WARNING! Clickzs.com associated with trojan/codec installs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rowan
    Too lazy to set a custom title
    • Mar 2002
    • 17393

    #1

    WARNING! Clickzs.com associated with trojan/codec installs

    pornstarsxtra.com - came across this site mentioned on another board. It appears to be an old school paysite, but it also has pages that show a fake video player window (it's just an image, no attempt at embedding a video) with a link to an executable:



    Description of IE SecPlugin
    IE SecPlugin is an adware application that hijacks search page and monitors internet activities of the user.

    WHOIS shows the registrant as Netsaits BV with the admin contact Gerco Marsch. clickzs.com has the same details.

    clickzs.com lives at 64.237.39.70, pornstarsxtra.com lives at 64.237.39.66. 127 IPs from that block are allocated to Netsaits BV, which includes those two IPs.

    So we have these two domains sharing the same company name, same admin contact, same host, same IP block.........

    It's not the first time clickzs has been associated with shifty stuff, it wasn't so long ago that they were linking their buttons to Zango.

    So who links to clickzs?

    clickzs.com - Inlinks (166,840)
    www.clicksz.com - Inlinks (95,762)

    If they ever decided to be more blatant about their installs then there'd be a lot of shit going down.
  • fris
    I have to go potty
    • Aug 2002
    • 55800

    #2
    a lot of people (big sites) use clickzs, this blows
    Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


    My Newest Theme

    Comment

    • GAMEFINEST
      Make STACK$
      • Nov 2006
      • 14470

      #3
      good heaeds up
      Compound interest.

      Comment

      • RawAlex
        So Fucking Banned
        • Oct 2003
        • 9465

        #4
        I think very few people either understand or choose to understand just how far these codec and spyware installers have gone into the porn business.

        I would place a guess today that 30% or more of the joins / money are going to these types of operations, either as direct sales or a traffic buys from PPC sites that use these tools to generate traffic.

        Comment

        • Quickdraw
          Confirmed User
          • Mar 2004
          • 1717

          #5
          Here is what just happened when browsing through freedailyporn.com(another site on 64.237.39.66 and same whois)

          The following log shows clicking a link to a gallery and being redirected to trojans on the 85.255 ip range posing as spyware removers. The redirect happened instantly and all the other files you see loaded from the initial redirected page.
          85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com

          Code:
          GET http://www.freedailyporn.com/
          200 OK
          ***Click starts here***
          GET http://vip.clickzs.com/tgp.php?fdp&thenudeteens.com/ebony/index.html
          302 Found to http://85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com
          
          GET http://85.255.115.222/ind.htm?e404=1&src=124&surl=vip.clickzs.com
          200 OK
          
          GET http://85.255.115.222/site.htm?lng=1&trg=cln&oip=0&trk=xicawxshtfnfffi
          200 OK
          
          GET http://85.255.115.222/_cntr.htm?trk=xicawxshtfnfffi
          200 OK
          
          GET http://free-spy-cam.net/index.htm?trk=xicawxshtfnfffi
          200 OK
          
          GET http://85.255.115.222/cnte-eshdvvw.htm?trk=xicawxshtfnfffi
          200 OK
          
          GET http://free-spy-cam.net/loading.htm
          200 OK
          
          GET http://69.50.172.115/sp/fpa/index.html
          200 OK
          
          GET http://85.255.115.222/cnte-ani_dthcbdg.htm?trk=xicawxshtfnfffi
          200 OK
          
          GET http://85.255.115.222/cnte-dhncgts.jar?trk=xicawxshtfnfffi
          200 OK
          
          GET http://85.255.115.222/back.htm
          200 OK
          
          GET http://85.255.115.222/com/ms/security/SecurityClassLoader.class
          404 Not Found
          
          GET http://85.255.115.222/riff_last.bin
          200 OK

          Comment

          • Tempest
            Too lazy to set a custom title
            • May 2004
            • 10217

            #6
            Originally posted by Quickdraw
            The following log shows clicking a link to a gallery and being redirected to trojans on the 85.255 ip range posing as spyware removers.
            I believe that the server has been hacked with a modified version of apache... I've seen that before and that's what the host said. Not to me, but someone else.

            Comment

            • Tempest
              Too lazy to set a custom title
              • May 2004
              • 10217

              #7
              By the way 85.255.112.0 – 85.255.127.255 is INHOSTER and it looks like they're associated with Intercage and the codec installing "group".

