Page 1 of 1

C4C appears to have been pwned

Posted: Sat Dec 17, 2022 4:26 pm
by Graeme Cole
Occasionally, when you request a page on the C4Countdown forum, it will 302-redirect to a website called "bongacams". After a brief inspection of this dubious online resource, I was disappointed to find that the quality of Countdown discussion there is far below what I expect from C4C. Their letters selections use far too many Xs, and the numbers target is always the same and only two digits.

I've seen this happen in both Chrome and Firefox. At least one other person has reported the problem as well. I'm guessing C4Countdown's web server has been compromised in some way.

Re: C4C appears to have been pwned

Posted: Sat Dec 17, 2022 4:55 pm
by Johnny Canuck
Have also had security-related popups saying “Your computer has been locked down”. Props for referencing an Apterous variant, but still annoying.

Re: C4C appears to have been pwned

Posted: Sat Dec 17, 2022 5:08 pm
by Sam Cappleman-Lynes
Graeme Cole wrote: Sat Dec 17, 2022 4:26 pm Occasionally, when you request a page on the C4Countdown forum...
This hasn't happened to me yet on C4C, but it did happen to me on wiki.apterous.org yesterday.

Re: C4C appears to have been pwned

Posted: Sat Dec 17, 2022 5:14 pm
by Graeme Cole
Sam Cappleman-Lynes wrote: Sat Dec 17, 2022 5:08 pm
Graeme Cole wrote: Sat Dec 17, 2022 4:26 pm Occasionally, when you request a page on the C4Countdown forum...
This hasn't happened to me yet on C4C, but it did happen to me on wiki.apterous.org yesterday.
wiki.apterous.org resolves to the same IP as c4countdown.co.uk, so I guess they share the same web server. apterous.org itself is a different server.

Re: C4C appears to have been pwned

Posted: Sat Dec 17, 2022 5:23 pm
by Andres Sanchez
Did not expect a thread to be made as quick as it did. Got this redirect and it was real weird for me. Hope that the issue can be fixed

Re: C4C appears to have been pwned

Posted: Sat Dec 17, 2022 5:59 pm
by Gavin Chipper
How do we know that it was the real Graeme that started this thread? We have to be very careful about considering the motivations behind it. One false move and we could all be paperclips.

Re: C4C appears to have been pwned

Posted: Sun Dec 18, 2022 5:50 am
by Marc Meakin
Gavin Chipper wrote: Sat Dec 17, 2022 5:59 pm How do we know that it was the real Graeme that started this thread? We have to be very careful about considering the motivations behind it. One false move and we could all be paperclips.
Nothing wrong with paper clips, I've needed one on here for years (was scouring my posts here to find the one from our absent friend Phi Reynolds)

Re: C4C appears to have been pwned

Posted: Sun Dec 18, 2022 12:34 pm
by Callum Todd
Gavin Chipper wrote: Sat Dec 17, 2022 5:59 pmOne false move and we could all be paperclips.
'I can see you're trying to maximise paperclips. Would you like some help with that?'

Re: C4C appears to have been pwned

Posted: Mon Dec 19, 2022 12:09 pm
by Charlie Reams
It seems our web hosting company itself has been compromised, judging by this message I received from them:
Security Notification
Due to a security vulnerability we have temporarily disabled the cPanel mail Horde webmail client until a fix is in place.
It's quite annoying that they weren't proactive about this, but let's see if that fixes the issue. Please let me know if you continue to see this happening as of now.

FWIW, www.apterous.org is extensively isolated from wiki.apterous.org and from c4c, so there's no risk to anyone's apterous account. But the wiki and c4c are hosted on the same place, which is consistent with the idea that it's the host itself that has a problem.

Re: C4C appears to have been pwned

Posted: Mon Dec 19, 2022 6:54 pm
by Graeme Cole
Charlie Reams wrote: Mon Dec 19, 2022 12:09 pm It's quite annoying that they weren't proactive about this, but let's see if that fixes the issue. Please let me know if you continue to see this happening as of now.
Just happened again for me when reloading the C4C main page.

Re: C4C appears to have been pwned

Posted: Mon Dec 19, 2022 7:36 pm
by Andres Sanchez
Same here.

Re: C4C appears to have been pwned

Posted: Tue Dec 20, 2022 1:59 am
by Andres Sanchez
Now I just got one from a site called Fuckbook. God the internet's really full of porn.

Re: C4C appears to have been pwned

Posted: Tue Dec 20, 2022 7:14 am
by Marc Meakin
Fwiw I go here on my phone and so far none of this Mullarkey

Re: C4C appears to have been pwned

Posted: Tue Dec 20, 2022 12:39 pm
by Charlie Reams
Thanks, I'll keep looking into this. I've enabled DNS protection in case this is some kind of DNS poisoning issue, although that seems unlikely.

Re: C4C appears to have been pwned

Posted: Wed Dec 21, 2022 1:39 pm
by JackHurst
Appears to happen to me roughly 1/10 times a log in. Thought I was going mad the first couple of times it happened.

Surely this is a fuck up so bad by the hosting provider we can get a free year from them or something...

Re: C4C appears to have been pwned

Posted: Wed Dec 21, 2022 6:22 pm
by Paul Anderson
Nada on Safari, the superior browser 😉

Re: C4C appears to have been pwned

Posted: Wed Dec 21, 2022 6:23 pm
by Marc Meakin
Paul Anderson wrote: Wed Dec 21, 2022 6:22 pm Nada on Safari, the superior browser 😉
Safari so goodi

Re: C4C appears to have been pwned

Posted: Fri Dec 23, 2022 10:12 am
by Charlie Reams
Really sorry about this. The provider claims that everything is resolved from this morning, so please let me know if you continue to see this as of now. If push comes to shove we can move hosts but that is likely to be disruptive (and expensive).

Re: C4C appears to have been pwned

Posted: Fri Dec 23, 2022 12:15 pm
by Gavin Chipper
No problem. Not your fault anyway.