| |||||
| | #31 | ||
| Resurrected Allied Ribbon of Bravery Join Date: May 2006 Location: Colorado/Midgardsormr
Posts: 1,657 Style: Light Theme V7 Thanks: 211
Thanked 124x in 79 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings
I need something explained to me: Alright, so I have Vista (purely because I bought a new computer that came with it, I would never pay for OS upgrade), and Realplayer didn't have a patch for Vista(just a Premium Trial Download). I checked in the programs list, and I only has Rhapsody, Realtek and Roxio under the "R"'s. Does this mean I don't have RealPlayer, never did and thus, immune? Or do I have the Trojan anyway and need to do something else to get rid of it? AVG never picked up anything other then various tracking cookies on a scan I did...
__________________ ![]() Quote:
Quote:
More Sig: | ||
| | |
| | #32 |
| Senior Veteran Iron Emblem of Service | Re: WARNING - Somepage linked to account hijackings
Never had Real Player to exploit, the problem with FFXIah probably isn't a problem for you. Also Real Player on Vista may not have the problem. You may have the trojan on your system but without the Real Player to exploit it may be rendered useless. This may or may not protect you from the Somepage problem, I don't know what that javascript does as it's been obfuscated to make it unreadable at a glance.
__________________ I use a Mac because I'm just better than you are. Paragon of Red Mage Excellence Paragon of Black Mage Excellence Maat Masher - RDM Shining Ray of Awesome HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout. |
| | |
| | #33 | |
| Raidou Kuzunoha Vs. Demi-Fiend Brass Wings of Service Join Date: May 2006 Location: Windurst
Posts: 6,704 Style: Light Theme V7 Thanks: 208
Thanked 2,061x in 1,127 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings Quote:
![]() This is why I don't play on PC. | |
| | |
| | #34 | |||
| Resurrected Allied Ribbon of Bravery Join Date: May 2006 Location: Colorado/Midgardsormr
Posts: 1,657 Style: Light Theme V7 Thanks: 211
Thanked 124x in 79 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings Quote:
which brings up another question... if this is java-based form Somepage, how did they get it? Possibly unrelated occurence?
__________________ ![]() Quote:
Quote:
More Sig: | |||
| | |
| | #35 |
| Senior Veteran Iron Emblem of Service | Re: WARNING - Somepage linked to account hijackings Most likely there is they are registered users on FFXIah and use the same username/password combo as their POL account.
__________________ I use a Mac because I'm just better than you are. Paragon of Red Mage Excellence Paragon of Black Mage Excellence Maat Masher - RDM Shining Ray of Awesome HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout. |
| | |
| | #36 |
| Roll Us a Giant Brass Ribbon of Service Join Date: Sep 2006 Location: the universe
Posts: 1,357 Style: Light Theme V7 Thanks: 350
Thanked 321x in 209 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings
I decided to do a little poking around myself on the ol' family PC (doesn't have FFXI on it). Went to somepage, and as Olorin pointed out, that tiny little box is indeed an iframe that's linked to a suspicious looking address. Googled the address and viewed the cached site. Looking in the source I found a nice little javascript code that contains the words realplayer, activex, and pol at least once each along with lots and lots of scattered JS code all in an eval(). All this simply proves is what you all already know, and that would be that somepage is not safe to visit anymore if you are running IE and have RealPlayer installed. For the rest of the world (people using something else beside IE), you seem to be relatively safe from this exploit. Thank you Olorin for bringing this news up. |
| | |
| | #37 | |
| 不完全の花 Administrator Iron Emblem of Service | Re: WARNING - Somepage linked to account hijackings Quote:
![]() What can I do to check my PC for infection and excise it if it exists? I've got Symantec antivirus and I don't believe I've ever installed Real crap on that box, but I want to be sure that there's not an opening for future variants. Certainly wouldn't want a keylogger to pick up admin access to this site and start abusing it too. And dammit again, somepage was still useful. ><
__________________ A trail of feelings, of awe and inspiration, should lead him to that castle: in the future: her arms enclosing him, her scent fills him with excitement, creates a moment so strong he can remember it in the past. | |
| | |
| | #38 |
| Senior Veteran Iron Emblem of Service | Re: WARNING - Somepage linked to account hijackings
It figures out what the web browser version is, then tries to determine the version of Real Player on it. It does different things depending on if the language is set to Chinese or US English. It generates a payload by padding a shell code with some other things. Then loads Real Player by opening c:\program files\netmeeting\testsnd.wav and the payload and has Real Player do the damage. I haven't made it all readable yet.
