
HCC expresses its appreciation for shriveled, hairless hacker balls
Ok, first thing’s first: From the “No Shit?” Department, HCC was the victim of a virus attack last Saturday night. I’m not a paid professional on matters of internet security, but I’ve talked to people who are and have researched similar events in an effort to understand all of this and maybe put people’s minds at ease, or at least back to whatever uneasy state they were in before Saturday. The thing that happened Saturday is what the cool kids call “frame injection” or an iframe virus, and it’s an increasingly popular pain in the ass on the Internet these days. It can happen through the direct hacking of a site’s host, or through malware that steals FTP passwords from your computer and uses them to add malicious code to your site’s pages. Most often, the malicious code will launch a pop-up window from your browser that looks like a Windows system message or other such spoofery, in the hopes that you will click on it and end up downloading a trojan or virus to your own computer. Needless to say, if you get some weird popup you don’t recognize at HCC or elsewhere, for the love of God don’t click on it.
A few hours after the attack, I arrived home to find this fun ball of shit waiting for me. And so I removed the offending code, changed our passwords, sacrificed a goat, had our host do a very thorough sweep of the entire site and had everyone with FTP access to the site do virus scans on their computers. So, the problem was eliminated shortly after it arose.
Obviously, none of that is much fun at all, but on the bright side, it appears that the attack on HCC was executed very, very poorly. The code that was inserted into our pages was incomplete, hence all that gibberish people were seeing at the top of the page. Browsers were rendering the code as plain text, meaning it wasn’t actually doing anything malicious at all. I’ve had a couple of cappers suggest that they may have picked up a virus from the site that night, and I suppose nothing’s impossible, but none of the added code that I saw was actually functional. So if you’ve been worried, I say make like a douchebag and chillax.
In other news… hey, wait, I don’t think we have much other news. No wonder I haven’t been blogging. I have a few experimental features I’m playing around with that I’ll talk about once I’ve decided they’re actually good ideas, for the most part at the moment I’m more concerned with making sure people are aware of and know how to use the features we already have, since I keep seeing evidence to the contrary. Speaking of which, I’m probably overdue for another “Hidden Secrets of HCC” blog.
Speaking of the blog, thanks go to Kip for sharing his random duck facts with us, and the offer remains enthusiastically open for any other cappers to contribute to the blog as well. Just shoot me and email using the form on the FAQ page if you don’t already have my email.
In non-HCC news, apologies to fans of the commune (there are fans of the commune, right?) for how slow the updates have been there, I’m mostly writing that site by myself now (notwithstanding the appreciated contributions from Hip and Zoog) so it’s probably going to ebb and flow depending on what I’ve got going on. Right now I’m working on converting that entire site to more modern coding, which is a huge project, but once that’s done I should have more time to actually, you know, add stuff worth reading. Oh, and another part of the reason for the delay: My band has a new album out. Enjoy, if you enjoy enjoying.
-Jazz
*Everybody's doin' the Zombie Stoned!*
ReplyDelete[you know, the song from MST3K: The Horror Of Party Beach.]
Frame injection can also be done by injecting code into a form entry that is submitted to some sort of SQL engine - hopefully altogether N/A to HCC site.
The attack was executed very poorly? that's a typical hallmark of virus and malware code: It's written so poorly it might as well be a Ferrigno Spammer caption. The harmful effect of malware code is often as much that it's written badly, as that it was written to do something bad.
And I presume nobody needs explanations of what a Script Kiddie is... let's say kind of like a beginning capper who hasn't caught on to invisible food jokes, but does just barely comprehend 'pull my finger' in a vague sort of way.
Agreed, we need more Blog entries.
I got a nasty malware that night, but I'm not sure exactly where it came from. I was attempting to access the site with Firefox and not having any luck posting caps due to the screwed up frame injection. Others said they weren't having issues at all so I tried loading my often neglected internet explorer. I clicked on what I thought were some "update explorer" pop ups and suddenly I spent the next week clearing the crap from my computer.
ReplyDeleteSo sadly even if HCC wasn't where I got the virus, the virus attack on HCC was partially responsible for me getting the malware. My own stupidity being the other responsible party.