo X." After a while you stop checking just to see that some random module has done some stuff you don't care about, and then you don't know when certain modules are out of date. We're still not sure what the attack vector was but one of the main candidates was known, patched holes in Drupal. I went from weekly updates about everything to daily updates about security. Drupal shouldn't have other options.

Status. We're not entirely out of the woods yet but it's looking promising, and we have installed various alarms in the system to blare at us whenever anything unexpected (a file getting updated outside of the areas that's supposed to happen) goes down. Hopefully if there is another breach we will catch it long before anything starts getting delivered.

  • Login or register to post comments

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
January 27th, 2011 at 1:43 PM | Why on firefox (Score:1)
somewittyname
Joined: 05/15/2009
MGoPoints: 1029

is it still saying it's an attack page? I can access fine on my phone and Safari.

  • Login or register to post comments
January 27th, 2011 at 1:47 PM | Is it safe to come out yet? (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

I feel like I am taking those first steps right out of the nuclear bunker to navigate the damage right now. Did we get our missles off at those Reds from tsio?

  • Login or register to post comments
January 27th, 2011 at 3:03 PM | Seriously (Score:1)
Eyebrowse
Eyebrowse's picture
Joined: 07/06/2009
MGoPoints: 1388

It's like I don't even know where I am anymore.  

On a more serious note, this whole malware disaster has really shown me the depths of my own addiction.  I can say I am both proud and saddened by the state of my inner self since then.  

Let's also not talk about how I haven't shaved or showered in days (okay weeks, but that's nothing out of the ordinary).  

  • Login or register to post comments
January 27th, 2011 at 3:11 PM | Addicted?! Who is addicted?! (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

Addicted?! Who is addicted?! I'm not addicted!

 

All I want to know is if that malware has any offers? TomVH? I think MGoMalware was great breakaway speed and punishing hits over the middle. He has to at least have 4 stars.

  • Login or register to post comments
January 27th, 2011 at 3:21 PM | Seriously (Score:1)
JeepinBen
JeepinBen's picture
Joined: 01/22/2010
MGoPoints: 9529

I have gotten record amounts of work done this week... At least my boss doesn't read MGoBlog and therefore doesn't know that my uptick in production was due to a lack of time on here...

"Over? Did you say, over? Nothing is over until we decide it is!"

  • Login or register to post comments
January 27th, 2011 at 3:28 PM | Emerging from Vault 13 (Score:1)
I Bleed Maize N Blue
I Bleed Maize N Blue's picture
Joined: 09/27/2008
MGoPoints: 4807

Michigan Resurgent?  Michigan Resurgent!

The beatings will continue until the uniforms improve!

  • Login or register to post comments
January 27th, 2011 at 1:47 PM | to arms! (Score:1)
Moe Greene
Moe Greene's picture
Joined: 08/01/2008
MGoPoints: 2132

When do we launch the MGoCounterattack?

Even the noobs that get negged into the stratosphere know that we must defend this house....

Lock and load!

No radio. Nothing of value.

  • Login or register to post comments
January 27th, 2011 at 1:49 PM | WOLVERINES!!!!!11!!1! (Score:1)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

  • Login or register to post comments
January 27th, 2011 at 1:52 PM | My guess is that Scout needed traffic numbers and sent this over (Score:1)
iawolve
iawolve's picture
Joined: 11/03/2008
MGoPoints: 2488

They had insight on all the future pending commits that we had not even heard of or had contemplated a michigan offer. s\ 

  • Login or register to post comments
January 27th, 2011 at 1:56 PM | I'm still inclined to blame (Score:1)
wlubd
wlubd's picture
Joined: 02/26/2009
MGoPoints: 4971

I'm still inclined to blame Danny Hope. Next Purdue commit we take, he might just kill someone...

Twitter

  • Login or register to post comments
January 27th, 2011 at 1:52 PM | Did you find any Baxter (Score:1)
TrppWlbrnID
TrppWlbrnID's picture
Joined: 10/29/2009
MGoPoints: 7875

Did you find any Baxter Updates?

2013 resolution - make it onto the 2014 favorite MGoPosters post, not ironically
  • Login or register to post comments
January 27th, 2011 at 1:52 PM | Fingers crossed.  Knock on (Score:1)
Tauro
Tauro's picture
Joined: 06/30/2008
MGoPoints: 656

Fingers crossed.  Knock on wood.  Rabbits foot purchased.  Anything else that helps!

