Page 1 of 1

https://springfiles.com/ is compromised?

Posted: 24 May 2018, 18:56
by The Yak
Trying to load unauthenticated scripts and sketchy textwall appearance.

Re: https://springfiles.com/ is compromised?

Posted: 25 May 2018, 11:20
by abma
can you provide details? (screenshot / urls / filenames of the scripts)

i don't see what you mean...


i don't maintain the page, jj does/did: the accesses to google look weird. I guess i'll add Access-Control-Allow-Origin and/or a Same-origin policy.

Re: https://springfiles.com/ is compromised?

Posted: 25 May 2018, 19:15
by The Yak
It seems to be normal now.

Re: https://springfiles.com/ is compromised?

Posted: 27 May 2018, 01:04
by Jonny5isalivetm
I got a similar bogus message while trying to load spring files recently.. again mustve been some sort of script andit loaded some crapware page your computer infected blabla

Perhaps the site is infected..

Re: https://springfiles.com/ is compromised?

Posted: 27 May 2018, 22:52
by The Yak
It happened again. Springfiles redirected to this thing:
Image

Re: https://springfiles.com/ is compromised?

Posted: 27 May 2018, 23:52
by raaar
!

I saw the above page too. It shows a popup.

Image

it's the second time today, but in the meantime I used the site just fine.

Re: https://springfiles.com/ is compromised?

Posted: 28 May 2018, 06:13
by Jonny5isalivetm
yea I got that same page I got past it with a page reload then springfiles worked normally

Re: https://springfiles.com/ is compromised?

Posted: 28 May 2018, 17:33
by abma
i've enabled several security headers in apache:

Header set Access-Control-Allow-Origin "https://springfiles.com"
Header set X-XSS-Protection "1; mode=block"
Header set Content-Security-Policy "default-src 'self';"
and found a lot of .php files modified / reverted these changes via git.

also i've deleted / disabled A LOT of drupal modules: this doesn't fix the real cause of the problem but should reduce the risk a lot.

not very satisfactory but should work for now. :(

Re: https://springfiles.com/ is compromised?

Posted: 29 May 2018, 19:05
by Forboding Angel
Make sure you are running the latest version. Don't skimp on updates.

Re: https://springfiles.com/ is compromised?

Posted: 02 Jun 2018, 05:04
by PicassoCT
Dear god, a leprosy case.

impure,
IMPURE,
IMPURE!

This all happend because you touch yourself at night and do not donate to the picasso foundation!