Forum Settings
Forums
New
Aug 27, 2009 8:57 AM
#1
Overlord

Offline
Nov 2004
5752
Yesterday it came to my attention that a malicious script exploited a bug in MAL's code, and was run on multiple different clubs/comments/messages and profiles. The script has been stopped from expanding beyond what it already has infected and should not continue to be posted.

However, there are many comments out there that still contain this script and they may unfortunately cause bogus code to be appended to your comments. Short of going throughout the entire site and deleting every instance of this script, there's not much I can do other than watch the script get pushed down to 'non-viewable' areas. New comments and posts will eventually bury it and the script won't be able to execute.

Sorry for the inconvenience everyone.
Pages (2) [1] 2 »
Aug 27, 2009 9:02 AM
#2
Offline
Dec 2008
2202
Thanks for fixing this, I guess.
Aug 27, 2009 9:03 AM
#3

Offline
Dec 2008
2228
At least you stopped the club from expanding.
Aug 27, 2009 9:09 AM
#4

Offline
Oct 2008
25738
Fucking stupid Script Kiddies.
Aug 27, 2009 9:14 AM
#5

Offline
Jan 2008
166
What did the script do anyways?

All I could tell is that it creates a new script element, sets the source as a 1x1 jpg image and appends the head element?
Aug 27, 2009 9:14 AM
#6

Offline
Apr 2008
148
Prongs said:
At least you stopped the club from expanding.


Well...if that would have been the biggest issue to you...

...not sure what you would have thought if you would have gotten a redirekt to a virus contaminated site or similar...
Aug 27, 2009 9:24 AM
#7
Anime DB Admin
BACK FOR MORE?

Offline
Jan 2007
12683
Ah, so that's what it was. Good to hear it's gone.

staff.applications  
guidelines.faq 
 

report.abuse  

thx.skittles  
thx.kina 
 

[H+] ³  
Aug 27, 2009 9:29 AM
#8

Offline
Nov 2008
71
From what I guessed and understood of it, it was grabbing two pieces of data (or trying to at least) from active session cookies and sending them to a website. The obvious guess would be username and password.

Source here:
http://projectviral.spazghost.com/forums/MALinjectionSRC.txt
Aug 27, 2009 10:00 AM
#9

Offline
Oct 2008
223
Does this have anything to do with my editing profile/blog entries not working. Most of the BBCode has gone and seems to be replaced by html.

Like this:
http://i171.photobucket.com/albums/u301/lee3319/profile/animebutton.jpg"; border="0">[img]http://i171.photobucket.com/albums/u301/lee3319/profile/animeright.jpg" border="0">
Aug 27, 2009 10:12 AM

Offline
Jul 2008
135
FFFFFFFFFUUUUUUUUUUU
Aug 27, 2009 10:17 AM

Offline
Feb 2008
55
Same case as lee3319

Quite annoying but rewrote it and now it's fine...I guess.
Aug 27, 2009 10:56 AM

Offline
Apr 2008
427
Rewtle said:
Thanks for fixing this, I guess.
Aug 27, 2009 11:06 AM

Offline
Oct 2008
6043
Figured there be an announcement about it sooner or later. That was a crazy little experience; thanks for taking care of things.
Aug 27, 2009 11:12 AM

Offline
Oct 2007
3267
Vipo said:
Fucking stupid Script Kiddies.
The script was most likely made by the hacker.
Aug 27, 2009 11:15 AM

Offline
Sep 2008
925
Alberto said:
Rewtle said:
Thanks for fixing this, I guess.
Aug 27, 2009 12:20 PM

Offline
May 2009
3266
Quick question, Are you going to ban the guy who created the club? Cuz I personally think that it was his fault please correct me if I am wrong.
Aug 27, 2009 1:43 PM
Offline
Sep 2008
415
lee3319 said:
Does this have anything to do with my editing profile/blog entries not working. Most of the BBCode has gone and seems to be replaced by html.

Like this:
http://i171.photobucket.com/albums/u301/lee3319/profile/animebutton.jpg"; border="0">[img]http://i171.photobucket.com/albums/u301/lee3319/profile/animeright.jpg" border="0">


Same thing happened to me, I had to rewrite the code and try erasing some parts a few times before it didn't change like that anymore.

And as always, thank you, Xinil, for fixing the other problem! *has already changed password*
Aug 27, 2009 3:19 PM

Offline
Jun 2007
2669
Websnake said:
From what I guessed and understood of it, it was grabbing two pieces of data (or trying to at least) from active session cookies and sending them to a website. The obvious guess would be username and password.

Source here:
http://projectviral.spazghost.com/forums/MALinjectionSRC.txt


There's a section in the code you posted that points to adstraight.com which is a pay per click service. So essentially whoever made this code was doing it to make money. Each time that little image loaded it would count as a click which was registered at adstraight.

You might want to report that to adstraight as well as send them a copy of the code so they can look it over and see if they can identify the specific user.
Aug 27, 2009 3:28 PM

Offline
Dec 2007
689
DeathfireD said:
There's a section in the code you posted that points to adstraight.com which is a pay per click service. So essentially whoever made this code was doing it to make money. Each time that little image loaded it would count as a click which was registered at adstraight.

You might want to report that to adstraight as well as send them a copy of the code so they can look it over and see if they can identify the specific user.

That's pretty clever. Props to this guy.
Aug 27, 2009 3:33 PM

Offline
Jun 2007
2669
oops my bad. No clicking was involved. Adstraight offers pay per impressions and that's what he was using with the little image. Every time someone viewed a post that was hacked it would be counted as an impression.
Aug 27, 2009 5:01 PM

Offline
Nov 2007
5130
So that's what's happening.



#Feitoism @ irc.rizon.net - the official IRC channel for Fate Testarossa.
Aug 27, 2009 5:56 PM

Offline
Jan 2009
709
O.O I just had that strange code pop up in my profile editing settings, and I had to redo my profile coding...oh well :D
Aug 27, 2009 7:30 PM

Offline
Apr 2009
375
Stupid Hackers! GET A LIFE!
Aug 27, 2009 8:04 PM

Offline
Oct 2007
3267
AnimeGURU475 said:
Stupid Hackers! GET A LIFE!
lol
Aug 27, 2009 10:12 PM

Offline
Jul 2007
99
Spam like crazy and push it down
Aug 27, 2009 11:59 PM

Offline
Dec 2007
689
ITT "Anime Guru" gives life advice.
Aug 28, 2009 12:26 AM

Offline
Nov 2007
31283
Thanks, I was bothered by those weird codes.
I Two Syaorans from Tsubasa RESERVoir CHRoNiCLE and TRC!!!
Aug 28, 2009 1:35 AM

Offline
Nov 2008
6655
Maybe this is also the reason why I appeared online yesterday though actually I wasn't, neither I used MALu =/
Aug 28, 2009 7:35 AM

Offline
Jan 2008
43
Hm...does this have anything to do with the fact that i now have to allow googlecode.com in order for MAL to work completely?

I'm using NoScript and was blocking googlecode.com and the other ad sites and everything worked, but since yesterday i can't add Animes / Change seen Episodes etc. anymore without permitting those scripts.
Aug 28, 2009 7:47 AM
Offline
Dec 2008
2202
Devilmore said:
Hm...does this have anything to do with the fact that i now have to allow googlecode.com in order for MAL to work completely?

I'm using NoScript and was blocking googlecode.com and the other ad sites and everything worked, but since yesterday i can't add Animes / Change seen Episodes etc. anymore without permitting those scripts.

Yes, I've had the same problem. I have to disable "NoScript" in order to get MAL to work completely.
Aug 28, 2009 8:44 AM

Offline
Apr 2009
119
Shoot! that thing make me rework my ID's in to my profile & remove that "border=0>" thing & it removed all the photos in my profile & the buttons does not give you the correct action. Thank God that was the end of it! ^^

Aug 28, 2009 8:54 AM

Offline
Oct 2008
4613
No way... I didn't even realize it until just now but thanks Xinil for always fixing things when it happens. You are the best!!^^
Aug 28, 2009 9:22 AM

Offline
Apr 2008
4287
I don't know what really happened but thanks for the fix ^^

Aug 28, 2009 9:46 AM

Offline
May 2008
1707
Motoyama said:
Alberto said:
Rewtle said:
Thanks for fixing this, I guess.
Aug 28, 2009 12:05 PM

Offline
Sep 2007
608
pim said:
Motoyama said:
Alberto said:
Rewtle said:
Thanks for fixing this, I guess.
Aug 28, 2009 1:17 PM

Offline
Jan 2008
1365
lol that's pimp.
Hello!
Aug 28, 2009 3:19 PM

Offline
Jul 2008
514
Rewtle said:
Devilmore said:
Hm...does this have anything to do with the fact that i now have to allow googlecode.com in order for MAL to work completely?

I'm using NoScript and was blocking googlecode.com and the other ad sites and everything worked, but since yesterday i can't add Animes / Change seen Episodes etc. anymore without permitting those scripts.

Yes, I've had the same problem. I have to disable "NoScript" in order to get MAL to work completely.


I too had this problem.
Aug 28, 2009 3:39 PM

Offline
May 2009
203
Rewtle said:
Thanks for fixing this, I guess.
"Non mihi, non tibi, sed nobis" Which means "It's not for me, It's not for you. It's for everyone"
Aug 28, 2009 9:00 PM

Offline
May 2009
1986
Aug 29, 2009 9:43 AM

Offline
Jun 2008
8053
I was wondering what those were, thanks for fixing it though! :)
Aug 29, 2009 10:57 AM

Offline
Jan 2008
470
I didn't see anything oO
Aug 29, 2009 11:30 AM
Offline
Nov 2007
8
Devilmore said:
Hm...does this have anything to do with the fact that i now have to allow googlecode.com in order for MAL to work completely?

I'm using NoScript and was blocking googlecode.com and the other ad sites and everything worked, but since yesterday i can't add Animes / Change seen Episodes etc. anymore without permitting those scripts.


MAL is using JQuery javascript library and instead of hosting it on MAL they are hosting it via Google Code. Lots of sites are doing this now as it saves a little bit of bandwidth and keeps the library up to date. You can find more info about it at http://code.google.com/apis/ajaxlibs/
Aug 29, 2009 12:39 PM

Offline
Sep 2007
484
Is this related to the club I was in this morning although I never joined it? This "biggest club" thing, whatever it was...
Aug 29, 2009 2:07 PM

Offline
Mar 2009
937
Yes Spade - the quote is not working now *sighs*

Shameless plug signature The Shorts Club

Aug 29, 2009 2:07 PM

Offline
Jul 2009
844
I had those problems too, thanks for fixing.

When the rosario on her chest is taken off, Moka's vampire inner self awakes.
Aug 29, 2009 5:49 PM
Offline
Feb 2009
1637
Oh I see. I thought it was just happening for me. But it only happened for like, 2 comments.
Thanks for the fix.
Aug 30, 2009 2:51 AM

Offline
Aug 2009
3902
well thx
Signature removed. Please follow the signature rules, as defined in the General Forum Guidelines!
Aug 30, 2009 2:24 PM

Offline
Mar 2008
468
Oh when it messed up all my bb code a couple of days ago I just erased the extra thing and added [/img] again. No other problems after that. Thought you made some changes or something around the site and didn't report it. :|
Aug 30, 2009 8:00 PM

Offline
Aug 2008
61
=__= it is really a hard work .. ^^".. I think ..
but really thanks XD
keep the good work =3

Ja na

Aug 31, 2009 9:35 AM

Offline
Apr 2009
145
Seny said:
Oh when it messed up all my bb code a couple of days ago I just erased the extra thing and added [/img] again. No other problems after that. Thought you made some changes or something around the site and didn't report it. :|


same thing happened to me today. i just replaced it with [/img] like you did. nothing much happened after that though i'm being cautious and changed my password.


Pages (2) [1] 2 »

More topics from this board

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

208 by hawkpelt5 »»
6 hours ago

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

423 by RED-clover12 »»
Apr 24, 10:19 AM

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - Apr 22

0 by Kineta »»
Apr 22, 8:10 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM

» Heavenly Easter Delusion: Devil and Dolce ( 1 2 3 4 5 ... Last Page )

Kineta - Mar 27

3331 by Terra_strong »»
Apr 17, 8:26 PM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login