I've been annoyed by the slow pace ever since I started investigating the source of the problem. That was over a month ago. As I said previously, this is really, really embarrassing for mapcore and bad for its image.
Posts by -Stratesiz-
-
-
Great pics!
Really inspiring stuff!
-
Thanks
~A Canon EOS 350D with EF 17-85mm f/4-5.6 IS USM and EF 70-300mm f/4-5.6 IS USM.
-
Time for some new photos from Hong Kong as well as Macau and Zhuhai in China:
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_31.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_30.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_28.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_36.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_27.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_29.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_37.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_35.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_33.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_32.jpg]
[Blocked Image: http://www.kolumbus.fi/casimir.tuomi/portfolio/photo_34.jpg]
Got a new zoom lens for shooting people~
-
Ixus 800IS works for me. But I've seen a great compact camera from Sony that is capable of taking excellent shots in dark surrondings without any flash. I need to check the model.
-
Quote from R_Yell
I understand that the "burn in hell" comment could be misunderstood, but again, there is any law that prevent me to say the media wasn't impressive? Are you one of those persons that cannot take criticism? I'm not bashing the work of anybody, just PR managed mods are boring, other people before me said the same more or less, we want to see some action and BM members should be aware of it. That's all.
Do not use strong expressions, such as "burn in hell", period. Critisism is always appreciated, as long as you formulate it in a constructive and respectable manner.
Judging by the pictures, Office Complex and We've Got Hostiles are the weakest links at the moment. Lighting and brushwork need refinement, looks too generic at the moment.
-
Quote from Thrik
Mojo's given me some logins so I'm going to try putting a duplicate of the forums on my own hosting and ask some of you to go there to see if the problems occurs. Then we can rule out whether it's something embedded in the forum files itself or a server/host-level issue.I'll aim to get that done tomorrow while I'm at work.

It's not just the forums. The problem occurs on the main front page as well, and we are talking about multiple trojans here. The source is something more complex and bigger.
-
Quote from Wunderboy
I looked at the source of the page and what stood out was this line:
Which is being inserted (with varying filenames) directly after the body tag. So it's obviously an injection.
If I had to hazard a guess, I'd say someone is getting into your site via a cpanel exploit and possibly editing you PHPBB template. Check was admin software and version your host gives you then go check the web and see if its the latest version. Chances are that its some 10th peer pyramid host who's never updated their software. The HaJ site gote hacked a while back because of a similar exploit.
Does it explain the different malwares encountered? So far I've seen three different ones using the same method. The previous malware tried to run a corrupt quicktime file using a Microsoft Data Access - Remote Data Services exploit.
Quote from -Stratesiz-Display MoreIt's back, but this time my antivirus program detects it. It's called Exploit.Multi.Qtp.f. (virus).It attempts to run a quicktime file called H4DbN1ZNzPe717qd.mov from web2.awareindia.com.
or
XS9AzX7TbCB80iCs.mov from 216-55-167-32.dedicated.abac.net.
or
GFIIh6RxK14TF8ts.mov from 69-64-72-35.dedicated.abac.net
(seems to be random, infected servers?) God I hate quicktime!
There is a chance that this is a different version of the same malware than the previous one. The virus was also reported at
http://www.antiviruslab.com/newentries.php?lang=gb on December 22, 2007 so it seems to be fresh from the oven. This is the 6th version of the same thing:
http://www.viruslist.com/en/find?search ... .Multi.Qtp.
Exploit.Multi.Qtp.c, on the other hand was released earlier and displays a number of hits on Google. The description of this particular version is worrying:
Quote from -Stratesiz-Here is a short snippet of the differences I found in the code:With issues:
Without issues:
<body id="phpbb" class="section-index ltr">
The root of all evil!:
[Blocked Image: http://koti.mbnet.fi/stratty/mapcore/mapcore_root_of_evil.jpg]
-
Quote from Mazy
I just got it for the first time, and on Firefox :GHmmm
It's because it's a new virus with different behavior: Exploit.HTML.IESlice.bz as Wunderboy noticed. The previous one, Exploit.Multi.Qtp.f appears to have left the building. It no longer attempts to run a strange quicktime file from a different server. However, it still relies on the random name.js trick to crash the browser in an attempt to force run some strange and hostile stuff. The magnitude of the problem seems to be far greater than expected I assume.
