closing tag is in template navbar
timefactors watches



TZ-UK Fundraiser
Page 6 of 8 FirstFirst ... 45678 LastLast
Results 251 to 300 of 387

Thread: TZ is redircting me to potential scam sites!

  1. #251
    Grand Master Rod's Avatar
    Join Date
    Jun 2003
    Location
    Co. Durham
    Posts
    10,251
    Still getting them despite using an ad blocker in Firefox

  2. #252
    Craftsman cinnabull's Avatar
    Join Date
    Sep 2008
    Location
    Warrington, centre of the Universe and home of the Mighty Wire
    Posts
    820
    Still happening to me as well. 12.02

    Stuart

  3. #253
    Master
    Join Date
    Sep 2014
    Location
    London
    Posts
    2,793
    Ongoing every time I click a link aaaggghhhh

  4. #254
    Master
    Join Date
    Jun 2014
    Location
    Driffield, UK
    Posts
    3,122
    Quote Originally Posted by Rod View Post
    Still getting them despite using an ad blocker in Firefox
    It was for me as well BUT I'd disabled adblocker for the tz site (so the fundraiser/clock would work). Once adblocker enabled for tz and the browser restarted then the adblocker worked fine.

  5. #255
    Using Chrome on MacBook Air. Cleared cache. No ADB. Not even logged in. Still getting scam popup tabs on click.

  6. #256
    Grand Master magirus's Avatar
    Join Date
    Nov 2003
    Location
    Up North hinny
    Posts
    39,473
    Seems to be ok on my iPad now, but still affecting iMac.


    Edit. iPad still affected. :-(
    Last edited by magirus; 3rd March 2017 at 13:37.
    F.T.F.A.

  7. #257
    Quote Originally Posted by Ozzie View Post
    Me too, saying I'm infected with a virus.


    You haven't, just close the pop up.

    My question is - is this just an annoying pop up thing or are personal details, log in and contents of PM's etc at risk?
    They're just pop ups, I wouldn't start clicking on anything though.

  8. #258
    Master
    Join Date
    Jan 2010
    Location
    Coming Straight Outer Trumpton
    Posts
    9,385
    Still on my mac and chrome browser even after clearing out the cache / cookies etc.

    Same on my iPad on safari but the ad blocker (Crystal) is doing its job.

  9. #259
    Grand Master Velorum's Avatar
    Join Date
    Apr 2013
    Location
    .
    Posts
    14,132
    Quote Originally Posted by kace View Post
    You haven't, just close the pop up.



    They're just pop ups, I wouldn't start clicking on anything though.
    Thanks!

    Good job the breast size selector website didn't draw me in

  10. #260
    Master jools's Avatar
    Join Date
    Jan 2007
    Location
    Īle de Merde
    Posts
    4,910
    ublock Origin on Firefox prevents the problem.

  11. #261
    Master
    Join Date
    Feb 2013
    Location
    London
    Posts
    3,216
    Swapped to the mobile version, no pop-ups!

    Switched back to the full site, and they're still gone. Whoopy doo!
    Last edited by apm101; 3rd March 2017 at 14:08.

  12. #262
    Grand Master Der Amf's Avatar
    Join Date
    Oct 2015
    Location
    UK
    Posts
    11,966
    On Chrome, I went to Settings - Show Advanced Settings - Clear browsing data - Obliterate cached images and files.

    Seemingly, I'm now fine

  13. #263
    Master
    Join Date
    Sep 2006
    Location
    Sunny Surrey
    Posts
    1,850
    All good now

  14. #264
    Grand Master Seamaster73's Avatar
    Join Date
    Jun 2006
    Location
    55°N
    Posts
    16,139
    They're back. >:-(

  15. #265
    Quote Originally Posted by Seamaster73 View Post
    They're back. >:-(
    Can you do a full refresh (CTRL+F5) and confirm that? I've ABP turned off now... and not a popup. The script code is also gone from the background....

    EDIT: Refreshed, ABP off.. tried 5 pages and reply button.. nothing. Also, the page code is clean - with no script injections as before.
    Last edited by JohnnyE; 3rd March 2017 at 14:30.

  16. #266
    Master
    Join Date
    Mar 2006
    Location
    Perth, Western Australia
    Posts
    3,252
    Curious, I was getting them yesterday but activated my AdBlock add-on in Firefox and they stopped. I'm using an old MAC.

