TSRA site compromised

As the name indicates, this is the place for gun-related political discussions. It is not open to other political topics.

Moderators: carlson1, Charles L. Cotton

User avatar

Topic author
BenGoodLuck
Member
Posts in topic: 2
Posts: 81
Joined: Mon Aug 08, 2005 6:27 pm
Location: Dallas

TSRA site compromised

#1

Post by BenGoodLuck »

Does anyone know what's going on with the Texas State Rifle Association's website? Google says it's been compromised:

Image
User avatar

The Annoyed Man
Senior Member
Posts in topic: 8
Posts: 26870
Joined: Wed Jan 16, 2008 12:59 pm
Location: North Richland Hills, Texas
Contact:

Re: TSRA site compromised

#2

Post by The Annoyed Man »

They phoned me about this the day before yesterday (I occasionally help them with their website). I referred them to their webhost. TSRA hasn't yet given me FTP access, so I can't search their hosting account for the corrupted file that does this. All of their meta tag settings are correct within the CMS, so this is either an external file or a corrupted file that is doing this.

They are having the company which handles the NRA website take over their website management soon, so maybe they'll get it clear up.

They are also several generations behind in updates to their CMS, including one that will require a complete rebuild of the site....so maybe this situation will force them to take the actions needed to get on top of things.
“Hard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.”

― G. Michael Hopf, "Those Who Remain"

#TINVOWOOT
User avatar

Charles L. Cotton
Site Admin
Posts in topic: 5
Posts: 17787
Joined: Wed Dec 22, 2004 9:31 pm
Location: Friendswood, TX
Contact:

Re: TSRA site compromised

#3

Post by Charles L. Cotton »

I don't have anything to do with the TSRA site, but here is a link to Google's warning. http://support.google.com/websearch/bin ... CHwQpwgwAA" onclick="window.open(this.href);return false;

I've never seen such a warning before. It's interesting that Google makes such a claim without giving the facts to justify scaring people away from a site. I wonder if it has anything to do with it being a gun-related site?

Chas.
User avatar

Charles L. Cotton
Site Admin
Posts in topic: 5
Posts: 17787
Joined: Wed Dec 22, 2004 9:31 pm
Location: Friendswood, TX
Contact:

Re: TSRA site compromised

#4

Post by Charles L. Cotton »

The Annoyed Man wrote:They are having the company which handles the NRA website take over their website management soon, so maybe they'll get it clear up.
That's not going to be cheap! We spend a lot on the NRA website.

Chas.
User avatar

Jumping Frog
Senior Member
Posts in topic: 1
Posts: 5488
Joined: Wed Aug 25, 2010 9:13 am
Location: Klein, TX (Houston NW suburb)

Re: TSRA site compromised

#5

Post by Jumping Frog »

Charles L. Cotton wrote:I don't have anything to do with the TSRA site, but here is a link to Google's warning. http://support.google.com/websearch/bin ... CHwQpwgwAA" onclick="window.open(this.href);return false;

I've never seen such a warning before. It's interesting that Google makes such a claim without giving the facts to justify scaring people away from a site. I wonder if it has anything to do with it being a gun-related site?

Chas.
Ohioans For Concealed Carry website was hit the same way.

If you linked there from google, you got the warning. If you typed the URL directly, there was no problem.

Same way with TSRA. Searching on google or bing is compromised. Enter the URL directly and it goes straight to the website.
-Just call me Bob . . . Texas Firearms Coalition, NRA Life member, TSRA Life member, and OFCC Patron member

This froggie ain't boiling! Shall not be infringed! Μολών Λαβέ
User avatar

AEA
Senior Member
Posts in topic: 1
Posts: 5110
Joined: Sat May 12, 2007 12:00 pm
Location: North Texas

Re: TSRA site compromised

#6

Post by AEA »

Ah so......it's a Google thing! :banghead:
Alan - ANYTHING I write is MY OPINION only.
Certified Curmudgeon - But, my German Shepherd loves me!
NRA-Life, USN '65-'69 & '73-'79: RM1
1911's RULE!
User avatar

The Annoyed Man
Senior Member
Posts in topic: 8
Posts: 26870
Joined: Wed Jan 16, 2008 12:59 pm
Location: North Richland Hills, Texas
Contact:

Re: TSRA site compromised

#7

Post by The Annoyed Man »

Charles L. Cotton wrote:I don't have anything to do with the TSRA site, but here is a link to Google's warning. http://support.google.com/websearch/bin ... CHwQpwgwAA" onclick="window.open(this.href);return false;

I've never seen such a warning before. It's interesting that Google makes such a claim without giving the facts to justify scaring people away from a site. I wonder if it has anything to do with it being a gun-related site?

