[FIXED] Malware on CMSMS.org

General project discussion. NOT for help questions.
Post Reply
User avatar
klendino
Forum Members
Forum Members
Posts: 67
Joined: Wed Oct 19, 2005 8:22 pm
Location: Caribbean

[FIXED] Malware on CMSMS.org

Post by klendino »

Since this morning I get a warning in Google Chrome:
Warning: Something's Not Right Here!
http://www.cmsmadesimple.org contains content from xxxxxxxxxxxx, a site known to distribute malware. Your computer might catch a virus if you visit this site.
Google has found malicious software may be installed onto your computer if you proceed. If you've visited this site in the past or you trust this site, it's possible that it has just recently been compromised by a hacker. You should not proceed, and perhaps try again tomorrow or go somewhere else.
Last edited by Rolf on Fri Sep 21, 2012 12:44 pm, edited 2 times in total.
Reason: removed links
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: Malware on CMSMS.org

Post by RonnyK »

is fixed....

Ronny
krussell
Forum Members
Forum Members
Posts: 32
Joined: Wed May 16, 2007 2:00 pm

Re: [FIXED] Malware on CMSMS.org

Post by krussell »

I am currently getting the malware warning:

"Warning: Something's Not Right Here!
http://www.cmsmadesimple.org contains content from "google-analytics.su", a site known to distribute malware. Your computer might catch a virus if you visit this site.. "
Wishbone
Power Poster
Power Poster
Posts: 1368
Joined: Tue Dec 23, 2008 8:39 pm

Re: [FIXED] Malware on CMSMS.org

Post by Wishbone »

I'm getting that as well.
jmcgin51
Power Poster
Power Poster
Posts: 1899
Joined: Mon Jun 12, 2006 9:02 pm

Re: [FIXED] Malware on CMSMS.org

Post by jmcgin51 »

same here (2225hrs Central US time, 07FEB2012) Firefox reports forum.cmsmadesimple.org as an attack site.
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm
Location: Fernie British Columbia, Canada

Re: [FIXED] Malware on CMSMS.org

Post by calguy1000 »

We're on it.

It seems we're the subject of targeted attacks.

We have fixed what they changed (numerous times).
We are just not sure how they are getting in. Some type of file upload vulnerability it seems.
We just haven't found which package and/or site that is on this server is vulnerable.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm
Location: Fernie British Columbia, Canada

Re: [FIXED] Malware on CMSMS.org

Post by calguy1000 »

I promise a full report when we find the solution to this.

If it's a vulnerability in CMSMS core:
- We'll fix it and spit out a new release.

If it's a vulnerability in an addon module:
- We'll find the bug and give the report to the author
(If it's one of my modules, there'll be a new release).

If it's a third party package
- We'll fix the bug and file a report, and let everybody here know.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
oliver341
Forum Members
Forum Members
Posts: 89
Joined: Sat Feb 23, 2008 3:51 pm

Re: [FIXED] Malware on CMSMS.org

Post by oliver341 »

Looks serious.

Yesterday I couldn't download CMSMS, I kept being redirected to Bing or a weird hostname which didn't resolve (probably a malware url which has since been deleted).

Now, the download page is missing all of its download links:

http://www.cmsmadesimple.org/downloads/
http://i39.tinypic.com/2e1dkdk.png
Zafazo
New Member
New Member
Posts: 9
Joined: Mon Dec 12, 2011 6:40 pm

Re: [FIXED] Malware on CMSMS.org

Post by Zafazo »

So has this been resolved?

It appears the download links have returned, I just don't want to download a vexed install of CMSMS.

Google doesn't appear to have visited the site since yesterday is why I am asking.

Much luck in resolving this issue.
baresi
Forum Members
Forum Members
Posts: 129
Joined: Fri Jul 27, 2007 4:15 pm

Re: [FIXED] Malware on CMSMS.org

Post by baresi »

Same question, are the downloads safe now?
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm
Location: Fernie British Columbia, Canada

Re: [FIXED] Malware on CMSMS.org

Post by calguy1000 »

Yes, the errors are all resolved.

The downloads always were safe... the hacker was injecting some html into the page source to fug with our analytics js... that's all.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
baresi
Forum Members
Forum Members
Posts: 129
Joined: Fri Jul 27, 2007 4:15 pm

Re: [FIXED] Malware on CMSMS.org

Post by baresi »

Thanks :)
Post Reply

Return to “General Discussion”