OhioCCW.org Main Website - Whats going on?

This area is for discussions that do not fit into the formal firearms discussions of the website. Common sense and non-controversial contributions are expected. Certain topics are forbidden. See the forum rules for more details.

Moderators: Chuck, Mustang380gal, Coordinators, Moderators

User avatar
jgarvas
OFCC Director
OFCC Director
Posts: 3164
Joined: Sun Jun 26, 2005 10:35 pm
Location: Northern Summit County
Contact:

OhioCCW.org Main Website - Whats going on?

Post by jgarvas »

So if you live under a rock in the forums you're just now going to learn that over the past few days we've heard a lot of complaints about malicious content on the OFCC main page at http://www.OhioCCW.org" onclick="window.open(this.href);return false;. We fix it, then they put it back. They are "the bad guys". Due to this we've decided to completely upgrade the website.

For those of you who were directed here by a link on the main page, here is the status of our website maintenance.

The main page is technically functional, but if you do anything that submits content to us other than the ContactUS page your submission will go into never-never land. So don't submit a DNPWA (CPZ) entry, don't suggest an attorney, or anything along those lines. It'll go nowhere meaningful.

Later tonight (I need a break) we're going to be focusing on changing the look and feel of that website and then moving the new version into production. It is very likely that many features won't be immediately available, such as the DNPWA list, the attorney directory, etc. We will bring them back, we just need to focus on returning to a live state, looking presentable, and then restoring features.

As of right now I do not believe there is any malware or virus linking javascript on the main page. By the time i hit submit that may change, so if you're not browsing with tools that look for that kind of thing don't go to OhioCCW.org and go get some spyware/malware software. If you do see something there, rest assured we're just going to delete that site anyway in a few hours so don't worry :)

When we get back at this and make some progress (aka, when my daughter goes to bed) I'll post some more updates here.

Updates below as new replies from me...
Jeff Garvas, President
Ohioans For Concealed Carry

Contrary to a popular belief when I brag about OFCC accomplishments I'm not looking for your thank you or personal recognition. I'd much prefer you send me an email telling me when you are going to get involved in doing what I've been doing since 1999. We are only as effective as we make ourselves. We need the next generation of OFCC to step to the plate.

Is that you?

To Contact Me: Use This Form and pick my name.
Brian D.
Posts: 16243
Joined: Mon Jul 04, 2005 8:42 pm
Location: SW Ohio

Re: OhioCCW.org Main Website - Whats going on?

Post by Brian D. »

Good luck. Dang, sounds like this will delay the posting of videos/pictures from the Picnic in the Park, at least over there on the main site. Maybe folks who took vid/pix could post them here on the forums instead, at least for the time being?
Quit worrying, hide your gun well, shut up, and CARRY that handgun!

********************************************************************************
1911 and Browning Hi Power Enthusianado.
Leone
Posts: 445
Joined: Wed Mar 18, 2009 11:37 am
Location: Cuyahoga County

Re: OhioCCW.org Main Website - Whats going on?

Post by Leone »

Jeff, just don't push the wrong button again. :P Your heart can't take that again this soon :wink:
Jake
OFCC Coordinator
OFCC Coordinator
Posts: 11325
Joined: Fri Apr 14, 2006 11:04 am
Location: N.E. Ohio
Contact:

Re: OhioCCW.org Main Website - Whats going on?

Post by Jake »

Tagged....
NRA Certified Instructor: Pistol
NRA Certified Range Safety Officer

Hope for the Best. Plan for the Worst.


http://www.salemhuntingclub.com" onclick="window.open(this.href);return false;
http://www.nraila.org/get-involved-loca ... -reps.aspx" onclick="window.open(this.href);return false;
pleasantguywhopacks
OFCC Patron Member
OFCC Patron Member
Posts: 16747
Joined: Mon May 28, 2007 2:20 pm
Location: Whitehouse, OH

Re: OhioCCW.org Main Website - Whats going on?

Post by pleasantguywhopacks »

I wonder if this someone against our cause or just another 13 yr old hacker doing this as a lark.
http://www.youtube.com/watch?v=qOxXpNBdrVE" onclick="window.open(this.href);return false;
When seconds count, the police are only minutes away!
Life Member NRA
dfrea
Posts: 330
Joined: Sat Jun 28, 2008 6:34 pm
Location: Grove City, OH

Re: OhioCCW.org Main Website - Whats going on?

Post by dfrea »

I think it is just the miricle of the internet rearing its ugly head. Seriously, Murphy strikes in I/T also.

The 13 year olds are too ambitious for this, they're trying to take down sites like YouTube. Can't see them finding their way here.
User avatar
Morne
OFCC Coordinator
OFCC Coordinator
Posts: 10631
Joined: Thu Jul 07, 2005 9:01 pm
Location: Wayne County

Re: OhioCCW.org Main Website - Whats going on?

