Skip to content
TORNLIFE More

TornW3B/weav3r.dev compromised AGAIN?

Started by Weav3r [1853324] Helper on in General Discussion.

98 replies · 5.13k views · thread synced · 6 days ago · View on torn.com
About this thread

Posts archived: 99 / 99 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
99
Discussion span
→
Authority score
59 / 100
Historical score
46 / 100
Story score
69 / 100
Engagement score
87 / 100

People posting, likes and official posts are not counted for this thread yet: on threads longer than one page they come from a periodic pass over the archive, which has not covered it.

Most-liked replies

Weav3r [1853324] Helper

Typing this up quickly on my laptop that I snuck into work for the day, so excuse any rushed tone in this announcement. I'm not bothering with formatting, so sorry if the post isn't pretty. And sshhhh.

 

As a lot of you know, TornW3B was compromised yesterday. If you navigated to the site and clicked anywhere you were redirected to some scammy crypto site. This was because of a script being injected into the header that caused a pop-under to render across all of the pages. It didn't happen on every click, which I suspect was something done intentionally in an attempt to not seem overly obvious. Still pretty obvious if you ask me, but, moving on..


While most of you have been supportive of my struggles during this time with my platform, and I want to thank all of you for that, I have seen a few voicing doubts. I'll admit, they're not entirely unfounded. At the end of September last year, my site was severely compromised, and then just about three months later, it happens again?


Yeah, that would seem pretty suspicious. I'd be raising an eyebrow too. But this isn't that. At least not exactly.


The previous incident, based on the evidence I had available, stemmed from the firewall failing (or ServerOptima failing, I guess I should say) and granting someone direct access into my server at that time. They'd done a lot of damage and managed to hide their tracks.


Since then, I hardened security. I installed several security and monitoring tools. If anything happened on the server that wasn't from my IP directly, I received either a message about it in Discord or an email.


This is why I had been fine leaving the server up and running despite the redirects occurring, because I could tell by my logs that my server still appeared to be secured. But I was at work and many hours from the nearest computer, so there was nothing I could do about it until I got home. After much discussion with members of Torn staff and Glasnost (who continues to serve as an advisor for my platform) I decided to bring down the site.


Not because of security issues with the site, but because of the nature of the website users were being redirected to: a crypto scam and phishing site. The redirect itself wasn't harmful.


When I got home, I didn't even take off my shoes. I spent hours scanning every corner of my codebase, looking for anything that had been tampered with. Nothing.


There was no SSH access beyond my own and Glasnost's. No files had been modified. Nothing was installed on my server. The database, which logs all connections and disconnections, showed nothing abnormal. Nothing to indicate any tampering whatsoever.


So I proceeded with diagnosing the redirects once I was confident there was nothing obvious that would cause damage if I spun the server back up. I configured my firewall to block access to everyone except my IP, spun it back up, and visited the site. Redirects were still occurring. So I shut down the server again. I cleared my Next.js cache and rebuilt. Tried again. Redirects had stopped completely.


Theoretically speaking, I probably could have relaunched the server at this point and done nothing more. But prior to diagnosing the issue, I was on Next.js version 16.0.0, which is subject to vulnerability CVE-2025-66478.


While my symptoms didn't seem entirely consistent with everything reported there, that was the only possible entry point I could find after spending half my night digging through configs, binaries, and whatever else they could have possibly touched. So I decided to backup my database and perform a full wipe of the server. If there was even the slightest chance someone had root access and was just trying to remain stealthy, I didn't want to take that chance. I could have been pwnd already and not even know it.


After wiping, I restored my source code from a commit that was created prior to when the attack seemed to begin. I updated every package and audited them to ensure no vulnerabilities remained. I tightened a few configurations as well, just because at this point I'm beyond paranoid.


But if you still don't have trust in the platform after this, you are welcome to feel that way. I'm not forcing anyone to use TornW3B. I make no money from this, and I hardly even use my own platform..mainly due to real life time constraints. Still, there is no cause for alarm. I don't believe anything major was compromised, and yes, that includes your API keys. But you are also welcome to rotate your API key if you just want to be sure, in the same way that I had wiped my server just to be sure. 


This is a hobby project that I did for my love of the community, and I will continue to work on it and improve it as long as I can because I just love doing it, and I love seeing people enjoy what I created.

 

That being said, I have been monitoring W3B very closely all day and see no reason to suspect any breach remains and feel confident in saying that I am moving TornW3B from a soft relaunch to a full relaunch. 

 

Love you all and thank you again <3

Auggie [924001]

Scammer gonna scam

 

Your website is one of the only ways to easily find bazaars right now, thanks for putting it up

Lantian [3029152]

While I'm really sorry for you, I want to thank you for not giving up on your project. It is honestly a huge help for many players.

Kudos to you for sure.

 

Also, once again appreciate the insight and honesty.

 

(I personally would love to hear more about what happened if you find out more - simply out of curiosity and love reading your analysis)

 

DarthRevan [2836054] Reporter

By the fact it was a script injected into the header of the site, is the presumption that it was a torn player this time correct? Whereas last time it was a server security error and was suspected to be an automatic attach from a bit which saw the weakness(if I’m recalling right) 

 

If that’s the case, is there any way to have a honey-pot trap to try figure out who it is if this happens again in the future 

Nexus [105937]

Reset your API keys, guys...

 

Whenever there is a breach, always reset passwords/API keys used on the breached site.

 

Not everything is always what it appears.

Weav3r [1853324] Helper

Unsure if you're trolling or if you genuinely don't know what TornW3B is. Both are likely so I'll just assume the latter. 

 

It's a site for aggregating all of Torn's bazaars into one place to easily find the best deals on items along with a bunch of statistics I've collected around every item. Most recently I added pricelists too, in order to compete with the monopoly TornExchange recently had on that market given the fall of ArsonWarehouse. 

Lolbits [2275419]

im sorry, hopefully whoever it is leaves you alone now on <3

 

also id bet good money collete is trolling, or just dumb, 50/50 ngl

Danilo [2835519]

Sorry that happenned bro... but I won't be using it in the future, sorry. I'm small fish both buying and selling, I'm no expert, but people can become scared of opening your site.

 

Weav3r [1853324] Helper

Entirely plausible that they just don't know about it too, there's a surprisingly large amount of players who just stay with Vanilla Torn and don't even know what scripts are available, for one reason or another. Also a lot of people who don't care about saving money, for some strange reason!