Welcome, Guest. Please login or register.

Author Topic: Avira Alert For Amiga.org  (Read 5807 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline Karlos

  • Sockologist
  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Nov 2002
  • Posts: 16882
  • Country: gb
  • Thanked: 6 times
    • Show only replies by Karlos
Re: Avira Alert For Amiga.org
« Reply #14 from previous page: July 10, 2010, 11:49:50 AM »
Until this problem is fixed, feel free to use the old browser proxy:

http://aoproxy.extropia.co.uk

I've added a snippet of code to eliminate the iframe from the page and removed the automatic redirect to the main site for modern browsers. You can see the effect in the page source:

Code: [Select]

<!-- http://amiga.org/forums/search.php?do=getdaily : retrieved in 0.593s -->
<!--
HeadIFrameEliminator:Bytes in: 17244, out: 17174, took 0.000 s
DegradeXHTMLRewriter:Bytes in: 17174, out: 17105, took 0.001 s
LinkRewriter:Bytes in: 17105, out: 17245, took 0.005 s
MainNavigationRewriter:Bytes in: 17245, out: 17245, took 0.000 s
CommonBlockRewriter:Bytes in: 17245, out: 17300, took 0.000 s
CSSRewriter:Bytes in: 17300, out: 4300, took 0.001 s
JavascriptRewriter:Bytes in: 4300, out: 3989, took 0.000 s
 -->


Unfortunately the iframe output breaks the page with respect to header based redirects, so you'll still see the "redirect" page when you click on "new posts" and the like, but I have confirmed the iframe is not present in any content that is passed through the proxy code.
« Last Edit: July 10, 2010, 11:53:33 AM by Karlos »
int p; // A
 

Offline Pyromania

  • Sent from my Quantum Computer
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1831
  • Country: 00
  • Thanked: 6 times
    • Show only replies by Pyromania
    • http://www.discreetfx.com
Re: Avira Alert For Amiga.org
« Reply #15 on: July 10, 2010, 02:01:37 PM »
Quote from: Mark;569756
Yes, there is an unpatched vBulletin exploit that has hit a number of forums so far.  There is a thread about it at Moo Bunny:
http://moobunny.dreamhosters.com/cgi/mbmessage.pl/amiga/174104.shtml

If anyone can reach Pyromania or the other mods quickly then please do so. I don't see any of them online at the moment.



I'm here
 

Offline smerf

  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 1666
    • Show only replies by smerf
Re: Avira Alert For Amiga.org
« Reply #16 on: July 10, 2010, 02:59:16 PM »
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.




Hi,

I get the same thing with my Avira, except mine says "Looney site warning, staying on this site can cause massive damage to brain cells especially from MAC users"

Do you want to "Place in virus pen"
                      "Delete"
                      "Do nothing"
                      "Leave as fast as your mouse can click"


smerf
I have no idea what your talking about, so here is a doggy with a small pancake on his head.

MorphOS is a MAC done a little better
 

Offline the_leander

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 3448
    • Show only replies by the_leander
    • http://www.extropia.co.uk/theleander/
Re: Avira Alert For Amiga.org
« Reply #17 on: July 10, 2010, 05:21:13 PM »
For those folk using Windows or in fact any other OS with a modern browser I suggest you disable javascript for this site.

Yes, that includes you MacOS and Linux users. Your browser can still be vulnerable to script based attacks and be made to do weird and wonderful things.

And yes, last night there was another attack.

Fun times.
Blessed Be,
Alan Fisher - the_leander

[SIGPIC]http://www.extropia.co.uk/theleander/[/SIGPIC]
 

Offline Karlos

  • Sockologist
  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Nov 2002
  • Posts: 16882
  • Country: gb
  • Thanked: 6 times
    • Show only replies by Karlos
Re: Avira Alert For Amiga.org
« Reply #18 on: July 10, 2010, 05:47:58 PM »
Quote from: the_leander;569811
For those folk using Windows or in fact any other OS with a modern browser I suggest you disable javascript for this site.

Yes, that includes you MacOS and Linux users. Your browser can still be vulnerable to script based attacks and be made to do weird and wonderful things.

And yes, last night there was another attack.

Fun times.


IMO, one should use a script blocker by default when viewing any site.
int p; // A
 

Offline Pyromania

  • Sent from my Quantum Computer
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1831
  • Country: 00
  • Thanked: 6 times
    • Show only replies by Pyromania
    • http://www.discreetfx.com
Re: Avira Alert For Amiga.org
« Reply #19 on: July 10, 2010, 06:27:27 PM »
Quote from: Managarm;569722
Hi All,

On my Windows XP machine my AV, Avira Anti-Virus 10.0.0.567 has just started complaining when I visit this site. Is this a false positive? (I'm assuming it is.) The infected file details are very vague and I can't find a proper description online of the type of infection.

Any ideas anyone? I've attached a couple of sreenshots.

Thanks,
Robin.


I just now accessed the site after Karlos did some cleanup and I get no warning messages using Avira AntiVirus under a Windows Virtual Machine. Could you try your Avira again and make sure it no longer gives you a warning?

@x56h34 & matt020

If you have time could you please check with your Avira as well?
« Last Edit: July 10, 2010, 06:32:01 PM by Pyromania »
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Avira Alert For Amiga.org
« Reply #20 on: July 10, 2010, 06:35:25 PM »
Quote from: Pyromania;569817
I just now accessed the site after Karlos did some cleanup and I get no warning messages using Avira AntiVirus under a Windows Virtual Machine.
Have you actually done the forensics and figured out how the security was breached and the websites modified? Have you actually fixed the vulnerability that was used?

Just removing the modifications done by the attacker will not work.
 

Offline Pyromania

  • Sent from my Quantum Computer
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1831
  • Country: 00
  • Thanked: 6 times
    • Show only replies by Pyromania
    • http://www.discreetfx.com
Re: Avira Alert For Amiga.org
« Reply #21 on: July 10, 2010, 06:40:00 PM »
Quote from: Piru;569818
Have you actually done the forensics and figured out how the security was breached and the websites modified? Have you actually fixed the vulnerability that was used?

Just removing the modifications done by the attacker will not work.



Your right of course and we already know this. Measures are being taken to fix the vulnerability that was used.
 

Offline issarad

  • Jr. Member
  • **
  • Join Date: Aug 2003
  • Posts: 51
    • Show only replies by issarad
Re: Avira Alert For Amiga.org
« Reply #22 on: July 10, 2010, 06:41:58 PM »
Not getting the warning from Avira anymore.  Thanks!
......
 

Offline Pyromania

  • Sent from my Quantum Computer
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 1831
  • Country: 00
  • Thanked: 6 times
    • Show only replies by Pyromania
    • http://www.discreetfx.com
Re: Avira Alert For Amiga.org
« Reply #23 on: July 10, 2010, 06:43:07 PM »
Quote from: issarad;569820
Not getting the warning from Avira anymore.  Thanks!


Thanx for checking.

:)
 

Offline x56h34

  • Hero Member
  • *****
  • Join Date: Sep 2003
  • Posts: 2921
    • Show only replies by x56h34
Re: Avira Alert For Amiga.org
« Reply #24 on: July 10, 2010, 11:22:38 PM »
It's ok for me now as well (Avira, latest definition files, Win 7). Thanks.
« Last Edit: July 11, 2010, 03:44:10 AM by x56h34 »