Malicious redirect from User Stories on blender.org #74870
Labels
No Label
legacy module
Rendering & Cycles
legacy module
User Interface
legacy project
Cycles
legacy project
Documentation
legacy project
Infrastructure: blender.org
legacy project
Infrastructure: Blender Web Assets
legacy project
Infrastructure: Websites
legacy project
User Interface
Priority
High
Priority
Low
Priority
Normal
Priority
Unbreak Now!
Status
Archived
Status
Confirmed
Status
Duplicate
Status
Needs Triage
Status
Resolved
Type
Bug
Type
Design
Type
Known Issue
Type
Report
Type
To Do
No Milestone
No project
No Assignees
3 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: infrastructure/blender-org#74870
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Short description of error
It seems that some pages on blender.org are infected with a malicious script that redirects to random, potentially dangerous websites. I encountered this problem on user stories pages, e.g. https://www.blender.org/user-stories/title-design-from-wonder-woman-to-xxx/.
I've inspected the page source and it appears that this is the malicious code:
Exact steps for others to reproduce the error
Added subscriber: @swtch
It probably will be worth checking if Blender binary releases distributed from blender.org were tampered with.
Added subscriber: @ideasman42
Thanks for letting us know, I've forwarded this to the sysadmin & other admins.
Added subscriber: @Sergey
Changed status from 'Needs Triage' to: 'Resolved'
Thanks for the report.
It has been taken care about.
The binaries and other sites were unaffected.