Page 1 of 3

MTGSalvation a haven for Malware

Posted: Wed Nov 14, 2012 2:09 pm
by ein
Recently, MTGSalvation was found to be a Malware distributor, according to several web browsers. This notably coincides with the apparent disappearance of its longtime owner, Hanes.

MTGSalvation is in a descent similar to the former humor site, MiseTings, wherein a group of hackers infected the main site during one of the long time periods where the owner, Mike Bregoli, was completely absent from maintaining the website. Under this MT timeline, it is likely MTGS has less than 6 months before Malware cripples the site and infects large swaths of computers of its userbase.

Posted: Wed Nov 14, 2012 2:39 pm
by Kaitscralt
I've heard it was a phisherman testing out his new rod and reel.

Posted: Wed Nov 14, 2012 3:20 pm
by Captain Murphy
Oh god. The was real curse all along...

Posted: Wed Nov 14, 2012 4:27 pm
by Thrillho

Posted: Wed Nov 14, 2012 5:56 pm
by admin
If you notice this site is getting the same alerts, this is just because there are some links to MTGS in the SYM thread discussing the bannings/sale over there.

Hope MTGS sorts these things out because otherwise our links to there may put us at a slight risk of being blacklisted too if they don't solve their issues in a reasonable timeframe.

Posted: Wed Nov 14, 2012 6:15 pm
by ( G_R )
So MTGS haxx'd us? :no:

Posted: Wed Nov 14, 2012 6:52 pm
by Azrael
I wonder if this was a disgruntled member or a third-party.

Posted: Wed Nov 14, 2012 6:58 pm
by ein
I wonder if this was a disgruntled member or a third-party.
Most definitely a third party. MTGS has had bad ads in the past (one even passively, in that I didn't click on it, infected a computer of mine a couple years ago). It's a consequence of poor ownership and a terrible monetization scheme (using sketchy ad companies, etc).

Posted: Wed Nov 14, 2012 7:00 pm
by ( G_R )
I think it's those ads. Hannes hasn't paid attention to that, and the reports of malware have been in CI for a while. Their former technician never had access/power to fix that, either.

EDIT: What ein said.

Posted: Wed Nov 14, 2012 7:00 pm
by FaheyUSMC
Hannes isn't "absent" from the site. Right now, he's going through some real-life transitions I am, quite literally, NOT at liberty to divulge other than what is going on for him takes far more precedence over a site dedicated to Magic: the Gathering. He has been working on the site in his very little spare time, but he is still around.

As for the malware issue, Chrome is currently blocking the site, and I won't be surprised if Firefox and IE are doing the same. Truth be told, it's not a site that would be targeted under normal circumstances by a group of hackers. This has the hallmarks of a bunch of children, and possibly people who were banned during the recent sweep.

Posted: Wed Nov 14, 2012 7:04 pm
by admin
Fahey, I can tell you that no member of this site who has been banned in MTGS is involved in any hacking activities. On the contrary, we had recently a banned member of MTGS alerting an MTGS aministrator (Galspanic) to the possibility of a hacking of the site by a third party, according to a rumor that has been divulged to one of the members in this site. Galspanic reportedly forwarded the information to Hannes.

Posted: Wed Nov 14, 2012 7:04 pm
by ein
Hannes isn't "absent" from the site. Right now, he's going through some real-life transitions I am, quite literally, NOT at liberty to divulge other than what is going on for him takes far more precedence over a site dedicated to Magic: the Gathering. He has been working on the site in his very little spare time, but he is still around.

As for the malware issue, Chrome is currently blocking the site, and I won't be surprised if Firefox and IE are doing the same. Truth be told, it's not a site that would be targeted under normal circumstances by a group of hackers. This has the hallmarks of a bunch of children, and possibly people who were banned during the recent sweep.


Whatever, dude. If hanes is not absent, why hasn't this cleared up yet? I think the data speaks for itself. This is EXACTLY the same thing that happened to MT, so....

Posted: Wed Nov 14, 2012 7:06 pm
by ( G_R )
It's the ads, I tells ya. I dare not go in there, but if you look in CI there's a thread about Malware from a while ago. No actions were taken to fix that problem and Google Crawler finally hit the site with a blacklist. Blaming it on banned members is naive at best, ill-intended at worst.

Posted: Wed Nov 14, 2012 7:08 pm
by FaheyUSMC
Hannes isn't "absent" from the site. Right now, he's going through some real-life transitions I am, quite literally, NOT at liberty to divulge other than what is going on for him takes far more precedence over a site dedicated to Magic: the Gathering. He has been working on the site in his very little spare time, but he is still around.