  17. #267
    Master
    Join Date
    Jan 2011
    Location
    Somerset
    Posts
    1,110
    I can't get rid of them on my android mobile despite installing adblockplus.

    scooter

  18. #268
    Quote Originally Posted by Der Amf View Post
    On Chrome, I went to Settings - Show Advanced Settings - Clear browsing data - Obliterate cached images and files.

    Seemingly, I'm now fine
    Did this (again) in Chrome and not getting any popups now. Seems fixed.

  19. #269
    Grand Master Seamaster73's Avatar
    Join Date
    Jun 2006
    Location
    55°N
    Posts
    16,139
    Quote Originally Posted by JohnnyE View Post
    Can you do a full refresh (CTRL+F5) and confirm that? I've ABP turned off now... and not a popup. The script code is also gone from the background....

    EDIT: Refreshed, ABP off.. tried 5 pages and reply button.. nothing. Also, the page code is clean - with no script injections as before.
    Looks like a one-off, seems OK since posting that.

  20. #270
    Grand Master Der Amf's Avatar
    Join Date
    Oct 2015
    Location
    UK
    Posts
    11,966
    Quote Originally Posted by scooter View Post
    I can't get rid of them on my android mobile despite installing adblockplus.

    scooter
    Try this:

    Settings -
    Applications -
    Application Manager -
    Chrome (or whichever browser you use) -
    Storage -
    Clear Cache

    I just did that on my Samsung, and I'm now free there too, it seems

  21. #271
    Quote Originally Posted by Seamaster73 View Post
    Looks like a one-off, seems OK since posting that.
    Yes indeed. The site IS infection free right now. Persistent problems will be down to local caching on people's devices.

  22. #272
    Craftsman
    Join Date
    Sep 2011
    Location
    nottingham
    Posts
    318
    does seem ok now..

  23. #273
    Logged out of TZ, cleared Safari caches/history, etc, (MacBook Air), turned off ABP, closed and reopened Safari, logged back in, and hooray!

    Looks like scam popups are gone (although I'm already missing the breast size one a little ).

  24. #274
    Craftsman
    Join Date
    Apr 2011
    Location
    lancashire
    Posts
    572
    Blog Entries
    1
    Seems to be ok for me now on safari. Had to send the kids out of the room every time i opened TZ.

  25. #275
    Grand Master Velorum's Avatar
    Join Date
    Apr 2013
    Location
    .
    Posts
    14,132
    Ive now cleared the cache and turned off Adblock

    Things seem fine now and its nice to have the clock and TF/Virgin banners back

  26. #276
    Grand Master thieuster's Avatar
    Join Date
    Mar 2009
    Location
    GMT+1
    Posts
    11,777
    Blog Entries
    8
    Works fine here! (Safari, Macbook). Looks as if it's faster than ever. Great work Eddie thank you very much!

    Menno

  27. #277
    Master
    Join Date
    Jun 2014
    Location
    Driffield, UK
    Posts
    3,122
    Another okay here now on Firefox.

    Looks like it's fixed.

  28. #278
    Master
    Join Date
    Jul 2011
    Location
    N.ireland
    Posts
    5,042

    Exclamation

    Working at last,phew.

  29. #279
    Master
    Join Date
    Jan 2011
    Location
    Somerset
    Posts
    1,110
    Quote Originally Posted by Der Amf View Post
    Try this:

    Settings -
    Applications -
    Application Manager -
    Chrome (or whichever browser you use) -
    Storage -
    Clear Cache

    I just did that on my Samsung, and I'm now free there too, it seems
    You beauty.

    scooter

  30. #280
    Grand Master Der Amf's Avatar
    Join Date
    Oct 2015
    Location
    UK
    Posts
    11,966
    Quote Originally Posted by scooter View Post
    You beauty.

    scooter
    Nicest thing anyone has said about me in months

  31. #281
    Quote Originally Posted by JohnnyE View Post
    One thing is for sure, the infected code lies in the template/skin - the main one. That's something at least... in theory, deletion of that template and a fresh install from a clean source *SHOULD* do it. However, the only way to TRULY know (given that your average php driven site is made up of thousands of files) is to create a clean site and do a migration of JUST the data from hacked->clean.

