Computer Glitch or Hacked?

Well there ya go. That's unfortunate and I don't have high hopes for the future of the site. Current ownership is obviously not taking this seriously, given the amount of users that use this site daily, and I see zero action being taken, to warn us of possible malware, bad links, etc.

According to this archive of the site, I'm guessing a guy named Thai owns it. For those who don't know, google 'wayback machine'. It's a non-profit archive of screenshots of websites throughout the years. I have use it occasionally when I'm tracking down info for clients.

https://web.archive.org/web/20021121112711/http://www.toyota-4runner.org:80/

So then did a google search of just this site using following search string, without the quotes

"site:https://www.toyota-4runner.org/ thai owns forum"

and this thread appeared on search results.
http://www.toyota-4runner.org/comments-suggestions/35756-who-founded-toyota-4runner-org.html

which states
"GatorGreg and Thai started it in November 2002"

So there you go. If you want to pay for previous WHOIS information to see if you can find which one registered the domain, or under what company they registered it, there are sites that will give you past WHOIS results for a fee. Otherwise, you can probably just google to find out who Greg and Thai are if you really need to know their last names.

Until they get this fixed, I'm outta here. No need to put my machine in danger of malware and virus crap.

Thai was online today according to their user profile. If they still have control over their forum account that is....
 
Only Thai knows. It would be easy for a-hole to lock them out fully, if user has gained access to the db. In that case, Thai would have to

go into webhosting cp (this site is hosted on AWS)
put entire site on lockdown (maintenance mode)
delete existing db
reupload from last good save (pre-hack)
go into db and change all passwords

and then ...

spin up a new server
create new db
upload latest copy of vbulletin software (or similar)
reconfigure everything
import all forum/sub-forum, posts, pm's and users
test and retest all is working
relaunch and delete old install

It's a shitton of work, although some here seem to think you can just easily get all this done in a night. Not if you're doing it right.
 
Well there ya go. That's unfortunate and I don't have high hopes for the future of the site. Current ownership is obviously not taking this seriously, given the amount of users that use this site daily, and I see zero action being taken, to warn us of possible malware, bad links, etc.

According to this archive of the site, I'm guessing a guy named Thai owns it. For those who don't know, google 'wayback machine'. It's a non-profit archive of screenshots of websites throughout the years. I have use it occasionally when I'm tracking down info for clients.

https://web.archive.org/web/20021121112711/http://www.toyota-4runner.org:80/

So then did a google search of just this site using following search string, without the quotes

"site:https://www.toyota-4runner.org/ thai owns forum"

and this thread appeared on search results.
http://www.toyota-4runner.org/comments-suggestions/35756-who-founded-toyota-4runner-org.html

which states
"GatorGreg and Thai started it in November 2002"

So there you go. If you want to pay for previous WHOIS information to see if you can find which one registered the domain, or under what company they registered it, there are sites that will give you past WHOIS results for a fee. Otherwise, you can probably just google to find out who Greg and Thai are if you really need to know their last names.

Until they get this fixed, I'm outta here. No need to put my machine in danger of malware and virus crap.

[MENTION=2]Thai[/MENTION] is still posting, he doesn't own the forum anymore (AFAIK)

http://www.toyota-4runner.org/off-topic/265995-site-hacked.html#post3190192\

^^ He said he heard back from Admin and the problem has been fixed, though I suppose it's possible the admin's account was hacked...

I'm guessing it was just a sketchy site upgrade, followed buy a suspicious email... maybe.
 
Fellas, please pardon my ignorance, but.... If I log out and simply read the posts here without actually posting anything or checking my private messages, would I still be at risk in terms of getting viruses, malware, and other dangerous things?
 
I'm guessing it was just a sketchy site upgrade, followed buy a suspicious email... maybe.

Site upgrades that don't go right typically don't rename the title of sub forums or change cookie crumb link titles.

Scroll down to footer. See those numbers? This info shows the software being used on the site, followed by the version. You can see this site uses something called vBadvanced, vBSEO, vBulletin, and something called Advanced user Tagging (Lite). You can search any of those version numbers to find out how old the current version of the software is. Showing people which out of date version of software you're using is on the footer of your theme template is like telling a hacker one of the doors to the house is open and there's chocolate cake in the fridge if you want it.
 

Attachments

  • numbers.jpg
    numbers.jpg
    86.5 KB · Views: 176
Last edited:
A little history...yes, Gatorgreg and me started this forum in 2002. I did the post whoring...Gatorgreg ran the forum in the background (and did posting). We did it out of love...literally, we made zero money. Whatever advertisement there was (minimal in those days) went to cost of running the forum.

Then, at some point, Gatorgreg handed keys of forum to ADMIN who then took over the forum software and advertisements, etc..

I am just a regular member. I am confused as you guys regarding what happened.
 
