Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: 1 ... 3 4 [5] 6 7

Author Topic: Warning - DSLzone site compromised  (Read 36577 times)

UncleUB

  • Helpful
  • Senior Kitizen
  • *
  • Posts: 29543
Re: Warning - DSLzone site compromised
« Reply #60 on: March 24, 2010, 04:19:11 PM »

@ the doctor,

I don't see how you can make jokes about something so serious as a malicious website attack  >:(
Logged

the doctor

  • Member
  • **
  • Posts: 26
Re: Warning - DSLzone site compromised
« Reply #61 on: March 24, 2010, 04:38:33 PM »

@ the joke is.. it could have been prevented....  >:( >:( >:( >:( >:( >:( >:( >:(
Logged
A great philosopher once wrote "Naughty, naughty, very naughty"

Quasimoto

  • Member
  • **
  • Posts: 12
Re: Warning - DSLzone site compromised
« Reply #62 on: March 24, 2010, 07:25:13 PM »

Could any of these noscript firefox extensions or such have stopped this getting in through firefox? or would it have gotten in regardless?
Logged
CappySpectrum

silversurfer44

  • Kitizen
  • ****
  • Posts: 4421
  • Lord Muck
    • Ben Novice Weather
Re: Warning - DSLzone site compromised
« Reply #63 on: March 24, 2010, 08:04:57 PM »

Hi Quasimoto, I use noscript with FF although I run a Linux OS. I don't think the extension would stop something like you all experienced because it did not show up on my machine. My experience with noscript is that it is excellent at stopping unwanted scripts running on the page itself, as for the page banner I don't know. Maybe you could get more information from the noscript website.
Logged
Colin II : It's no good being a pessimist, it wouldn't work anyway.

CurlyWhirly

  • Reg Member
  • ***
  • Posts: 370
Re: Warning - DSLzone site compromised
« Reply #64 on: March 24, 2010, 10:04:21 PM »

Will be sorry to see you guys go... :cry2:

Regards,

thar
Cheers thar.

I can't risk malware getting onto my PC as I use my PC for online banking and also buying stuff online.

I value my security and won't go on to websites that could pose a risk in the future.

We have heard virtually nothing about the type of malware (trojans) and who is to say that it is only our e-mail addresses that have been harvested by spammers?

If the site wasn't kept up to date there could be a case of us having our passwords harvested for example  :hmm:
Logged
Mike

CurlyWhirly

  • Reg Member
  • ***
  • Posts: 370
Re: Warning - DSLzone site compromised
« Reply #65 on: March 24, 2010, 10:05:57 PM »

Could any of these noscript firefox extensions or such have stopped this getting in through firefox? or would it have gotten in regardless?
I also use NoScript and it didn't stop wierd things happening on my PC which I assume was caused by the malware?
Logged
Mike

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Warning - DSLzone site compromised
« Reply #66 on: March 24, 2010, 11:31:57 PM »

I'm not sure if theres some new and weird stuff thats going around atm.

I currently have here a laptop for repair that appears to have been root-kitted :(
Its a bit of a nightmare this one - it got past AVG, and according to the owner, got in via an ad displayed on a website that they frequent (nothing naughty).  The time of the attack, and also from looking at their browser history would seem to confirm this.

Over the years I normally enjoy the challenge of sweeping up infected PCs as viruses are something I sidetracked into when doing my dissertation.
.. But this one is a real nasty.

Im still working on it.... as malware bytes says its clean, but Rootkitrevealer is still showing something weird and Im still having probs accessing some essential windows files but so far this is what its done/did

~ Disabled access to Control Panel, Task Manager, Sys restor,  cmd, windows event logging and various sys32 files.
~ Disabled regedit - no access to the registry.
~ Disabled:AVG. Stopped access to M$ sites & other AV type sites.
~ Stopped any AV or malware scanners being run such as HJT, malwarebytes.
~ Trojan still ran when in safe mode - had also accessed memory module.
~ Multipart which regenerated itself using polymorphic naming.  Was about a dozen parts so if you didnt get it all at once, it just simply regen'd itself.
~ Took over Windows Administrator account.  I tried to access via administrator in safe mode and it had changed the main admin password so you couldnt get in.
~ Changed numerous policies & permissions (machine was XPHome so no gpedit :/)
~ Blew a massive hole in the firewall and opened various ports, and now the machine was a nice target for just about any piece of crap that was floating around the internet. - To be precise another 23 viruses, trojans and other assorted malware.


Stresses that the above did NOT come from the dslzone attack..  and its NOT the same thing that you guys are seeing.

