Welcome, Guest. Please login or register.

Author Topic: Rougue er all  (Read 6811 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline DiskDoctor

  • Sr. Member
  • ****
  • Join Date: Jan 2009
  • Posts: 308
    • Show only replies by DiskDoctor
Re: Rougue er all
« Reply #44 from previous page: July 25, 2009, 04:23:41 PM »
Quote from: Piru;516808
The website is infected with pharming attacks: As soon as you browse the site the malicious code will attempt to take over your system by using multitudes of different methods, including infected swf and pdf documents abusing vulnerabilities in Flash player and Adobe Acrobat.

The malicious files are hosted in chinese (.cn) domains.

It is quite likely that amigann is innocent victim here aswell, and the site has been hacked. I'll investigate further soon. Meanwhile, I am urging caution when browsing the site. Even better, avoid the site altogether.

update1:

As far as I can tell the malware comes from malicious google ads. Suspicious URLs look like:
Code: [Select]

http://****mail.org/licky/etChunksFrom.swf
http://****anag.cn/rf/fromFactLooks.swf
http://****ci.cn/redirect/include/spl.php?stat=Linux|Mozilla%205.0|FI|Mozilla


Man, this is ill.

How in the hell could Google, Inc. help in delivering malicious content to the users??  Do they have a disclaimer in their ad argreement that they aren't responsible for the content?  Is this LEGALLY correct?

You know G Inc is some sort of a virgin in an IT world.  They made cool search, cool video storage (by buying it), coll ajax mail, cool cellphones, browser, but unlike Microsoft or Apple, no one ever sued them yet.  

Maybe it is high time someone did then?

After reading this, I would be first person todo so.
Was: Mac Mini PPC running MorphOS 2.4
Now: Amiga Forever 2010 with AmiKit and AmigaSYS
Not used: Icaros Desktop 1.2 (reason: no wifi)
Planned soon: an OS4 system
Shortly then: a MOS notebook (wifi is a must-have)
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Rougue er all
« Reply #45 on: July 25, 2009, 04:39:09 PM »
Quote from: DiskDoctor;516816
How in the hell could Google, Inc. help in delivering malicious content to the users?
Google isn't, directly.

The ads are such that they have either time or IP address (or something else) triggering the extra content. At the time of the ad purchase or when google looks at it, it appears perfectly legit. Only after the trigger fires the malware is activated. I've seen this trick being used quite a lot lately. Many high profile sites have been hit.

There's very little google can do to fight against such attacks.
Quote
Maybe it is high time someone did then?
I don't know what that would accomplish really.

Users can fight against these attacks by making sure that their antivirus, operating system and applications are always kept up to date. Windows users should install Secunia Personal Software Inspector.
« Last Edit: July 25, 2009, 04:44:06 PM by Piru »
 

Offline DiskDoctor

  • Sr. Member
  • ****
  • Join Date: Jan 2009
  • Posts: 308
    • Show only replies by DiskDoctor
Re: Rougue er all
« Reply #46 on: July 25, 2009, 04:44:49 PM »
Quote from: Piru;516817
Google isn't, directly.

The ads are such that they have either time or IP address (or something else) triggering the extra content. At the time of the ad purchase or when google looks at it, it appears perfectly legit. Only after the trigger fires the malware is activated. I've seen this trick being used quite a lot lately. Many high profile sites have been hit.

There's very little google can do to fight against such attacks.

I don't know what that would accomplish really.


Someone's legal responsitivity for someone else's loss.

You know my type.  Help in malware distribution is a crime I guess, both here, in US, name it.

Technical limitations MUST NOT drive some action's legal justification.  You do something wrong and you cannot fix it, LEAVE IT OR TAKE RESPONSITIVITY.
« Last Edit: July 25, 2009, 04:47:28 PM by DiskDoctor »
Was: Mac Mini PPC running MorphOS 2.4
Now: Amiga Forever 2010 with AmiKit and AmigaSYS
Not used: Icaros Desktop 1.2 (reason: no wifi)
Planned soon: an OS4 system
Shortly then: a MOS notebook (wifi is a must-have)
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Rougue er all
« Reply #47 on: July 25, 2009, 04:47:44 PM »
Quote from: DiskDoctor;516818
Someone's legal responsitivity for someone else's loss.

You know my type.  Help in malware distribution is a crime I guess, both here, in US, name it.

So, I guess this means that if someone hacks your computer and uses it to distribute malware, you should be held accountable for all damages? ;)

IMHO google is equally a victim here.
 

Offline DiskDoctor

  • Sr. Member
  • ****
  • Join Date: Jan 2009
  • Posts: 308
    • Show only replies by DiskDoctor
Re: Rougue er all
« Reply #48 on: July 25, 2009, 04:51:58 PM »
Quote from: Piru;516819
So, I guess this means that if someone hacks your computer and uses it to distribute malware, you should be held accountable for all damages? ;)

IMHO google is equally a victim here.


It depends.  If you conciously left your notebook without any password in some public place, then YOU.

Google should fix their security procedures; limit technologies, rise prices and store&check all served content etc. IMAO.
Was: Mac Mini PPC running MorphOS 2.4
Now: Amiga Forever 2010 with AmiKit and AmigaSYS
Not used: Icaros Desktop 1.2 (reason: no wifi)
Planned soon: an OS4 system
Shortly then: a MOS notebook (wifi is a must-have)
 

Offline DiskDoctor

  • Sr. Member
  • ****
  • Join Date: Jan 2009
  • Posts: 308
    • Show only replies by DiskDoctor
Re: Rougue er all
« Reply #49 on: July 25, 2009, 05:03:14 PM »
@Piru

OK but this is off topic.  I'll just leave the matter and have discussed with someone else.

Actually my temper here comes from the fact that this October I start PG IP Law studies So I kindda like those issues :lol:
Was: Mac Mini PPC running MorphOS 2.4
Now: Amiga Forever 2010 with AmiKit and AmigaSYS
Not used: Icaros Desktop 1.2 (reason: no wifi)
Planned soon: an OS4 system
Shortly then: a MOS notebook (wifi is a must-have)
 

Offline Tension

Re: Rougue er all
« Reply #50 on: July 26, 2009, 09:47:14 PM »
Quote from: Piru;516808
The website is infected with pharming attacks: As soon as you browse the site the malicious code will attempt to take over your system by using multitudes of different methods, including infected swf and pdf documents abusing vulnerabilities in Flash player and Adobe Acrobat.

The malicious files are hosted in chinese (.cn) domains.

It is quite likely that amigann is innocent victim here aswell, and the site has been hacked. I'll investigate further soon. Meanwhile, I am urging caution when browsing the site. Even better, avoid the site altogether.

update1:

As far as I can tell the malware comes from malicious google ads. Suspicious URLs look like:
Code: [Select]

http://****mail.org/licky/etChunksFrom.swf
http://****anag.cn/rf/fromFactLooks.swf
http://****ci.cn/redirect/include/spl.php?stat=Linux|Mozilla%205.0|FI|Mozilla


I wondered why my acrobat reader was going mental!!