Jump to content

  • Log in with Facebook Log in with Twitter Log In with Google      Sign In   
  • Create Account

Photo
- - - - -

Help: Website Being Reported As Unsafe!


  • Please log in to reply
12 replies to this topic

#1 Sid

Sid

    Earning Trust

  • Members
  • Pip
  • 3 posts

Posted 21 July 2010 - 08:39 PM

Dear Admin/Mods,

Your website: www.testmy.net or any page on it is being reported as being unsafe. We are getting the following message whenever we access your website or any page on it.

"This website has been reported to contain the following threats:

Malicious software threat: This site contains links to viruses or other software programs that can reveal personal information stored or typed on your computer to malicious persons."



This is a cool site and I especially love the accurate results it gives out whenever I test my broadband connection, but I have been getting this message since the past 1 hour. You guys have been doing a swell job, but I wouldn't want any of us worried about this site being unsafe. So, can you please look into this and clear up this?

I have included the screenshot of the message we are getting.

Attached Thumbnails

  • screenshot.JPG


#2 zalternate

zalternate

    I'm a Quitter

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,514 posts
  • Location: British Columbia. Viewing the craziness of the World with just the Facts

Posted 21 July 2010 - 09:37 PM

As per http://www.testmy.ne...ebsite-warning/ Is their any information on what the threat is?

I PMed CA3LE earlier about it.

Edited by zalternate, 21 July 2010 - 09:43 PM.

<a href="http://www.bccla.org">British Columbia Civil Liberties Association / www.bccla.org</a>
<a href="http://www.aclu.org">American Civil Liberties Union / www.aclu.org</a>
.A quote from Benjamin Franklin: "They that can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
<a href="http://www.eff.org/"...rg/">Electronic Frontier Foundation / www.eff.org</a>
<BR /> <A HREF="http://www.eff.org/br"> <IMG SRC="http://www.eff.org/b...r/brstrip.gif"> </A> </DIV> <BR />

#3 CA3LE

CA3LE

    TestMy.net Webmaster

  • Administrator
  • 7,473 posts
  • Location: 00110110 00110000 00110010

Posted 22 July 2010 - 02:42 AM

Thank you so much for reporting this. You actually brought to our attention a major problem. Someone hacked the site and had included an iframe into the site structure.

It is very important to us to have users like you to let us know when stuff like this happens. Websites that are highly visible on the internet like testmy.net are prone to things like this. It happened that this time it was an easy fix. There are allot of files moving around on the server right now (with the speedtests being rebuilt) and in the mix some file permissions got messed up. I had a feeling at the time that command was mistyped, that's why you always double check! So anyways, that was seriously a couple days ago... hackers are seriously just out there scanning for a weak spot.

Luckily we caught this fast and got it resolved quickly. I wish I would have noticed hours sooner, but hey.

"Working to improve our Internet one connection at a time."
CA3LE.png


#4 Sid

Sid

    Earning Trust

  • Members
  • Pip
  • 3 posts

Posted 22 July 2010 - 07:13 AM

Thank you so much for reporting this. You actually brought to our attention a major problem. Someone hacked the site and had included an iframe into the site structure.

It is very important to us to have users like you to let us know when stuff like this happens. Websites that are highly visible on the internet like testmy.net are prone to things like this. It happened that this time it was an easy fix. There are allot of files moving around on the server right now (with the speedtests being rebuilt) and in the mix some file permissions got messed up. I had a feeling at the time that command was mistyped, that's why you always double check! So anyways, that was seriously a couple days ago... hackers are seriously just out there scanning for a weak spot.

Luckily we caught this fast and got it resolved quickly. I wish I would have noticed hours sooner, but hey.




Lovely! :) Glad that you guys are taking things seriously and have acted upon it right away. Builds up my trust and confidence. :) Thanks a lot!

#5 CA3LE

CA3LE

    TestMy.net Webmaster

  • Administrator
  • 7,473 posts
  • Location: 00110110 00110000 00110010

Posted 22 July 2010 - 03:29 PM

Always, my users safety and security are very important to me. It kinda ties into our privacy policy. I personally have allot of opinions about internet ethics a practices... and especially when a hacker tries to exploit my users I'm all over it. There are a ton of measures that I have in place on the server to ensure it's security. testmy.net has at least 5-10 full on bruteforce hacking attempts a day. But, I have curtain things set to run on non-standard ports and tons of systems in place to sniff stuff out... testmy.net's server also gives people only a couple of chances to enter admin/root login information correctly... if else { blacklist } [nerdly]

There is always going to be hackers. Hell, messing around like that myself is how I learned allot of stuff. I just hate the destructive hackers. I'm mostly surprised at how quickly they noticed the security hole. Whoever did that obviously has some sort of bot scanning the internet.

Well, thanks again!

-Damon

"Working to improve our Internet one connection at a time."
CA3LE.png


#6 zalternate

zalternate

    I'm a Quitter

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,514 posts
  • Location: British Columbia. Viewing the craziness of the World with just the Facts

Posted 22 July 2010 - 04:07 PM

I'm mostly surprised at how quickly they noticed the security hole. Whoever did that obviously has some sort of bot scanning the internet.

