www.ClassicTW.com
https://mail.black-squirrel.com/

Grimy Trader?????
https://mail.black-squirrel.com/viewtopic.php?f=15&t=22835
Page 1 of 1

Author:  mob [ Thu Aug 20, 2009 10:52 pm ]
Post subject:  Grimy Trader?????

Really weird, I was warned by the search engine and then by my AV proggy that grimy's contained malicious code. Is he fighting back? Not sure what the deal is, anyone else having probs?

Author:  Promethius [ Thu Aug 20, 2009 11:34 pm ]
Post subject:  Re: Grimy Trader?????

McAfee didn't detect anything when I went to the site and nothing showed in Yahoo and Google's search as being bad (McAfee SiteAdvisor). But some AVs catch what others don't.

Author:  Singularity [ Fri Aug 21, 2009 3:26 am ]
Post subject:  Re: Grimy Trader?????

How in the world would a site like grimy's have anything malicious?

There are more false positives than there are actual viruses it seems.

Author:  mob [ Fri Aug 21, 2009 4:45 am ]
Post subject:  Re: Grimy Trader?????

Thats what I thought was weird, it was through google first off. I thought that has to be one of those situations where it is a false positive. So I visited the site and my AV proggy went nutz....but then when I tried to d/l something it would say server down. I don't know I was asking if anyone else has any issues...thanks for the input Ill have to see whats up on my end.

Author:  T0yman [ Fri Aug 21, 2009 11:39 am ]
Post subject:  Re: Grimy Trader?????

I think it is the new version of firefox, mine did it today when I did the new update.

Author:  RammaR [ Sun Aug 23, 2009 10:11 pm ]
Post subject:  Re: Grimy Trader?????

Grimy Trader - Scrubbed Clean!

On Aug. 18th, someone was able to FTP a modified file into the site that redirected visiting browsers to download something from another site. The code has been removed and the FTP security has been fully revamped so that it can't happen again. Google has also re-scanned the site and removed their warning screen.

I've run multiple virus scans on my computer and found nothing. I don't know that anything actually got downloaded or installed, but I encourage you to scan your PC just to be safe. The code was only up on the site between Aug 18th and the 22nd.

I know the IP address that the malicious FTP originated from and am following up with the provider.

Sorry for the hassle, I'm still trying to figure out how they got in. Seems like either an attack on the host server or a brute force thing. But the Grimy Trader isn't a real high-profile target. You know, he likes to keep a low-profile!

It's safe to visit. If you run into any problems, please let me know!

RammaR

Author:  maidenariana [ Mon Aug 24, 2009 10:57 am ]
Post subject:  Re: Grimy Trader?????

I built a website for a local restaurant here and it had the exact same thing happen to it. I had an ftp account as part of the Joomla installation and that is how he got in.

I took similar steps and beefed up the password on the ftp account. I also blocked the IP which was an overseas address. This happened about 3 weeks ago and shocked the heck out of me. I had never seen an instant forced download of that nature before and prior to that always thought the need for anti-virus scanning and real-time protection was overblown. I am sure a bunch of you reading this are thinking that you have to click on something or allow an activex script to run - No and no. I am glad to hear Grimy's is back. But, anyone that visited it recently should run MalwareBytes and a full anti-virus scan (something like Avast) just to be safe.

Author:  mob [ Mon Aug 24, 2009 9:38 pm ]
Post subject:  Re: Grimy Trader?????

Awsome RammaR! Glad you got that fixed, it was really strange cause I had visited the site a few days before and it was fine, then I got all these warnings from google and from my AV software a few days later. I knew I wasn't crazy...well nah I am crazy...

Either way thanks for your support and work man!

Author:  RammaR [ Wed Aug 26, 2009 7:13 pm ]
Post subject:  Re: Grimy Trader?????

Grimy is offline for a few days, should be back up shortly - may be changing hosting services....

Author:  Helix [ Wed Aug 26, 2009 7:53 pm ]
Post subject:  Re: Grimy Trader?????

Yell at us when you are back :)

Helix

Author:  RammaR [ Fri Aug 28, 2009 6:11 pm ]
Post subject:  Re: Grimy Trader?????

Grimy Trader is back up for another year!

Page 1 of 1 All times are UTC - 5 hours
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/