OrthodoxChristianity.net
August 01, 2014, 05:51:45 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Reminder: No political discussions in the public fora.  If you do not have access to the private Politics Forum, please send a PM to Fr. George.
 
   Home   Help Calendar Contact Treasury Tags Login Register  
Pages: 1   Go Down
  Print  
Author Topic: Noticing Malware coming from www.orthodoxchristianity.net...  (Read 3093 times) Average Rating: 0
0 Members and 1 Guest are viewing this topic.
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« on: January 06, 2010, 02:03:55 PM »

Grace and Peace,

I'm noticing Malware getting blocked by Malwarebytes' Anti-Malware from an IP Address 95.169.190.73. I just thought you should know.
Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Anastasios
Webdespota
Administrator
Merarches
*******
Offline Offline

Faith: Eastern Orthodox
Jurisdiction: Greek Old Calendarist
Posts: 10,440


Metropolitan Chrysostomos of Florina

anastasios0513
WWW
« Reply #1 on: January 06, 2010, 02:17:54 PM »

Thanks for letting me know. That is not the IP address of our server at all. It is coming from the Russian Federation. Could you be more descriptive as to what the alert says?
Logged

Met. Demetrius's Enthronement

Disclaimer: Past posts reflect stages of my life before my baptism may not be accurate expositions of Orthodox teaching.

I served as an Orthodox priest from June 2008 to April 2013, before resigning for personal reasons
Anastasios
Webdespota
Administrator
Merarches
*******
Offline Offline

Faith: Eastern Orthodox
Jurisdiction: Greek Old Calendarist
Posts: 10,440


Metropolitan Chrysostomos of Florina

anastasios0513
WWW
« Reply #2 on: January 06, 2010, 02:30:53 PM »

Google has listed our site as clean for all recent history:
http://google.com/safebrowsing/diagnostic?site=orthodoxchristianity.net

Did you only now start seeing this warning?
Logged

Met. Demetrius's Enthronement

Disclaimer: Past posts reflect stages of my life before my baptism may not be accurate expositions of Orthodox teaching.

I served as an Orthodox priest from June 2008 to April 2013, before resigning for personal reasons
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« Reply #3 on: January 06, 2010, 05:56:57 PM »

Google has listed our site as clean for all recent history:
http://google.com/safebrowsing/diagnostic?site=orthodoxchristianity.net

Did you only now start seeing this warning?

Grace and Peace Father,

Yes I noticed it today. My virus software is blocking it but it comes up every time I refresh a page. It doesn't necessary have to be a virus, it may well be Malware or Adware. But I thought you guys and gals should know since it's your site.

If you check out that IP Address with tools like DNStuff it's coming out of Russia.  Huh

It just states that Malwarebytes' has blocked activity from that IP address.
« Last Edit: January 06, 2010, 05:58:15 PM by ignatius » Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Anastasios
Webdespota
Administrator
Merarches
*******
Offline Offline

Faith: Eastern Orthodox
Jurisdiction: Greek Old Calendarist
Posts: 10,440


Metropolitan Chrysostomos of Florina

anastasios0513
WWW
« Reply #4 on: January 06, 2010, 07:18:46 PM »

I am happy you have alerted me. I am just not sure where there could be spyware or adware or malware. I checked our server (which is not at that IP address) and there have been no unauthorized intrusions in to the server or files changed in the sources directory...so not sure. Could you send me a private message with the error message/log info from this program you have, because otherwise I will never be able to figure out what to look for.

Thanks!

Fr Anastasios
Logged

Met. Demetrius's Enthronement

Disclaimer: Past posts reflect stages of my life before my baptism may not be accurate expositions of Orthodox teaching.

I served as an Orthodox priest from June 2008 to April 2013, before resigning for personal reasons
Entscheidungsproblem
Formerly Friul & Nebelpfade
Protokentarchos
*********
Offline Offline

Faith: Machine God
Posts: 4,495



WWW
« Reply #5 on: January 06, 2010, 10:07:04 PM »

I've tried to replicate the error with Anti-Malware, but didn't find anything wrong with it.

