My IM site is being blocked, but not any other forums.

Support for IntegraMOD 140

Moderator: Integra Moderator

My IM site is being blocked, but not any other forums.

PostAuthor: gcomfx.com » Thu Dec 14, 2006 11:59 am

"Internet access to the requested website has been denied based on your user profile and organization's Internet Usage Policy. Malicious Code/Virus"

One of my members sent me an email with the above info. Seems he can look up other forums, just not mine. Heck he can even visit some porn sites. <img>
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

Re: My IM site is being blocked, but not any other forums.

PostAuthor: Drop-Forged » Thu Dec 14, 2006 6:26 pm

Does your site use Prill???

That might trigger a tight filter.
Last edited by Drop-Forged on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
[url=http][img=left]http://www.christiansoldiers.com/Sig/sig.png[/img][/url]
[url=http]Free IntegraMod 141 Themes at webhutch.net[/url]

Drop-Forged
Integra Member
Integra Member
 
Posts: 167
Likes: 0 post
Liked in: 0 post
Joined: Sat Apr 08, 2006 7:07 pm
Cash on hand: 0.00

PostAuthor: gcomfx.com » Wed Jan 03, 2007 9:38 am

Nope... no Prill. Or if I do, it's not running.
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

Re: My IM site is being blocked, but not any other forums.

PostAuthor: Helter » Wed Jan 03, 2007 11:33 am

what is your URL?
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3

PostAuthor: gcomfx.com » Fri Jan 05, 2007 12:17 pm

100mphclub.com
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

Re: My IM site is being blocked, but not any other forums.

PostAuthor: jwernerny » Mon Jan 08, 2007 4:58 am

One of my sites (the Snow Tire FAQ Forum -- http://www.snowtire.info/forum/) recently had a similar problem. One day it was working, and the next day it was completely gone (the directory was removed from the server)! After talking to support at wb-hosting I found out that my forum install had been compromised to the point that some malicious code was installing back doors to the system. As a automatic security measure, everything in those directories was quarantined. While not the best for my forum, I think it was the right course of action.

Once I had talked to them, they cleaned most of the infected files and restored the directory. I then went through and looked for extras, and there were some in all of the writable directories.

I have a more detailed post on this I will put in the security forum when I get out of work. I tried to post it Friday night, but I couldn't. For now, http://www.cmsimple.dk/forum/viewtopic. ... 1ca5596ddf presents a good primer on what happened. [edit] Look for "Sun May 07, 2006 9:38 pm" to get to a useful post. [/edit]

I am not sure if it was a flaw in IM that allowed the placement of the original script, or if someone else on the share server got hit with a c99 shell install. (The c99 shell allows full access to the OS, including scannng for unprotected directories and automatic install of files in them.)

- John
Last edited by jwernerny on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
User avatar
jwernerny
Members
Members
 
Posts: 87
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 3:58 am
Cash on hand: 0.00
Location: Fairport, NY

PostAuthor: gcomfx.com » Mon Jan 08, 2007 6:50 am

I was hacked a while back. We nuked the whole account and started with a fresh install with current fixes (at that time) I had just upgraded the day I got hacked, bad update. <img>

Anyway, I only have one person giving me this error and he was checking the site at work. My guess is they manually blocked him from the site.
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

Re: My IM site is being blocked, but not any other forums.

PostAuthor: Helter » Mon Jan 08, 2007 8:32 am

I thought this might be the case, but it appears that you have a dns issue on your server

FAIL Open DNS servers ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it for domains it is not authoritative for (it is possible that the DNS server advertises that it does recursive lookups when it does not, but that shouldn't happen). This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address. Problem record(s) are:

Server 66.225.246.241 reports that it will do recursive lookups. [test] See this page for info on closing open DNS servers.
FAIL Mismatched glue ERROR: Your nameservers report glue that is different from what the parent servers report. This will cause DNS servers to get confused; some may go to the IP provided by the parent servers, while others may get to the ones provided by your authoritative DNS servers. Problem record(s) are:

ns2.gcomfx.com.:
Parent server (a.gtld-servers.net) says A record is 66.225.246.241, but
authoritative DNS server (66.225.246.240) says it is 205.234.132.158
ns1.gcomfx.com.:
Parent server (a.gtld-servers.net) says A record is 66.225.246.240, but
authoritative DNS server (66.225.246.240) says it is 66.225.219.6
ns1.gcomfx.com.:
Parent server (a.gtld-servers.net) says A record is 66.225.246.240, but
authoritative DNS server (66.225.246.241) says it is 66.225.219.6
ns2.gcomfx.com.:
Parent server (a.gtld-servers.net) says A record is 66.225.246.241, but
authoritative DNS server (66.225.246.241) says it is 205.234.132.158


when your site does not resolve correctly many mail servers will kick any mail originating from your site because your mail server url cannot be verified. Your host should be able to solve this easily enough. Also you need an SPF record. (a very likely reason your site may be tagged)

Your domain does not have an SPF record. This means that spammers can easily send out E-mail that looks like it came from your domain, which can make your domain look bad (if the recipient thinks you really sent it), and can cost you money (when people complain to you, rather than the spammer). You may want to add an SPF record ASAP, as 01 Oct 2004 was the target date for domains to have SPF records in place (Hotmail, for example, started checking SPF records on 01 Oct 2004).


http://www.openspf.org/
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3

PostAuthor: gcomfx.com » Mon Jan 08, 2007 9:09 am

Passed the info along to my host. Thanks!!!
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

PostAuthor: gcomfx.com » Mon Jan 08, 2007 10:04 am

Host reply:

You had some errors in your DNS zone which I have cleared up. Please refresh your browser and flush your DNS (start -> run -> `ipconfig /flushdns`) if that does not work. This change may be immediate but if it isnt, please wait between 3 and 36 hours for the DNS change to fully propagate through the internet.
Last edited by gcomfx.com on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Paul (gcomfx) - 100mphclub.com originator
[size=99px]
User avatar
gcomfx.com
Sr Integra Member
Sr Integra Member
 
Posts: 251
Likes: 0 post
Liked in: 0 post
Joined: Wed Apr 12, 2006 8:34 am
Cash on hand: 0.00

Re: My IM site is being blocked, but not any other forums.

PostAuthor: Helter » Mon Jan 08, 2007 4:41 pm

when it seems to be working correctly, you can check it here
http://www.dnsreport.com/

some of the cautions are not very realistic. Dont worry about things like both nameservers being on the same box, because unless you have a server farm, it is you only alternative
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4168
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 187.60
Location: Seattle Wa
IntegraMOD version: IM 3


Return to IntegraMOD 140

Who is online

Registered users: Bing [Bot], Google [Bot], Majestic-12 [Bot]