Malware on a vendor website

  • Thread starter Thread starter aqua_code
  • Start date Start date
  • Tagged users Tagged users None
Status
Not open for further replies.
And this is why I don’t like using third-party dependencies in apps that I build.
Code:
brew install node
Run that once and you’ll sit for days while the entirety of the Internet is installed onto your computer.
 
Last edited:
@ScottR The problem I see here is that the vendor will be hit by lost sales for a couple of days, and then this message will be lost. The owners of r2r have been made aware, publicly, and have been quiet so far. This is only inviting scammers to a niche market that’s apparently easy to take advantage of.
I agree. There needs to be closure here. Whether that be via this thread or their business. I believe they should be given a chance to at least reply. It could be whoever built their website installed it unbeknownst to them. Should they suffer if that’s the case? No. They may not even stand to benefit from the malware. Why would a coral seller even risk it? Perhaps they have their reasons. Maybe not.
 
Reminder all, while healthy debate and discussion is more than welcome, back and fourth arguing, name calling and profanity is not. Please keep it civil.
Thank you :)
 
Reminder all, while healthy debate and discussion is more than welcome, back and fourth arguing, name calling and profanity is not. Please keep it civil.
Thank you :)
You can take the posts but I'm keeping the likes! :p
 
Reminder all, while healthy debate and discussion is more than welcome, back and fourth arguing, name calling and profanity is not. Please keep it civil.
Thank you :)

I must have missed the action? I didn’t see the back and forth, name calling or profanity? As mayor here, maybe you’d be a good one to ask? What is R2R doing to protect its members against such things?
 
I must have missed the action? I didn’t see the back and forth, name calling or profanity? As mayor here, maybe you’d be a good one to ask? What is R2R doing to protect its members against such things?
I believe the site owner requested the OP send them a PM in regards to whom the vendor is so he could reach out to them. Not positive if they did or not.
 
I believe the site owner requested the OP send them a PM in regards to whom the vendor is so he could reach out to them. Not positive if they did or not.

The OP did, not sure if the site owner did anything. On a site, where a minimum of tens of thousands of dollars are exchanged each day, I’d sure hope the site owners are looking out for their members.

1,000 people’s cards with $10,000 limits = $10,000,000. Kind of a big deal?
 
People that DO understand it, understand that it’s simple coding, embedded into their site. And that THEY put it there. Not some “Boogyman”
It is most likely is the "Boogyman" or should I say hacker that put it in there.
Websites are routinely hacked and they then modify the scripts and upload malware files. Based on the data so far this is not a new exploit but an old one, which means that nobody sat there and wrote this code. Some script kiddie most likely hacked the sites hosting password and then uploaded an exploit that he had in is toolbox. Most likely this is going to take at least a day to fix as they will have to contact the person who setup the website and have them wipe it clean and reload a copy from a backup.
 
Interested to know also as this past weekend, my malware was constantly flagging certain vendor
 
@35ppt is just liking everyone’s comments as he’s happy whatever he wrote wasn’t read. Go ahead and pm your deleted comments buddy :)
 
@35ppt is just liking everyone’s comments as he’s happy whatever he wrote wasn’t read. Go ahead and pm your deleted comments buddy :)
Hey I don't know why you want to have a problem with me man. It's just a fish forum bud. If you would like to have a discussion please explain why I'm wrong. Others have backed up what I said. ;Yawn
 
Is there something to look for to see if we may have been affected by this malware?
 
There's a protocol that should be followed here and disclosing information to people that aren't qualified to understand it - and certainly aren't qualified to do anything about it - typically does more harm than good. If you are not in a position to provide productive help & assistance there is simply no reason for you to know anything. You may think there is because you view yourself as some sort of victim - but you're wrong.

"AHHHH - a website is trying to steal my information BLAH BLAH BLAH" - guess what. If a nefarious group wants your credit card information and any other data ever put online about you - they already have it. You are more at risk when you think that store clerk is doing you a favor by asking to see your ID when you hand them your credit card.

And what happens if you are "hacked"? Your credit card company takes the loss (or the vendor) - I'm not interested in discussing the impacts of that at this time but bottom line is - you , the consumer, are the most protected entity in any online purchasing activity.

If the vendor's response is that they are not aware of it - it's going to take some time to track down how it got there, what it's been doing, how long, to whom, for what purpose etc etc.

None of that happens in minutes, hours or days.

Most people throwing a fit at this stage of something like this are not going to alter their perception, change their mind or act any differently to the vendor just because some information is disclosed - which makes all the negative comments and demands to know what happened essentially a waste of typing.

Now - if the vendor and their IT / Website folks are refusing to follow the protocol from their side - THAT is when all information should be made public.

