Welcome, Guest. Please login or register.

Author Topic: Is Aminet OK/infected?  (Read 13100 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Is Aminet OK/infected?
« Reply #14 on: May 11, 2012, 03:04:47 PM »
I'd like to hear an explanation for this however. Unless if the method of original penetration can be figured out and blocked it could happen again and again (as has happened with certain other amiga related sites). Also, it seems that the domain name used to distribute the malware expired (or was changed deliberately).

Some official word from aminet would be in order I'd say.
 

Offline carls

  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 1047
    • Show only replies by carls
Re: Is Aminet OK/infected?
« Reply #15 on: May 11, 2012, 03:37:11 PM »
Quote from: Piru;692729
Unfortunately you cannot trust anything coming from aminet at this stage. The FTP could be distributing malware as well, though luckily windows binaries are in the minority...


Correct. I should've considered Windows and Emulator users before posting. My bad.
Amiga: Too weird to live, too rare to die.
 

Offline desivTopic starter

  • Hero Member
  • *****
  • Join Date: Oct 2009
  • Posts: 1270
    • Show only replies by desiv
Re: Is Aminet OK/infected?
« Reply #16 on: May 11, 2012, 03:37:28 PM »
As a side, I also ran a "full scan" on my machine to be safe.  It found 1 instance of the file on my hard disk (not running, but waiting to be called I'm sure) and recommended a "boot scan" which I did.

The boot scan found a few more waiting to be called..

If  you went there with a Windows machine, even tho your AV caught it, I'd recommend a full scan.
I'll use another product's scan after this to be sure...

desiv
(Didn't I say NOT to go there if you have Windows?  It's bad enough I did..  And it's bad because I've seen encoded javascript "bad programs" before.  Not enough to recognize them, but enough to know there probably shouldn't have been one on Aminet..)
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show only replies by Hitek
Re: Is Aminet OK/infected?
« Reply #17 on: May 11, 2012, 06:19:49 PM »
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
 

Offline desivTopic starter

  • Hero Member
  • *****
  • Join Date: Oct 2009
  • Posts: 1270
    • Show only replies by desiv
Re: Is Aminet OK/infected?
« Reply #18 on: May 11, 2012, 06:25:32 PM »
Quote from: Hitek;692763
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.

I can still get to Amibay, although there were people there saying they were getting virus alerts..
I'm using Linux at the moment..  :razz:
(No, I'm not saying there are no Linux baddies out there...)

Yeah, several people on Amibay are having problems with the main page if they are using Windows (not sure which versions), but several others using Linux aren't having issues..

desiv
« Last Edit: May 11, 2012, 07:02:48 PM by desiv »
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show only replies by Hitek
Re: Is Aminet OK/infected?
« Reply #19 on: May 11, 2012, 06:33:05 PM »
Interesting, I can get to it on my ubuntu box too, but not on my win7 box. I wonder if there is some OS detection going on there.
 

Offline zipper

Re: Is Aminet OK/infected?
« Reply #20 on: May 11, 2012, 06:33:35 PM »
hxxp://ldsysgcaix.igg.biz/d/404.php?go=1 seems same type as the Aminet one.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show only replies by Hitek
Re: Is Aminet OK/infected?
« Reply #21 on: May 11, 2012, 06:50:16 PM »
Quote from: zipper;692767
hxxp://XXXXXXXX.igg.biz/d/404.php?go=1 seems same type as the Aminet one.


yeah, that's what I was saying. Same type of injection attack used on aminet. Probably not a coincidence. The code seems to change as well. I got one earlier for XXXXXXXX.usa.cc/site/main.php? earlier.
 

Offline paul1981

Re: Is Aminet OK/infected?
« Reply #22 on: May 11, 2012, 07:47:26 PM »
Quote from: Hitek;692763
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.

DON'T GO THERE!!!
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG!

STAY WELL AWAY!!
 

Offline Snoozy

  • Sr. Member
  • ****
  • Join Date: Sep 2011
  • Posts: 251
    • Show only replies by Snoozy
Re: Is Aminet OK/infected?
« Reply #23 on: May 11, 2012, 08:14:49 PM »
Whats happened to amibay? my pc won't let me go there (firefox)

How did they catch the virus from aminet? surely they must have had some form of protection?
 