    An easier route to fix comes if Eddie's hosts can run a security scan and return a list of the EXACT infected php files. If they can do that, its easier to remove BUT you remain vulnerable due to out of date VB software.

    Quite often you see the malicious code crudely injected at the foot of the page code. Here, we have a <script> injected VERY PRECISELY in the middle of the page code. When all this is over, I would strongly advise you set a new password - and if you re-use that password (tut tut!!) change it on other sites/services. There is no point in doing it yet, until the infection is confirmed as gone - but if you re-use your TZ password elsewhere, I'd be changing it now on those other sites/services.
    Change password even if people haven't entered it to log in since this started (personal;ly I never log out and so it keeps my session open pretty much constantly) ? You think the password database could have been compromised and decrypted ?

  32. #282
    Quote Originally Posted by rsykes2000 View Post
    Change password even if people haven't entered it to log in since this started (personal;ly I never log out and so it keeps my session open pretty much constantly) ? You think the password database could have been compromised and decrypted ?
    Whether people have entered it again or not, its stored in the forum's SQL Database tables. If malicious code was capable of injecting script code into the main forum page, then it is capable of executing other things in the background.

    It would be prudent to change your password for sure, and if its one you use elsewhere.. do the same in those places too.

    Highly recommend the likes of lastpass.com to assist with all this (although there are many other options out there).

  33. #283
    Grand Master VDG's Avatar
    Join Date
    Mar 2010
    Location
    Whitehole
    Posts
    18,967
    Looks like it's gone. All hail Krystal lads!

    Good question re passwords sec, if they are encrypted then no need to change them I suppose..
    Fas est ab hoste doceri

  34. #284
    Quote Originally Posted by VDG View Post
    Looks like it's gone. All hail Krystal lads!

    Good question re passwords sec, if they are encrypted then no need to change them I suppose..
    As long as they weren't re-entered during the 'attack'.

  35. #285
    Master Caruso's Avatar
    Join Date
    Nov 2012
    Location
    Worthing
    Posts
    2,603
    Quote Originally Posted by JohnnyE View Post
    If malicious code was capable of injecting script code into the main forum page, then it is capable of executing other things in the background.
    Not necessarily, the database should use separate authentication from the file system if best practise has been followed. But I don't know enough about the setup to know for sure. It certainly is a concern if you're exchanging Bank Details via PM for the purposes of watch sales.

  36. #286
    Grand Master Velorum's Avatar
    Join Date
    Apr 2013
    Location
    .
    Posts
    14,132
    I hope that the 'Pits and Pelts' thread hasn't been corrupted

  37. #287
    Grand Master JasonM's Avatar
    Join Date
    Feb 2010
    Location
    Cambridgeshire
    Posts
    16,150
    Quote Originally Posted by Velorum View Post
    I hope that the 'Pits and Pelts' thread hasn't been corrupted
    How could you tell? The whole thread is a corruption of decency.

  38. #288
    Grand Master Velorum's Avatar
    Join Date
    Apr 2013
    Location
    .
    Posts
    14,132
    I prefer to think of it as specialist interest sub forum for discerning gentlemen

  39. #289
    Craftsman
    Join Date
    Jul 2014
    Location
    Bristol, England
    Posts
    386
    That was annoying. Ended up reading a book.

  40. #290
    Craftsman
    Join Date
    Aug 2014
    Location
    .
    Posts
    742
    Thankfully that's over. Not been able to access TZ at work due to NSFW content!

  41. #291
    Master Kirk280's Avatar
    Join Date
    Jan 2012
    Location
    Manchester
    Posts
    7,051
    Quote Originally Posted by JohnnyE View Post
    Whether people have entered it again or not, its stored in the forum's SQL Database tables. If malicious code was capable of injecting script code into the main forum page, then it is capable of executing other things in the background.

    It would be prudent to change your password for sure, and if its one you use elsewhere.. do the same in those places too.

    Highly recommend the likes of lastpass.com to assist with all this (although there are many other options out there).
    Looks like JohnnyE knows what he is talking about - he's been giving good advice all through this thread.

    Well I think it's good advice, IT is like witchcraft to me!!

  42. #292
    Quote Originally Posted by Kirk280 View Post
    Looks like JohnnyE knows what he is talking about - he's been giving good advice all through this thread.

