Amiga.org

Amiga computer related discussion => General chat about Amiga topics => Topic started by: Managarm on July 10, 2010, 12:22:50 AM

Title: Avira Alert For Amiga.org
Post by: Managarm on July 10, 2010, 12:22:50 AM
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.
Title: Re: Avira Alert For Amiga.org
Post by: x56h34 on July 10, 2010, 01:39:12 AM
Same here with Avira and Win 7.
Title: Re: Avira Alert For Amiga.org
Post by: matt020 on July 10, 2010, 01:45:50 AM
I also receved this warning from Avira.
Title: Re: Avira Alert For Amiga.org
Post by: som99 on July 10, 2010, 01:46:50 AM
Just chill, it's nothing to be worried about :)
Title: Re: Avira Alert For Amiga.org
Post by: Plaz on July 10, 2010, 02:12:31 AM
My site scanner isn't complaining. (not running Win7 though)

Plaz
Title: Re: Avira Alert For Amiga.org
Post by: AmigaHeretic on July 10, 2010, 02:23:48 AM
Quote from: som99;569737
Just chill, it's nothing to be worried about :)


I'm not so sure.  Amiga.org had been infected with the "brutal dildo" thing for an unknown period of time.  They just fixed that a day or two ago.

Maybe this is related?
Title: Re: Avira Alert For Amiga.org
Post by: AmigaHeretic on July 10, 2010, 02:30:16 AM
Quote from: AmigaHeretic;569739
I'm not so sure.  Amiga.org had been infected with the "brutal dildo" thing for an unknown period of time.  They just fixed that a day or two ago.

Maybe this is related?


Quick look through the source code and no "brutal dildo" stuff.

This however is the first line of the html code:

http://stolenvessels.com/images/7rt8/index.php

??
Title: Re: Avira Alert For Amiga.org
Post by: Drummerboy on July 10, 2010, 02:39:52 AM
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.


If you Browse with Amiga.. No Virus Problem!!.. :afro:
Title: Re: Avira Alert For Amiga.org
Post by: issarad on July 10, 2010, 02:55:34 AM
Yeah, got it on my Win7 and avira combo, too.  I'm guessing it's more than likely just a false positive.
Title: Re: Avira Alert For Amiga.org
Post by: halvliter'n on July 10, 2010, 03:21:08 AM
Quote from: AmigaHeretic;569740
Quick look through the source code and no "brutal dildo" stuff.

Haha.. There was something about Iphone mobile porn and ex girlfriends too.

Has no virus warning here then.
Title: Re: Avira Alert For Amiga.org
Post by: ChaosLord on July 10, 2010, 03:49:22 AM
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.

 I am getting the same warning!  This is scary!  @Karlos Please fix.
Title: Re: Avira Alert For Amiga.org
Post by: Mark on July 10, 2010, 06:30:30 AM
Yes, there is an unpatched vBulletin exploit that has hit a number of forums so far.  There is a thread about it at Moo Bunny:
http://moobunny.dreamhosters.com/cgi/mbmessage.pl/amiga/174104.shtml

If anyone can reach Pyromania or the other mods quickly then please do so. I don't see any of them online at the moment.
Title: Re: Avira Alert For Amiga.org
Post by: mpiva on July 10, 2010, 06:31:11 AM
I just got same warning. Running AVIRA on WinXP.
Title: Re: Avira Alert For Amiga.org
Post by: Piru on July 10, 2010, 10:00:36 AM
http://www.amiga.org/forums/project.php?issueid=65#note255
Title: Re: Avira Alert For Amiga.org
Post by: Karlos on July 10, 2010, 11:49:50 AM
Until this problem is fixed, feel free to use the old browser proxy:

http://aoproxy.extropia.co.uk

I've added a snippet of code to eliminate the iframe from the page and removed the automatic redirect to the main site for modern browsers. You can see the effect in the page source:

Code: [Select]