As for the malware issue, Chrome is currently blocking the site, and I won't be surprised if Firefox and IE are doing the same. Truth be told, it's not a site that would be targeted under normal circumstances by a group of hackers. This has the
hallmarks of a bunch of children, and possibly people who were banned during the recent sweep.
:rolleyes:

Whatever, dude. If hanes is not absent, why hasn't this cleared up yet? I think the data speaks for itself. This is EXACTLY the same thing that happened to MT, so....
So because it hasn't been cleared up immediately, it must be that he's absent!

I mean, there's no way in hell he has a social life as well. Or that he might be having dinner right now after work?

Posted: Wed Nov 14, 2012 7:10 pm
by ( G_R )
So you have a contact in Curse, and you know Hannes personally? (Real question, not trolling you)

Posted: Wed Nov 14, 2012 7:11 pm
by FaheyUSMC
So you have a contact in Curse, and you know Hannes personally? (Real question, not trolling you)
I do have a contact in Curse, yes. As for knowing Hannes, I do not. What with having this thing called "The Atlantic Ocean" between us... :P

Posted: Wed Nov 14, 2012 7:14 pm
by ( G_R )
Well I find it odd that you are defending Hannes, that's all. I mean, not even the MTGS admins have been able to contact him for pressing matters about the site, or at least I have not heard of them getting a "BRB, IRL stuff" message from him.

Posted: Wed Nov 14, 2012 7:14 pm
by ein
Hannes isn't "absent" from the site. Right now, he's going through some real-life transitions I am, quite literally, NOT at liberty to divulge other than what is going on for him takes far more precedence over a site dedicated to Magic: the Gathering. He has been working on the site in his very little spare time, but he is still around.

As for the malware issue, Chrome is currently blocking the site, and I won't be
surprised if Firefox and IE are doing the same. Truth be told, it's not a site that would be targeted under normal circumstances by a group of hackers. This has the hallmarks of a bunch of children, and possibly people who were banned during the recent sweep.
:rolleyes:

Whatever, dude. If hanes is not absent, why hasn't this cleared up yet? I think the data speaks for itself. This is EXACTLY the same thing that happened to MT, so....
So because it hasn't been cleared up immediately, it must be that he's absent!

I mean, there's no way in hell he has a social life as well. Or that he might be having dinner right now after work?
What? MTGS has had ad problems for a long time (and that have finally caught up with them). And I recall that at least one recent technician never had his powers turned on, and several Admins have had to wait a
really long time for being turned on as well. When I was on staff, there was *always* these "well, when hanes ever shows up again" comments about stuff that needed doing. These events go back a year or so, and CLEARLY suggest a pattern of absenteeism. That's one looooooong dinner.

Posted: Wed Nov 14, 2012 7:15 pm
by Yannaria
past experience leads me to believe that Hannes is just MIA again.

Posted: Wed Nov 14, 2012 7:18 pm
by FaheyUSMC
Well I find it odd that you are defending Hannes, that's all. I mean, not even the MTGS admins have been able to contact him for pressing matters about the site, or at least I have not heard of them getting a "BRB, IRL stuff" message from him.
I can only pass on what Nai told me, and even then I have to be relatively vague in what I say because I told Nai that I wouldn't divulge what he told me. Journalistic integrity, credibility, whatever.

I was actually supposed to have a sit-down and a Q&A with the admins scheduled by now. Nai and I had talked about it, and Galspanic and Megiddo were supposed to be all for it. The only one I understood that was against it was ExpiredRascals, but considering how I didn't trust him since
my appeal to my most-recent suspension, I wasn't too surprised. I was hoping to be able to help put this shit behind them, but it seems they either forgot or aren't going to do it.

Posted: Wed Nov 14, 2012 7:22 pm
by Yannaria
why the hell would you be talking to the Admins?

Posted: Wed Nov 14, 2012 7:25 pm
by FaheyUSMC
Is there a reason I shouldn't be talking to the admins?

Posted: Wed Nov 14, 2012 7:27 pm
by ( G_R )
Is there a reason I shouldn't be talking to the admins?
Be careful, they are corrupt. /JK

I believe he means to ask you what important matters you, a seemingly regular Joe member of Sally, have to discuss with them in what has now come to be known as a "summit".

Posted: Wed Nov 14, 2012 7:28 pm
by Yannaria
You seem to have implied that it is some important discussion that just has to happen, but Expired Rascals is stopping it because he's immature or something. I mean if you were like "oh man I pm'd Nai about something but he never got back to me" it wouldn't have caught me off guard because that happens, instead you were like "We were going to have a sit down Q and A but blah blah"

one sounds far more serious than the other.

