Thanks for the patience gang, and the good comments. It was a difficult test for me to have TB effected and infected like that for almost a week. But, we're now back. We should all thank Josh Pettit and Barb Raphael for getting us back up. Josh is a real pro with this software (amongst other things). I'm sure that he has a lot of work left to do here at TreeBuzz before we are done.
The ads are still messed up, but they will fix that next. Here's some of what he found went on and what he did to fix us:
[ QUOTE ]
Hey Mark,
Well - I'll be darn, it was this security hack which has been going around. Although your server reacted differnetly than most. What the hacker does, is put an iFrame at the bottom of the page which loads a bo-zillion popups, spyware, adware etc.... It's a real pain, because many users get themselves infected with stuff, just by viewing your page.
But in your case, they were only able to modify one file - the ubbthreads.php script... which then oddly "broke" so it just bombed out blank rather than displaying all the junk. So in this case it was good.
I have applied the security fixes to:
addpost.php
addpost_newpoll.php
showflat.php
showtheaded.php
includepollresults.php
I also corrected the permissions on the ubbthreads.php file - which was the only file "writable" so that it shouldn't be able to be modified by a hacker in the future.
So you should be clear from future attacks.
Now - do you run your own server, or are you hosted by someone.
This hacker usually leaves a backdoor script in place, which is a danger to every site on the webserver. It's a script called "bindz" or "pwned" which usually resides in the /tmp directory. If you are hosted by someone, you should tell them that a recent UBB.Threads security bug may have allowed these scripts to be uploaded to the server. And they'll want to take steps to actually remove them from the server and make sure things are secure. This will need to be done by whoever is administrating the actual server software - in most cases this will be your hosting company. If it's your server, and you're not saavy in that, I can refer you to a company which cleans comprimised servers.
[/ QUOTE ]
Anyone know what he is talking about? (Glen? /forum/images/graemlins/smirk.gif)
I think Josh is as good with his work as we are with ours! /forum/images/graemlins/grin.gif