Offline rockape

  • Sr. Member
  • ****
  • Join Date: Nov 2005
  • Posts: 383
    • Show only replies by rockape
    • http://lincsamiga.org.uk/
Re: Is Aminet OK/infected?
« Reply #24 on: May 11, 2012, 08:32:27 PM »
Hi,

I tried logging into Amibay using an A1200 and got:


"Unable to add cookies, header already sent.
File: /homepages/1/d277227762/htdocs/amibay/forum/index.php(1) : eval()'d code
Line: 7"


Regards, Michael

aka rockape
« Last Edit: May 11, 2012, 08:37:32 PM by rockape »
"A veteran is someone who, at one point in their life wrote a blank check made payable to \'Their Country\' for an amount of \'up to and including their life\'.
 

Offline desivTopic starter

  • Hero Member
  • *****
  • Join Date: Oct 2009
  • Posts: 1270
    • Show only replies by desiv
Re: Is Aminet OK/infected?
« Reply #25 on: May 11, 2012, 08:46:10 PM »
Quote from: Snoozy;692778
..surely they must have had some form of protection?

Haven't you had that discussion yet,, where you learned that no protection is 100% effective??  :laugh1:

desiv
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
 

Offline Snoozy

  • Sr. Member
  • ****
  • Join Date: Sep 2011
  • Posts: 251
    • Show only replies by Snoozy
Re: Is Aminet OK/infected?
« Reply #26 on: May 11, 2012, 08:51:03 PM »
Quote from: desiv;692780
Haven't you had that discussion yet,, where you learned that no protection is 100% effective??  :laugh1:

desiv

Errrr what do you mean i thought the stork brought children once they were born :laugh1:

I dare not go to amibay at the moment - when did they get infected?
 

Offline TenWheeler

  • Newbie
  • *
  • Join Date: Apr 2012
  • Posts: 8
  • Country: 00
    • Show only replies by TenWheeler
Re: Is Aminet OK/infected?
« Reply #27 on: May 11, 2012, 09:44:38 PM »
Aminet is now clean.  But Amibay is now infected.
Amiga 4000D, OS3.9, GVP 040, Mediator, Radeon 9250, Spider 2, 8GB CF.
Amiga 3000D OS2.04, 030/25Mhz 16MB, 1.5GB SCSI HD
Amiga 2000 OS3.1.4, 030/25Mhz, 6MB, 4GB CF Buddha, Opailvision, A2088.
Amiga 500 and 1000 stock.
 

Offline Hitek

  • Newbie
  • *
  • Join Date: Mar 2012
  • Posts: 5
    • Show only replies by Hitek
Re: Is Aminet OK/infected?
« Reply #28 on: May 11, 2012, 10:11:28 PM »
Quote from: paul1981;692774
DON'T GO THERE!!!
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG!

STAY WELL AWAY!!

Do you not have virus protection? Any modern virus package should protect against that.

Quote from: Snoozy;692778
Whats happened to amibay? my pc won't let me go there (firefox)

How did they catch the virus from aminet? surely they must have had some form of protection?

Amibay didn't "catch" the virus from aminet, both sites appear to have been hacked at some level. It could have been somebody sneaking something in via sql injection, or someone gaining root level access to the server, it's hard to tell at this point.

Either way, I'm surprised it hasn't been fixed yet. I'm sure *someone* over there has to know about it.

Keith
 

Offline WotTheFook

  • Full Member
  • ***
  • Join Date: Mar 2007
  • Posts: 159
    • Show only replies by WotTheFook
    • http://www.amibay.com
Re: Is Aminet OK/infected?
« Reply #29 from previous page: May 11, 2012, 10:35:43 PM »
We do know about it, I've been researching it all evening.

AmiBay and ClassicAmiga have both been hit with the same script exploit attack that hit Aminet.

It has only been partially effective and the root access, FTP and e-mail have not been compromised. A config file has been corrupted and there is a URL redirect to an ibiz.cc site in place, however, this is only affecting the home page. You should block this ibiz.cc redirect if it comes up on your machine.

If a Java icon appears in your Systray, you should kill it immediately, as this is part of the exploit that is attempting to download malware to your machine.

We hope to have this repaired by tomorrow morning. We backed up the site early this morning and once we have checked the backup config files, we can get the site fully functional again.

In the interim, you can access via any other AmiBay page except the home page. A Google link that isn't the home page will let you access the site, but please ensure that your anti-virus and malware protection is up to date.

WotTheFook aka Merlin
« Last Edit: May 11, 2012, 10:38:07 PM by WotTheFook »