ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX
10 December 2011, 11:37 AM | #121 |
"TRF" Member
Join Date: Mar 2010
Location: Maui
Watch: Patek
Posts: 2,032
|
sorry if i came off harsh, i know its tough to fix these server side issues, hang in there
|
10 December 2011, 11:41 AM | #122 | |
Banned
Join Date: Aug 2011
Real Name: Mickey®
Location: Atlanta, GA
Watch: Swiss Made
Posts: 5,801
|
Quote:
|
|
10 December 2011, 11:44 AM | #123 | |
"TRF" Member
Join Date: Jun 2010
Real Name: Ashley
Location: Brisbane
Watch: Rolex Sub 1680 '79
Posts: 2,301
|
Quote:
The reason you're only getting 15% of users reporting it is that you have a lot of people running unsophisticated or older browsers like IE on this forum. There is a block of javascript code attempting to pull down a malware payload on every pageload on TRF. You need to kill apache and point nginx to a holding page until this is over, every minute you try to keep the site up in its present state is doing damage to TRF users.
__________________
-- Omega Seamaster Grand-Lux Stepped Pie-Pan 14K Gold OJ2627 '53 --
-- Omega Cal 320 Chronograph 18K Gold OT2872 '58 -- -- Omega Cal 321 Speedmaster Pro 145.012 '67 -- -- Rolex Submariner 1680 "Ghost" '79 -- -- Rolex SS Daytona 116520 '04 -- |
|
10 December 2011, 11:47 AM | #124 |
2024 SubLV41 Pledge Member
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 42,013
|
BTW a new exploit has surfaced to attack iPads running Safari. It just causes an overflow since the Java Trojan won't download to an iPad.
Just sharing in the spirit of teamwork. iPads and iPhones running Tapatalk seem to still be fine. Have been using both with no problems But I tried the iPad with Safari just to check. It ran for several minutes before picking up the probe and then it would just close Safari as the redirect tried to load the jar files. Sent from my iPad using Tapatalk
__________________
Does anyone really know what time it is? |
10 December 2011, 11:49 AM | #125 | |
"TRF" Member
Join Date: Aug 2008
Real Name: Chris
Location: Boston
Watch: 116610,116233,OsQz
Posts: 1,109
|
I thought so. Hmmm
Quote:
|
|
10 December 2011, 11:51 AM | #126 | |
"TRF" Member
Join Date: Aug 2008
Real Name: Chris
Location: Boston
Watch: 116610,116233,OsQz
Posts: 1,109
|
Quote:
|
|
10 December 2011, 11:53 AM | #127 |
"TRF" Member
Join Date: Aug 2008
Real Name: Chris
Location: Boston
Watch: 116610,116233,OsQz
Posts: 1,109
|
Sounds like we have a lot of other experienced It/networking people finally chiming in.
|
10 December 2011, 11:56 AM | #128 |
"TRF" Member
Join Date: Aug 2008
Real Name: Chris
Location: Boston
Watch: 116610,116233,OsQz
Posts: 1,109
|
I am prob not the only one that felt I would enrage an admin/mod with my concern. Glad this is such an open place.:)
It pains me to see the forum have any issues at all but it happens. |
10 December 2011, 12:01 PM | #129 |
TRF Moderator & 2024 SubLV41 Patron
Join Date: May 2005
Real Name: God
Location: Washington, D.C.
Watch: What do you think?
Posts: 37,966
|
I've been getting the same message for the past couple of days. Norton 360 has been blocking the attacks.
__________________
Despite the high cost of living, it's still very popular. Tosser Cabinet Member Official Member: 'Perpetual 30' Vegas International GTG 2016 Official Member "WIS-CON" Las Vegas International GTG 2017 Official Member "WIS-CON" Las Vegas International GTG 2018 Official Member "WIS-CON" Las Vegas International GTG 2019 |
10 December 2011, 12:06 PM | #130 | ||
TRF Moderator & 2024 SubLV41 Patron
Join Date: Jul 2007
Real Name: Rob
Location: Nearby.
Posts: 24,931
|
Quote:
What I can suggest ATM is to up your firewall/and or loggout from the forum until this issue is resolved. Personal commitments and an ongoing search for the source are persistent Quote:
This will be resolved in due time, rest assured!
__________________
He who wears a Rolex is always on time, even when late!! TRF's "After Dark" Bar & Nightclub Patron-Founding Member.. |
||
10 December 2011, 12:25 PM | #131 |
"TRF" Member
Join Date: Oct 2010
Real Name: Nathan
Location: US, Latin America
Watch: GMT IIc 18K/SS
Posts: 3,349
|
I have been browsing with safari via my iPhone with no apparent issues so far.
While I hate to be without TRF for even a few minutes I also would be supportive of TRF being taken offline in order to clean things up so that those with less sophisticated or secure systems would not be unwittingly infected. Many thanks to Steve, et al, for working towards a speedy resolution
__________________
(Member NAWCC since 1976) 116713LN GMT-IIc 18k/SS (Z) + 116520 SS Daytona (M) + 16700 GMT Master (A) + 16610LV Submariner (V) + 16600 Sea Dweller (Z) + 116400 Milgauss White Dial (V) + 70330N Tudor Heritage Chronograph Grey w/Black Sub Dials (J) + 5513 Submariner Serif Dial (5.2 Mil) Who else needs an Intervention? (109 297) (137 237) (73 115) (221) (23) (56) (229) P-Club Member #5 RIP JJ Irani - TRF Legend |
10 December 2011, 12:35 PM | #132 | |
TRF Moderator & 2024 SubLV41 Patron
Join Date: May 2005
Real Name: God
Location: Washington, D.C.