What the hell is going on here??!
Everytime the forums go down a new virus/malware whatever emerges!
-
I like!~
Lambda core looks cool!
-
I'm talking about top notch cinemas. The Nordic countries are also expensive in general.
God I hate this constant Exploit.Multi.Qtp.f malware attack from Mapcore!
-
Best ending in a game ever!!
The price was just right for a game like this. It was like 20 euros, which is nothing since a normal cinema ticket is 11 euros.
Ps. fix that evil server exploit mapcore virus now!!!
-
It's back, but this time my antivirus program detects it. It's called Exploit.Multi.Qtp.f. (virus).
It attempts to run a quicktime file called H4DbN1ZNzPe717qd.mov from web2.awareindia.com.
or
XS9AzX7TbCB80iCs.mov from 216-55-167-32.dedicated.abac.net.
or
GFIIh6RxK14TF8ts.mov from 69-64-72-35.dedicated.abac.net
(seems to be random, infected servers?) God I hate quicktime!
There is a chance that this is a different version of the same malware than the previous one. The virus was also reported at
http://www.antiviruslab.com/newentries.php?lang=gb on December 22, 2007 so it seems to be fresh from the oven. This is the 6th version of the same thing:
http://www.viruslist.com/en/find?search ... .Multi.Qtp.
Exploit.Multi.Qtp.c, on the other hand was released earlier and displays a number of hits on Google. The description of this particular version is worrying:
http://research.sunbelt-software.com/th ... tid=157219.
QuoteHigh risks are typically installed without user interaction through security exploits, and can severely compromise system security. Such risks may open illicit network connections, use polymorphic tactics to self-mutate, disable security software, modify system files, and install additional malware. These risks may also collect and transmit personally identifiable information (PII) without your consent and severely degrade the performance and stability of your computer.
As for the page it appears on, does it really matter if it's a server-side issue? It's everywhere, even on the front page. The threat is real, so fix it please! This is getting really annoying and embarrassing for Mapcore now!
-
-
See here:
viewtopic.php?p=184989#p184989
My IE crashed as well every time this mysterious .js thing appears. I put my virus program settings higher and the crashes ended but the problem remains: Mapcore is under attack!~
-
As I'm writing this reply, it appeared again. The js. file name appears to be completely random (kemuo.js this time). I have spotted it everywhere on the forum pages. I haven't tested the mapcore front page (portal page) much but I haven't seen it there.
I refuse to load that .js thing on my computer, I don't have it in my cache.
UPDATE: It appears in intervalls. I get it like virtually 5 times in a row on various forum pages, then it disappears for a while. This thing is mean. How is this even possible?
-
This thing is evil!
The js. file name keeps changing!
So far I've seen:
Quote<body id="phpbb" class="section-index ltr"><script language='Javascript' type='text/javascript' src='dhkfn.js'></script>
and
Quote<body id="phpbb" class="section-viewtopic ltr"><script language='Javascript' type='text/javascript' src='mufox.js'></script>
There is definitely something going on!
I've saved the html codes for these two hits as well. Tell me if you want them.
-
Ok, I saved the html code of the front page with the problem, and after an immediate refresh without the problem. For some reason IE states that there is an error on that particular row irrespective of the page or row amount. Feels strange.
Here is a short snippet of the differences I found in the code:
With issues:
Quote<body id="phpbb" class="section-index ltr"><script language='Javascript' type='text/javascript' src='mkwed.js'></script>
Without issues:
Quote<body id="phpbb" class="section-index ltr">
The root of all evil!:
[Blocked Image: http://koti.mbnet.fi/stratty/mapcor…oot_of_evil.jpg]
Full code here:
Hope this helps!
-
So what is this Microsoft Data Access - Remote Data Services Dat... something, "signed by Microsoft" the site wants me to run on a random basis?
IE also reports an error on row 484 everytime this happens.
Quote from Senturai get a popup every now and then from microsoft access something something. that's about all; however i reckon this means it's not unintentional.
-
It's not just the main page, it's everywhere. Occasionally, I get it even when I write a reply.