_

  • Cameras
  • Accessories
  • News
  • Partners
  • About
  • Contact

cinema5D attacked – please read

Most of you have probably received a “reported attack site” warning on their browser when visiting cinema5D during the weekend. Unfortunately it turns out that our system was infected with a virus by a hacker who used our platform to infiltrate our user’s systems. The hacker has come in through a vulnerability in one of our installed softwares.

attack

Our Servers:

As I’m writing this our site is still flagged as serving bad code, but the system itself has been cleaned, we have removed the malicious code and updated to the latest release of the software in question. The warning messages will disappear as soon as google has rescanned our site (this hasn’t happened in more than 10 hours so far).
I have received and read reports that we are not the only site affected. For a detailed explanation of how we were infected scroll down.

Your Computer:

Here’s the good part:

The IP address serving malware (93.186.170.0) had already been flagged by StopBadware.org by the time the infected code was served. This means content from this IP address was automatically blocked for users of up-to-date web browsers.
Mac users don’t seem to be affected.
If you had a security tool, like Sophos, you would have been alerted to a security risk before an infection could have taken place.
It seems like you needed to click on a popup and install software to get infected

Here’s the shitty part:

Those users with old web browsers like Internet Explorers 6 on a PC didn’t get a “reported attack site” warning and might have been infected.
We have received word of some users having an infected PC after clicking a link that said “install the software to view the video”…

Do I Now Have Malware?

In order to be at risk, you would have to:

  1. Use an old/vulnerable web browser.
  2. Agree to download a PDF/Java app
  3. Run/opened the PDF/Java app

If you believe this may be the case, Sophos Labs have an explanation of how to clean up an infection. Furthermore, please contact us so we can update this post to help other users.

How Do I Know cinema5D Is Now Malware Free?

The Google Safe Browsing tool will verify that cinema5D does not pose a malware risk hopefully within the next hours. You can check back there.

dslr_blend1

Sorry

We’re very sorry for any inconvenience this issue might have caused for you and for the unavailability of our resources. We will look for better security and regular updates of our software in the future. These weren’t fun days for cinema5D and we definitely have learned a lesson.

Apologies from the cinema5D home base in Austria,
if you have any questions about this incident you may contact me here
Sebastian Wöber

(cinema5D admin)

Details about the attack

We were running version 2.82 of OpenX ad server.

A security vulnerability in OpenX 2.82 allows unauthorized users to edit your banner ad code. The attacker used this to add one line of code to each ad (in the ‘Advanced’ tab, if you are an OpenX user).

The additional code looks very much like any regular ad served by OpenX:

iframe1 OpenX Malware Infection on WhoIsHostingThis.comThis was visible only when you edited a banner ads ‘Advanced’ properties or happened to check the site’s HTML very closely.

  • Posted On: 23rd August 2010
  • By: Sebastian Wöber
  • Under: cinema5D news
Tweet