Quit poking at the situation - it's been reported, the proper people know about it - now let them do what they need to do and wait patiently for information.

Does anyone really think that the vendor and R2R teams want this to stick around any longer than necessary?
 
There's a protocol that should be followed here and disclosing information to people that aren't qualified to understand it - and certainly aren't qualified to do anything about it - typically does more harm than good. If you are not in a position to provide productive help & assistance there is simply no reason for you to know anything. You may think there is because you view yourself as some sort of victim - but you're wrong.

"AHHHH - a website is trying to steal my information BLAH BLAH BLAH" - guess what. If a nefarious group wants your credit card information and any other data ever put online about you - they already have it. You are more at risk when you think that store clerk is doing you a favor by asking to see your ID when you hand them your credit card.

And what happens if you are "hacked"? Your credit card company takes the loss (or the vendor) - I'm not interested in discussing the impacts of that at this time but bottom line is - you , the consumer, are the most protected entity in any online purchasing activity.

If the vendor's response is that they are not aware of it - it's going to take some time to track down how it got there, what it's been doing, how long, to whom, for what purpose etc etc.

None of that happens in minutes, hours or days.

Most people throwing a fit at this stage of something like this are not going to alter their perception, change their mind or act any differently to the vendor just because some information is disclosed - which makes all the negative comments and demands to know what happened essentially a waste of typing.

Now - if the vendor and their IT / Website folks are refusing to follow the protocol from their side - THAT is when all information should be made public.

Quit poking at the situation - it's been reported, the proper people know about it - now let them do what they need to do and wait patiently for information.

Does anyone really think that the vendor and R2R teams want this to stick around any longer than necessary?
What happens if we normalize this behavior and brush it off as nothing? It’s like leaving your door unlocked.
 
There's a protocol that should be followed here and disclosing information to people that aren't qualified to understand it - and certainly aren't qualified to do anything about it - typically does more harm than good. If you are not in a position to provide productive help & assistance there is simply no reason for you to know anything. You may think there is because you view yourself as some sort of victim - but you're wrong.

"AHHHH - a website is trying to steal my information BLAH BLAH BLAH" - guess what. If a nefarious group wants your credit card information and any other data ever put online about you - they already have it. You are more at risk when you think that store clerk is doing you a favor by asking to see your ID when you hand them your credit card.

And what happens if you are "hacked"? Your credit card company takes the loss (or the vendor) - I'm not interested in discussing the impacts of that at this time but bottom line is - you , the consumer, are the most protected entity in any online purchasing activity.

If the vendor's response is that they are not aware of it - it's going to take some time to track down how it got there, what it's been doing, how long, to whom, for what purpose etc etc.

None of that happens in minutes, hours or days.

Most people throwing a fit at this stage of something like this are not going to alter their perception, change their mind or act any differently to the vendor just because some information is disclosed - which makes all the negative comments and demands to know what happened essentially a waste of typing.

Now - if the vendor and their IT / Website folks are refusing to follow the protocol from their side - THAT is when all information should be made public.

Quit poking at the situation - it's been reported, the proper people know about it - now let them do what they need to do and wait patiently for information.

Does anyone really think that the vendor and R2R teams want this to stick around any longer than necessary?

I respectfully disagree with your entire post. Quit poking the situation? Really?
Just leave this to the guys that can do something ?
 
Figures I visited this site a couple of times this month, ugg.
 
What happens if we normalize this behavior and brush it off as nothing? It’s like leaving your door unlocked.
There is zero evidence of that happening here - so it's useless to discuss in this thread.

And no - its nothign like leaving your door unlocked. Does malware on a website enable your neighbor to walk in your house and attempt to physically harm you? Nope.
 
Well, besides anti-virus and pop up blockers. Here is another piece of advice for online purchases.

Step 1: Get a pre-paid credit card like Visa or Bluebird.

Step 2: Add money to it for buying things on the web. Preferably through a service like PayPal.

Step 3: Laugh it off as someone uses it for more than the change left on card. For me, every time my card was jacked, App game and Euros. Some kind of trend?

Step 4: Call your card support and get a new card mailed.

I am on my 3rd Bluebird card in about 5 years of use.
 
Status
Not open for further replies.

TOP 10 Trending Threads

ARE YOU READY TO CONFESS TO CRAZIEST, DUMBEST, FUNNIEST THING YOU’VE EVER DONE IN REEFING?

  • Yeah, I'll confess! (Share your story in the comments!)

    Votes: 62 55.4%
  • Nah, I'll keep mine a secret...(Don't be like that, share with the class!)

    Votes: 50 44.6%
Back
Top
Home
Post thread…
Market
What's new