Chas.
I referred Gail to that page yesterday and told her to follow those instructions. I suppose it is possible that google is pulling some funny business, but I suspect not. I think that the truth is the site has actually gotten something injected into it which is malicious, but without FTP access, and access to the ICD hosting account so that I can look directly at the database, I can't do much to help them.

If I were them, I'd take the whole site down and start over. They're still on Joomla 1.5.20. The latest security release in that development fork is 1.5.26, and the current development fork is already at 2.5.6. The current development fork has a totally different data structure, and is as different from 1.5.x as that one was from 1.0.x. It is also more flexible and more secure. They really need to just start over, but in the meantime, without being willing to invest some money in hiring somebody like me and giving that person the access they need, TSRA's website is dead in the water. And, they are hampered by the need to have the board approve such expenditures, so nothing gets done right away.
“Hard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.”

― G. Michael Hopf, "Those Who Remain"

#TINVOWOOT
User avatar

74novaman
Senior Member
Posts in topic: 2
Posts: 3798
Joined: Wed Feb 18, 2009 7:36 am
Location: CenTex

Re: TSRA site compromised

#8

Post by 74novaman »

The Annoyed Man wrote:
Charles L. Cotton wrote:I don't have anything to do with the TSRA site, but here is a link to Google's warning. http://support.google.com/websearch/bin ... CHwQpwgwAA" onclick="window.open(this.href);return false;

I've never seen such a warning before. It's interesting that Google makes such a claim without giving the facts to justify scaring people away from a site. I wonder if it has anything to do with it being a gun-related site?

Chas.
I suppose it is possible that google is pulling some funny business, but I suspect not. I think that the truth is the site has actually gotten something injected into it which is malicious, but without FTP access, and access to the ICD hosting account so that I can look directly at the database, I can't do much to help them.
I agree. I doubt its intentional on googles part, but it could be some lefty programmer type is attacking gun sights with malware. :???:
TANSTAAFL
User avatar

pbwalker
Senior Member
Posts in topic: 4
Posts: 3032
Joined: Thu May 01, 2008 10:12 am
Location: Northern Colorado

Re: TSRA site compromised

#9

Post by pbwalker »

The Annoyed Man wrote:They phoned me about this the day before yesterday (I occasionally help them with their website). I referred them to their webhost. TSRA hasn't yet given me FTP access, so I can't search their hosting account for the corrupted file that does this. All of their meta tag settings are correct within the CMS, so this is either an external file or a corrupted file that is doing this.

They are having the company which handles the NRA website take over their website management soon, so maybe they'll get it clear up.

They are also several generations behind in updates to their CMS, including one that will require a complete rebuild of the site....so maybe this situation will force them to take the actions needed to get on top of things.
Agreed, and I'd also put $5 on it possibly being an issue with the shared hosting provider. The IP address points back to Savvis (hosting provider), and if you attempt to access via http://64.14.78.167" onclick="window.open(this.href);return false;, it directs you to an error page for Sureserver / Suresupport (likely a reseller or v-hoster). It's likely that another site using the same IP is compromised.
*NRA Endowment Member* | Veteran
Vote Adam Kraut for the NRA Board of Directors - http://www.adamkraut.com/
User avatar

The Annoyed Man
Senior Member
Posts in topic: 8
Posts: 26870
Joined: Wed Jan 16, 2008 12:59 pm
Location: North Richland Hills, Texas
Contact:

Re: TSRA site compromised

#10

Post by The Annoyed Man »

pbwalker wrote:
The Annoyed Man wrote:They phoned me about this the day before yesterday (I occasionally help them with their website). I referred them to their webhost. TSRA hasn't yet given me FTP access, so I can't search their hosting account for the corrupted file that does this. All of their meta tag settings are correct within the CMS, so this is either an external file or a corrupted file that is doing this.

