ATTENTION: THE SITE WAS HACKED, NOW FIXED
April 16, 2008
It came to my attention 2 days ago that this site was hacked somehow and a malware virus was attached to many if not all of the HTML pages. I am doing everything I can to restore a backup of the site to eliminate the malware. In the meantime, if any of you have visited the site since 4/10/08 [using a Windows machine], you must run and antivirus program immediately. I’m am very sorry that this has happened. Please let me know if there is anything I can help you with.
UPDATE 4/17/08 12:13am We’ve been working to restore the site from backups so you might notice some missing directories and files. I believe the hacking was through the Coppermine Photo Gallery, in case anyone out there is using it on their sites. It’s just a suspicion though. Confirmed. I believe it was only HTML/PHP files that were altered to expose visitors to the virus. Images, mp3s, etc, were not altered or infected. It seems that the gallery had a sql injection vulnerability which was exploited. What that means is that every .php and .html file was injected with an iframe code containing a malware virus. I believe the virus targeted Windows users only.
UPDATE 4/17/08 2:52pm The entire site has been successfully restored from a clean backup. Therefore, there should no longer be a threat to visitors. The security hole in the gallery is being patched as we speak. I have also notified Google to do a complete evaluation of the site to assure that it is clean. I will post the results as soon as they are available.
UPDATE 4/18/08 3:00pm There was another breach before the patch was applied. Everything is restored again and clean. The patch was successfully installed, so there should be no further danger of hacking or infecting. I am still waiting on Google to give the site a clean bill of health. Stayed tuned.
Livejournal Feed