Well, thanks again!

-Damon


I think they found the hole in 'IP Board' and just did a quick search for any board with it.
<a href="http://www.bccla.org">British Columbia Civil Liberties Association / www.bccla.org</a>
<a href="http://www.aclu.org">American Civil Liberties Union / www.aclu.org</a>
.A quote from Benjamin Franklin: "They that can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
<a href="http://www.eff.org/"...rg/">Electronic Frontier Foundation / www.eff.org</a>
<BR /> <A HREF="http://www.eff.org/br"> <IMG SRC="http://www.eff.org/b...r/brstrip.gif"> </A> </DIV> <BR />

#7 CA3LE

CA3LE

    TestMy.net Webmaster

  • Administrator
  • 7,473 posts
  • Location: 00110110 00110000 00110010

Posted 22 July 2010 - 07:12 PM

Well, that's what I would have normally thought..... buuuuuuut they had also exploited the other site of the site... the side that's not tied to IPB.

"Working to improve our Internet one connection at a time."
CA3LE.png


#8 zalternate

zalternate

    I'm a Quitter

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,514 posts
  • Location: British Columbia. Viewing the craziness of the World with just the Facts

Posted 22 July 2010 - 07:34 PM

Well, that's what I would have normally thought..... buuuuuuut they had also exploited the other site of the site... the side that's not tied to IPB.



Or maybe to do with the cross site login?

Edited by zalternate, 22 July 2010 - 09:28 PM.

<a href="http://www.bccla.org">British Columbia Civil Liberties Association / www.bccla.org</a>
<a href="http://www.aclu.org">American Civil Liberties Union / www.aclu.org</a>
.A quote from Benjamin Franklin: "They that can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
<a href="http://www.eff.org/"...rg/">Electronic Frontier Foundation / www.eff.org</a>
<BR /> <A HREF="http://www.eff.org/br"> <IMG SRC="http://www.eff.org/b...r/brstrip.gif"> </A> </DIV> <BR />

#9 CA3LE

CA3LE

    TestMy.net Webmaster

  • Administrator
  • 7,473 posts
  • Location: 00110110 00110000 00110010

Posted 23 July 2010 - 12:51 AM

Or maybe to do with the cross site login?


No, because that side of the site is just querying IPB... it's not tied together. The problem was because the permissions were publicly writable, I've addressed the issue.

"Working to improve our Internet one connection at a time."
CA3LE.png


#10 mudmanc4

mudmanc4

    TMN Seasoned Veteran

  • Moderators
  • 10,038 posts
  • Location: In The Plex

Posted 23 July 2010 - 09:09 AM

Done it myself recently man, it's easy to do when your ina hurry , and decide to use your ftp program to change permission instead of on the host, as some of us know ftp doesnt always change them hahaha but says it does.

Anyhow, I know testmy.net is secure as anything can be , and takes this very serious

on top of that, there's alot ALOT coming out of russia right now

So how's everybody doing in that little head of yours ? ™


#11 zalternate

zalternate

    I'm a Quitter

  • Members
  • PipPipPipPipPipPipPipPip
  • 1,514 posts
  • Location: British Columbia. Viewing the craziness of the World with just the Facts

Posted 23 July 2010 - 09:51 AM

Total Site Update IN THE PIPE
A completely new testmy.net is on the horizon. Due to release November 2010. Hey, if you don't like change don't worry because the old tests and tools still be here too.


New buttons on the speed test site to push. The "test my Internet" button, that is the dual test.



I keep reading bits about all sorts of forums, blog type software(e107 CMS) and such getting attacked. Whether it's the professionals doing it or someone who took the professionals code and tried to make it do something for themselves.

Edited by zalternate, 23 July 2010 - 09:51 AM.

<a href="http://www.bccla.org">British Columbia Civil Liberties Association / www.bccla.org</a>
<a href="http://www.aclu.org">American Civil Liberties Union / www.aclu.org</a>
.A quote from Benjamin Franklin: "They that can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
<a href="http://www.eff.org/"...rg/">Electronic Frontier Foundation / www.eff.org</a>
<BR /> <A HREF="http://www.eff.org/br"> <IMG SRC="http://www.eff.org/b...r/brstrip.gif"> </A> </DIV> <BR />

#12 michaelc

michaelc

    Earning Trust

  • Members
  • Pip
  • 1 posts

Posted 28 June 2011 - 12:12 PM

I have this same problem - apart from getting rid of the javascript and setting correct permissions - how did ou get rid of microsoft warning?

#13 CA3LE

CA3LE

    TestMy.net Webmaster

  • Administrator
  • 7,473 posts
  • Location: 00110110 00110000 00110010

Posted 28 June 2011 - 05:03 PM

I have this same problem - apart from getting rid of the javascript and setting correct permissions - how did you get rid of Microsoft warning?


Which warning are you talking about exactly.

"Working to improve our Internet one connection at a time."
CA3LE.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Speed Test Version 13.37
© 2013 TestMy Net LLC - TestMy.net - Terms & Privacy