Riskware Warnings
Chris_Sav Offline
Administrator
*******

Posts: 486
Threads: 133
Joined: Jan 2018
Reputation: 0
#10
RE: Riskware Warnings
Yes pretty much but there are two separate issues there.

Insecure domain: The forum has not been upgraded to HTTPS encoded transmission (SSL) from plain text HTTP. This is of lesser importance as no sensitive data apart from UID/password is exchanged between your browser and the forum. Browsers are all warning of armageddon if you access sites using the older protocol, but it does not matter unless you are sending banking details or the like over the internet, then they need to be encoded.

The riskware: Yes I am certain the site has been infected by the insertion of code that runs a script on a Nigerian website. There is a known simple vulnerability in MyBB that used to allow this. All the perpetrator had to do was to send a mod a PM containing the insertion code and that bypassed all security once the mod opened it. At the moment the script just appears to insert a tracker on your PC, but it could do much more such as install a keylogger and get all your passwords. As you are seeing the warning you are safe and the transmission stopped.

The second issue is worrying! and easily fixable but no-one has access to the full forum moderation access. Poor Malcolm appears out of the game long term, my emails / pm's have not been answered. I have traced a phone number to where he used to live near Blackpool but get no reply to ringing or leaving a message on the answerphone. I have swapped pm's with benjiesdad the last mod to log on two years ago and he cannot help. Malcolm's account has only been used once, and then only briefly since 6th June.

The future of the forum is also once again uncertain. The domain registration runs out on 12th September and the forum will die unless Malcolm has set up an 'auto-renew'.

I have a long history in IT but retired twenty years ago so most of my knowledge is out of date. I do still own a large forum elsewhere but not MyBB coding unfortunately.

I am off to The Island on Tuesday for the duration so will not be in a position to help further until the start of September. There will be bills to pay and only Malcolm can do that, the existence of the forum is not cost free so we have a lot to thank Malcolm for as well as running it.
[Image: chris-quill-blue.gif]Laurel Bank II Marshal, Classic TT & Manx GP
(This post was last modified: 11-08-2022, 09:57 AM by Chris_Sav.)
11-08-2022, 09:34 AM
Find Reply


Messages In This Thread
Riskware Warnings - by Chris_Sav - 09-06-2022, 09:42 AM
RE: Riskware Warnings - by Chris_Sav - 25-07-2022, 04:26 PM
RE: Riskware Warnings - by captainsparkledotcom - 25-07-2022, 07:31 PM
RE: Riskware Warnings - by Chris_Sav - 25-07-2022, 09:29 PM
RE: Riskware Warnings - by captainsparkledotcom - 26-07-2022, 07:59 AM
RE: Riskware Warnings - by Chris_Sav - 29-07-2022, 09:08 AM
RE: Riskware Warnings - by milestone 11 - 02-08-2022, 02:52 PM
RE: Riskware Warnings - by Chris_Sav - 02-08-2022, 06:43 PM
RE: Riskware Warnings - by Alfie Noakes - 10-08-2022, 09:27 PM
RE: Riskware Warnings - by dommyman - 29-08-2022, 07:33 PM
RE: Riskware Warnings - by Chris_Sav - 11-08-2022, 09:34 AM
RE: Riskware Warnings - by Splashdown - 11-08-2022, 03:27 PM
RE: Riskware Warnings - by Rednine - 15-08-2022, 02:24 PM
RE: Riskware Warnings - by Alfie Noakes - 29-08-2022, 09:20 PM
RE: Riskware Warnings - by Chris_Sav - 31-08-2022, 10:29 PM
RE: Riskware Warnings - by Chris_Sav - 01-09-2022, 02:12 PM
RE: Riskware Warnings - by Alfie Noakes - 01-09-2022, 08:36 PM
RE: Riskware Warnings - by BenjiesDad - 02-09-2022, 07:58 PM
RE: Riskware Warnings - by Chris_Sav - 21-06-2023, 10:45 PM



Users browsing this thread: 1 Guest(s)