[SOLVED] URGENT! Has Forum been hacked? Or is a Firefox vulnerability being

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
cnymike
Power Poster
Power Poster
Posts: 446
Joined: Sun Jan 22, 2006 3:24 am

[SOLVED] URGENT! Has Forum been hacked? Or is a Firefox vulnerability being

Post by cnymike »

I'm using Firefox 2.0.0.7 on my PC and something very disturbing just happened to me while I was attempting to post to the forum. When I clicked on "Post" or "Preview" I was immediately taken to a "PayPal" page titled, Error Detected and the address was https://www.paypal.com/cgi-bin/webscr

This is not comforting. Any ideas what is happening here?

I switched to Safari 3.0.3 and was able to preview and post this message. But using Firefox resulted in the redirected to PayPal or PayPal spoof page. What is going on here?
Last edited by cnymike on Mon Oct 15, 2007 10:39 pm, edited 1 time in total.
cnymike
Power Poster
Power Poster
Posts: 446
Joined: Sun Jan 22, 2006 3:24 am

Re: URGENT! Has Forum been hacked? Or is a Firefox vulnerability being exploite

Post by cnymike »

I am now using Firefox v2.0.0.7 on my Mac and I am not getting the error, nor the PayPal webpage loading when I click on Preview or Post.

So something is going on with the PC version of Firefox, at least for me, which is causing me great concern. Why would the Post or Preview buttons being clicked cause the browser to go to a PayPal page with an Error Detected message?
cnymike
Power Poster
Power Poster
Posts: 446
Joined: Sun Jan 22, 2006 3:24 am

Re: URGENT! Has Forum been hacked? Or is a Firefox vulnerability being exploite

Post by cnymike »

Further investigation reveals that what is happening to me with Firefox is related to my Firewall settings. I don't understand what is going on but I have discovered that if I add cmsmadesimple.org to be ignored by the Privacy settings in my Firewall software, the Post and Preview buttons work as expected and no longer give me the PayPal error page. Apparently the PayPal donation button link is somehow being utilized when the Post or Preview is clicked on and by disabling the Privacy settings in the Firewall , this behavior ceases. Go figure. Just another screwy thing to waste time on.
Post Reply

Return to “CMSMS Core”