Post by Morne »

pleasantguywhopacks wrote:I wonder if this someone against our cause or just another 13 yr old hacker doing this as a lark.
I thought I heard that this was connected to some recent bans that have been handed out. I would LOVE to know which troll is doing it!
Thus spoke Zarathustra.

Footsoldier in the Conservative Insurrection of the GOP.

Remember, only you can prevent big government!
dfrea
Posts: 330
Joined: Sat Jun 28, 2008 6:34 pm
Location: Grove City, OH

Re: OhioCCW.org Main Website - Whats going on?

Post by dfrea »

Morne wrote:
pleasantguywhopacks wrote:I wonder if this someone against our cause or just another 13 yr old hacker doing this as a lark.
I thought I heard that this was connected to some recent bans that have been handed out. I would LOVE to know which troll is doing it!
I suppose I can see that scenario too...
User avatar
Sigma40
Posts: 1593
Joined: Sun Aug 03, 2008 2:47 pm
Location: Austin, Texas

Re: OhioCCW.org Main Website - Whats going on?

Post by Sigma40 »

I wonder if it's that guy that's always promoting his "Point-shoot" methods and articles?
"If ye love wealth better than liberty, the tranquility of servitude better than the animating contest of freedom, go home from us in peace. We ask not your counsels or your arms. Crouch down and lick the hands which feed you. May your chains set lightly upon you, and may posterity forget that you were our countrymen."
-Samuel Adams
User avatar
DEFCON1
Posts: 878
Joined: Mon Nov 24, 2008 7:25 pm
Location: Vandalia, ohio

Re: OhioCCW.org Main Website - Whats going on?

Post by DEFCON1 »

opencarry.org is under attack as well. This must be the antis.

So how much of the board do we stand to lose? All of our sage advise and pertinent discussion down the drain? Are we going to have to start from scratch?
Member in exile, out searching for Scavok.
User avatar
jgarvas
OFCC Director
OFCC Director
Posts: 3164
Joined: Sun Jun 26, 2005 10:35 pm
Location: Northern Summit County
Contact:

Re: OhioCCW.org Main Website - Whats going on?

Post by jgarvas »

Update

Ok, its not going to happen tonight, I'm about to fall asleep on my keyboard ;-)

To answer some of the questions above, it could be anyone. Once a known exploit is found you seek it out and take advantage of it, then someone on our side finds it and shuts it down. There should be absolutely no lost data. We have not lost any story content, we have not lost anything in the database (DNPWA / CPZs, Attorney Directory, etc). Backups are fairly reliable in this respect, but we didn't even need to look at backups. I just managed to prove that by converting the DNPWA database over and upgrading that software. The attorney directory should be a no-brainer as its the same software.

What we're struggling with at the moment is mostly cosmetic in nature. We're trying to find a presentable layout, color scheme and menu structure that we like. Keep in mind that the website is still there and available, its just that if you submit anything it won't stay there after we flip the switch. So that everyone knows where we are, I've pointed them to this thread for status updates. More tomorrow some time in the late afternoon / evening.

please do not post chit chat in this thread.
Jeff Garvas, President
Ohioans For Concealed Carry

Contrary to a popular belief when I brag about OFCC accomplishments I'm not looking for your thank you or personal recognition. I'd much prefer you send me an email telling me when you are going to get involved in doing what I've been doing since 1999. We are only as effective as we make ourselves. We need the next generation of OFCC to step to the plate.

Is that you?

To Contact Me: Use This Form and pick my name.
User avatar
djthomas
Posts: 5961
Joined: Sun Jan 22, 2006 11:09 am

Re: OhioCCW.org Main Website - Whats going on?

Post by djthomas »

I know Jeff doesn't want chit chat on this thread but I figure he's probably not able take the time to answer all the questions. I'm going to throw my two cents out there as someone who deals with cyber crime issues and website vandalism fairly frequently. I'm in no way speaking on behalf of Jeff or OFCC; I simply want to provide a bit of insight before the conspiracy theories really take off.

I seriously doubt this is the doing of people who oppose our cause. These attacks happen every day on the Internet. Most of them are completely automated and done through kits that search for popular sites built using software packages with vulnerabilities. There is very little human interaction other than to start the attack and track the progress. Back in the old days (i.e. pre 2008) these were mostly being done by "script kiddies" who lacked both serious criminal intent and technical ability. The kits today are sold (a big change) to exactly the opposite people - the criminally (read: financially) inclined with a fair amount of technical expertise. The objective is to throw malicious software up or use the server to do things like host phishing pages. The services of the system and any personal computers subsequently infected can then be resold on the black market to other cyber criminals looking to make a dishonest buck.

