Virus alert?

The latest Team MightyBoy news and updates, plus your ideas and feedback
User avatar
oti
Posts: 303
Joined: Sat Mar 26, 2005 11:36 pm

McAfee is giving me alert on the following virus when browsing TAMON forums.


JS/Exploit-MhtRedir.gen Trojan.

It gets deleted every time, but its something new that has popped up.
altoworks.info now being domain squatted... joy.
[url=http://www.altoworks.info][img]http://img261.echo.cx/img261/8177/avatarcopy5jq.jpg[/img][/url]
Gladier
Posts: 235
Joined: Sun Feb 06, 2005 11:22 am
Location: Central Coast

this is different to the last one...

Nod32 comes up with a visual basic sript exploit.Phel.I trojan. But the trojan doesnt come from tamon... it comes from 82.179.170.11 which is a pc in north central netherland. cant resolve the ip to a host name and only ftp, http and dns ports are open.

probably the best option would be to block the ip address in an internal firewall till brayden can get ontop of it

security patches to prevent the trojan are available at
http://www.microsoft.com/technet/securi ... 5-001.mspx

the virus is spread through mhttp.

there is/was another case of this where a site was hacked and the html code was changed..
User avatar
Brayden
Posts: 9101
Joined: Sun Apr 11, 2004 3:09 am
Location: Canberra ACT
Contact:

Hey guys, I'm not getting any virus warnings on my PC (WinXP / Norton / FireFox / D-Link router w/firewall)
The only time this site was hacked it wasn't malicious, just an html index page and some other little file structure changes.

The site host has made some unannounced changes to the server that caused a few issues over the last couple of days but they're absolutely useless at giving support. Thankfully I managed to solve that.
eDave is currently working on the new site and it will be hosted on a new server, which will see an end to these niggling issues.
F8B EFI turbo - Three pots and a snail.
User avatar
Brayden
Posts: 9101
Joined: Sun Apr 11, 2004 3:09 am
Location: Canberra ACT
Contact:

Gladier, thanks for that IP address. I've blocked it from accessing the server, which should hopefully fix the problem.

As this problem is a Microsoft exploit, I would suggest that people don't use shitty Internet Explorer and switch to something like FireFox or Opera. ;)
F8B EFI turbo - Three pots and a snail.
User avatar
Josh
Posts: 1263
Joined: Tue Apr 13, 2004 2:22 am
Location: Canberra ACT
Contact:

Image! w00t!
[url=http://www.tamon.org/?page=owners&id=10][img]http://www.tamon.org/forum/images/ute_specs.gif[/img][/url]
User avatar
eDave
Posts: 513
Joined: Mon Apr 12, 2004 9:11 pm
Location: Sydney, Australia
Contact:

fix in progress

EDIT: fixed. f*#king stupid ghey hacker script kiddies
User avatar
Brayden
Posts: 9101
Joined: Sun Apr 11, 2004 3:09 am
Location: Canberra ACT
Contact:

:bow: \:D/
F8B EFI turbo - Three pots and a snail.
mowog
Posts: 970
Joined: Sun Apr 25, 2004 2:22 am

I was trying to browse klass last night using Mozilla and I kept getting the
Active X warning(I have active x completely blocked) I was getting about 12 or so warnings and also a page was trying to open but was blank presumably because of Active x being blocked. I had to keep clicking X on both to get rid of it, every time I tried acces a page it would come up, eventually i gave up, but it's not here tonight (I am on IE tonight) can't remember the dtails but it was some Ad title in CC wherever that is.
User avatar
eDave
Posts: 513
Joined: Mon Apr 12, 2004 9:11 pm
Location: Sydney, Australia
Contact:

Sorry mate, mozilla doesnt have ActiveX
I think you're thinking of Javascript as that's what this hack was.
Gladier
Posts: 235
Joined: Sun Feb 06, 2005 11:22 am
Location: Central Coast

i take it that it was the first few lines of javascript at the top of every page?
User avatar
eDave
Posts: 513
Joined: Mon Apr 12, 2004 9:11 pm
Location: Sydney, Australia
Contact:

Yeah.
It was simply an encoded script which when run would write an iframe to the browser and attempt to load another site.
I've secured up the forum a bit as well, so hopefully it won't happen again before I move it over the new server (where, if anyone plays around with it, will get utterly punished).

Phear /\/\3 |<1dd13z.
Gladier
Posts: 235
Joined: Sun Feb 06, 2005 11:22 am
Location: Central Coast

i went and did come research on EVAL... i didnt think it looked like it should be there... looks like its a preety powerful command
User avatar
eDave
Posts: 513
Joined: Mon Apr 12, 2004 9:11 pm
Location: Sydney, Australia
Contact:

yeah - but the secret is to replace eval with alert and it displays the code they've encrypted.
mowog
Posts: 970
Joined: Sun Apr 25, 2004 2:22 am

I run both ie and mozilla I don't particularly like mozilla I only use it for email usually but I am pretty sure I was on mozilla at the time but if U say I couldn't have been then I couldn't have been!
I think someone should write a poison pill script that when a hacker tries to put some spam or ad or whatever on your computer it automatically sends back a poison pill that after say a day Or when some event occurs like the 500th "E" is received at it starts to wreck the script on their computer.
Gladier
Posts: 235
Joined: Sun Feb 06, 2005 11:22 am
Location: Central Coast

umm just quicklydave... you need to remove it from the main site and from braydens cpanel ....
Post Reply