  • Login or register to post comments
January 27th, 2011 at 1:54 PM | Um, does this mean Demetrius (Score:1)
Zone Left
Zone Left's picture
Joined: 07/03/2008
MGoPoints: 13952

Um, does this mean Demetrius Hart isn't coming?  I don't know what the hell else that could have been about.

It's all John Navarre's fault.

 

  • Login or register to post comments
January 27th, 2011 at 1:56 PM | I don't understand (Score:1)
wolverine1987
wolverine1987's picture
Joined: 07/07/2008
MGoPoints: 2928

a single thing you wrote Brian. Sounds like some stuff is happening though, so good luck.

"Everyone gets dumped Gabe. Let me give you some advice: a little coverup on your Adams Apple will make it appear smaller. Which will make you appear less like a transvestite." 

  • Login or register to post comments
January 27th, 2011 at 2:00 PM | Hacker or Bot? (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

Brian,

Do you think this was done by a person or done by a bot?  It doesn't really matter, I was just curious.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:02 PM | Good luck Brian, hope you get (Score:1)
dennisblundon
dennisblundon's picture
Joined: 02/23/2010
MGoPoints: 6630

Good luck Brian, hope you get this back up and running again soon. For those of you eagerly awaiting my ability to post again I have a couple of gems ready on deck. One is a projected depth chart for 2011, complete with win/loss predictions for next years schedule. The other is why aren't we recruiting Cardale Jones with more tenacity. It will be glorious.

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | . (Score:1)
MGoShoe
MGoShoe's picture
Joined: 04/23/2009
MGoPoints: 19230

LSA '89 - MBB Natl Champions, Big 10/Rose Bowl Champions | @MGoShoe

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | I know nothing (Score:1)
Blue-Chip
Blue-Chip's picture
Joined: 01/06/2010
MGoPoints: 2950

about computer viruses.  Was there some goal in mind with this malware, or was it specifically designed to be a pain in Brian's proverbial backside?

Your friendly neighborhood contrarian.

  • Login or register to post comments
January 27th, 2011 at 5:34 PM | Get in. Stay In. (Score:1)
ottomatic
Joined: 01/12/2011
MGoPoints: 142

The goal of most modern malware is to operate quietly. Get in, stay in, and exfiltrate data, or gain control of additional systems. The malware that infected the MGOBLOG site attempted (for some not all) to download  a payload of a known spyware, there's a good chance it would have redirected to additional malware as well. The ultimate aim being that criminal syndicate want to steal your shit and control your computer.

Worldwide there are close to 7 million computers still infected with conficker. Those infected systems can be thought of as a zombie army ready to take commands and participate in distributed denial of service attacks (DDOS). The criminal syndicates that control these assets will even rent them out. In some of the shadier corners of the internet you can bid-on or buy a zombie contingent to launch your attack.

Sort of like paying Scam Newton to win the BCS.

  • Login or register to post comments
January 27th, 2011 at 2:04 PM | We're HEEEERRREEEE! (Score:1)
MGoBlueForLife
MGoBlueForLife's picture
Joined: 10/15/2010
MGoPoints: 174

They can't stop us, they can only hope to Malware us! Which they did, but were STILL HERE!
YEAH!

Can't see the line, can you Russ?
-Clark W. Griswold

  • Login or register to post comments
January 27th, 2011 at 2:05 PM | (No subject) (Score:1)
Laser Wolf
Joined: 07/09/2008
MGoPoints: 1692

  • Login or register to post comments
January 27th, 2011 at 2:06 PM | I am still not taking any (Score:1)
a non emu
Joined: 06/30/2008
MGoPoints: 683

I am still not taking any chances on my work computer. I am running firefox with AdBlock, and NoScript set to everything, including iFrames, disabled. One promising thing is that the site no longer shows up as an attack site on Firefox, so looks like you are more or less out of the woods. But, good luck! My MGoWithdrawal symptoms have been terrible recently.

Need. Moar. Mgo. Less. Malware.

  • Login or register to post comments
January 27th, 2011 at 2:06 PM | I am clueless (Score:1)
Hugh Jass
Hugh Jass's picture
Joined: 01/03/2011
MGoPoints: 719

to this kind of technology psycho babble.  You were talking a foreign language to me.  I have faith that a Blog about Michigan football will rise from the ashes and be bigger and better than ever!  Also thanks for saving all my mgopoints that I have wasted several hours of potentially productive time to earn -  You Rock!

