Page 1 of 2 12 LastLast
Results 1 to 15 of 22

Thread: KB is infected with Malware

  1. #1
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86

    KB is infected with Malware

    I have tried this on more than one computer and get the same result ever time.

    Close your browser and open it again or go into incognito / privacy mode. This deletes all the cookies.

    Go to google and search "kiwi biker" or some other topic that will bring up results.

    When you click on the link you get taken to somewhere else with popup adverts. It only does it the first time. The second time you click on the link it goes to the correct location.

  2. #2
    Join Date
    23rd October 2013 - 18:30
    Bike
    72 Kawasaki A7, 05 Kawasaki W650
    Location
    Tauranga
    Posts
    1,289
    Yep I noticed that a few days ago. Obviously the crack team at KB IT Department have been away from the keyboards for a while.

  3. #3
    Join Date
    9th August 2005 - 19:52
    Bike
    CBR450RR
    Location
    Hamilton
    Posts
    6,368
    Blog Entries
    77
    Yeah nah, bet you're using Avast
    Zen wisdom: No matter what happens, somebody will find a way to take it too seriously. - obviously had KB in mind when he came up with that gem

    Artificial intelligence is no match for natural stupidity

  4. #4
    Join Date
    23rd October 2013 - 18:30
    Bike
    72 Kawasaki A7, 05 Kawasaki W650
    Location
    Tauranga
    Posts
    1,289
    Quote Originally Posted by Mental Trousers View Post
    Yeah nah, bet you're using Avast
    Nope I'd never touch that shit.

  5. #5
    Join Date
    4th April 2011 - 18:44
    Bike
    A fast one
    Location
    Auckland
    Posts
    762
    Hmm interesting I had this happen a few weeks ago. Hasn't happened again since however.

  6. #6
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86
    Quote Originally Posted by Mental Trousers View Post
    Yeah nah, bet you're using Avast
    Don't rely in AV software to save you.

    My guess is a vulnerability it vBullietin that has allowed someone to modify the mod_rewrite rules or .htaccess in apache.

    Might be a patch or else they will need to upgrade to a newer version.

  7. #7
    Join Date
    27th March 2006 - 10:29
    Bike
    KTM 1190 Adv R and a bunch of dirties
    Location
    Burglary capital of Unzud
    Posts
    2,879
    Privacy mode huh. What are you looking at?
    Quote Originally Posted by Albert
    Two things are infinite: the universe and human stupidity; and I'm not sure about the universe

  8. #8
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86
    Quote Originally Posted by The End View Post
    Hmm interesting I had this happen a few weeks ago. Hasn't happened again since however.
    It only does it once. I think that it writes a cookie to prevent it happening again to the same person. Close your browser and open it again or you might need to delete cookies.

    Or go into incognito / privacy mode.

    You also need to be clicking on a link from google etc. Opening the site directly won't trigger it.

    You should then see it again.

  9. #9
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86
    Quote Originally Posted by paturoa View Post
    Privacy mode huh. What are you looking at?
    https://support.mozilla.org/en-US/kb...ut-saving-info
    https://support.google.com/chrome/answer/95464?hl=en

    IE also has this feature but wouldn't recommend using that....

  10. #10
    Join Date
    9th August 2005 - 19:52
    Bike
    CBR450RR
    Location
    Hamilton
    Posts
    6,368
    Blog Entries
    77
    Quote Originally Posted by RogIrwin View Post
    My guess is a vulnerability it vBullietin that has allowed someone to modify the mod_rewrite rules or .htaccess in apache.

    Might be a patch or else they will need to upgrade to a newer version.
    More likely it's Google.

    https://www.google.com/url?sa=t&rct=...85970519,d.dGc

    That's the first link you get when you search Google for "kiwibiker". So they're not taking you directly to this site, they're passing you through something else.

    If you logout, kill off your Incognito window, come back to this page as a guest and click on that link it takes you to filestore72.info rather than to this site.

    Same thing happens with Bing.

    Duckduckgo, ixquick and DogPile take you straight to this site. I haven't tried any others.

    However, I'll check the site just in case.
    Zen wisdom: No matter what happens, somebody will find a way to take it too seriously. - obviously had KB in mind when he came up with that gem

    Artificial intelligence is no match for natural stupidity

  11. #11
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86
    Quote Originally Posted by Mental Trousers View Post
    More likely it's Google..
    No. KB has malware installed on it.

    http://youtu.be/L9tjcB_ij-0?t=5m49s

  12. #12
    Join Date
    9th August 2005 - 19:52
    Bike
    CBR450RR
    Location
    Hamilton
    Posts
    6,368
    Blog Entries
    77
    Quote Originally Posted by RogIrwin View Post
    No. KB has malware installed on it.

    http://youtu.be/L9tjcB_ij-0?t=5m49s
    Nope. There's only a single rewrite rule in any of the .htaccess files and that writes a forbidden.

    Others are significantly harder to detect so they're going to take a while.
    Zen wisdom: No matter what happens, somebody will find a way to take it too seriously. - obviously had KB in mind when he came up with that gem

    Artificial intelligence is no match for natural stupidity

  13. #13
    Join Date
    20th June 2005 - 14:27
    Bike
    Fatbob
    Location
    the 'Tron
    Posts
    1,348
    Quote Originally Posted by Mental Trousers View Post
    Nope. There's only a single rewrite rule in any of the .htaccess files and that writes a forbidden.

    Others are significantly harder to detect so they're going to take a while.
    http://www.vbulletin.com/forum/forum...lestore72-info

    Solution: disabling register_globals, and/or initializing $vbseo_crules, $seo_replace_inurls at the start of vbseo.php.

  14. #14
    Join Date
    27th April 2014 - 00:20
    Bike
    DR650
    Location
    Nelson
    Posts
    86
    Quote Originally Posted by Mental Trousers View Post
    Nope. There's only a single rewrite rule in any of the .htaccess files and that writes a forbidden.

    Others are significantly harder to detect so they're going to take a while.
    Do you have a backup of the site from the last time that you modified it? Has to be at least a few months ago. They see what files have changed.

    I use a tool called meld - http://meldmerge.org/

    It will give you a side by side view of files that have changed in a directory. Also gives you a line by line view of changes in each file. Could be really useful for finding things like this.

  15. #15
    Join Date
    9th August 2005 - 19:52
    Bike
    CBR450RR
    Location
    Hamilton
    Posts
    6,368
    Blog Entries
    77
    Quote Originally Posted by TerminalAddict View Post
    http://www.vbulletin.com/forum/forum...lestore72-info

    Solution: disabling register_globals, and/or initializing $vbseo_crules, $seo_replace_inurls at the start of vbseo.php.
    Chur bro
    Zen wisdom: No matter what happens, somebody will find a way to take it too seriously. - obviously had KB in mind when he came up with that gem

    Artificial intelligence is no match for natural stupidity

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •