Downtime

Published January 11, 2008
Advertisement
Well, that was a fun 24 hours.

About two hours before the site went down, people started reporting that they were seeing an ActiveX popup on every page of the site. It was in response to this that the site was brought down. (I would have done it earlier, but I was out when it was reported and didn't get back until later. Brought the site down as quickly as I could when I got back).

Removing the script was easy; most of the downtime was spent investigating how it had happened, and investigating what could be done to stop it happening again. I'm confident that the measures I've put in place have closed the hole for the time being. (There's still plenty more stuff to shore up, but I can work on it without the site being down).

Unlike the attacks last year, I am confident that there was no attempt made to access the site database. Hence, we are not asking you to reset your passwords. I don't think this attacker was even trying to get that kind of data; rather, they were looking to infect machines with what was most likely a botnet program.

If you were unlucky enough to browse the site in the couple of hours before it went down, using Internet Explorer, and you accepted the ActiveX download, and your antivirus software didn't stop you, then you need to run a malware sweep of your computer immediately. I'm extremely sorry that you have to do this, and hope we never cause you to have to do it again.

On the bright side. While the webserver was down, I took the opportunity to mess with the indexes on the database server. Browsing the forums should, I hope, now be a bit faster.
Previous Entry Avatars fixed
Next Entry A small XNA tip
0 likes 8 comments

Comments

jollyjeffers
Many thanks for your hard work Richard, it's greatly appreciated!

Jack
January 11, 2008 06:42 PM
Prinz Eugn
You're our hero!
January 11, 2008 07:09 PM
Jarrod1937
Yes, thank you. Though i am curious. How did the script get there? Last time it was one of the banners, was that the case this time? If so, then i wonder, isn't there a screening process for the banners? Otherwise it would seem very easy to purchase banner time and just put up a malicious banner.
January 11, 2008 07:17 PM
superpig
No, it had nothing to do with the banners on either occasion.
January 11, 2008 07:21 PM
Jarrod1937
Oh, in that case i just have a terrible memory then :)
January 11, 2008 07:21 PM
dmatter
Quote:Original post by superpig
On the bright side. While the webserver was down, I took the opportunity to mess with the indexes on the database server. Browsing the forums should, I hope, now be a bit faster.

Yes, actually it is noticeably faster for me. Well done
January 12, 2008 08:21 AM
Evil Steve
Quote:Original post by dmatter
Yes, actually it is noticeably faster for me. Well done
Yup, same here. I used to get a noticeable lag when loading forum index pages; seems a lot faster now (Or there's a lot less traffic [smile])
January 12, 2008 04:59 PM
cNoob
It was a good job I was away from my computer in those few hours then :)
Just commenting to thank you and all the moderators on gamedev your all doing wonderful jobs at keeping the comunity alive and a safe place =]
January 12, 2008 07:10 PM
You must log in to join the conversation.
Don't have a GameDev.net account? Sign up!
Profile
Author
Advertisement
Advertisement