TSRA site compromised

As the name indicates, this is the place for gun-related political discussions. It is not open to other political topics.

Moderators: carlson1, Charles L. Cotton

User avatar
G.A. Heath
Senior Member
Posts: 2987
Joined: Sat Mar 31, 2007 9:39 pm
Location: Western Texas

Re: TSRA site compromised

Post by G.A. Heath »

tommyg wrote:I have been hearing stories about google attempting to block out pro gun websites. This looks like one of their attempts
use another search engine for now
Google is innocent in this case, see the above discussion. The culprits here are criminals who inserted links into the TSRA website that have since been removed. With that said Google wasn't the only search engine providing the results, BING and Yahoo provided similar results. Is google gun friendly? No. Are they Anti-Gun? Maybe, Just because they have made a decision against weapons in their shopping results doesn't mean that they are. That could have been a lawyer induced decision, possibly in an effort to avoid a threatened lawsuit (We probably will never know). They haven't taken down gun related content out of their search results or youtube so I don't really think they are 100% anti-gun.
How do you explain a dog named Sauer without first telling the story of a Puppy named Sig?
R.I.P. Sig, 08/21/2019 - 11/18/2019
User avatar
Charles L. Cotton
Site Admin
Posts: 17788
Joined: Wed Dec 22, 2004 9:31 pm
Location: Friendswood, TX
Contact:

Re: TSRA site compromised

Post by Charles L. Cotton »

92f-fan wrote:Im disappointed that folks here think that Google due to the perceived anti gun stance some how fabricated all this.... :confused5

The warnings are there to protect the tech innocent .... Not to promote some political stance....
I didn't say Google did; I questioned the possibility. I did so based upon years of using Google as my preferred search engine and never once seeing that warning in many thousands of searches.

I still don't like the generic warning that something is possibly compromised. That doesn't tell me anything. If it is designed to help those who aren't tech savvy, all it does is scare them away from the site without providing any information about the level of the risk, if any.

Chas.
EconDoc
Member
Posts: 168
Joined: Wed Nov 10, 2010 5:33 pm
Location: Austin, Texas

Re: TSRA site compromised

Post by EconDoc »

It worked correctly for me. My preferred search is Dogpile.com. They are a meta-search engine that goes out to Google, Bing, Yahoo, and one or two others.

:patriot: :txflag:
Sauron lives and his orc minions are on the march. Free people own guns.
User avatar
92f-fan
Senior Member
Posts: 533
Joined: Mon Nov 02, 2009 4:08 pm
Location: Carrollton

Re: TSRA site compromised

Post by 92f-fan »

Google has a ton of detailed information on the compromises available to the webmaster. All free. TAM or anyone else who can help fix it can get details from google about what they found in the webmasters tools.

They dont show detail to search users because most search users dont care ( and cant do anything about it ) - they are blindly clicking links trying to locate stuff.
Also showing TOO much info to search users is a BIG security problem. For example if I know how to exploit a certain version of Joomla for example I can use google to find targets running that version. Or perhaps exploited sites are easier to access for OTHER bad guys. Putting a detailed target on the sites is not good either ...
aceat64
Junior Member
Posts: 26
Joined: Sat Feb 13, 2010 1:15 am

Re: TSRA site compromised

Post by aceat64 »

I work at a datacenter, we see this sort of thing all the time. What has happened is that an attacker has somehow gained access to the server or the ability to upload/modify files. Typical vectors of attack:
  • Outdated or unpatched software (CMS software, blogs, forums, etc)
  • Insecure passwords
  • Custom written PHP, ASP or CGI scripts that lake basic security precautions (most common seem to be "form mailers")
  • For shared hosting, compromises from another site being leveraged to compromise the entire server or other sites on the server
  • Someone social engineered the hosting company to grant them access to the server, somewhat rare
  • So called "0 day" exploits, these are really rare
User avatar
The Annoyed Man
Senior Member
Posts: 26884
Joined: Wed Jan 16, 2008 12:59 pm
Location: North Richland Hills, Texas
Contact:

Re: TSRA site compromised

Post by The Annoyed Man »

Well somebody fixed it, whatever was causing it:
Screen Shot 2012-07-10 at 3.59.52 PM.png
“Hard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.”

― G. Michael Hopf, "Those Who Remain"

#TINVOWOOT
User avatar
92f-fan
Senior Member
Posts: 533
Joined: Mon Nov 02, 2009 4:08 pm
Location: Carrollton

Re: TSRA site compromised

Post by 92f-fan »

The Annoyed Man wrote:Well somebody fixed it, whatever was causing it:
Screen Shot 2012-07-10 at 3.59.52 PM.png
great news :hurry:
koolaid
Senior Member
Posts: 292
Joined: Thu Jul 16, 2009 12:24 pm

Re: TSRA site compromised

Post by koolaid »

If you are running on a common CMS platform and don't have the resources available to keep things patched and secure, it is probably worth looking into moving to a managed solution where the hosting provider is responsible for these sorts of things.

Blogs and CMS software are constantly exploited by spammers and botnet creators because it is an easy way to quickly get their malware/scam site pushed up in Google's index for popular search terms and drive unsuspecting people to get their computers hijacked. This is the reason Google flags sites that get hacked, even if they aren't serving up malware themselves. The advent of the nofollow tag has pushed things from simple comment spamming into more nefarious tactics, like injecting the garbage code into the site templates.
01/02/2010 - Plastic
Post Reply

Return to “Gun and/or Self-Defense Related Political Issues”