<!-- http://amiga.org/forums/search.php?do=getdaily : retrieved in 0.593s -->
<!--
HeadIFrameEliminator:Bytes in: 17244, out: 17174, took 0.000 s
DegradeXHTMLRewriter:Bytes in: 17174, out: 17105, took 0.001 s
LinkRewriter:Bytes in: 17105, out: 17245, took 0.005 s
MainNavigationRewriter:Bytes in: 17245, out: 17245, took 0.000 s
CommonBlockRewriter:Bytes in: 17245, out: 17300, took 0.000 s
CSSRewriter:Bytes in: 17300, out: 4300, took 0.001 s
JavascriptRewriter:Bytes in: 4300, out: 3989, took 0.000 s
 -->


Unfortunately the iframe output breaks the page with respect to header based redirects, so you'll still see the "redirect" page when you click on "new posts" and the like, but I have confirmed the iframe is not present in any content that is passed through the proxy code.
Title: Re: Avira Alert For Amiga.org
Post by: Pyromania on July 10, 2010, 02:01:37 PM
Quote from: Mark;569756
Yes, there is an unpatched vBulletin exploit that has hit a number of forums so far.  There is a thread about it at Moo Bunny:
http://moobunny.dreamhosters.com/cgi/mbmessage.pl/amiga/174104.shtml

If anyone can reach Pyromania or the other mods quickly then please do so. I don't see any of them online at the moment.



I'm here
Title: Re: Avira Alert For Amiga.org
Post by: smerf on July 10, 2010, 02:59:16 PM
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.




Hi,

I get the same thing with my Avira, except mine says "Looney site warning, staying on this site can cause massive damage to brain cells especially from MAC users"

Do you want to "Place in virus pen"
                      "Delete"
                      "Do nothing"
                      "Leave as fast as your mouse can click"


smerf
Title: Re: Avira Alert For Amiga.org
Post by: the_leander on July 10, 2010, 05:21:13 PM
For those folk using Windows or in fact any other OS with a modern browser I suggest you disable javascript for this site.

Yes, that includes you MacOS and Linux users. Your browser can still be vulnerable to script based attacks and be made to do weird and wonderful things.

And yes, last night there was another attack.

Fun times.
Title: Re: Avira Alert For Amiga.org
Post by: Karlos on July 10, 2010, 05:47:58 PM
Quote from: the_leander;569811
For those folk using Windows or in fact any other OS with a modern browser I suggest you disable javascript for this site.

Yes, that includes you MacOS and Linux users. Your browser can still be vulnerable to script based attacks and be made to do weird and wonderful things.

And yes, last night there was another attack.

Fun times.


IMO, one should use a script blocker by default when viewing any site.
Title: Re: Avira Alert For Amiga.org
Post by: Pyromania on July 10, 2010, 06:27:27 PM
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.


I just now accessed the site after Karlos did some cleanup and I get no warning messages using Avira AntiVirus under a Windows Virtual Machine. Could you try your Avira again and make sure it no longer gives you a warning?

@x56h34 & matt020

If you have time could you please check with your Avira as well?
Title: Re: Avira Alert For Amiga.org
Post by: Piru on July 10, 2010, 06:35:25 PM
Quote from: Pyromania;569817
I just now accessed the site after Karlos did some cleanup and I get no warning messages using Avira AntiVirus under a Windows Virtual Machine.
Have you actually done the forensics and figured out how the security was breached and the websites modified? Have you actually fixed the vulnerability that was used?

Just removing the modifications done by the attacker will not work.
Title: Re: Avira Alert For Amiga.org
Post by: Pyromania on July 10, 2010, 06:40:00 PM
Quote from: Piru;569818
Have you actually done the forensics and figured out how the security was breached and the websites modified? Have you actually fixed the vulnerability that was used?

Just removing the modifications done by the attacker will not work.



Your right of course and we already know this. Measures are being taken to fix the vulnerability that was used.
Title: Re: Avira Alert For Amiga.org
Post by: issarad on July 10, 2010, 06:41:58 PM
Not getting the warning from Avira anymore.  Thanks!
Title: Re: Avira Alert For Amiga.org
Post by: Pyromania on July 10, 2010, 06:43:07 PM
Quote from: issarad;569820
Not getting the warning from Avira anymore.  Thanks!


Thanx for checking.

:)
Title: Re: Avira Alert For Amiga.org
Post by: x56h34 on July 10, 2010, 11:22:38 PM
It's ok for me now as well (Avira, latest definition files, Win 7). Thanks.