If someone ever invented a low fat vitamin - filled vegetable that tasted like fudge covered Rice Krispies treats - I'd probably eat better

 

 

  • Login or register to post comments
January 27th, 2011 at 2:31 PM | Me too (Score:1)
michgoblue
michgoblue's picture
Joined: 11/16/2009
MGoPoints: 11209

I know nothing other than that the Board is screwed up and I can't respond to anything other than the main page.

  • Login or register to post comments
January 27th, 2011 at 2:07 PM | This post equals (Score:1)
Laser Wolf
Joined: 07/09/2008
MGoPoints: 1692

But it sounds like good things are afoot. Huzzah!

  • Login or register to post comments
January 27th, 2011 at 2:07 PM | Still getting the warning on FF (Score:1)
Don
Don's picture
Joined: 06/30/2008
MGoPoints: 19184

FWIW.

We need to get a complete record of phone calls and emails going back and forth from Eastern Europe/Russia to:

• West Lafayette

• Columbus

• East Lansing

• Rivals


  • Login or register to post comments
January 27th, 2011 at 2:10 PM | LOL @ "how long would it take (Score:1)
bryemye
Joined: 09/14/2009
MGoPoints: 2374

LOL @ "how long would it take to start over"

"a couple hours."

The BURN philosophy to dealing with this stuff is usually best.

My Blog

  • Login or register to post comments
January 27th, 2011 at 2:14 PM | For anyone infected (Score:1)
CRex
CRex's picture
Joined: 09/28/2009
MGoPoints: 8727

For anyone infected and running a version of Windows I suggest: Windows Defender.

Yes it is a Microsoft product, but it is free and good at what it does. I started using it back when Vundo hit the scene and was blowing by things like McAfee and Norton. I'd have machines come in with McAfee flashing "OMG VUNDO DETECTED! DOOM! DOOM! DOOM!" but unable to clean it. However installed Windows Defender resulted in Vundo being blown away in under an hour. Basically it looks like MS is tired of being a bad joke in the security arena and is out for blood. It updates daily and does a major Rev at least 2 or 3 times a year.

Should you be a Michigan student and using McAfee 8.0/8.1/8.5/9.0 or whatever version is currently up on itd.umich.edu/bluedisc get rid of it and get something better. Sometime around 8.0 McAfee lost its mojo in terms of virus detect and their spyware detection is a freaking joke. Plus they do things like decide system32.exe is a virus and delete it. System32.exe is a key Windows system file and deleting it basically bricks your computer. Get rid of it and avoid Virus Busters (the UMich group) like the plague. They have no clue what they're doing (assuming they do anything, given their page hasn't been updated since 2004).

As a side note, don't run multiple virus scanners at one. They end up trying to scan the same chunk of memory from time to time and bad things happen. So if you get a new one, be sure to remove the old one.

  • Login or register to post comments
January 27th, 2011 at 2:35 PM | MS Security Center (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

If MS Security Center is part of Windows Defender (or vice-versa), it didn't do it's job on my Dad's computer.  It was infected and he had MS Security Center installed.  It didn't even bat an eye at the malware propogated thru this site.  My brother-in-law does workstation support for a Fortune 100 company and recommends the current version of Norton.  Say what you will about Norton (or any of the other anti-virus software products) but I have it installed and was not infected.

My Dad decided to go with something called Viper that's supposed to work well on Windows 7 (all of the PCs I use are Win XP).  I'm not saying CRex doesn't know what he's talking about, I'm just trying to add more information since most of the comments here indicate this subject is beyond a lot of folks comprehension (no offense to anyone).

Unfortunately, there are people out there that want to ruin other's internet experience.  A lot of you use your computers for work, home finance, personal archives, etc.  Please don't let something like this ruin all of your hard work.  Get some sort of anti-virus protection.  If you decide to go the freebie route, do some reasearch first to see what it can and cannot do.  Don't be cheap just for the sake of being cheap.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:56 PM | What on earth is MS Security (Score:1)
CRex
CRex's picture
Joined: 09/28/2009
MGoPoints: 8727

What on earth is MS Security Center beyond a generic webpage that provides updates and links to various tools.  It's not some kind of program you can install, just a links of removal tools and links to updates, post infection removal tools and scanners.  Thus I have no idea what parts of that system your dad had installed or didn't have installed.  

