Page 1 of 13

Site shutdown today from .RAR virus files uploaded?

Posted: Thu Jun 29, 2023 12:52 pm
by francisfinley stimpy
francisfinley stimpy wrote: Wed Jun 28, 2023 11:24 pm FYI - dont open random files like that from the internet - even if someone says its legit.
Guys it looks like malicious actors have been into the forex-station website and we have to change our passwords.

NEVER DOWNLOAD OR OPEN FILES YOU ARE UNSURE OF - I know the pursuit of money warps brains and this is no different but you have got to be careful downloading and opening stuff.
The rar file didn't look legitimate so I didn't open/run those files.

1. Please scan your pc using a FULL virus scan - AVG/AVAST/Microsoft Defender & also run Malware Bytes once over. (You do not need to pay for these - select free/trial versions).
2. If your email address and password is used for any other service online go and change that password immediately.


Good practices

a) Never download or open/run anything you are unsure of - check twice.
b) Use a different password for each service you use - use a password manager.

Site shutdown today from .RAR virus files uploaded?

Posted: Fri Jun 30, 2023 8:39 pm
by Jimmy
Okay, who's got the viruses?

Dearest Forex Station family,

This morning at 10:00am (Australian time) we noticed .RAR files which were uploaded to posts that contained garbled files and viruses. As soon as I saw this I shut down the whole board to prevent anyone from downloading further.

Today, Mrtools and I have been working together as well as consulting with with the developers (and host) to beef up our security and make sure everything is 100% solid on our site as well as remove those .RAR files with viruses. They are now fully CLEANED.

We still have to make sure that everything is working properly to restore the site.

Please bear with us over the next 24 hours, we will be running several security and software updates this weekend. The site will be available, but we may need to restart and test our backend which will cause some downtime.

We will keep you all up to date.

Every single one of our members must at least have Malwarebytes (free version) on their systems.

Guys, if you don't have any protection you need to at least have the free version of Malwarebytes on your PC. Run a "Full Scan" and be sure your files are clean before posting them up.

This has been an absolute headfuck for us. Members, you need to make sure the stuff you're uploading isn't viruses!

Jimmy.

Re: Site shutdown today from .RAR virus files uploaded?

Posted: Fri Jun 30, 2023 10:09 pm
by TransparentTrader
Jimmy wrote: Fri Jun 30, 2023 8:39 pm Dearest Forex Station family,

Thank you again for your patience during the restoration and clean-up of our site.

Today, Mrtools and I have been working together as well as consulting with with the developers (and host) to beef up our security and make sure everything is 100% solid on our site.

We still have to make sure that everything is working properly to restore the site.

Please bear with us over the next 24 hours we will be running a several security and software updates this weekend. The site will be available, but we may need to restart and test our backend which will cause some downtime.

We will keep you all up to date.

Jimmy.

Quick question: I noticed there are some posts that have gone missing as a result of what has happened with the updates.

viewtopic.php?t=8413428#p1295517218

viewtopic.php?p=1295517224#p1295517224

These are two examples of posts I had loaded before the updates. Will they be restored when all is said and done?

Re: Site shutdown today from .RAR virus files uploaded?

Posted: Fri Jun 30, 2023 10:44 pm
by Jimmy
TransparentTrader wrote: Fri Jun 30, 2023 10:09 pm Quick question: I noticed there are some posts that have gone missing as a result of what has happened with the updates.

viewtopic.php?t=8413428#p1295517218

viewtopic.php?p=1295517224#p1295517224

These are two examples of posts I had loaded before the updates. Will they be restored when all is said and done?
Thank you for posting and replying.

No. Sadly, today, we've had to restore the entire site from our secure backup server (that creates backups twice a day) to ensure everything is back to normal. So essentially, the site was restored, as-is 12 hours ago. So anything that was posted after 1:00am last night, Australian time (11:00 am Thursday, New York) will not be here :sad:

Over the weekend we still need to run tests and keep a watchful eye on our logs and everything else.

Please accept our apologies for the downtime and having to revert the site back to an earlier time - it's the only option we had and it's a huge shame, but that's why we run two backups per day to help us restore to an earlier time with the least amount of (new) posts and files lost.

Re: Security updates today and this weekend

Posted: Fri Jun 30, 2023 10:59 pm
by TransparentTrader
Jimmy wrote: Fri Jun 30, 2023 10:44 pm Thank you for posting and replying.

No. Sadly, today, we've had to restore the entire site from our secure backup server (that creates backups twice a day) to ensure everything is back to normal. So essentially, the site was restored, as-is 12 hours ago. So anything that was posted after 1:00am last night, Australian time (11:00 am Thursday, New York) will not be here :sad:

Over the weekend we still need to run tests and keep a watchful eye on our logs and everything else.

Please accept our apologies for the downtime and having to revert the site back to an earlier time - it's the only option we had and it's a huge shame, but that's why we run two backups per day to help us restore to an earlier time with the least amount of posts and files lost.

Unfortunate news but it's good nothing worse happened. Hopefully, nobody posted anything of major importance for that short period of time.

Good thing you guys have twice-daily backups. I couldn't even begin to imagine what would happen if the loss was more substantial!

No more RAR files

Posted: Sat Jul 01, 2023 1:18 am
by Jimmy
Further update

RAR files are now out of the game and have been disabled. From now on if you need to post something "archived" make it a ZIP file please and nothing else.

There are quite a few existing RAR files on our site and we understand that they may be of importance so if there's something from a specific post, or if you're a member who wants their RAR files, let us know and we will retrieve it on our end, repackage it in a ZIP file and re-upload it (or send it to you).

This has to be done for now until we are 110% certain that our site is free from bullshit.

Thanks.

Re: No more RAR files

Posted: Sat Jul 01, 2023 1:57 am
by moey_dw
Man i never understand why you guys why u wanna use RAR to upload things... just use ZIP

Re: Site shutdown today from .RAR virus files uploaded?

Posted: Sat Jul 01, 2023 2:12 am
by wojtek
Perhaps there's a possibility to automatically scan (by the hosting server)
each file when it's attached (the post is sent) and reject the infected files?

Re: Site shutdown today from .RAR virus files uploaded?

Posted: Sat Jul 01, 2023 8:11 pm
by boytoy
Is there any way rar files will be back again on forexstation?

I know rar is questionable but if its still allowed in future it would be cool to have zip + rar as rar compresses files more

Just suggesting

Re: Site shutdown today from .RAR virus files uploaded?

Posted: Sun Jul 02, 2023 12:11 am
by Chickenspicy
Anybody else never actully pay for rar subscription?
I havent paid since age 13
Its literally just zip being knocked off