Mangband.org = Malicious website?

Think you've found a bug? Please report it here.
Post Reply
Dinare
Pitiful-Looking Beggar
Posts: 2
Joined: Sun 13.11.2011, 21:00

Mangband.org = Malicious website?

Post by Dinare » Sun 13.11.2011, 21:48

First off, I'd like to say that I love Mangband, and I play constantly on my own private server* with a few friends.

Recently I have been blocked from Mangband.org by my anti-virus software with this message.

Image

Surprised, I looked into this IP address, and all I found out is that it apparently belongs to Warrior whom I gather is an important person here on the forums.

I am unsure what to make of this information, but I figured I should tell you guys, since this website could really take a nosedive if virus protection is starting to block it by default. I certanly wouldn't have bothered adding it to the ignore list on my anti-virus if it was my first time to the website.

* The reason I don't play on the main server is because of a security issue. More specifically the Personal Information in the "@" menu that is viewable by everyone.

PowerWyrm
Balrog
Posts: 1574
Joined: Sun 27.11.2005, 15:57

Re: Mangband.org = Malicious website?

Post by PowerWyrm » Mon 14.11.2011, 12:13

The website has been recently hacked and didn't get restored completely. Every time I connect I need to relog, and even then I get messages about expired certificates, untrusty pages and so on... I guess it's the same problem with your antivirus.

Thorbear
Two-Headed Troll
Posts: 131
Joined: Wed 12.01.2005, 15:00
Contact:

Re: Mangband.org = Malicious website?

Post by Thorbear » Mon 14.11.2011, 13:08

Zaxx wrote:The website has been recently hacked and didn't get restored completely. Every time I connect I need to relog, and even then I get messages about expired certificates, untrusty pages and so on... I guess it's the same problem with your antivirus.
IIRC I needed to relog every time even before it got hacked.
Dinare wrote:First off, I'd like to say that I love Mangband, and I play constantly on my own private server* with a few friends.

Recently I have been blocked from Mangband.org by my anti-virus software with this message.

Image

Surprised, I looked into this IP address, and all I found out is that it apparently belongs to Warrior whom I gather is an important person here on the forums.

I am unsure what to make of this information, but I figured I should tell you guys, since this website could really take a nosedive if virus protection is starting to block it by default. I certanly wouldn't have bothered adding it to the ignore list on my anti-virus if it was my first time to the website.

* The reason I don't play on the main server is because of a security issue. More specifically the Personal Information in the "@" menu that is viewable by everyone.
Malwarebytes will no longer block Mangband.org with next update (http://forums.malwarebytes.org/index.ph ... opic=99776)

As for the info in the @ screen, it has been discussed before, some of the main points for keeping it being; 1) It is used to recognize each other across various character names. 2) It doesn't show your IP or domain on default, so no actual identifying information is shown there. 3) You *can* change what is displayed there, as this is just info the client sends.
It is sad for the community however, that you find this to be an issue.
Personally I'd like to see it replaced with some sort of "master" account, which you could tie together all your characters.
I am Thorbear...

Dinare
Pitiful-Looking Beggar
Posts: 2
Joined: Sun 13.11.2011, 21:00

Re: Mangband.org = Malicious website?

Post by Dinare » Mon 14.11.2011, 16:06

Ah, I was unaware that MalwareBytes had a system for reporting false positives, makes sense I guess. I am glad it will be fixed at the next update.

Regarding the "@" menu, whether or not that information is personally identifiable or not depends on the person, and I am not in a position where I can change that information(Changing the username through the control panel doesn't work, and I need to keep this account, along with the Computer name). Unless you are saying I can change what is displayed through other means?

I wouldn't mind if this information was available only to the administrator of the server, as this is information that would be useful to that person. I would also be in favor of a "master" account.

Unfortunate as it is. You won't see me on the main server unless this situation has changed.

Thorbear
Two-Headed Troll
Posts: 131
Joined: Wed 12.01.2005, 15:00
Contact:

Re: Mangband.org = Malicious website?

Post by Thorbear » Mon 14.11.2011, 16:32

Dinare wrote:... Unless you are saying I can change what is displayed through other means? ...
You can download the sourcecode, modify the values sent to the server, and compile it.
Altho I do realize that this is not necessarily an easy thing to do if you're not familiar with programming in C
I am Thorbear...

Post Reply