Welcome, Guest. Please login or register.

Author Topic: Is Aminet OK/infected?  (Read 13104 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show all replies
Re: Is Aminet OK/infected?
« on: May 11, 2012, 06:19:49 PM »
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show all replies
Re: Is Aminet OK/infected?
« Reply #1 on: May 11, 2012, 06:33:05 PM »
Interesting, I can get to it on my ubuntu box too, but not on my win7 box. I wonder if there is some OS detection going on there.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show all replies
Re: Is Aminet OK/infected?
« Reply #2 on: May 11, 2012, 06:50:16 PM »
Quote from: zipper;692767
hxxp://XXXXXXXX.igg.biz/d/404.php?go=1 seems same type as the Aminet one.


yeah, that's what I was saying. Same type of injection attack used on aminet. Probably not a coincidence. The code seems to change as well. I got one earlier for XXXXXXXX.usa.cc/site/main.php? earlier.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show all replies
Re: Is Aminet OK/infected?
« Reply #3 on: May 11, 2012, 10:11:28 PM »
Quote from: paul1981;692774
DON'T GO THERE!!!
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG!

STAY WELL AWAY!!

Do you not have virus protection? Any modern virus package should protect against that.

Quote from: Snoozy;692778
Whats happened to amibay? my pc won't let me go there (firefox)

How did they catch the virus from aminet? surely they must have had some form of protection?

Amibay didn't "catch" the virus from aminet, both sites appear to have been hacked at some level. It could have been somebody sneaking something in via sql injection, or someone gaining root level access to the server, it's hard to tell at this point.

Either way, I'm surprised it hasn't been fixed yet. I'm sure *someone* over there has to know about it.

Keith