Forum acts strange - Be aware !

Posted By: rayp

Forum acts strange - Be aware ! - 10/20/18 19:40

Hi.

Some already may have noticed that Forum acts strange.

Links like Picture- or YouTube links now redirecting to strange Websites...

After reloading the page everything seams to be normal again.

This is not normal.
Be carefull.

edit:
If your mouse Cursor doesnt switch to the finger Cursor over links like normal, reload the page and do NOT click the link. Even if the link is a valid YouTube link for example!
I might over react here, but this is far from normal.
Its like a randomly appearing invisible layer masks the valid links with some redirect stuff.
Posted By: rayp

Re: Forum acts strange - Be aware ! - 10/21/18 23:20

Example. I want to click edit here. But mouse Cursor did not Change to finger Cursor. Instead the whole window acts like one link button. See Hyperlink info bottom of Screen.

Redirect to somewhere:

Reloading the page helps for a while. Just watch out your Cursor what you are really clicking.
Posted By: Quad

Re: Forum acts strange - Be aware ! - 10/22/18 08:21

This forum software is old and exposed. Probably many known vulnerabilities can be exploited. I suggest switching to a more modern and secure discussion(like discourse) software and archiving this forum on read only mode.
Posted By: AndrewAMD

Re: Forum acts strange - Be aware ! - 10/22/18 18:11

I have documented this extensively in the other thread and believe I found a root cause.

Repeatable behavior if you clear your cookies correctly:
http://www.opserver.de/ubb7/ubbthreads.php?ubb=showflat&Number=474505#Post474505

I managed to single out and block the two(2) malicious javascripts, thus ending the unwanted behavior on my personal browser only:
http://www.opserver.de/ubb7/ubbthreads.php?ubb=showflat&Number=474507#Post474507

Root cause found in (hacked?) ubb scripting, which launches the two(2) malicious javascripts:
http://www.opserver.de/ubb7/ubbthreads.php?ubb=showflat&Number=474547#Post474547

Can you spot the one evil line of code?
http://www.opserver.de/ubb7/ubb_js/image.js

Hint: here is the same script, from the horse's mouth:
https://www.ubbcentral.com/forums/ubb_js/image.js
Posted By: rayp

Re: Forum acts strange - Be aware ! - 10/22/18 18:29

I guess so too. Since saturday!

Browsing this site seams a secure risk now.
Ask myself what happens on redirection?
Driveby download?
Posted By: AndrewAMD

Re: Forum acts strange - Be aware ! - 10/22/18 19:09

Originally Posted By: Quad
This forum software is old and exposed. Probably many known vulnerabilities can be exploited. I suggest switching to a more modern and secure discussion(like discourse) software and archiving this forum on read only mode.
Or just update UBB.threads to 7.6.2, released in September 2018.

So why not switch to a secure forum while we're at it? This way, we kill two birds with one stone.
© 2024 lite-C Forums