<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Forum on Omid Farhang</title><link>https://omid.dev/tags/forum/</link><description>Recent content in Forum on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Wed, 25 Apr 2012 20:20:00 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/forum/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>Online forums hacked and misused on a large scale</title><link>https://omid.dev/2012/04/25/online-forums-hacked-and-misused-on-a-large-scale/</link><pubDate>Wed, 25 Apr 2012 20:20:00 +0000</pubDate><guid>https://omid.dev/2012/04/25/online-forums-hacked-and-misused-on-a-large-scale/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-ugYDuGCnbtg/T5hVdq9BaKI/AAAAAAAAFsI/PLGFWSjJaKA/s1600-h/Forum_Ad_English%25255B2%25255D.jpg" alt="Forum_Ad_English" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Online: Online forums have, for some time, apparently been the target of hackers who inject additional code. However, the attackers aren&amp;rsquo;t interested in publishing cool slogans or political messages, they&amp;rsquo;re looking for money. They steal Google traffic from the forums and exploit this traffic via ads. Their main targets appear to be forums that are based on the &lt;a href="https://www.vbulletin.com/"&gt;vBulletin software&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Unlike the “Look how cool I am” crackers, these attackers have very discreet working methods. They hide their code deeply within the system and ensure that their redirections don&amp;rsquo;t attract much attention. Only users who visit forum pages for the first time via a search engine such as Google are redirected to a &lt;em&gt;url123.info&lt;/em&gt; URL. This site initially displays a strange blocking alert (“Access denied”) followed by some arbitrary text and then loads a full-page ad by InfinityAds. The ads are probably a direct source of income for the intruders even though each ad is only worth a few pennies. However, as some forum operators have reported that their &lt;a href="http://www.vbseo.com/f3/hacked-url123-info-53045/"&gt;traffic has dropped&lt;/a&gt; by more than 70 per cent, and the phenomenon seems to be a rather wide-spread one, the overall yield is likely to be considerable.&lt;/p&gt;</description></item><item><title>MyBB downloads were infected</title><link>https://omid.dev/2011/10/25/mybb-downloads-were-infected/</link><pubDate>Tue, 25 Oct 2011 17:33:00 +0000</pubDate><guid>https://omid.dev/2011/10/25/mybb-downloads-were-infected/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2011/10/MyBB_logo_200.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2011/10/MyBB_logo_200.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.h-online.com/"&gt;The H-Security&lt;/a&gt;&lt;/strong&gt;: In a blog posting, the MyBB &lt;a href="http://blog.mybb.com/2011/10/25/some-closure-on-the-1-6-4-security-vulnerability/"&gt;development team has confirmed&lt;/a&gt; that the download package for version 1.6.4 of MyBB had been modified to include malicious code. Unknown attackers were able to exploit a vulnerability in the MyBB web site&amp;rsquo;s CMS (content management system) to inject and execute PHP code.&lt;/p&gt;
&lt;p&gt;The attackers placed a contaminated version of MyBB, containing a backdoor, on the server. It is unclear exactly when the hack took place, meaning that all downloads of 1.6.4 prior to 6 October could be affected. Users with MyBB systems are advised to check their installations and apply a patch. For rapid disinfection, the &lt;a href="http://blog.mybb.com/2011/10/06/1-6-4-security-vulnerabilit/"&gt;developers are advising&lt;/a&gt; users to replace the /index.php file with a clean version and to delete the /install/ directory.&lt;/p&gt;</description></item></channel></rss>