__________________ I use a Mac because I'm just better than you are. Paragon of Red Mage Excellence Paragon of Black Mage Excellence Maat Masher - RDM Shining Ray of Awesome HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout. |
| | |
| | #39 |
| Kerio | Re: WARNING - Somepage linked to account hijackings
well this is all still scary... i wonder now what other crap i have on my computer that can potentially harm my POL account. I mean i don't exactly have the most expensive stuff, but it's still a scary thought. Are there any other popular ffxi sites i should avoid? vanadiel atlas is still fine right?? How about alakazham? Killing ifrit? or even Piko's pots or Kida's fishing database?? |
| | |
| | #40 | ||
| Junior Member | Re: WARNING - Somepage linked to account hijackings Quote:
Vista's as secure as a tank, as long as the user doesn't cripple the security. Nobody has yet managed to infect a Vista machine with a non-administrative user logged on, to the best of my knowledge. At the very least, none of my customers with Vista have yet called me to come fix a virus or spyware issue, and some of those customers couldn't go five minutes without catching Vundo when they had XP. ------------------------------------------ Quote:
Last edited by Greyfist; 12-12-2007 at 03:03 PM. Reason: Automerged Doublepost | ||
| | |
| | #41 | |
| sweet broken hearted machine Starlight Medal Join Date: Oct 2004 Location: Facility A220S-0024, Room 211
Posts: 8,539 Style: Light Theme V7 Thanks: 1,998
Thanked 2,215x in 1,505 Posts
| Re: WARNING - Somepage linked to account hijackings Quote:
As to this problem... really people. Browsing the internet is like going to bars. Sure, most of the time you won't have problems, but all it takes is one bitch to steal your wallet and screw you over. Or give you VD. Bring protection. First, the easiest and most sure way is to get a second computer. Also the most expensive, though you should be able to find a computer for under $100. If you can't, PM me with your location and budget, and I'll be happy to help you look for a secondary PC. This is also insanely useful when your main box goes down. Second is to download a LiveCD and use it whenever you want to browse the web. http://damnsmalllinux.org/ should work well. Third is to download CDs for a free OS (BSD and Linux being the most common ones, I recommend Ubuntu personally) and set up a Dual Boot between Windows and the other OS. Instructions for this are very easy to find on da interwebs. Fourth, probably the hardest, not to mention slowest for your PC, would be to run a virtual box inside Windows, and run something else (again, such as DSL) inside that to browse the web. I'm pretty sure this isn't 100% safe, but given that it seems like this problem wouldn't have even affected normal firefox users, it should be plenty safe against these RMTs. Still, no matter what, why the hell would anyone in their right mind browse with ActiveX left unchecked? If this is correct, it's exactly as I said, someone leaving a gaping security hole and being unsafe. Using ActiveX in IE is nearly the same as offering to show your wallet to anyone you pass on the street. Browsing in IE is bad enough, but allowing ActiveX is just plain retarded. | |
| | |
| The following user says "Thank You" to Feba for above post: | Ameroth (12-12-2007) |
| | #42 |
| Dynamis Guru Bronze Ribbon of Service Join Date: May 2006 Location: Roe Dilund
Posts: 585 Style: Light Theme V7 Thanks: 267
Thanked 54x in 45 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings The first post in this thread will help you manually check and clean out your system. Also, a simple thing to do is to open up the Windows Task Manager, click the Processes tab, and see if any of the files listed on the link above are in the list. I personally don't run a virus scanner - I find them too demanding on my computer to be worthwhile. Instead I keep my task manager open almost all the time so I'm able to see if anything funky is running in the background. I also use Ad-Aware and SpyBot about once a month to take care of the browser cookies and scripts. I haven't used AVG yet, but I hear nothing but good words about their programs. Btw.. <3 Damn Small Linux
__________________ Olorin - Ramuh Server WHM75 BRD75 BLM75 RDM75 SMN39 SCH37 - TheAfterLife LS ![]() |
| | |
| The following user says "Thank You" to Olorin401 for above post: | Taskmage (12-12-2007) |
| | #43 |
| Nekoai Nanashi Allied Ribbon of Glory Join Date: Dec 2005 Location: Dumfries, Virgina
Posts: 2,257 Style: Dark Theme V6 Thanks: 1,257
Thanked 212x in 164 Posts
My Mood: | Re: WARNING - Somepage linked to account hijackings
The UAC must be shut off to save the sanity of any users for are forced to use Vista >_> /em installs PCLinux atm. |
| | |
| | #44 | ||
| sweet broken hearted machine Starlight Medal Join Date: Oct 2004 Location: Facility A220S-0024, Room 211
Posts: 8,539 Style: Light Theme V7 Thanks: 1,998
Thanked 2,215x in 1,505 Posts
| Re: WARNING - Somepage linked to account hijackings Quote:
Imagine a computer as a car-- you need the keys to get in the door, pop the hood or trunk, and turn it on so you can change everything. Now, most people don't mind turning a key to unlock their doors and start their engine. But if you start requiring them to use the key every time they want to open the doors, be it to get in or get out; not to mention change the radio dial, turn up the AC, turn on cruise control, activate the windshield wipers, is it really any surprise that they're going to get pissed off and remove all the locks? Computers are no different-- UAC actively encourages the user to either not pay attention to it, or to remove it entirely. Good security is far more than a dialog box that says "OK", security is partially a matter of the OS not allowing things to run as root without user approval, yes, but it's also about making sure that the user knows and pays attention to what they're doing. ------------------------------------------ Quote:
Last edited by Feba; 12-12-2007 at 03:31 PM. Reason: Automerged Doublepost | ||
| | |
| | #45 |
| Kerio | Re: WARNING - Somepage linked to account hijackings
how do i know if i'm running this active X thing in my IE? i use firefox, is it any different?
|
| | |
![]() |
| Tags |
| account, hijackings, linked, somepage, warning |
| Thread Tools | |
| Display Modes | |
| |