in

Malware attack at the GMC

UPDATE: The situation is now over, and the iframe has been removed. Google will still list the GMC as a “malicious website” until they recrawl it.

Some users at the official Game Maker Community have today reported receiving warnings from their antivirus software or web-browsers when viewing the forum.

The alerts are triggered from an iframe which appears to have been maliciously inserted in the forum header and were first reported at around 1:10pm BST.

Two hours after the attack was originally reported it was clear that the GameMaker Community remained vulnerable, as the offending URL in the iframe had been changed from its original to another dubious site.

KC LC’s attempted explanation, “It’s probably being generated by one of the advertisers on YYG”, does not seem remotely plausible to me and I believe the code is more likely to have been the result of a MySQL injection.

NakedPaulToast helpfully provided a link identifying the vulnerability within the Invision Power Board software which is used to run the forum.

A vulnerability has been identified in Invision Power Board (IP.Board), which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error in the “xmlout.php” script when processing the “name” parameter, which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.

http://www.frsirt.com/english/advisories/2008/2487

A patch was released on August 29th, so obviously the forum software has not been kept up-to-date.

At around 3:10pm BST YoYo Games CEO Sandy Duncan began writing a post to users of the forum- however this post has not yet appeared.

What do you think?

11 Comments

Leave a Reply
  1. I’m not sure if this is the case with IPB, but some forum software may store template files in the database. There are most likely also other ways to alter the IPB database to result in the malicious iframe being embedded in the page.

  2. I’ve been browsing the GMC knowing that this was happening (using Firefox) and I ran some software today and my computer is still clean. Could be shitty software’s or could just be that it’s safe to goto the GMC. I go with option 2.

  3. I’m glad I check Game Maker Blog every day before I go to the GMC. It’s quite possible that you’ve saved my computer from infection, Mr. Gamble. Thanks!

5 Pings & Trackbacks

  1. Pingback:

  2. Pingback:

  3. Pingback:

  4. Pingback:

  5. Pingback:GMC Malware Attack « Scorptek -> GMNews

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

GMC Malware: Live Blog

GMC Malware free