Warning: Avoid the NWN2DB Website

Moderator: Moderator

Locked
User avatar
chambordini
Lead Gnome
Posts: 2556
Joined: Tue Apr 19, 2011 6:54 am
Location: Songfarla

Warning: Avoid the NWN2DB Website

Unread post by chambordini » Wed Aug 02, 2017 1:04 pm

It's compromised, don't use it. You have been warned.

User avatar
Flasmix
Retired Staff
Posts: 2499
Joined: Mon Jun 29, 2009 9:22 am
Location: Cult of Skebbeton HQ

Re: Warning: Avoid the NWN2DB Website

Unread post by Flasmix » Wed Aug 02, 2017 1:06 pm

The whole website is compromised? I heard it was just an exploit in one build that could erase all your saved builds.
"Orcs have to commute long distances to access the resources privileged Elves and Men enjoy."
- Wirg, Social Justice Warpriest

User avatar
Aspect of Sorrow
Custom Content
Posts: 2204
Joined: Fri Mar 28, 2014 7:11 pm
Location: GMT-4
Contact:

Re: Warning: Avoid the NWN2DB Website

Unread post by Aspect of Sorrow » Wed Aug 02, 2017 1:08 pm

Cross domain injection issue.
Vithsiris Helvi'viir Heretic Drow
Short Stories
- - -
AoS Player Tools
Logon Issue/Resources

User avatar
chambordini
Lead Gnome
Posts: 2556
Joined: Tue Apr 19, 2011 6:54 am
Location: Songfarla

Re: Warning: Avoid the NWN2DB Website

Unread post by chambordini » Wed Aug 02, 2017 1:09 pm

AoS says some XSS (cross site) injection pointing to an ukranian server, people in the IRC started reporting their Anti Virus software flagging up and getting weird ads on Chrome.

User avatar
Nemni
Scripter
Posts: 576
Joined: Wed May 27, 2009 3:10 am

Re: Warning: Avoid the NWN2DB Website

Unread post by Nemni » Wed Aug 02, 2017 1:15 pm

That's some real bad timing with the RCR window!

User avatar
mrm3ntalist
QC Coordinator
Posts: 7122
Joined: Wed Feb 29, 2012 5:31 pm
Location: Skala Kallonis, Lesvos, Greece

Re: Warning: Avoid the NWN2DB Website

Unread post by mrm3ntalist » Wed Aug 02, 2017 1:21 pm

Nemni wrote:That's some real bad timing with the RCR window!
I use the the nwn2db and never had an issue. I suggest using a malware program (Malwarebytes antimalware for example ) just to be safe.

I just used it and there were no ads, malware and or viruses.
Mendel - Villi of En Dharasha Everae | Nikos Berenicus - Initiate of the Mirari | Efialtes Rodius - Blood Magus

Spelling mistakes are purposely entered for your entertainment!

User avatar
matelener
Retired Staff
Posts: 621
Joined: Thu Jun 19, 2014 6:02 am

Re: Warning: Avoid the NWN2DB Website

Unread post by matelener » Wed Aug 02, 2017 1:22 pm

Got infected half an hour ago.

chad878262
Quality Control
Posts: 8418
Joined: Thu Sep 18, 2014 6:55 pm

Re: Warning: Avoid the NWN2DB Website

Unread post by chad878262 » Wed Aug 02, 2017 1:31 pm

@AoS, is there any status update on the BGtSCC builder you are working on? Is it still a-ways out or close to ready?
Chord Silverstrings - Bard and OSR Squire / Tarent Nefzen - Arcane Wand Merchant and Master Alchemist / Irrace Arkentlar - Drow Adventurer / Finneaus Du'Veil - Gem Merchant and Executive Officer of SCCE

Tarent's Wands and Elixirs

A Wand Crafter's guide to using wands

User avatar
Aspect of Sorrow
Custom Content
Posts: 2204
Joined: Fri Mar 28, 2014 7:11 pm
Location: GMT-4
Contact:

Re: Warning: Avoid the NWN2DB Website

Unread post by Aspect of Sorrow » Wed Aug 02, 2017 1:36 pm

May do a handoff, or add a printout option for builds in the coming beta server.
Vithsiris Helvi'viir Heretic Drow
Short Stories
- - -
AoS Player Tools
Logon Issue/Resources

User avatar
aaron22
Recognized Donor
Posts: 3526
Joined: Sat Feb 06, 2016 3:39 pm
Location: New York

Re: Warning: Avoid the NWN2DB Website

Unread post by aaron22 » Wed Aug 02, 2017 4:15 pm

this is no good. bad new for me. is it infecting apple devices?

User avatar
The Last Question
Posts: 57
Joined: Tue Dec 29, 2015 8:13 am

Re: Warning: Avoid the NWN2DB Website

Unread post by The Last Question » Wed Aug 02, 2017 4:18 pm

any news about nwn2db? Still dangerous?

User avatar
chambordini
Lead Gnome
Posts: 2556
Joined: Tue Apr 19, 2011 6:54 am
Location: Songfarla

Re: Warning: Avoid the NWN2DB Website

Unread post by chambordini » Wed Aug 02, 2017 4:20 pm

Dunno, I once sent an email to the admin there but he never replied and I don't think anyone that we know has ever been successful contacting them.

User avatar
Endelyon
Global Admin
Posts: 2707
Joined: Sun Jul 06, 2014 4:24 am

Re: Warning: Avoid the NWN2DB Website

Unread post by Endelyon » Wed Aug 02, 2017 4:23 pm

We don't really have any details on the scope of the injection, just that it happened to at least one user. It's likely that it only affects certain builds where the code has been propagated. Just viewing your own builds and making your own builds is probably fine (especially if they're set as private and don't have any strange comments on them).

User avatar
LuvHandles
Posts: 65
Joined: Mon Apr 03, 2017 11:13 pm
Location: Colorado, USA

Re: Warning: Avoid the NWN2DB Website

Unread post by LuvHandles » Wed Aug 02, 2017 4:35 pm

BGTSCC has so much custom content, I use a spreadsheet of my own creation to plan builds.

I was considering building an app to mine data from the BGTSCC module for build planning, but I thought that would be overkill. Maybe it's not such a bad idea after all. I already created a library that can read most of the NWN2 file formats from back when I was doing NWN2 mod development.

User avatar
Endelyon
Global Admin
Posts: 2707
Joined: Sun Jul 06, 2014 4:24 am

Re: Warning: Avoid the NWN2DB Website

Unread post by Endelyon » Wed Aug 02, 2017 4:41 pm

Locking this post because it keeps making me approve these individually since I flagged this as a global announcement. :lol: If we get any more information we'll post it here.

Locked