Virus attack from the news section.
-
- Snes9x White Belt
- Posts: 13
- Joined: Sat Jul 26, 2008 10:08 pm
Virus attack from the news section.
The news section of snes9x.com attacked me with a virus.
-
- Hero of Hyrule | Official Port Recruiter
- Posts: 2586
- Joined: Mon May 24, 2004 5:06 pm
- Location: 255.255.255.255
Why did you spam this across the forums -_-" and to top it off why did you make this one a poll

Unofficial Test Monkey For:
* Snes9X GX (Wii)
* Snes9X EX (Android)
* Snes9X 64-bits (PC/Mac)
ZSNES|Ben Heck|NSRT|Bob Smiley
-
- Snes9x White Belt
- Posts: 13
- Joined: Sat Jul 26, 2008 10:08 pm
Why Poll?
This was the first one I posted! that's why it's a poll.
I sounding an alarm, to make sure everyone knows that the news section is unhealthy right now.
I sounding an alarm, to make sure everyone knows that the news section is unhealthy right now.
-
- Snes9x Brown Belt
- Posts: 1158
- Joined: Mon Jan 10, 2005 6:34 am
-
- Hero of Hyrule | Official Port Recruiter
- Posts: 2586
- Joined: Mon May 24, 2004 5:06 pm
- Location: 255.255.255.255
There is no virus on the news section... using firefox 3.0.1 and antivir v8.01.01.12 with the latest definitions.

Unofficial Test Monkey For:
* Snes9X GX (Wii)
* Snes9X EX (Android)
* Snes9X 64-bits (PC/Mac)
ZSNES|Ben Heck|NSRT|Bob Smiley
- kolechovski
- Snes9x Brown Belt
- Posts: 1100
- Joined: Fri May 28, 2004 6:16 pm
Thanks to some dickhead spamming the site had a virus....
I can't reply to threads because
^oh, it seems it did post to this thread, after all.
comes up and i get the new thread form instead.Reported Attack Site!
This web site at www.snes9x.com has been reported as an attack site and has been blocked based on your security preferences.
Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.
Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.
^oh, it seems it did post to this thread, after all.
- kolechovski
- Snes9x Brown Belt
- Posts: 1100
- Joined: Fri May 28, 2004 6:16 pm
Actually it's a warning message displayed by firefox due to a google safebrowsing listing:
http://safebrowsing.clients.google.com/ ... /index.php
http://safebrowsing.clients.google.com/ ... /index.php
-
- Hero of Hyrule | Official Port Recruiter
- Posts: 2586
- Joined: Mon May 24, 2004 5:06 pm
- Location: 255.255.255.255
well that certainly explains how come last time I checked new posts in this thread I got an error about this thread being an attack site 


Unofficial Test Monkey For:
* Snes9X GX (Wii)
* Snes9X EX (Android)
* Snes9X 64-bits (PC/Mac)
ZSNES|Ben Heck|NSRT|Bob Smiley
I tried emailing the webmaster and "Gary", whoever he is, but got undeliverable email notices, so I'll post it here.
"Google and firefox both claim that SNES9X.com is a malicious site, and sure enough, when I visit the News page something from coldwop.com tries to infect my system. Likely the site was hit by a hacker. Given the popularity of SNES9X, one would think this problem would have been dealt with immediately, but there are posts on the forum mentioning this dated from back in July, with no replys from a webmaster. Given SNES9X's legacy, it seems like a bad idea to ignore this issue. Thank you."
"Google and firefox both claim that SNES9X.com is a malicious site, and sure enough, when I visit the News page something from coldwop.com tries to infect my system. Likely the site was hit by a hacker. Given the popularity of SNES9X, one would think this problem would have been dealt with immediately, but there are posts on the forum mentioning this dated from back in July, with no replys from a webmaster. Given SNES9X's legacy, it seems like a bad idea to ignore this issue. Thank you."
-
- Hero of Hyrule | Official Port Recruiter
- Posts: 2586
- Joined: Mon May 24, 2004 5:06 pm
- Location: 255.255.255.255
AFAIK, Gary quit the scene a long time ago, and Jerremy pokes his head in every once in a VERY GREAT while.
given that the server itself uses windows...
given that the server itself uses windows...

Unofficial Test Monkey For:
* Snes9X GX (Wii)
* Snes9X EX (Android)
* Snes9X 64-bits (PC/Mac)
ZSNES|Ben Heck|NSRT|Bob Smiley
- kolechovski
- Snes9x Brown Belt
- Posts: 1100
- Joined: Fri May 28, 2004 6:16 pm
Here is me poking my head in again 
If anyone would have send me a message on this forum, then I would have been able to react a whole lot faster (this forum has my current email address, jerremy@snes9x.com has been given up years ago due to the insane amount of spam it gets daily).
Anyways, the damage has been done and I am in the process of cleaning up the mess. It seems that the code that 'manages' the website (which dates from 1999 and its very outdated ! ) was open for sql-injection.
This was then used to update all news / journal messages to add some scripts from various mallicious sites. (spelling)
This has -nothing- to do with Windows and everything to do with unsecure coding. SQL Injection wasnt heard off much (and the url of the 'management' pages wherent known). Its no excuse though.
I'm unsure how they figured out what page it was, but no matter. The SQL injection will be fixed, the pages will be clean up. I have, however, no idea how to 'unblacklist' the site.

If anyone would have send me a message on this forum, then I would have been able to react a whole lot faster (this forum has my current email address, jerremy@snes9x.com has been given up years ago due to the insane amount of spam it gets daily).
Anyways, the damage has been done and I am in the process of cleaning up the mess. It seems that the code that 'manages' the website (which dates from 1999 and its very outdated ! ) was open for sql-injection.
This was then used to update all news / journal messages to add some scripts from various mallicious sites. (spelling)
This has -nothing- to do with Windows and everything to do with unsecure coding. SQL Injection wasnt heard off much (and the url of the 'management' pages wherent known). Its no excuse though.
I'm unsure how they figured out what page it was, but no matter. The SQL injection will be fixed, the pages will be clean up. I have, however, no idea how to 'unblacklist' the site.
Great to hear from you. You are right, someone should have at least tried to PM you
As for the blacklist removal, I've found the following FAQ for google safebrowsing: http://serpguard.com/faq2/

As for the blacklist removal, I've found the following FAQ for google safebrowsing: http://serpguard.com/faq2/