Daggerfall unity website

Post here if you need help getting started with Daggerfall Unity or just want to clarify a potential bug. Questions about playing or modding classic Daggerfall should be posted to Community.
kust
Posts: 1
Joined: Thu Dec 09, 2021 6:02 pm

Daggerfall unity website

Post by kust »

When trying to go to the daggerfall unity's website a malaware popup appears. Press allow to confirm you are human.
Attachments
malaware.PNG
malaware.PNG (11.96 KiB) Viewed 640 times

User avatar
Shapur
Posts: 154
Joined: Wed Apr 21, 2021 5:11 pm
Location: Czech Republic
Contact:

Re: Daggerfall unity website

Post by Shapur »

kust wrote: Thu Dec 09, 2021 6:06 pm When trying to go to the daggerfall unity's website a malaware popup appears. Press allow to confirm you are human.
Hi,
could you post a link? I have a feeling that's some fake.
This is the only official one.
Link to my github here.
And here is my nexus profile.

User avatar
Shapur
Posts: 154
Joined: Wed Apr 21, 2021 5:11 pm
Location: Czech Republic
Contact:

Re: Daggerfall unity website

Post by Shapur »

Nevermind, that is the real one.
Did the website get hit by some malware?
It's not how it's supposed to be.
Link to my github here.
And here is my nexus profile.

User avatar
Shapur
Posts: 154
Joined: Wed Apr 21, 2021 5:11 pm
Location: Czech Republic
Contact:

Re: Daggerfall unity website

Post by Shapur »

Do not click on any of those weird popups.
Link to my github here.
And here is my nexus profile.

User avatar
BadLuckBurt
Posts: 948
Joined: Sun Nov 05, 2017 8:30 pm

Re: Daggerfall unity website

Post by BadLuckBurt »

Shapur wrote: Thu Dec 09, 2021 6:47 pm
kust wrote: Thu Dec 09, 2021 6:06 pm When trying to go to the daggerfall unity's website a malaware popup appears. Press allow to confirm you are human.
Hi,
could you post a link? I have a feeling that's some fake.
This is the only official one.
He's talking about dfworkshop.net, the main site. I just tried and got redirected as well.

@Admins / moderators, I think there has been some malicious content injected to the Wordpress (I think it uses Wordpress?) database. It's usually Javascript <script> tags being added to the page content.
DFU on UESP: https://en.uesp.net/w/index.php?title=T ... fall_Unity
DFU Nexus Mods: https://www.nexusmods.com/daggerfallunity
My github repositories with mostly DFU related stuff: https://github.com/BadLuckBurt

.

User avatar
Shapur
Posts: 154
Joined: Wed Apr 21, 2021 5:11 pm
Location: Czech Republic
Contact:

Re: Daggerfall unity website

Post by Shapur »

BadLuckBurt wrote: Thu Dec 09, 2021 6:52 pm
Shapur wrote: Thu Dec 09, 2021 6:47 pm
kust wrote: Thu Dec 09, 2021 6:06 pm When trying to go to the daggerfall unity's website a malaware popup appears. Press allow to confirm you are human.
Hi,
could you post a link? I have a feeling that's some fake.
This is the only official one.
He's talking about dfworkshop.net, the main site. I just tried and got redirected as well.

@Admins / moderators, I think there has been some malicious content injected to the Wordpress (I think it uses Wordpress?) database. It's usually Javascript <script> tags being added to the page content.
Yep, seems like the website got attacked.
Link to my github here.
And here is my nexus profile.

User avatar
Magicono43
Posts: 1141
Joined: Tue Nov 06, 2018 7:06 am

Re: Daggerfall unity website

Post by Magicono43 »

Yeah, can confirm here as well that it instantly gets redirected to spam/malware type stuff.

User avatar
XJDHDR
Posts: 258
Joined: Thu Jan 10, 2019 5:15 pm
Location: New Zealand
Contact:

Re: Daggerfall unity website

Post by XJDHDR »

I've found that a malicious script seems to have become attached to the website, which is causing these redirects.

If you have Adblock Plus, uBlock Origin or some other similar blocking addon, you can add this rule to stop these redirects in the meantime:

Code: Select all

||stat.belonnanotservice.ga^

User avatar
Interkarma
Posts: 7247
Joined: Sun Mar 22, 2015 1:51 am

Re: Daggerfall unity website

Post by Interkarma »

Thanks for the alert. I've taken website down while I investigate.

User avatar
Interkarma
Posts: 7247
Joined: Sun Mar 22, 2015 1:51 am

Re: Daggerfall unity website

Post by Interkarma »

I've restored whole site and database from recent backup prior to redirect hack. Restored site scans clean and currently has additional paid protection in place for some peace of mind.

As a precaution, I've reset all passwords for the few users who have access to blog (only myself and a couple of other members here) and purged all non-essential plugins. This might break some older posts that embed rich content such as gfycat animations or code formatting. I'd rather keep plugins to a bare minimum for now until I can complete review.

The site and all plugins are always kept up to date, so not certain how hack was initially executed. I'll keep monitoring site proactively and dig through logs to discover more.

Post Reply