As Jeff said, it could be anyone, but there has been a lot of malicious software coming from the eastern European regions like Lithuania, Russia, Croatia, etc. Trust me, these people don't give half a rat's rear about what OFCC stands for. All they care is that the website is popular. They'd just as easily roll OCAGV's site, except it probably doesn't draw enough traffic to bubble up on their tool's radar.

It's quite fascinating to look at a diagram of how a typical online criminal operation runs. It truly is an underground economy with many products and services being offered by people who don't know each other and simply want to make money. Hacked websites are just one small piece in the overall picture.
User avatar
jgarvas
OFCC Director
OFCC Director
Posts: 3164
Joined: Sun Jun 26, 2005 10:35 pm
Location: Northern Summit County
Contact:

Re: OhioCCW.org Main Website - Whats going on?

Post by jgarvas »

djthomas wrote: I seriously doubt this is the doing of people who oppose our cause.
I fully concur with this assessment ;-) The attacks are about as controllable as spam, and in many cases they really are spam. I've noticed a huge trend as djthomas pointed out. Back in the early 2000 time frame "script kids" looked for exploitable code on your website to deface it. These forums were once defaced by a turkey based hacking group just to make a political statement most people couldn't read. A few months ago someone found a "hole" in the OhioCCW.org website that let you inject content into the website. Instead of using that opportunity to delete our site and try to hurt us they quietly injected content that redirected visitors to websites that paid them for hits. Nobody noticed it because all they wanted was to get those hidden links indexed in google along side our higher search ranking. Nobody here likely ever hit those links. Google eventually figured it out and emailed us to advise us that they were yanking all of our indexing until we fixed it.

The difference is in the past it was about destruction, and today its about profit, at the expense of injecting stuff into your website without destruction so you don't' react to fix it.

If you look at how we require people to sit there and think about which pictures are cats and which are not (when registering for these forums) you can see how tricky we need to get in order to fight automation. It doesn't take but a few weeks for spammers to "figure out" how to automate a script/robot to circumvent those "CAPTCHA" programs that ask you to read funny letters and type them in. What we use here is genius in design since it draws the images randomly on the fly so that nothing gives away a file name. Newer versions actually change the photo makeup too. Getting into our forums is almost too hard for real people. If we shut that off we'd have hundreds of fake accounts within a few hours.

so the update, a bit late:

- The new website looks horrible. (just kidding)
- It's not going to go public anytime soon, but I'd like to aim for Friday or Saturday nights. Sunday at the latest, even if we need to turn it on with substantially incomplete clean-up.

When you change the dimensions and layout of a website it tends to break things you designed around in the past. For example, the DNPWA and CPZ areas work fine, but there is a bunch of random "code" being presented instead of text. Functional, but cosmetically not what we want to present yet. I hope that the effort were putting into this will give us more opportunities to make the main website a much more useful resource.

If you have ideas about how we can make the main website better for both those of you who know what is going on and the 'prospective new guy" trying to learn the issues and the intricacies of Ohio's laws, go ahead and drop me a PM. I'll read them when I make updates to this thread, and as we move forward we'll see what we can do.
Jeff Garvas, President
Ohioans For Concealed Carry

Contrary to a popular belief when I brag about OFCC accomplishments I'm not looking for your thank you or personal recognition. I'd much prefer you send me an email telling me when you are going to get involved in doing what I've been doing since 1999. We are only as effective as we make ourselves. We need the next generation of OFCC to step to the plate.

Is that you?

To Contact Me: Use This Form and pick my name.
pleasantguywhopacks
OFCC Patron Member
OFCC Patron Member
Posts: 16747
Joined: Mon May 28, 2007 2:20 pm
Location: Whitehouse, OH

Re: OhioCCW.org Main Website - Whats going on?

Post by pleasantguywhopacks »

I hope this isn't considered chit chat .

I decided to hit the main web page today and holy freaking !%@%@.
I got nailed by a vicious down loader that installed a Security Center phishing thing. I couldn't get past bootup without it flooding and locking up my puter. It took all day and two fists full of hair to get back up.

SO it isn't safe to go to the main web page no matter what anyone says! I will not be frequenting it again until this is resolved. I suggest no one else do so either.
http://www.youtube.com/watch?v=qOxXpNBdrVE" onclick="window.open(this.href);return false;
When seconds count, the police are only minutes away!
Life Member NRA
User avatar
Rapidfire
Posts: 153
Joined: Sat Aug 13, 2005 8:28 pm
Location: Paulding County- North west side of the State

Re: OhioCCW.org Main Website - Whats going on?

Post by Rapidfire »

Avast catches the bugs for me. Never had anything get by it yet. (knock on wood) :lol:
Knowledge is knowing a tomato is a fruit.
Wisdom is not putting it in a fruit salad.
Post Reply