meta: brief malware event

Submitted by Brian on

The site was down from about 6:45 to 9 due to malware. This time we:

1. Took the site down immediately. Malware had been up about 10 minutes, I think.

2. Identified the offending script.

3. Locked down that directory so that it will run nothing.

Never say never but we did a much better job this time around and have identified the offending vulnerability to deal with it, something we had issues with before. The offending directory is one of the areas users can upload to, of which there are no others, and we've just shut off any ability for someone to execute in it.

Sorry for anyone who got hit in that brief window. We are just about at the point where this should not happen again, I think.

Pulling Guard

October 30th, 2011 at 11:19 PM ^

Is there a reason pretty much all the comments I make using a computer get blocked by "your submission has triggered the spam filter and will not be accepted"?

I can usually make one comment, but it happens on the second and I basically get banned for a day. The android app works fine though.

I might be getting a capcha wrong, but I've tried to be extra careful with them. Still, I don't see why getting one wrong should shut you down completely.

Sac Fly

October 31st, 2011 at 1:14 AM ^

Maybe a few of the other users can give some input, but I have never once had to input a capcha to post here before. What browser do you use, what settings do you have on, any add-ons, proxy, static/dynamic IP, or any other security feature that might make you look like an ad bot?