DW_a_mom wrote:
Just FYI, I am wondering if I should eventually move this over to WP Discussion, since it seems likely we're discussing a virus coming from the site.
Most of the time that is unlikely. Is possible that that a hacker may embed something on this site that may pose are isk tot he client, however the client could just as well encounter that problem elsewhere. If for the sake of argument it was, it is relying on a exploit that is a weakness in the client program/os, or it is a makes use of trickery or misdirection to get in (more likely).
I have done stuff like embedded code in a ebay listing the redirected to google. the reimbursed me for the listing when I demonstrated, then offered me a gift which I declined, and them promptly did nothing about it for months. In any event it is deception, but I was relying on the fact that they incredibly were using client side scripting to try and control malicious code. Rule one is you can't control what happens on the client side. that is the users domain. beyond superficial, this site infrastructure is mostly server side. Injecting malicious code is possible on the server side, and consequently on the client side if it is left unchecked. This ancient version of phpBB has known vulnerabilities so it is certainly possible. However if it was infecting peoples computers we would here more than this. I would worry more about privacy more than anything. People who report these things like "this site infected my computer", often willing let a malicious program in another way, then they are deal with the consequences of a such program interacting with their browsing experience.
A payload of simply redirecting a browser to goggle, serves no purpose. A small possibility is just to see if they can do it. It is also much more likely is a quirk, bug, bad interaction (malware or not). As much as I like firefox there is still a likely hood of within any pluggable program for the plug-in to interact badly with one another. However it a damn site easier to fix than the problems faced by IE.