Joan, I am not sure how we tell but I will share this bit from one of my people. I am terribly alarmed because I was on Ancestry last night and a fake looking Adobe update window came up. I think we need to know the extent of this hacking and need to know as soon as the information is available. Quote: earlier tonight, I was checking my county links, and my virus scan picked up a malware on the usgenweb site when I entered it, and when I entered one of neighboring websites when I checked that link. It appears to be a fake "Upload Adobe Flashplayer Now" scam, that appears as a pop up. I am advising folks (as I've always done) to never click on these items or similiar items when browsing the net. My virus scanner indicated that it was a Trojan program and very malicious. Karen -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Joan Asche Sent: Friday, October 16, 2009 6:10 AM To: [email protected] Subject: Re: [STATE-COORD] Hacker Attack (Again) How can we tell if our sites are infected. Will it set off antivirus programs? J. Asche On Thu, Oct 15, 2009 at 7:30 PM, Sherri <[email protected]> wrote: > ********************* Please forward to all Project Lists > ********************************** > > The National USGenWeb Project site and all sites hosted on theusgenweb.org > domain, as well as a few other Project sites have been hit again by a > hacker that has included some malware code at the end of the majority of the > pages on each site. We are working with the hosting service right now to > get the sites cleaned and the code removed. Please ask ALL Project > Coordinators that have their sites hosted on theusgenweb.org or anyone that > specifically gets notices that they're sites are infected to not connect by > ftp to the sites until at least the 16th as we work to try to ensure that we > have the sites cleaned once again. > > For folks that have only visited the USGenWeb National site or any of the > other affected sites using their browser, the risk is very minor that your > computer has been infected. If you've connected by ftp and downloaded files > from any of the infected sites, I'd suggest running a full virus scan on > your computer and I'd also recommend running at least a couple of spyware > scans to add an additional level of confidence that your system is clean. > > All sites that are hosted on theusgenweb.org server will have the passwords > changed before you can log in again. I'll be starting on this immediately > so that the downtime will be minimized as much as possible. > > If anyone has any specific questions or problems, please let me know. > > Sherri Bradley > National Coordinator > USGenWeb Project > Information about the USGenWeb Project at http://usgenweb.org > Advisory Board Agenda http://usgenweb.org/agenda2.php > > > > > > ------------------------------- > To unsubscribe from the list, please send an email to [email protected] with the word 'unsubscribe' without the quotes in the subject and the body of the message > ------------------------------- To unsubscribe from the list, please send an email to [email protected] with the word 'unsubscribe' without the quotes in the subject and the body of the message
According to a tech from IX, this attack is "internet-wide" - meaning it has affected many hosting services. It may be connected to this: http://www.kval.com/news/tech/63768427.html I find it interesting that although I use both gmail and earthlink, I was not notified of this. The "Update Adobe" is what I am hearing is the indicator that the page has been hacked. So, it does sound like Ancestry/RootsWeb has also been compromised. I know ARGenWeb is on a totally different server from USGenWeb and we were also hacked. Betsy At 06:47 AM 10/16/2009, you wrote: >Joan, I am not sure how we tell but I will share this bit from one of my >people. I am terribly alarmed because I was on Ancestry last night and a >fake looking Adobe update window came up. I think we need to know the >extent of this hacking and need to know as soon as the information is >available. > >Quote: >earlier tonight, I was checking my county links, and my virus scan picked up >a malware on the usgenweb site when I entered it, and when I entered one of >neighboring websites when I checked that link. It appears to be a fake >"Upload Adobe Flashplayer Now" scam, that appears as a pop up. I am advising >folks (as I've always done) to never click on these items or similiar items >when browsing the net. My virus scanner indicated that it was a Trojan >program and very malicious. > >Karen > >-----Original Message----- >From: [email protected] >[mailto:[email protected]] On Behalf Of Joan Asche >Sent: Friday, October 16, 2009 6:10 AM >To: [email protected] >Subject: Re: [STATE-COORD] Hacker Attack (Again) > >How can we tell if our sites are infected. Will it set off antivirus >programs? > >J. Asche > >On Thu, Oct 15, 2009 at 7:30 PM, Sherri <[email protected]> wrote: > > ********************* Please forward to all Project Lists > > ********************************** > > > > The National USGenWeb Project site and all sites hosted on theusgenweb.org > > domain, as well as a few other Project sites have been hit again by a > > hacker that has included some malware code at the end of the majority of >the > > pages on each site. We are working with the hosting service right now to > > get the sites cleaned and the code removed. Please ask ALL Project > > Coordinators that have their sites hosted on theusgenweb.org or anyone >that > > specifically gets notices that they're sites are infected to not connect >by > > ftp to the sites until at least the 16th as we work to try to ensure that >we > > have the sites cleaned once again. > > > > For folks that have only visited the USGenWeb National site or any of the > > other affected sites using their browser, the risk is very minor that your > > computer has been infected. If you've connected by ftp and downloaded >files > > from any of the infected sites, I'd suggest running a full virus scan on > > your computer and I'd also recommend running at least a couple of spyware > > scans to add an additional level of confidence that your system is clean. > > > > All sites that are hosted on theusgenweb.org server will have the >passwords > > changed before you can log in again. I'll be starting on this immediately > > so that the downtime will be minimized as much as possible. > > > > If anyone has any specific questions or problems, please let me know. > > > > Sherri Bradley > > National Coordinator > > USGenWeb Project > > Information about the USGenWeb Project at http://usgenweb.org > > Advisory Board Agenda http://usgenweb.org/agenda2.php > > > > > > > > > > > > ------------------------------- > > To unsubscribe from the list, please send an email to >[email protected] with the word 'unsubscribe' without the >quotes in the subject and the body of the message > > > > >------------------------------- >To unsubscribe from the list, please send an email to >[email protected] with the word 'unsubscribe' without the >quotes in the subject and the body of the message > > > >------------------------------- >To unsubscribe from the list, please send an email to >[email protected] with the word 'unsubscribe' without >the quotes in the subject and the body of the message