ATTENTION: THE SITE WAS HACKED, NOW FIXED
It came to my attention 2 days ago that this site was hacked somehow and a malware virus was attached to many if not all of the HTML pages. I am doing everything I can to restore a backup of the site to eliminate the malware. In the meantime, if any of you have visited the site since 4/10/08 [using a Windows machine], you must run and antivirus program immediately. I’m am very sorry that this has happened. Please let me know if there is anything I can help you with.
UPDATE 4/17/08 12:13am We’ve been working to restore the site from backups so you might notice some missing directories and files. I believe the hacking was through the Coppermine Photo Gallery, in case anyone out there is using it on their sites. It’s just a suspicion though. Confirmed. I believe it was only HTML/PHP files that were altered to expose visitors to the virus. Images, mp3s, etc, were not altered or infected. It seems that the gallery had a sql injection vulnerability which was exploited. What that means is that every .php and .html file was injected with an iframe code containing a malware virus. I believe the virus targeted Windows users only.
UPDATE 4/17/08 2:52pm The entire site has been successfully restored from a clean backup. Therefore, there should no longer be a threat to visitors. The security hole in the gallery is being patched as we speak. I have also notified Google to do a complete evaluation of the site to assure that it is clean. I will post the results as soon as they are available.
UPDATE 4/18/08 3:00pm There was another breach before the patch was applied. Everything is restored again and clean. The patch was successfully installed, so there should be no further danger of hacking or infecting. I am still waiting on Google to give the site a clean bill of health. Stayed tuned.
8 Responses to ATTENTION: THE SITE WAS HACKED, NOW FIXED
NIGHT OF HUNTERS TOUR
No shows booked at the moment.
FIND US ON FACEBOOK
Tori Online





hey… after i tape de html direction and meanwhile the intro was working…. my antivirus get activited… i don’t know… is probably a chance that there is something that wasn’t… “cleaned”???
By the way… i love this site, here in my country nobody knows or speak of her.And even found the make up artist, photographers, videos, quotes, etc. … makes me cry of happines.
What a pain for you to have to go through. Thanks for letting us know and thanks again for an amazing sight.
Any clue on how to rid the malware from a computer (PC)? My antivirus software couldn’t cover it. I tried two differnt types, and I still have remnants left on my laptop, making it difficult to do anything with it. If you know of any tricks, please let me know (I still get “you computer is infected” popups by the malware and it request (approx. ever 10 minutes) to have internet access, so it can re-install VirusHeat (which it did when it first got infected, but I apparatnly didn’t manage to get all of it off).
Thanks, and sorry your site went down.
Hi Ashley, I’m so sorry that you were infected – I feel terrible. I did a couple searches and found some resources that might help. 1 2 3. I actually didn’t experience getting infected since I am using a mac, so I am hoping that these sites have something that will work for you.
I ended up getting a mac afterwards…definitly works better. Couldn’t get teh PC to repair, though (don’t feel bad, it was a poorly made Lenova and I was just lucky it didn’t explode or I lose all my data before hand. So, no worries
I’m so sorry for the problem. I love this page. In spanish there is not too much information about Tori. Good luck and thanks
You should do a google webmaster tools check to clear your page status in google, it still shows up as being malware affected and scaring off potential google-reffered visitors. Be safe!
hi doru, thanks – this is exactly what i’m doing actually but it is taking a while