PDA

View Full Version : Niddy's Nook - Malicious script



piston10
April 23rd, 2006, 20:07
Within the last hour I tried to get into the Niddy's Nook site from the address given by bkk gwm in his post on the 'sending funds' thread. Not possible, so I used the Nook's home page address. A few seconds after entering, Norton Anti-Virus came up with a 'Malicious Script' message and advised me to block it. I did so, but on entering the site again the same thing happened.

I don't know much about these things, but the timing of the message seems to suggest a connection between the site and the message. I'm not even sure what exactly a 'malicius script' is, and have no idea how serious a threat it poses to a protected or unprotected PC. I'm sure there are people out there who will have views on this and put me right if I'm panicking unnecessarily. Anyway, I pass the information on for what it's worth.

atri1666
April 24th, 2006, 00:01
Can not confirm. I dont have any problems with the homepage and my firewall is on highest level and i block all bad scripts.

April 24th, 2006, 00:20
Put AGV free edition on your PC ! Pay nothing and protect virus same as Norton !


http://www.grisoft.com/doc/1

bkkguy
April 24th, 2006, 01:07
the javascript at the very top of the web page certainly looks like the type of thing Norton would class as a malicious script - until it is removed or someone takes the time to decode it I wouldn't be visiting the site with javascript enabled!

bkkguy

elephantspike
April 24th, 2006, 01:22
That is a strange script; at the top and bottom of the page, outside the html tags.

bkkguy
April 24th, 2006, 01:39
Put AGV free edition on your PC ! Pay nothing and protect virus same as Norton !

but this is not a virus and AGV free anti-virus software does not protect against malicious code that exploits browser vulnerabilities so you may not be surfing as safe as you think you are!

bkkguy

April 24th, 2006, 04:35
AVG Free Edition is available free-of-charge to home users! AVG Free Edition is for private, non-commercial, single home computer use only.
Use of AVG Free Edition within any organization or for commercial purposes is strictly prohibited.


AVG Free Edition has the following limitations:

AVG Free Edition cannot be installed on server operating systems (such as Windows Server 2003), nor can it be used for the scanning of network drives.
Scheduling options in the AVG Free Edition are very limited (only one scheduled update per day, one scheduled scan per day etc.).
AVG Free Edition receives updates via a lower priority service. Priority updating via ultra reliable Akamai servers is only available for purchased products.


AVG Free Edition does not offer advanced testing options, such as automatic healing, password-protected archives reporting, adjustment of scan process priority and many others.
AVG Free Edition has no technical support!

http://www.grisoft.com/doc/289/lng/us/tpl/tpl01

American Teacher-old
April 24th, 2006, 14:03
Hello All! Thanks so much for bringing my attention to the phantom scripts on my website page. I have been (and still am) - as many of you know - on a short vacation in Chiang Mai, and therefore have been out of the loop for about a week now. However, upon hearing about these possible problems, I have contacted my webmaster who is currently diagnosing and fixing any errors on the site. I will report back as soon as he has fixed everything and can explain what went wrong. Preliminary reports seem to suggest that our web hosting company was not as secure as we had thought. If this is the case, we are prepared to switch web hosting to an alternative and more reliable company by no later than tonight.

I will get back to you as soon as I have more details. Again, thank you to all for bringing this to my attention.

Fondly,
Chris

American Teacher-old
April 25th, 2006, 11:10
Well, it was our web host. I guess that's what you get for going with the cheaper rate. Anyhow, we have upgraded with a new web hosting company now and should be back online (with everything corrected) by later tonight.

So sorry for anyone trying to access our website during these difficult few days.

www.niddysnook.com (http://www.niddysnook.com)

Fondly,
Chris

PS - Thanks again to everyone who so kindly sent me email privately to alert me of the situation. I will be back in Pattaya tomorrow.