PDA

View Full Version : Virus threats on the site lately



happystuff
7-22-23, 9:15pm
Hi Alan, Over the course of the last 2-3 days, my virus protection program (Avast) has popped-up this warning about blocking a virus on/in the site. Don't know of that is something that needs addressing or what. Just thought I would mention it.

5592

Alan
7-22-23, 10:34pm
Thanks for pointing that out, it's the first I've heard of it. The message you shared refers to a re-direct to another site which appears to be on an internet blacklist, which means that one or more of the major tech players such as Google, etc., may have found something fishy on that site which has yet to be addressed. The site in question is a long standing Yahoo site which provides an API (Application Programming Interface) repository which our site software uses to power its BB Code functions.

A couple of quick scans I've just completed of our site found no instances of virus or malware and a quick internet search came up empty on any indication of why the yahooapis site is on a blacklist.

To be safe, I've put in a ticket with our web host asking them to do a more complete scan of our site for problems. I'll let you know how that goes.

Tradd
7-22-23, 10:44pm
I have to say I’ve not gotten any notices of weirdness with the site. I only surf it on my iPhone and iPad with Safari.

happystuff
7-23-23, 7:35am
Thanks, Alan. Just as an FYI, got it again this morning when I came to the home page to login. This is the only site I'm getting it from and my virus protection seems to be blocking it every time.

Again, thank you for this and all the other things you do around here!!!

Alan
7-23-23, 2:22pm
Got a response back from my support ticket affirming that there are no virus or malware problems with our site. After doing a little more research on the yui.yahooapis.com site I was surprised to find that it is no longer in service and hasn't been since 2017. This led me to research how our vBulletin software deals with the API call to Yahoo and I found that vBulletin inserted local API to their product in one of their security updates years ago which made their embedded call to Yahoo obsolete, although the call seems to still be referenced somewhere in the thousands of files which make up our version of the software.

If I were more confident in my ability to find and remove that call without breaking something, I'd do it, and maybe after more research I will. In the meantime I'm afraid you'll have to put up with that annoying message. I'm also curious why it's only just now showing up after all this time? I suppose getting to the bottom of things like this is what keeps our hobbies interesting.

iris lilies
7-23-23, 2:35pm
Got a response back from my support ticket affirming that there are no virus or malware problems with our site. After doing a little more research on the yui.yahooapis.com site I was surprised to find that it is no longer in service and hasn't been since 2017. This led me to research how our vBulletin software deals with the API call to Yahoo and I found that vBulletin inserted local API to their product in one of their security updates years ago which made their embedded call to Yahoo obsolete, although the call seems to still be referenced somewhere in the thousands of files which make up our version of the software.

If I were more confident in my ability to find and remove that call without breaking something, I'd do it, and maybe after more research I will. In the meantime I'm afraid you'll have to put up with that annoying message. I'm also curious why it's only just now showing up after all this time? I suppose getting to the bottom of things like this is what keeps our hobbies interesting.
I’m glad you consider this potentially interesting. A challenge that is for you so good for you.

happystuff
7-23-23, 5:58pm
Got a response back from my support ticket affirming that there are no virus or malware problems with our site. After doing a little more research on the yui.yahooapis.com site I was surprised to find that it is no longer in service and hasn't been since 2017. This led me to research how our vBulletin software deals with the API call to Yahoo and I found that vBulletin inserted local API to their product in one of their security updates years ago which made their embedded call to Yahoo obsolete, although the call seems to still be referenced somewhere in the thousands of files which make up our version of the software.

If I were more confident in my ability to find and remove that call without breaking something, I'd do it, and maybe after more research I will. In the meantime I'm afraid you'll have to put up with that annoying message. I'm also curious why it's only just now showing up after all this time? I suppose getting to the bottom of things like this is what keeps our hobbies interesting.

Thanks for the information. I did do a deep virus scan of my computer and everything came out clean. Interesting why now and also if I am actually the only one getting it. I may try a different browser next time I visit the site.

Thanks again!

jp1
7-23-23, 6:42pm
I come here typically from either my iPhone or my windows 10 computer. Neither has been giving me any warnings.