Fellas, please pardon my ignorance, but.... If I log out and simply read the posts here without actually posting anything or checking my private messages, would I still be at risk in terms of getting viruses, malware, and other dangerous things?
Any time you initiate a connection you are at some form of risk. Risk grows the more you engage (visit pages, download/view attachments, login etc)

That said, content available on this site is low risk. You're not activating plugins , you're not sending PII (typically) Site is also low risk target overall since PII isn't typically exchanged, no payment information, not a huge forum in comparison to most and mods are active enough to prevent run-away threads. Most updated anti-virus and browser/operating systems would prevent most attempts that would be here.
 
I just saw a large "DON'T GET HACKED" advertisement at the top of the page and I haven't been googling this any time recently. I moved to another page before I had a chance to get a screen shot of it and now I can't get it to come back. Very shady.
 
Any time you initiate a connection you are at some form of risk. Risk grows the more you engage (visit pages, download/view attachments, login etc)

That said, content available on this site is low risk. You're not activating plugins , you're not sending PII (typically) Site is also low risk target overall since PII isn't typically exchanged, no payment information, not a huge forum in comparison to most and mods are active enough to prevent run-away threads. Most updated anti-virus and browser/operating systems would prevent most attempts that would be here.

Exactly. I have zero financial information on this forum. I don’t click on the banners. I look most of the stuff on my iPad/iPhone. Otherwise i use my iMac. I don’t see any risk to be honest...but then again, i am no computer expert. YMMV.


I am getting PMs. Clarify...Gatorgreg used to own the domain and software. Some 5-10 yrs ago, he handed the keys (everything) to Admin. Admin does the software, advertisements, etc.. Gatorgreg and I have ZERO control over the forum. No need to PM us for details on the forum.

We got out because we have day jobs...and my goal in life is just to postwhore. :D
 
Last edited:
I just got the Instagram announcement too. So, I guess my email address is known to the hackers and I'll be getting even more spam now. I'll log out and stop posting or clicking any ads here until the all-clear signal.
 
I have also noticed at least on my end/computer that when posting some phrases and or key words after posting are turning into links, one example is...... LED tail lights.

Is anyone else seeing this issue??

I see that on many forums I'm on, especially when not logged-in, it's advertising.
Never seen that here.
 
I see that on many forums I'm on, especially when not logged-in, it's advertising.
Never seen that here.

The same here, never seen it here, but are you seeing the "tail lights" coming out as a link in my post you qouted, or am I only seeing as a link?

Edit: And do you see it as a link in this post?
 
Last edited:
The same here, never seen it here, but are you seeing the "tail lights" coming out as a link in my post you qouted, or am I only seeing as a link?

Edit: And do you see it as a link in this post?
I'm seeing it as a link, not something I've ever seen when logged in.
 
The same here, never seen it here, but are you seeing the "tail lights" coming out as a link in my post you qouted, or am I only seeing as a link?

Edit: And do you see it as a link in this post?

Yeah, when I hover over it it shows up as a link.
That's new. IDK if I actually hovered on it earlier.

Get used to it.
 
I've been trying to figure this issue out as well. The other day when the whole site went down it showed a different google script than it normally does when it goes down for maintenance. Also it seems from what I have seen that only the 4th gen section saw changes to titles and stuff (correct me if I'm wrong). I also just received the same email as several other members on here about the 100 gift card. I'll update if I receive anything else
 
<<<< puts tin foil hat on.

Regarding the email some people have received. One part that jumps out at me is "DM us your 4runner pic and as much description as possible". Makes me think that they want to post fake ads for "For Sale" vehicles using your info. :behindsofa:
 
I've been trying to figure this issue out as well.

Nothing to figure out really. Just have to wait until Admin can troubleshoot and clean up, and hopefully upgrade forum software or it will never stop unless admin has knowledge of patching the code to fix this security flaw. Even with the knowledge, the amount of time to do it wouldn't be worth it because you'd be editing core files which could break something else.

If there is not a clean backup, it's definitely going to be a challenge to find the bad code. Hopefully the logs provide some clues.

If anyone knows admin, can you have them check their PM or have them shoot me one? I made an offer to help.
 
Last edited:
I have also noticed at least on my end/computer that when posting some phrases and or key words after posting are turning into links, one example is...... LED tail lights.

That is more likely malware on your own system.

Basically what's happening is there's a piece of software that's monitoring what you see on the screen and what you type. It has a list of keywords and links it needs to disseminate so when it sees a keyword, it turns it into a link that it has been told to disseminate. The goal is to have you think it's a normal part of the page and click on it.

I'd do a very thorough sweep of your machine with Avast!, Spybot, and Malware Bytes.
 
I got that email too. It had something to do with an instagram account. I did see the part where you could win a $100 amazon giftcard. I just ignored it since I dont bother with most social media.
 

Members online

Forum statistics

Threads
278,307
Messages
3,554,050
Members
248,016
Latest member
Advally Service

Trending content

Back
Top