http://www.carlssonplanet.com
For safety reasons we're re-uploading the entire website from a local backup after the intrusion. This is being done to ensure that no other files besides the ones found in the forums has been compromised. Also going through and clearing out old scripts and checking permissions on files and folders... this will take a while.
Info from earlier:
The CarlssonPlanet forums has been compromised and taken offline. The compromise consisted of a PHP exploit resulting in all forum pages to contain hidden links to sites trying to download malicious trojans in the background. Specifically the links were leading to the niklejo.net website (link leads to Google Safe Browsing diagnostics page for niklejo.net - some interesting info there).
Everyone that has visited the CarlssonPlanet forums in the last 2 days (and everyone else for that matter!) should make sure they have antivirus software installed and that it is running and up-to-date with the latest virus definitions.
More information will come as we gather it. To read more about the exploit that was used here on the CarlssonPlanet forums, please visit http://blog.unmaskparasites.com/2009/04 ... hp-exploit.
The important thing to note here that this exploit did NOT in any way result in any kind of breach of data, i.e. no passwords or other personal information has been stolen. The script that was used here merely edited existing web pages on the server to include those links.
Google Safe Browsing diagnostics page for carlssonplanet.com
Unmask Parasites security report for carlssonplanet.com
We are deeply sorry about the unavailability of the CarlssonPlanet forums and any damage caused. We will be working hard to get the forums back up as soon as possible, and will be working with our web host to patch this security hole.