PDA

View Full Version : CFC Website - Hacked Again ( New ) !



Bob Armstrong
09-21-2009, 07:55 PM
CFC Website - Hacked Again ( New ) !

I thought these two prior posts from ChessTalk needed to be brought to all members' attention, as they are a new warning about entering the ratings part of the CFC website ! EKG apparently did clean the last infection ( or didn't ), but now it has been hacked anew. So I am reposting the two posts:

" Quote:
Originally Posted by Egidijus Zeromskis
Sorry to say, but seems that the site (rating part) was hacked again.

Now it has a link to "a0v.org/x.js"

Posted by Steve Karpik:

This is very sad. There are two possibilities. Either the contractors hired by the CFC to clean the database of infected strings didn't do a very good job. Or equally as bad they didn't implement a filter on input data to prevent further injection attacks. In either case, the CFC web site is still in bad shape.

Some browsers like Chrome and Firefox will warn you not to visit the CFC web site. Internet Explorer won't do you that service. For the time being, I would recommend that CFC members don't query the web site for their ratings. After conducting a limited and unscientific survey of the CFC database, it seems that only some portion of the database has been infected but that's scant comfort if the data you're looking up is polluted with links to malware.

It looks right now that a fully patched computer will block the malware that is being distributed through the link to "a0v.org/x.js"; however, it is probably best to be safe rather than sorry.

As of mid-August, over 55,000 web sites worldwide had been compromised by this attack. That doesn't excuse the fact that the CFC web site is a mess -- it just shares its mess with 55,000 other badly maintained web sites. "

I'm sure the executive will have a statement on this shortly.

Bob

Bob Armstrong
09-23-2009, 12:39 AM
On ChessTalk recently, IT specialist Steve Karpik posted that there was no excuse for the CFC website having been cleaned, and then immediately thereafter, the ratings page hacked.

So I asked Steve as follows:

" Hi Steve:

Because the ratings page has been hacked ( a new one ), you suggested to me at one point that the page should be taken off-line for the moment, so users don't get infected ( you said good anti-virus would likely protect most, but the CFC should not be letting its members take the risk ). Do you still feel this way? We have heard nothing from the Executive about this new infection since Governor Egis Zeromskis reported it the other day. What should the CFC be doing about this new infection/hacking?

Bob "

Has the CFC now got EKG cleaning up the new virus? Should the page be down until this is done, to minimize risk to members?

Bob