!!!! Share... addtoany link malware!!!!!!!

Discussion in 'TemplateCodes' started by musikal, Jun 26, 2010.

  1. musikal Customer

    Hello to all,

    In the default Neo2 tempalte, there is a link at the top ofthe page called "Share" which is a link to the site AddToAny - Share Button, Email Button, Subscribe Button

    Today, my site would not load. Malwarebytes which i run resident, would not let me access my own site, claimed it is potentially dangerous.

    The site would only load the the very top bar of the page and nothing below it. Went to the addtoany website and again Malwarebytes blocked this site, it tried to redirect me.

    I suggest anyone having a "Share" link (AddToAny - Share Button, Email Button, Subscribe Button) temporarily REM the line of code out.

    The code can be found in the layout.tpl file you are using.

    Anyone viewing your site at this time will be flagged by security software and may lead to a drastic dropoff in your page views.

    Hope this is taken care, if you love your site, you owe it to yourself to fix this immediatly.

    Written 26 June 2010 1015AM MST

    Tom
  2. bowers01 Genius At Work

    addtoany is on lots of sites, malware bytes doesnt say anything on my pc when i view the demo.templatecodes.com
    Maybe your site/web serrver has been hacked.
    Nick
  3. musikal Customer

    Not there

    Nick,

    Thanks for the reply, but that addtoany link is not on the demo address you mentioned above. It is on my neo2 template in the upper left hand corner.

    Only brought this up because I've been working on my site all week and just this morning this started to happen. I assume you're running the paid, resident version of MWB. The free version will not run resident or block anything.

    It's saved my butt too many times to ignore.

    Tom
  4. Mike-N-Tosh Developer & Moderator

    There have been numerous accusations against addtoany regarding malware, hijacking, etc., yet none have been actually proven to the best of my knowledge. Addtoany is suggested and reviewed by many very reputable sites and technology leaders.

    Here's the latest report from Google itself:
    Safe Browsing Site diagnostics

    I'm not taking any sides here, just trying to set logic and facts in place.

    Facts are that pretty much any script/widget in some way, shape or form could possibly get hijacked/hacked/injected/etc..

    It appears that you have been a victim, however I would be careful about proclaiming who or what you claim is doing the hacking in a public forum.
  5. musikal Customer

    Understood. Today the site I mentioned is working fine and loaded zip fast.

    I did check this on my 3 XP Pro machines and all reported the same warning, so and so IP was blocked.

    Overall, thought it might be helpful to others. I'm not here to start any flames whatsoever.

    My only point is, it could have been disastrous for a Windows machine.

    I make a good part of my living maintaining 100+ machines and have to either clean them or reimage them after they've been attacked. When I see this, I try to warn others. Nothing worse than losing a ton of unbacked up data!

    Case closed.
  6. Lhotch curmudgeon

    Your initial post insinuates this is a template code issue however your quoted comments above state that the link is not in the template codes template, only on your site.

    This indicates YOUR site is the one that has been compromised and that this actually has nothing at all to do with template codes.
  7. musikal Customer

    It's a moot point now because they have since cleaned up the site.

    FYI, the Share button on the template was purchased that way, I simply removed it. Done.

    As far as the template itself goes, I think it is one of the finest ever created. And help from TC is 1000% positive! I'm truly sorry if my comment implied the template has a problem, it was the link button on the template.

    Tom
  8. seymourjames All Hands On Deck

    There are numerous rumors etc. which don't appear to be proven. People are free to remove this facility if they wish by simply deleting it from their template (layout.tpl). I really don't have an opinion. Neo templates have it on them and Sigma ones don't. If you can show me some definitive proof that there is a problem I will remove it from future sales of the Neo template. We would certainly not wish to be using it either even on our demo site.
  9. musikal Customer

    It was my own lack of security. After full scans of all my machines found nothing, I discovered that my dsl modem had no password assigned. Something must have gotten in.
    Everything in my system was locked down except that. Never had that happen.

    It would appear I was redirected, yet only from that site. First time ever, been online since 1986.

    My apologies to everyone!

    Tom

Share This Page