They are having the company which handles the NRA website take over their website management soon, so maybe they'll get it clear up.

They are also several generations behind in updates to their CMS, including one that will require a complete rebuild of the site....so maybe this situation will force them to take the actions needed to get on top of things.
Agreed, and I'd also put $5 on it possibly being an issue with the shared hosting provider. The IP address points back to Savvis (hosting provider), and if you attempt to access via http://64.14.78.167" onclick="window.open(this.href);return false;, it directs you to an error page for Sureserver / Suresupport (likely a reseller or v-hoster). It's likely that another site using the same IP is compromised.
Is Savvis the same as ICD Soft? Because that is who Gail told me is their webhost.
“Hard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.”

― G. Michael Hopf, "Those Who Remain"

#TINVOWOOT

MeMelYup
Senior Member
Posts in topic: 1
Posts: 1874
Joined: Mon Nov 15, 2010 3:21 pm

Re: TSRA site compromised

#11

Post by MeMelYup »

Bing does the same as Google. You click on it and it takes you to the correct website, it appears the titles are just messed up.
User avatar

pbwalker
Senior Member
Posts in topic: 4
Posts: 3032
Joined: Thu May 01, 2008 10:12 am
Location: Northern Colorado

Re: TSRA site compromised

#12

Post by pbwalker »

The Annoyed Man wrote:
pbwalker wrote:
The Annoyed Man wrote:They phoned me about this the day before yesterday (I occasionally help them with their website). I referred them to their webhost. TSRA hasn't yet given me FTP access, so I can't search their hosting account for the corrupted file that does this. All of their meta tag settings are correct within the CMS, so this is either an external file or a corrupted file that is doing this.

They are having the company which handles the NRA website take over their website management soon, so maybe they'll get it clear up.

They are also several generations behind in updates to their CMS, including one that will require a complete rebuild of the site....so maybe this situation will force them to take the actions needed to get on top of things.
Agreed, and I'd also put $5 on it possibly being an issue with the shared hosting provider. The IP address points back to Savvis (hosting provider), and if you attempt to access via http://64.14.78.167" onclick="window.open(this.href);return false;, it directs you to an error page for Sureserver / Suresupport (likely a reseller or v-hoster). It's likely that another site using the same IP is compromised.
Is Savvis the same as ICD Soft? Because that is who Gail told me is their webhost.
It looks like ICDSoft uses Savvis datacenters (and their IP space apparently) in the US. http://www.icdsoft.com/data.php" onclick="window.open(this.href);return false;
*NRA Endowment Member* | Veteran
Vote Adam Kraut for the NRA Board of Directors - http://www.adamkraut.com/
User avatar

Charles L. Cotton
Site Admin
Posts in topic: 5
Posts: 17787
Joined: Wed Dec 22, 2004 9:31 pm
Location: Friendswood, TX
Contact:

Re: TSRA site compromised

#13

Post by Charles L. Cotton »

Icdsoft has data centers in Boston, Hong Kong and somewhere in Germany. Unless TSRA changed hosts, they are using Icdsoft.

Chas.
User avatar

Topic author
BenGoodLuck
Member
Posts in topic: 2
Posts: 81
Joined: Mon Aug 08, 2005 6:27 pm
Location: Dallas

Re: TSRA site compromised

#14

Post by BenGoodLuck »

Thanks for the suggestion - typing https://www.tsra.com/" onclick="window.open(this.href);return false; takes you to the site.
User avatar

Charles L. Cotton
Site Admin
Posts in topic: 5
Posts: 17787
Joined: Wed Dec 22, 2004 9:31 pm
Location: Friendswood, TX
Contact:

Re: TSRA site compromised

#15

Post by Charles L. Cotton »

bentcursor wrote:Thanks for the suggestion - typing https://www.tsra.com/" onclick="window.open(this.href);return false; takes you to the site.
I forgot it was on a secure server. I bet the SSL has expired.

Chas.
Post Reply

Return to “Gun and/or Self-Defense Related Political Issues”