I find it fairly odd, since the IP it is linking to seems to come up clean through Google clean browsing and through Anti-Malware itself.  The best bet would be to check the logs to see what exactly it says is happening.  A couple questions: a) when you load and refresh, in the status bar, do you notice it mentioning any site besides orthodoxchristianity.net?, b) are you having this problem with any other websites now or is it still just orthodoxchristinaity.net?

It sounds like it is likely more of a local problem, rather than something on the server.  I'm not sure why that IP would even be mentioned in loading this site (and can't get it to do so on my own machine), unless something locally on your machine is trying to force it.  It might also be a false positive.
Logged

As a result of a thousand million years of evolution, the universe is becoming conscious of itself, able to understand something of its past history and its possible future.
-- Sir Julian Sorell Huxley FRS
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« Reply #6 on: January 07, 2010, 01:00:02 AM »

Grace and Peace,

I'm only noticing it on this thread...

http://www.orthodoxchristianity.net/forum/index.php/topic,25198.45.html

every time I enter or post on this thread I see the notice come up....

14:55:46   chris   IP-BLOCK   81.169.145.86
14:56:56   chris   IP-BLOCK   95.169.190.73

It's diffidently coming up only when I've visiting this forum.
Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Fr. George
formerly "Cleveland"
Administrator
Stratopedarches
*******
Offline Offline

Faith: Orthodox (Catholic) Christian
Jurisdiction: GOA - Metropolis of Pittsburgh
Posts: 19,980


May the Lord bless you and keep you always!


« Reply #7 on: January 07, 2010, 01:06:52 AM »

Maybe someone is targeting people who are watching/on this site...
Logged

"The man who doesn't read good books has no advantage over the one who can't read them." Mark Twain
---------------------
Ordained on 17 & 18-Oct 2009. Please forgive me if earlier posts are poorly worded or incorrect in any way.
Entscheidungsproblem
Formerly Friul & Nebelpfade
Protokentarchos
*********
Offline Offline

Faith: Machine God
Posts: 4,495



WWW
« Reply #8 on: January 07, 2010, 01:43:06 AM »

Thanks for the info, ignatius.

It is the following picture that is causing the problem:

http://en.academic.ru/pictures/enwiki/66/Byzantium1204.png

from this post.
Logged

As a result of a thousand million years of evolution, the universe is becoming conscious of itself, able to understand something of its past history and its possible future.
-- Sir Julian Sorell Huxley FRS
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« Reply #9 on: January 07, 2010, 09:57:11 AM »

Thanks for the info, ignatius.

It is the following picture that is causing the problem:

http://en.academic.ru/pictures/enwiki/66/Byzantium1204.png

from this post.

You are more than welcome. So was it a virus or just Malware/Adware?
Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Entscheidungsproblem
Formerly Friul & Nebelpfade
Protokentarchos
*********
Offline Offline

Faith: Machine God
Posts: 4,495



WWW
« Reply #10 on: January 07, 2010, 10:56:43 AM »

Thanks for the info, ignatius.

It is the following picture that is causing the problem:

http://en.academic.ru/pictures/enwiki/66/Byzantium1204.png

from this post.

You are more than welcome. So was it a virus or just Malware/Adware?
Neither.  For some reason, anti-malware has blacklisted the IP that the image was hosted on.  The image is clean, the website doesn't seem to actively possess any threats, so it is likely that either the site had issues in the past or malicious sites are hosted on the same server or on the same server farm.
Logged

As a result of a thousand million years of evolution, the universe is becoming conscious of itself, able to understand something of its past history and its possible future.
-- Sir Julian Sorell Huxley FRS
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« Reply #11 on: January 08, 2010, 12:44:41 PM »

Thanks for the info, ignatius.

It is the following picture that is causing the problem:

http://en.academic.ru/pictures/enwiki/66/Byzantium1204.png

from this post.

You are more than welcome. So was it a virus or just Malware/Adware?
Neither.  For some reason, anti-malware has blacklisted the IP that the image was hosted on.  The image is clean, the website doesn't seem to actively possess any threats, so it is likely that either the site had issues in the past or malicious sites are hosted on the same server or on the same server farm.

