BetaONE will rise again!


Reply
  #21  
Old 13th Nov 07, 04:54 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
Try B1 again after clearing cookies. i cleaned redirect screen.
__________________

Reply With Quote
  #22  
Old 13th Nov 07, 10:06 AM
freezer121 freezer121 is offline
BetaONE Supporter
 
Join Date: Oct 2001
Location: UK
Posts: 239
freezer121 is on a distinguished road
I cleared my Firefox betaone cookie, restarted and brought up the site; NOD lit up again, this time with a different trojan name. I made a nonsense of capturing the screen so can't be more explicit - sorry.

Most worrying, I saw a reference to Paypal (bottom left of the screen) before I got to B1. Don't know if it was loading the Donate button or up to no good!

NOD terminated whatever was going on and asked me to submit the trojan, which I did.

Having spent most of yesterday morning scanning with Defender, Counterspy and NOD, I am confident NOD is keeping me clean - but it's quite an exciting ride to B1 these days.
Reply With Quote
  #23  
Old 13th Nov 07, 02:37 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
Got this again today:




It now seems to be loading even more sites than previously. If you compare this screenshot to the previous one, you will notice that the site is different. O, and I did clear my cookies. Get the same in IE7 and in Firefox.



Cheerz
Dave
__________________



Last edited by Voodoo : 13th Nov 07 at 02:58 PM.
Reply With Quote
  #24  
Old 13th Nov 07, 04:54 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
It seems that there could be be multiple instances of the exploit installed on different pages on the server. Might have to go through them one by one as virus scanners don't seem to be able to detect them on the server
__________________

Reply With Quote
  #25  
Old 14th Nov 07, 08:53 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
Mike, did you fix this? Much appreciated.

Cheerz
Dave
__________________


Reply With Quote
  #26  
Old 17th Nov 07, 09:38 AM
freezer121 freezer121 is offline
BetaONE Supporter
 
Join Date: Oct 2001
Location: UK
Posts: 239
freezer121 is on a distinguished road
It all seems fine now, thanks for fixing it.
Reply With Quote
  #27  
Old 17th Nov 07, 07:18 PM
KingCobra's Avatar
KingCobra KingCobra is offline
Senior Member
 
Join Date: Dec 2001
Location: Illinois
Posts: 2,409
KingCobra is on a distinguished road
Send a message via Yahoo to KingCobra
I have been surfing betaone with my wii to be safe. IS the problem really fixed now. Where did it come from.
__________________
Reply With Quote
  #28  
Old 18th Nov 07, 01:53 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
It seems to have come from another web admin on the server installing a program with a security flaw or other vulnerability. Please be assured that the server is constantly being updated and regular AntiVirus scans do take place, it's just hard for any single AV program to catch all the numerous windows exploits in circulation. The recent spate of problems stems from a a trojan that inserted a java script 'exploit' into one of the redirect pages for the B1 website. Unfortunately, once the system was cleaned of the trojan the javascript remained. The affected file was cleaned by hand and write protected to prevent any further problems. There was around a 24 hours delay before the users saw any benefit from the 'disinfection(?)' whilst local cache's were cleared etc.
All should b e fine now and i apologize for any inconvenience caused.

EDIT: @ Cactus: The index.php is fine, it's the portal redirect that isn't updated when we update the VBulletin software that was infected A few permission changes on the server and a quick lookie see later and it's all sorted BTW, Where the hell have you been??? Its been too long- PM me and come in from the wilderness We miss ya bud!
__________________


Last edited by DoG : 18th Nov 07 at 02:01 AM. Reason: Additional info
Reply With Quote
  #29  
Old 18th Nov 07, 07:28 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
Shit, it is back again and now loads more sites than before? How can this be?

DoG, help.

Cheerz
Dave
__________________


Reply With Quote
  #30  
Old 19th Nov 07, 01:32 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
Fixed- again

Not sure what is going on but it seems that the file attributes were changed to allow the file to be written to again. I changed the security settins so it should be good now.
Clear all cookies and internet cache and try again please.
__________________

Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected job search sites lead to info theft for 46,000 NewsBot NeoWin News 0 19th Aug 07 08:18 PM
Hundreds Click on 'Click Here to Get Infected' Ad NewsBot DriverHeaven News 0 20th May 07 06:36 PM
Don't get infected on Valentine's Day Alpine BetaONE News 0 14th Feb 07 11:21 PM
HP Mistakenly Distributes Drivers Infected with Virus NewsBot NeoWin News 0 2nd Jun 06 09:30 PM
Infected email from betaone? Dave Chit Chat 8 17th Feb 06 06:58 AM


All times are GMT +1. The time now is 02:33 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.