Exploit warning

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
I don't think there is a problem on AGD. This site has an active scanner and is scanned by both Securi and Norton. I will have the server team look, but I would guess this is on your end. I also scanned it directly just now and found nothing.
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
Ha! I hope not. I had actually thought he posted before, I see a post count of 1.

Anyway - a server deep scan is underway by the server team. I will keep everyone alerted to any issues, but it is a few hours worth of scanning - so don't expect any news too soon.

Andy
 

PaaskeUK

Affiliate Guard Dog Member
Joined
Sep 15, 2010
Messages
415
Reaction score
143
Nah my research on this seems to be an exploit in adobe flash player. So I really doubt it has nothing to do with you site at all Andy :) I have a good scanner and also McAfee thingy and no warnings at all for AGD.
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
ok, good. I don't have any flash on AGD as far as I am aware. All banners are even non-flash banners. Either way - AGD will be fully scanned. It is daily anyway, but never hurts to get the server team on it :)
 

progger

New Member
Joined
Nov 12, 2013
Messages
13
Reaction score
3
guys this warning is maybe from other page, i have more tabs open - is maybe a issue from other page...

i check it later...

regards
Progger
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
Thanks to progger for mentioning this. While there wasn't an exploit on any community pages - we did find some buried deep. In places that were non-accessible anymore (since the move to XenForo from vBulletin), but they are all now removed. Much appreciated. Running a third virus/malware scanner now :) I'm ok being OVERprotected.
 

TheGamblingGuru

Turning Over Stones
Joined
Jan 23, 2009
Messages
1,052
Reaction score
25
Thanks to progger for mentioning this. While there wasn't an exploit on any community pages - we did find some buried deep. In places that were non-accessible anymore (since the move to XenForo from vBulletin), but they are all now removed. Much appreciated. Running a third virus/malware scanner now :) I'm ok being OVERprotected.
I found this really interesting that AVG that progger was using found this "exploit", but apparently Securi had missed it?

____
____
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
well... he did say he thinks it was probably on a different tab ;)

The exploits I found were in places where you couldn't even navigate to. it was some old stuff that I completely removed from the server (translations that we don't do anymore and OpenX ads). Either case I looked at the code and so did the server team. Wasn't anything that gained access to the database or server.
 

TheGamblingGuru

Turning Over Stones
Joined
Jan 23, 2009
Messages
1,052
Reaction score
25
The exploits I found were in places where you couldn't even navigate to.

You think that is maybe why Securi had missed it?

I was just reading over Securi's website the other night and kinda even thinking about using them but now after reading this I'm not so sure that it would be that beneficial.

____
____
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
yeah, that's exactly it. I'm using ClamAV tied to Maldet (ClamAV for the virus definitions, Maldet for the scanning) now. This will scan all files on my server whereas Securi will scan all files that are navigable (I believe).
 

TheGamblingGuru

Turning Over Stones
Joined
Jan 23, 2009
Messages
1,052
Reaction score
25
Ah ok, I was thinking that Securi was a deep scanner. I'll have to check out the two above that you mentioned.

____
____
 

Guard Dog

Guard Dog
Staff member
Joined
Dec 13, 2006
Messages
11,353
Reaction score
3,179
The new Securi stuff might. I think I must be grandfathered in. I'm on a free version that no longer seems to exist. The new stuff looks like it digs pretty deep. Not cheap, though.
 
Top