(RESOLVED) I think I'm experiencing technical difficulties here at Scified. Anyone else?
6822 Views16 RepliesninXeno426
MemberPraetorianDec-22-2020 2:47 PMExactly as stated I'm having some big problems here. Can anyone help? Anyone else experiencing anything strange?
Admin note (December 23rd, 10:15am EST): Affected pages have been restored, offending accounts have been removed and exploits have been patched and resolved. - Chris
Nothing the God of biomechanics wouldn't let you in heaven for
BigDave
MemberDeaconDec-22-2020 3:11 PMSomething Strange? Who ya Gonna Call?
But on a Serious Note! YES!
I am experiencing being able to be Logged In and Comment on some Pages but some i get taken to a LOG IN Page which i am NOT sure is Suspicious so be Careful.
But i have Contacted some Members of Staff and Hopefully it will be Sorted ;)
R.I.P Sox 01/01/2006 - 11/10/2017
ninXeno426
MemberPraetorianDec-22-2020 3:13 PMSame exact thing here. I've sent a message as well. I have some weird things on a couple of my topics as well.
Nothing the God of biomechanics wouldn't let you in heaven for
BigDave
MemberDeaconDec-22-2020 3:16 PMYES some Pages got Hack/Script/Bot
ADVICE...... if you are TAKEN to the LOG-IN PAGE like image i shown...
scified.scienceontheweb.net is NOT a known WEBPAGE and so DO-NOT attempt to LOG-IN as it could be a Hijack to Steal your USER DETAILS!
R.I.P Sox 01/01/2006 - 11/10/2017
ninXeno426
MemberPraetorianDec-22-2020 3:26 PMYep I saw the same damn thing on two of my topics. I steered clear of it. Thanks for the heads up BigDave.
Nothing the God of biomechanics wouldn't let you in heaven for
Dark Nebula
StaffNeomorphDec-23-2020 2:28 AMWe are very aware of the bugs and other problems on the site.
We've been messaging Chris about it, and all we can do now is wait until he fixes these bugs. When will that happen, is unknown.
Chris
AdminEngineerDec-23-2020 6:40 AMHey guys, I am aware of the issue and am looking into this actively. Please refer to the website URL, if the domain is a subdomain (example: scified.something.com) do NOT enter any log in details. If you were logged in prior to opening a page, you should NOT need to log in again. Also, if you're browsing on mobile and it tries to load a desktop version of the site with broken images, something is definitely off.
I'm in the process of tracking this down and will have it resolved ASAP. Thank you to everyone who has let me know!
Chris
AdminEngineerDec-23-2020 7:17 AMPROBLEM RESOLVED: A few new accounts had signed up yesterday and attempted to exploit areas of the profile section. I have since located the exploit and resolved affected code which should prevent any and all future attempts by similar means.
Thank you to everyone who alerted me of this issue. I've nuked the offenders from orbit, just to be sure.
BlackAnt
MemberFacehuggerDec-23-2020 2:17 PMHeard somewhere around the blogs watercooler, "I think a refund is in order after all this nonsense."
"But BigDave you don't have to put quarters in these Xbox's to surf the web site."
Bigdave, "I still want my refund WHERE IS MY DAMN QUARTER!"
LOOOOOOOOOOOL
Disclaimer:
The story, all names, characters, and incidents portrayed in this electronic publication are fictitious. No identification with actual persons (living or deceased), places, buildings, and products is intended or should be inferred. No person or entity associated with this blog received payment or anything of value, or entered into any agreement, in connection with the depiction of "ALIEN or Engineer" products. NO Aliens or Engineers were harmed in the making of this blog.
dk
MemberTrilobiteDec-23-2020 5:21 PMI logged out and backed off when I saw the hacked window.
Thanks for a pretty quick fix.
Now, I think we need to talk about the bonus situation.
ninXeno426
MemberPraetorianDec-23-2020 9:59 PMRight. You see, Mr. Dk and I feel that the bonus situation has never been on a-an equitable level.
Nothing the God of biomechanics wouldn't let you in heaven for
ninXeno426
MemberPraetorianDec-23-2020 10:03 PMBut really thank you guys.
Nothing the God of biomechanics wouldn't let you in heaven for
Thoughts_Dreams
MemberNeomorphDec-26-2020 8:43 AM*With a kind of Apone voice* Everything is clear here we're back to normal people.
Thanks to the staff for getting rid of the nonsense.
BigDave
MemberDeaconDec-27-2020 4:02 AMAt least some Subjects that took us to the Dodgy Log-in can NOW be Safely Accessed... Cheers Chris ;)
Hope everyone had a Great and Safe Holiday Period ;)
R.I.P Sox 01/01/2006 - 11/10/2017
BlackAnt
MemberFacehuggerDec-27-2020 11:07 PMHow do we know it is really fixed? There can be a lot of hidden code in any of the links.....
Key loggers, everything bad! I hope Chris had a back up of the site without the malicious code. Then he put the back up in the place of the site without there being any chance there could be any bad code on the site right now.
Dare I say it people watch your computers for while and reload your operating systems. I am not sure as to why these hackers would just put a password harvesting malware on a blog like this so it makes no F! IN G sense.
I think we have a more involved thing going on. That being said just watch your computers and anything you doing on your client computer at your houses could be compromised by doing anything at this site.
So like everything in life it is a risk. Best practice is to surf to this website only from a computer that nothing can happen to...in other words you have no sensitive information on that system. This was meant to look like a novice attacked the site....however, with pros you would have never known anything was different in the first place and that is the only reason why I am even making this post right now....however I could be wrong so everyone lets work together and be vigilant and report anything wrong instantly to the admins!!!!!!
hox
MemberFacehuggerDec-28-2020 2:17 AMYou don’t need a locked down computer to browse this site. As with all websites, use your common sense and watch out for suspicious messages inviting you to install or update software on your computer.
One thing I would say is that alien-covenant.com needs its own TLS certificate for its login page. Whilst not being a simple thing to exploit, a man-in-the-middle attack can sniff any password that you enter in a login page if there is no padlock symbol being shown in the browser.