Front Office Football Central  

Go Back   Front Office Football Central > Archives > FOFC Archive
Register FAQ Members List Calendar Mark Forums Read Statistics

Reply
 
Thread Tools
Old 07-13-2009, 08:02 PM   #1
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Inquiry for all you crazy cool web designer folk

On one of the websites I designed and maintain, I am suddenly getting the following message from AVG when I go to it:

"Exploit MDAC ActiveX code execution (type 170)"

It looks like a fairly common error from what I tell from Google, but it's all people who have come across it, not people like me who need to fix it. Odd thing is, when I checked at work on three browsers, I didn't get it. Only a handful of people have seen it (and I was actually surprised to see it here) I last went to the site probably a month ago and never got it - and I know I don't have anything ActiveX-related on the site. Any suggestions?
__________________
Commissioner of the RNFL

PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:15 PM   #2
SirFozzie
Hall Of Famer
 
Join Date: Nov 2000
Location: The State of Insanity
Do you have outside ads on your site? One of your ad providers may be cracked...
__________________
Check out Foz's New Video Game Site, An 8-bit Mind in an 8GB world! http://an8bitmind.com
SirFozzie is offline   Reply With Quote
Old 07-13-2009, 08:17 PM   #3
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Nope, no ads at all.

I do use AJAX as well, which I can't recall if that uses ActiveX at all (but the site has been running fine for two years without a sign of this warning)
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:18 PM   #4
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
And in case you want to check it out for yourself...

hxxp://www.leasterpool.com

Not sure what looking at the site will get you, but its worth a shot.
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:22 PM   #5
Ronnie Dobbs2
Pro Rookie
 
Join Date: Jun 2012
Location: Bahston Mass
There's all this goofy hmtl at the bottom of that page.

Code:
removed for potential malware

PF, PM me if you want the code
__________________
There's no I in Teamocil, at least not where you'd think

Last edited by Ronnie Dobbs2 : 07-13-2009 at 08:30 PM.
Ronnie Dobbs2 is offline   Reply With Quote
Old 07-13-2009, 08:24 PM   #6
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
...really? What the hell...
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:25 PM   #7
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
I probably can't see it because I get the alert and the page doesn't finish loading. I assume you don't get the alert?
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:26 PM   #8
Ronnie Dobbs2
Pro Rookie
 
Join Date: Jun 2012
Location: Bahston Mass
No alert, maybe because I'm running NoScript?
__________________
There's no I in Teamocil, at least not where you'd think
Ronnie Dobbs2 is offline   Reply With Quote
Old 07-13-2009, 08:27 PM   #9
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Probably. I am going to scan those pages client-side and see if I see anything. I don't see anything in my source code that I have.
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:29 PM   #10
Ronnie Dobbs2
Pro Rookie
 
Join Date: Jun 2012
Location: Bahston Mass
I should elaborate - I don't see that code when the page loads, but when I look at the source code. It's actually about halfway down.
__________________
There's no I in Teamocil, at least not where you'd think
Ronnie Dobbs2 is offline   Reply With Quote
Old 07-13-2009, 08:30 PM   #11
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Right, I got it. Thanks
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:32 PM   #12
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Of course, nothing when I scan the folder and nothing when I check out that page.
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:40 PM   #13
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Ha, as soon as I tried to open that file, Ronnie - I got the alert and I didn't see the piece that you pointed out earlier. Huh...I am really perplexed now.
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:45 PM   #14
Ronnie Dobbs2
Pro Rookie
 
Join Date: Jun 2012
Location: Bahston Mass
Try to open it in a text editor rather than a browser.
__________________
There's no I in Teamocil, at least not where you'd think
Ronnie Dobbs2 is offline   Reply With Quote
Old 07-13-2009, 08:55 PM   #15
Ronnie Dobbs2
Pro Rookie
 
Join Date: Jun 2012
Location: Bahston Mass
Isolating it a bit further... those ads do appear on your "Message Board" tab, along with what NoScript sees as a PHP script that says

< IFRAME >httpd-php@http://www2.guestbooks4free.com/guestbook.php?username=leasterpool&ts=14439.077882407406

with the spaces removed.

This seems to describe the problem as I'm seeing it, down to the obfuscated JavaScript. I tried to decode it but no luck.

http://www.guardian.co.uk/technology...ecurity.google
__________________
There's no I in Teamocil, at least not where you'd think

Last edited by Ronnie Dobbs2 : 07-13-2009 at 08:58 PM.
Ronnie Dobbs2 is offline   Reply With Quote
Old 07-13-2009, 08:57 PM   #16
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
Ah yes...I did forget about that damn guestbook. I bet you any money it is that piece of crap. I know there are ads on that thing. Let's do a test...
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 08:59 PM   #17
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
You da man, Robbie. Glad you found that piece. The code you posted before was actually the ads on that page. Must have been something wonky with it. Took out that tab, and bam - works fine.

No worries all, thanks a lot to everyone that pitched in
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Old 07-13-2009, 09:08 PM   #18
RainMaker
General Manager
 
Join Date: Jun 2006
Location: Chicago, IL
You may also want to throw some of the javascript into external files js files.
RainMaker is offline   Reply With Quote
Old 07-14-2009, 07:44 AM   #19
PackerFanatic
Pro Starter
 
Join Date: Jul 2005
Location: Appleton, WI
That might help actually narrow it down easier next time. But I think getting a guestbook/message board that isn't cheap would be a better route. I installed a full blown forum for them and they said it was just too much, heh. Oh well, thanks for the tip.
__________________
Commissioner of the RNFL
PackerFanatic is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 07:33 AM.



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.