Hi Guys. I'm noticing the same warning in the thread on Protestants and Icons... just so you know.
Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Anastasios
Webdespota
Administrator
Merarches
*******
Offline Offline

Faith: Eastern Orthodox
Jurisdiction: Greek Old Calendarist
Posts: 10,440


Metropolitan Chrysostomos of Florina

anastasios0513
WWW
« Reply #12 on: January 08, 2010, 01:10:47 PM »

Is your program telling you it is because of one of the linked images?
Logged

Met. Demetrius's Enthronement

Disclaimer: Past posts reflect stages of my life before my baptism may not be accurate expositions of Orthodox teaching.

I served as an Orthodox priest from June 2008 to April 2013, before resigning for personal reasons
ignatius
Baptacathadox
OC.net guru
*******
Offline Offline

Faith: Roman Catholic > Eastern Orthodox
Jurisdiction: OCA - Diocese of the South
Posts: 1,690


My Son Aidan... :-)


« Reply #13 on: January 08, 2010, 01:20:47 PM »

Is your program telling you it is because of one of the linked images?

Sorry Father it doesn't give me that much info but it appears to be the same issue as before. My guess it's one of the linked images as before. I'm not trying to get anyone worried or anything I just thought someone should know.
Logged

St Basil the Great (330-379 A.D.): “I think then that the one goal of all who are really and truly serving the Lord ought to be to bring back to union the churches who have at different times and in diverse manners divided from one another.”
Entscheidungsproblem
Formerly Friul & Nebelpfade
Protokentarchos
*********
Offline Offline

Faith: Machine God
Posts: 4,495



WWW
« Reply #14 on: January 08, 2010, 02:30:44 PM »

Yup, it is another linked image.

http://mariedenazareth.com/typo3temp/pics/576c12baa6.jpg from this post.
Logged

As a result of a thousand million years of evolution, the universe is becoming conscious of itself, able to understand something of its past history and its possible future.
-- Sir Julian Sorell Huxley FRS
Anastasios
Webdespota
Administrator
Merarches
*******
Offline Offline

Faith: Eastern Orthodox
Jurisdiction: Greek Old Calendarist
Posts: 10,440


Metropolitan Chrysostomos of Florina

anastasios0513
WWW
« Reply #15 on: January 08, 2010, 02:42:27 PM »

Basically if it is a linked image, there will be nothing we can do about it. We could theoretically ban hotlinking to images outside our forum,  but then people would attach the images here and use up all our bandwidth. So if you see such warnings again, know that they are not coming from this site. If you see a warning not related to an image, let us know.
Logged

Met. Demetrius's Enthronement

Disclaimer: Past posts reflect stages of my life before my baptism may not be accurate expositions of Orthodox teaching.

I served as an Orthodox priest from June 2008 to April 2013, before resigning for personal reasons
Velsigne
Elder
*****
Offline Offline

Faith: Orthodox
Posts: 441



« Reply #16 on: April 08, 2013, 11:39:26 PM »

Hi,

You are getting malware attacks on this thread: an ex-catechumen comparing the Episcopalian Lent

93.125.99.4
Logged
dcommini
Tha mi sgulan na Trianaid
OC.net guru
*******
Offline Offline

Faith: Orthodox
Jurisdiction: Antiochian
Posts: 1,198


Beannachd Dia dhuit

dcommini
WWW
« Reply #17 on: April 09, 2013, 08:02:19 PM »

I just did my own scan and it came back negative for malware. Perhaps it is one of the photos again.
Logged

Gun cuireadh do chupa thairis le slàinte agus sona - May your cup overflow with health and happiness
Check out my blog...
Velsigne
Elder
*****
Offline Offline

Faith: Orthodox
Posts: 441



« Reply #18 on: April 10, 2013, 02:34:23 AM »

I just did my own scan and it came back negative for malware. Perhaps it is one of the photos again.

Okay, thanks for checking on that.
Logged
Tags:
Pages: 1   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 45 queries.