Posted: Wed Nov 14, 2012 7:30 pm
by admin
Alright people, if you read something with a link to MTGS in here, you might come with this sort of warning. Rest assured, this is just an alert that there is a link to a site listed as Malware, but you can still browse safely over here.

Image

Posted: Wed Nov 14, 2012 7:32 pm
by FaheyUSMC
Nai and I had been talking off-and-on during the whole debacle that happened recently. Galspanic, Megs, and Nai are the only admins I trust, and I expressed that sentiment to Nai. I never had contact with ER until my suspension appeal in which he basically said, "Yeah, there's no concensus on it you should be suspended, but fuck you you're suspended anyways!"

The point of the Q&A had been to try to narrow down the scope of the questions being asked and give a single post (or several, if necessary) where people could have asked questions they wanted answers to, and the admins would provide the answers. It would have been neater, and if there's anything that we have seen, it's when the admins are able to answer people in a manner like that (most recently, the summit they had with Belgareth that ended up repairing a lot of the issues people had with WCT), the shit tends to die down. That had been my intent.
n
As I said, Nai had been all for it, and from what I understand Galspanic and Megs had been as well. I can only surmise that ER was against it, but as I said I never truted him to do the right thing anyways.

As an aside, it looks like a Google crawler came upon a malicious ad, and not something with direct access to the forums. So, yeah...someone needs to be on top of that.

Posted: Wed Nov 14, 2012 7:35 pm
by admin
OK, thanks for clearing this Fahey, and again, I can assure you that the allegations of malicious attacks to MTGS by banned members also members of this site are totally unfounded. Some people are just paranoid like that.

Posted: Wed Nov 14, 2012 7:37 pm
by FaheyUSMC
As I said, it has the hallmarks of script kiddies, if it had been an attempt at a coordinated attack. Not a group of super 1337 h4xx0rz

Posted: Wed Nov 14, 2012 7:42 pm
by admin
I mean, the thought that someone would buy the theory of a group of former banned members of MTGS joining in another site just to coordinate malicious attacks on websites like some bunch of 12yo script kiddies is something that baffles me beyond belief. Tough I did learn to significantly lower my expectations during these last months.

Image

Posted: Wed Nov 14, 2012 7:43 pm
by FaheyUSMC
Actually, my point had been that if anything, banned former members were a more likely culprit than Anonymous was. Not that it was the exact answer.

Posted: Wed Nov 14, 2012 7:44 pm
by admin
Well, I guess everyone is certainly entitled to have its own theories, as far fetched as these may be.

Posted: Wed Nov 14, 2012 7:47 pm
by ein
Well, I guess everyone is certainly entitled to have its own theories, as far fetched as these may be.
You strike a smile in me, your stories ring of perjury construed with self empowering theeeeeeeeeemes.

Ah, Eve6!

Posted: Wed Nov 14, 2012 7:52 pm
by Kaitscralt
*watches Fahey*

Posted: Wed Nov 14, 2012 7:55 pm
by FaheyUSMC
*watches Fahey*
Roll a Perception check.

Posted: Wed Nov 14, 2012 8:11 pm
by ( G_R )
In other news, I'm not getting the warning anymore from Salvation. Apparently Hannes showed up and shut down the advertisements.

Posted: Wed Nov 14, 2012 8:13 pm
by admin
Still blacklisted in other sources....

http://sitecheck.sucuri.net/results/for ... vation.com

Posted: Wed Nov 14, 2012 8:14 pm
by Thrillho
Hannes isn't "absent" from the site. Right now, he's going through some real-life transitions I am, quite literally, NOT at liberty to divulge other than what is going on for him takes far more precedence over a site dedicated to Magic: the Gathering.
Do you not know what "absent" means?

Posted: Wed Nov 14, 2012 8:15 pm
by Blackhound
Malicious attacks on websites

HUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU!!!!!!!!

Posted: Wed Nov 14, 2012 8:16 pm
by Thrillho
So because it hasn't been cleared up immediately, it must be that he's absent!

I mean, there's no way in hell he has a social life as well. Or that he might be having dinner right now after work?
ab·sent   [adj., prep. ab-suhnt; v. ab-sent, ab-suhnt] Show IPA
adjective
1.
not in a certain place at a given time; away, missing ( opposed to present): absent from class.

Posted: Wed Nov 14, 2012 8:28 pm
by Yannaria
hannes rolled a sneak check