Leave a Comment Cancel reply

Connect with:
Facebook Google Twitter LinkedIn

Your email address will not be published. Required fields are marked *

  • Latest Video Reviews
    • 5D3 post processing OSX Workflow video: Simple post processing of 5D Mark III RAW footage in OSX You have probably seen our extensive written guide on how to get Magic Lantern's 24p ...
    • scr_5d3_bmcc Canon 5D mark III RAW vs. Blackmagic Cinema Camera RAW Today we already published a test video of the impressive Canon 5D mark III RAW ...
    • scr_5d3 Canon 5D mark III 24p RAW test – A RAW in the park Yes, the source for the video above is a 1080p 14bit RAW shot with the ...
  • Subscribe to our Newsletter
  • Categories
    • Accessories
    • Announcements
    • Camera Bodies
      • Apertus
        • Axiom Camera
      • Arri
        • Arri Alexa XT
      • Blackmagic Design
        • Blackmagic Cinema Camera
        • Blackmagic Pocket Cinema Camera
        • Blackmagic Production Camera 4K
      • Canon
        • Canon 1100D
        • Canon EOS 100D
        • Canon EOS 1D
        • Canon EOS 1D X
        • Canon EOS 1DC
        • Canon EOS 5D mk2
        • Canon EOS 5D mk3
        • Canon EOS 60D
        • Canon EOS 6D
        • Canon EOS 70D
        • Canon EOS 7D
        • Canon EOS 7D mk2
        • Canon EOS C100
        • Canon EOS C300
        • Canon EOS C50
        • Canon EOS C500
        • Canon EOS M
        • Canon EOS T2i / 550D
        • Canon EOS T3i / 600D
        • Canon EOS T4i / 650D
        • Canon EOS T5i / 700D
        • Canon Powershot G1 X
      • Concept Cameras
      • GoPro
        • GoPro Hero 3
      • Ikonoskop
      • JVC
        • JVC PX100
      • KineRAW
        • KineRAW MINI
      • Leica M type 240
      • Nikon
        • Nikon A99
        • Nikon Coolpix A
        • Nikon D3200
        • Nikon D4
        • Nikon D7000
        • Nikon D800
      • Panasonic
        • Panasonic AF100
        • Panasonic GH2
        • Panasonic GH3
        • Panasonic Lumix
      • Pentax
      • RED
        • Dragon
        • RED One
        • RED Scarlet-X
      • Samsung
      • Sony
        • Sony A65
        • Sony A77
        • Sony F3
        • Sony F5
        • Sony F55
        • Sony HX9v
        • Sony NEX-5N
        • Sony NEX-6
        • Sony NEX-7
        • Sony NEX-EA50
        • Sony NEX-FS100
        • Sony NEX-FS700
        • Sony NEX-VG30
        • Sony NEX-VG900
        • Sony RX100
        • Sony VG-20
    • Camera Movement
      • Aerial
      • Crane
      • Sliders
      • Steadycam
    • Cameras
    • cinema5D news
    • Contests
    • Distribution
    • Editing & Field Recording
      • Color Correction
      • Disk Recorders
      • Editing on a Mac
      • Music
      • Software
        • Final Cut Pro
        • Premiere Pro
    • Events
      • IBC 2011
      • IBC 2012
      • NAB 2011
      • NAB 2012
      • NAB 2013
    • Filmmakers
    • Firmware
      • Firmware Update
      • hacking
      • Picture Styles
    • Follow Focus
    • Gear
      • Audio
        • Microphones
      • Bags
      • Baseplates
      • Battery
      • DIY
      • Handheld Rigs
      • Lenses
        • Filters
        • Mounts / Adapters
      • Mattebox
      • Memory
      • Storage
      • Tripod & Mounting
    • HDSLR
    • Interviews
    • Kickstarter
    • Lighting
      • Greenscreen
      • LED
    • Monitoring
      • EVF's
      • Field Monitors
      • Loupes
      • Streaming
    • News
    • Rebates
    • Review
      • video review
    • Rumors
    • Technology
      • 4K
      • 6K
      • Aliasing / Moiré
      • Global Shutter
      • Highspeed
      • Lowlight
      • RAW
      • Slow Motion
      • Timelapse
      • Very Small Cameras
    • The Art
      • Video Picks
      • Workshops
    • Uncategorized
  • Twitter
    • cinema5D tops Premiumbeat's '10 Filmmaking Sites You Should Be Reading' list - http://t.co/V0XWUTMDx8
      about 13 hours ago
    • @AsherShellim strange - which flavor of ProRes?
      about 22 hours ago
    • 10 Filmmaking Sites You Should Be Reading | http://t.co/YgJIN1QZFk http://t.co/O3zcUJStbX
      1 day ago
CINEMA5D

cinema5D is a website that specializes in video reviews of cinema capable new cameras and accessories.
We are an independent group of camera professionals who have been at the forefront of the HDSLR revolution.
Our reviews are our personal opinion yet we try to provide an objective view at every tool we test.

Recent Posts
  • cinema5D tops Premiumbeat’s ’10 Filmmaking Sites You Should Be Reading’ list
  • First Video of Metabones Speedbooster for your BMCC MFT
  • Recreating the ‘Bullet Time’ Effect from The Matrix with 1 GoPro
  • ‘Relentless’ – the ‘MoVi’ for the rest of us?, part 2
  • The 5D mark III can do 25fps in RAW 1080p
Archives
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012