The point being that new variants of viruses are being released all the time and thats why making sure our AV is kept up to date and patched.
Ive been online now for about 13/14 yrs and iirc the only time ive ever suffered from such like is back in 2002/2003 on the very night that sql slammer was released into the wild.   It got me about 30mins after it was released... but it was so new that none of the AVs could offer any protection against it.  It was a few days before M$ released a patch for  MSDE sql and even longer before the AVs started offering protection.
:'(

None of us should be too complacent either, because I know of several forums which have been attacked through brand new security issues that have come to light, luckily these were more minor stuff such as spam bots type and not malicious stuff...  but in the world of computing we all have constantly alert :/



Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Warning - DSLzone site compromised
« Reply #67 on: March 24, 2010, 11:36:07 PM »

The thing here is thar has done a damn good job trying to keep things running smoothly over at dslzone and its a shame that its come to this.  Im pretty sure no-one could have done anymore in the same situation.

I will re-iterate and confirm that the malicious code that was injected has now been removed. 
The only person that can advise if the forum software has now been updated and patched is James.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

Quasimoto

  • Member
  • **
  • Posts: 12
Re: Warning - DSLzone site compromised
« Reply #68 on: March 25, 2010, 03:24:42 AM »

Yeah, thar has limited access. :/ If only he had full access he could have fixed it much quicker than James.

It really makes one paranoid browsing the net. It took me nearly a whole day to fix mine from Feb 6. So hard to pin point these problems down and whatever nasties it disables etc.

The one that happened to mine nuked the login info for the DHCP service as well as other nasties. Thankfully I was triple booting to solve this as it was also stalling or hanging Trend Micro Pro 2010. It just wouldn't load but it wasn't crashing either. I'd probably be in serious snook if my only install was Win7.

I really wish UAC was like OS X accounts or such. Nothing can change unless you enter the admin username and pass. Goes to show how somewhat useless UAC really is.

Saying that, nobody is safe. http://www.neowin.net/news/safari-firefox-and-ie8-hacked-chrome-left-untested
« Last Edit: March 25, 2010, 04:27:19 AM by Quasimoto »
Logged
CappySpectrum

CurlyWhirly

  • Reg Member
  • ***
  • Posts: 370
Re: Warning - DSLzone site compromised
« Reply #69 on: March 25, 2010, 08:05:25 AM »

I will re-iterate and confirm that the malicious code that was injected has now been removed. 
The only person that can advise if the forum software has now been updated and patched is James.
Yes it is for this very reason that I won't be visiting there anymore.

I know James is a busy man (running ADSL24) but the lack of clarification is wrong in my opinion.
Logged
Mike

CurlyWhirly

  • Reg Member
  • ***
  • Posts: 370
Re: Warning - DSLzone site compromised
« Reply #70 on: March 25, 2010, 08:14:18 AM »

Im still working on it.... as malware bytes says its clean, but Rootkitrevealer is still showing something weird.
Mmm... I just tried to install the trial version of RootKit Revealer and I got this error message:




I've not run a rootkit utility before but surely this shouldn't happen?

I think I'm going to restore a Norton Ghost backup image before all this weird behaviour started i.e. around a week ago  ???

Logged
Mike

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Warning - DSLzone site compromised
« Reply #71 on: March 25, 2010, 10:35:28 AM »

From the screen cap it seems like youre using Vista. Unfort RKR doesnt work properly on Vista due to some differences in the O/S .

http://forum.sysinternals.com/topic12028&KW=Vista.html


Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

CurlyWhirly

  • Reg Member
  • ***
  • Posts: 370
Re: Warning - DSLzone site compromised
« Reply #72 on: March 25, 2010, 11:33:16 AM »

From the screen cap it seems like youre using Vista. Unfort RKR doesnt work properly on Vista due to some differences in the O/S .

http://forum.sysinternals.com/topic12028&KW=Vista.html
Yes I'm using Vista Home Premium 64-bit.

That explains it, thanks.
Logged
Mike

Quasimoto

  • Member
  • **
  • Posts: 12
Re: Warning - DSLzone site compromised
« Reply #73 on: March 26, 2010, 04:47:38 AM »

Mmm... I just tried to install the trial version of RootKit Revealer and I got this error message:

http://i44.tinypic.com/25u0js8.jpg


I've not run a rootkit utility before but surely this shouldn't happen?

I think I'm going to restore a Norton Ghost backup image before all this weird behaviour started i.e. around a week ago  ???



Makes you feel kind of paranoid after this doesn't it? I felt all dirty when I cleaned the system out from the infection way back. Somewhat shatters the trust thinking things are failing to work.
« Last Edit: March 26, 2010, 04:50:15 AM by Quasimoto »
Logged
CappySpectrum

HPsauce

  • Helpful
  • Kitizen
  • *
  • Posts: 2606
Re: Warning - DSLzone site compromised
« Reply #74 on: March 26, 2010, 09:10:20 AM »

I currently have here a laptop for repair that appears to have been root-kitted :(
I've seen quite a few systems in recent weeks with any/all of the "symptoms" you listed, there's been quite a rash of them.
And in most cases once the defences are breached a whole horde of nasties flood in behind.

The worrying thing is that in most cases the users are cautious people with proper protection in place and have no recollection of doing anything risky at all.
Logged
Pages: 1 ... 3 4 [5] 6 7
 

anything