Watch: What do you think?
Posts: 37,966
|
I use IE with Verizon Yahoo as my browser on XP machines. I have no problem accessing TRF. The only issue I've had in the past two days was noted in post #129 above.
When I browse for Rolex Forum in Yahoo, TRF comes up immediately with no issues. However, when I did a similar search using Google, I got the following message: Quote:
This may be a Google problem more than a TRF problem.
__________________
Despite the high cost of living, it's still very popular. Tosser Cabinet Member Official Member: 'Perpetual 30' Vegas International GTG 2016 Official Member "WIS-CON" Las Vegas International GTG 2017 Official Member "WIS-CON" Las Vegas International GTG 2018 Official Member "WIS-CON" Las Vegas International GTG 2019 |
|
10 December 2011, 12:52 PM | #133 | |
"TRF" Member
Join Date: Sep 2009
Location: USA
Watch: 1675
Posts: 171
|
Quote:
I purposely and carefully surfed here using Firefox with the "noscript plugin" (forbidding rolexforums.com, and links) and java turned off. "position your firewall appropriately" ??? Sorry, but firewalls DO NOT prevent drive by downloads. As long as you keep this site operational you ARE contributing to the possible infection of older, unpatched machines. (I pity the person who is surfing this forum with IE6). The culprit could be hiding anywhere from "signatures" to "avatars", hidden iFrames. As suggested, the site should be taken offline, or DNS pointed to a "Sorry" page. |
|
10 December 2011, 01:01 PM | #134 | |
"TRF" Member
Join Date: Jun 2010
Real Name: Ashley
Location: Brisbane
Watch: Rolex Sub 1680 '79
Posts: 2,301
|
Quote:
__________________
-- Omega Seamaster Grand-Lux Stepped Pie-Pan 14K Gold OJ2627 '53 --
-- Omega Cal 320 Chronograph 18K Gold OT2872 '58 -- -- Omega Cal 321 Speedmaster Pro 145.012 '67 -- -- Rolex Submariner 1680 "Ghost" '79 -- -- Rolex SS Daytona 116520 '04 -- |
|
10 December 2011, 01:11 PM | #135 | |
TRF Moderator & 2024 SubLV41 Patron
Join Date: Jul 2007
Real Name: Rob
Location: Nearby.
Posts: 24,931
|
Quote:
My advice to you and anyone else receiving the warnings, is "to log out"!!!! TRF is not holding you hostage to log in, nor is it doing nothing!! All i'm asking is to keep the antagonism to yourself until the fix has been resolved! There's more to it than you can see or fathom. My post was an alternative, not a directive!!
__________________
He who wears a Rolex is always on time, even when late!! TRF's "After Dark" Bar & Nightclub Patron-Founding Member.. |
|
10 December 2011, 04:02 PM | #136 |
Facilitator
Join Date: Nov 2005
Real Name: Steve
Location: Omnipresent
Posts: 33,587
|
Please be patient guys we are working on getting this resolved asap.
I hope the solution will be obtained shortly. Please accept my apologies. I do not have any evidence of compromised accounts or computers at this stage, it may be a false positive, but it is best to err on the side of caution.
__________________
Most folks are about as happy as they make up their minds to be. ~Abraham Lincoln Nothing compares to the simple pleasure of a bike ride. ~John F. Kennedy ROLEXploitation - yeah I'm a victim |
10 December 2011, 06:27 PM | #137 |
"TRF" Member
Join Date: Dec 2007
Location: Melbourne, AU
Watch: Pepsi
Posts: 4,370
|
Until there is a fix to the problem, it seems to me that by disabling scripting will disable the access of the malware.
In IE, this can be done by changing the security level of the browser: 1. Goto "Tools" -> "Internet Options", and select the "Security" tab 2. Select "Internet zone", tick "Enabled Protected Mode", select "Custom Level" 3. Scroll down the Settings to "Scripting" section: 4. Right under "Scripting", there is "Active scripting", either check Disable, or Prompt. Then click "OK" and "OK" to get out. By choosing "Disable", some website may break, You can choose "Prompt" and make sure you say "no" in TRF. In Firefox, it's easier: 1. goto "Tools" -> "Options" 2. goto "Content" tab at the top. 3. uncheck "Enable Javascript". Hope this helps. P.S. If you google "Disable Javascript in IE", there are several answers that contains malware by itself. Be careful! |
11 December 2011, 12:40 PM | #138 |
Facilitator
Join Date: Nov 2005
Real Name: Steve
Location: Omnipresent
Posts: 33,587
|
The problem has been resolved.
It was related to a Tapatalk script. Tapatalk has not been reinstalled at this stage. The google warning takes a day to remove, but everything is running properly as of now.
__________________
Most folks are about as happy as they make up their minds to be. ~Abraham Lincoln Nothing compares to the simple pleasure of a bike ride. ~John F. Kennedy ROLEXploitation - yeah I'm a victim |
11 December 2011, 12:46 PM | #139 |
2024 SubLV41 Pledge Member
Join Date: Oct 2008
Real Name: Sink-O!
Location: a praire in AZ
Watch: ROLEX-less atm...
Posts: 14,021
|
Great news StevO !
__________________
*Positive Waves Baby* Lug Hole Loyalist / Chamfer Line Inspector INFORTHE WIN SUB-MAH-REEEN-ER ~ !
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
*Banners
Of The Month*
This space is provided to horological resources.