Windows Defender (spyware only) and Microsoft Security Essentials (spyware + virus) both do realtime and benchmark in 95+% for detection rating.  Security Essentials actually benchmarked hirer than AVG (the most popular free antivirus) during the 2010 tests by SpywareTools.  

As it stands right now I think SE is pushing about a 95% in latest tests and normally is in the 95-98% range for detection (above average in rootkit detection and repair, below average in zero threat handling*).  I like it better because its idiot proof and updates via normal Windows mechanisms which I feel is better for less savvy folks.     Security Essentials is known for its fast boots and good realtime protection, with actual scanners taking a bit longer (but you can do those at 2 am when you're asleep).  

I'll avoid any kind of flamewar over who likes what, no tool is perfect.  Rather just be an intelligent consumer and Google likes like "Microsoft Security Essentials detection rating" and "Microsoft Security Essentials review".  Don't rely on single accounts or "he said/she said" stuff.  av-tests.org, icsalabs.com/ and virusbtn.com/ are all good places to go for reviews beside just general Googling.  

*For non techies, zero day means the exploit hits without any warning.  Normally you see hackers talking on their forums about exploits and people have time to patch or prepare.  A zero day is a sucker punch out of nowhere.

  • Login or register to post comments
January 27th, 2011 at 2:13 PM | I can't believe I read all that !! (Score:1)
Catahoulajak
Catahoulajak's picture
Joined: 02/25/2009
MGoPoints: 72

 I don't comment a whole lot, but damn it feels good to be able to if I want now !! It's been a long time since I had a comment box.

PUNCH EM IN THE MOUTH!!

  • Login or register to post comments
January 27th, 2011 at 2:17 PM | Also I just noticed (Score:1)
Catahoulajak
Catahoulajak's picture
Joined: 02/25/2009
MGoPoints: 72

 My profile info just updated, it was stuck at 50 weeks for almost a year. I felt like such a newbie !!

PUNCH EM IN THE MOUTH!!

  • Login or register to post comments
January 27th, 2011 at 2:14 PM | I thought we were destroyed (Score:1)
MGoBSam
MGoBSam's picture
Joined: 10/18/2010
MGoPoints: 521

I thought we were destroyed until my brother asked "how long would it take to recreate it from scratch?"

 

Someone buy Brian's brother a drink.

  • Login or register to post comments
January 27th, 2011 at 2:16 PM | Kaspersky (Score:1)
scblue
scblue's picture
Joined: 06/20/2009
MGoPoints: 14

My home computer was infected by the malware.  I downloaded and created a Kaspersky rescue disk - http://support.kaspersky.com/viruses/rescuedisk and it removed all the bad stuff.  Just burn the ISO on a cd and boot from that cd.  Computer works fine now and the download is free.  It's worth a try!

 

  • Login or register to post comments
January 27th, 2011 at 2:23 PM | "Their extremely awesome (Score:3 Normal)
Go Blue Eyes
Go Blue Eyes's picture
Joined: 12/05/2010
MGoPoints: 574

"Their extremely awesome advice is to look for the bad things and remove them."

I guess that's like calling the fire department and they say, "Put water only on the spots that are on fire."

  • Login or register to post comments
January 27th, 2011 at 2:55 PM | If points come back into existence (Score:1)
WolverBean
Joined: 06/30/2008
MGoPoints: 849

remind me to +1 you for this.

  • Login or register to post comments
January 27th, 2011 at 5:26 PM | Seconded! (Score:1)
Benoit Balls
Benoit Balls's picture
Joined: 11/27/2010
MGoPoints: 858

Seconded!

ALWAYS remember the golden rule: He who has the gold, makes the rules

 

  • Login or register to post comments
January 27th, 2011 at 2:24 PM | How do we know if we are affected? (Score:1)
profitgoblue
Joined: 09/01/2009
MGoPoints: 19415

Is it blantantly obvious if our home/work computer is affected by this virus thing?  I am about as computer savvy as my 3-year old son . . .

Disgruntled former moderator.  I got a lot of problems with you people!

  • Login or register to post comments
January 27th, 2011 at 2:39 PM | Pop-Up (Score:1)
Bronco648
Bronco648's picture
Joined: 08/20/2008
MGoPoints: 998

You'll have a pop-up that won't go away.  If you try to close it, it will tell you you need to buy some sort of product and ask for a credit card number.  This is what my Dad experienced.