    Well I think it's good advice, IT is like witchcraft to me!!
    Just to calm nerves.. I'm sure Eddie will be along if he needs to be.. but the whole site was copied down today to a local PC and manually virus scanned. It came up clean after the malicious code had been manually removed.

    These types of hacks aren't personal. Every "onclick" popup was raising a bit of money per click.. for the guys who did it. They dont know us.. nor care - it was probably an automated attack anyway. Chances are - they have so many infected sites out there earning them click money that they are laughing all the way to the bank and couldn't care what our logins are!

    BUT.. given that nobody REALLY knows how the script got there in the 1st place.. and hosts never answer that question.. its prudent to change your password. Yes, they're encrypted... but there's ways around that - ways that are easily found on Google for older versions of the forum software.

    No cause for alarm at all. Just be careful to slowly wean yourself off the websites you are now missing... and stay away from the P&P thread in the Boys' Room!
    Last edited by JohnnyE; 3rd March 2017 at 20:24.

  43. #293
    Grand Master magirus's Avatar
    Join Date
    Nov 2003
    Location
    Up North hinny
    Posts
    39,473
    Quote Originally Posted by Velorum View Post
    I hope that the 'Pits and Pelts' thread hasn't been corrupted

    It's thankfully still intact, which is more than can be said for the nether regions of the majority of ladies these days.


    Quote Originally Posted by JasonM View Post
    How could you tell? The whole thread is a corruption of decency.

    Taking sharp steel to a ladies private areas is much more indecent.


    Quote Originally Posted by Velorum View Post
    I prefer to think of it as specialist interest sub forum for discerning gentlemen

    Indeed Sir, those who aren't interested should look elsewhere.
    F.T.F.A.

  44. #294

    Don't rush to reset your passwords just yet!

    Just got a PM from TaketheCannoli... he can't post a reply here nor start a new thread:

    In light of the recent pop-ups issue and taking your advice I've just changed my password and the email address my notifications go to and the result is that I can no longer reply to or start threads and I've lost access to sales corner! Also my inbox limit has been set to 50 so I've had to clear it to send this to you - what's going on?

    It's as though my privileges have been set to those of a new member. I can see my profile and my joining date still shows 2011 and my post count is still above 8000.
    Best to hang on resetting anything for now.

  45. #295
    Quote Originally Posted by JohnnyE View Post
    Whether people have entered it again or not, its stored in the forum's SQL Database tables. If malicious code was capable of injecting script code into the main forum page, then it is capable of executing other things in the background.
    Surely the password is encrypted so useless to anyone else?

  46. #296
    Quote Originally Posted by Kingstepper View Post
    Surely the password is encrypted so useless to anyone else?
    Yes, on the face of it, but there are tutorials out there showing how to unencrypt the older VBulletin password tables.

  47. #297
    Quote Originally Posted by JohnnyE View Post
    Yes, on the face of it, but there are tutorials out there showing how to unencrypt the older VBulletin password tables.
    Thanks. Disappointing if they can be cracked.

  48. #298
    Quote Originally Posted by Kingstepper View Post
    Thanks. Disappointing if they can be cracked.
    It would take a determined hack - one that would need to be targeted/personal... so I really don't think its a worry here.

    EDIT: The solution of sorts is unique passwords wherever you go. I installed Lastpass a good while back and was audited with an initial secure rating of 17%!! I had what I thought was a great password - but I was re-using it everywhere. It took a few weeks of work, but via Lastpass and its password generator, I'm now at 99% on the same security audit!
    Last edited by JohnnyE; 3rd March 2017 at 21:51.

  49. #299
    Grand Master Glamdring's Avatar
    Join Date
    Oct 2007
    Location
    Doncaster, UK
    Posts
    16,651
    I've found Lastpass to be irritatingly unreliable. It often disappears from my toolbar and I have to start it again. I use it but I don't trust it. I keep every password/email login in an Excel file stored off-computer. If the browser or Lastpass let me down, which they do, I copy and paste from the Excel file.

  50. #300
    Quote Originally Posted by Glamdring View Post
    I've found Lastpass to be irritatingly unreliable.
    Fair point! I've just been buying car insurance there... whilst lastpass wouldn't let me type in the login name to the entry. It can be glitchy indeed.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Do Not Sell My Personal Information