Nobody home...

  • Login or register to post comments
January 27th, 2011 at 2:50 PM | So... (Score:1)
modaddy21
modaddy21's picture
Joined: 11/09/2009
MGoPoints: 1313

if we never got the pop-up we are good?  I have McAfee Security Center through my internet provider (Cox) and it says no virus or spyware.

  • Login or register to post comments
January 27th, 2011 at 2:57 PM | Thanks Bronco (Score:1)
profitgoblue
Joined: 09/01/2009
MGoPoints: 19415

No pop-up here (knock on wood!).

Disgruntled former moderator.  I got a lot of problems with you people!

  • Login or register to post comments
January 27th, 2011 at 2:25 PM | uggh, malware (Score:1)
sharkhunter
Joined: 01/29/2009
MGoPoints: 2247

Photobucket

  • Login or register to post comments
January 27th, 2011 at 2:29 PM | I'm not trying to get ahead (Score:1)
SanFrancisco_Wo...
SanFrancisco_Wolverine's picture
Joined: 11/16/2009
MGoPoints: 2078

I'm not trying to get ahead of you Brian, I am really just curious.  How long do you think it will take before we get points and voting back up and running as well as the ability to view our account and recent posts?  This change in formatting is making me muy nerviouso.

Formerly akron_wolverine and columbus_wolverine.  New home, new name.  A year in Columbus was enough.

  • Login or register to post comments
January 27th, 2011 at 2:33 PM | hard lesson (Score:1)
entirely reasonable
entirely reasonable's picture
Joined: 07/24/2008
MGoPoints: 2513

Memo:

Do not renew the GERG Robinson Antivirus.

That is all.

"Play hard and with great effort"

  • Login or register to post comments
January 27th, 2011 at 2:38 PM | Is this going to get rid of (Score:1)
His Dudeness
His Dudeness's picture
Joined: 11/24/2008
MGoPoints: 13558

Is this going to get rid of all the retarded commenters who just post stupid pics all the time?

No?

KTHXBAI

or uh, Duder, or El Duderino if you're not into the whole brevity thing.

  • Login or register to post comments
January 27th, 2011 at 3:06 PM | (No subject) (Score:3 Normal)
jhackney
jhackney's picture
Joined: 12/11/2008
MGoPoints: 18446

  • Login or register to post comments
January 27th, 2011 at 2:44 PM | I am just glad i have a (Score:1)
joelrodz
joelrodz's picture
Joined: 09/26/2009
MGoPoints: 372

I am just glad i have a MAC....disease free since 2005 (NTKOD)

  • Login or register to post comments
January 27th, 2011 at 3:03 PM | Amen (Score:1)
u_of_mfootball.com
u_of_mfootball.com's picture
Joined: 01/24/2011
MGoPoints: 17

brother ... me too ... since 2000 ... n lovin it

http://www.university-of-michiganfootball.com

  • Login or register to post comments
January 27th, 2011 at 4:44 PM | You noob (Score:1)
ottomatic
Joined: 01/12/2011
MGoPoints: 142

My first Mac was the Mac IIFX circa. 1990. 9000.00 USD without RAM or Video card. By 1997 my kids were using it as key-banger toddler toy.

As for infections on a Mac. Last year I clicked on a link on this site (I'm not blaming) to a bit torrent of a UM game. The destination had some  additional links regarding sound problems and the need to download an additional file, yada, yada, yada ... that additional link tried to download a  remote control app that would have executed on the Mac. So yeah, I love the security of Mac but I still run ClamXAV as well as other precautions.

  • Login or register to post comments
January 27th, 2011 at 2:52 PM | This partial site retro-ization (Score:1)
Sgt. Wolverine
Sgt. Wolverine's picture
Joined: 06/30/2008
MGoPoints: 3523

has made me realize how much I miss the boxes around each individual comment.  These particular boxes are sort of unwieldy and ugly, but I think it would be worth reconsidering the decision to remove the boxes from the comments.  I find the boxed comments easier to follow.

Sportscenter.com raves: Sgt. Wolverine, "Michigan's biggest fan"!

  • Login or register to post comments
  • 1
  • 2
  • next ›
  • last »
Powered by Pressflow, an open source content management system
Theme provided by Roopletheme; sidebars adapted from Chris Murphy.