              Comment

              • graphicsp1mp
                Registered User
                • May 2007
                • 35

                #8
                damn this shit is huge isnt it

                nice find rowan

                Graphics Pimp

                Comment

                • NTM
                  So Fucking Banned
                  • Jul 2006
                  • 1087

                  #9
                  Clickzs

                  Comment

                  • Turboface
                    Back in Black
                    • Mar 2002
                    • 9976

                    #10
                    Using a remotely hosted traffic trading script service is just a flawed idea from the get go.
                    Search Engine Optimization Services for Adult Sites

                    Comment

                    • en21
                      Confirmed User
                      • May 2006
                      • 2640

                      #11
                      those big site should be able to afford paid script
                      Free Asian Sex : http://www.asian4free.com
                      Free Amateur Sex : http://www.lustamateur.com
                      Free Porn : http://www.mysexbookmark.com
                      Free Sex : http://www.goliathlist.com
                      Free Hardcore : http://www.xlust.com
                      Sex For Free : http://www.sexforfee.com

                      Comment

                      • Iron Fist
                        Too lazy to set a custom title
                        • Dec 2006
                        • 23400

                        #12
                        Brutal. It's no wonder why I dont use any 3rd party software on my network, just can't trust anyone anymore.
                        i like waffles

                        Comment

                        • percy
                          Registered User
                          • Aug 2002
                          • 11

                          #13
                          Hello,

                          it looks like our server has been hacked. We are working on the problem.

                          Thanks

                          Percy

                          Comment

                          • percy
                            Registered User
                            • Aug 2002
                            • 11

                            #14
                            This was not our doing, someone hacked our server and placed something on the server causing that fake video player window and it's executable to appear. We are working on the problem and will have it fixed asap.

                            Thanks again

                            Percy
                            Netsaits/ClickZs

                            Comment

                            • martinsc
                              Too lazy to set a custom title
                              • Jun 2005
                              • 27043

                              #15
                              Originally posted by percy
                              This was not our doing, someone hacked our server and placed something on the server causing that fake video player window and it's executable to appear. We are working on the problem and will have it fixed asap.

                              Thanks again

                              Percy
                              Netsaits/ClickZs

                              better get this fixed soon....
                              Make Money

                              Comment

                              • boneless
                                Confirmed User
                                • Dec 2002
                                • 3625

                                #16
                                ah it was all an error peeps, nothing to see here.

                                same with that zango bs you guys pushed right? also a hack or error.

                                seems that clicksz gets more and more shitty, and i for one hope every big site owner will drop this shit on the fly.
                                icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com

                                Comment

                                • Quickdraw
                                  Confirmed User
                                  • Mar 2004
                                  • 1717

                                  #17
                                  Originally posted by percy
                                  Hello,

                                  it looks like our server has been hacked. We are working on the problem.

                                  Thanks

                                  Percy
                                  Are you able to tell how long ago you were hacked?

                                  Comment

                                  • Godsmack
                                    Confirmed User
                                    • Apr 2004
                                    • 4525

                                    #18
                                    Originally posted by boneless
                                    ah it was all an error peeps, nothing to see here.

                                    same with that zango bs you guys pushed right? also a hack or error.

                                    seems that clicksz gets more and more shitty, and i for one hope every big site owner will drop this shit on the fly.
                                    Yeah, good thing there are hackers, so we can all blame them LOL
                                    Download the much improved Free Tube Script adult/mainstream tube solution for FREE!

                                    Comment

                                    • JamesK2
                                      Confirmed User
                                      • Aug 2004
                                      • 6589

                                      #19
                                      Originally posted by boneless
                                      ah it was all an error peeps, nothing to see here.

                                      same with that zango bs you guys pushed right? also a hack or error.

                                      Comment

                                      • u-Bob
                                        there's no $$$ in porn
                                        • Jul 2005
                                        • 33063

                                        #20
                                        Originally posted by Tempest
                                        By the way 85.255.112.0 ? 85.255.127.255 is INHOSTER and it looks like they're associated with Intercage and the codec installing "group".
                                        correct, inhost(er) is just one of many fake hosting companies used by scammers and thieves.

                                        Comment

                                        • u-Bob
                                          there's no $$$ in porn
                                          • Jul 2005
                                          • 33063

                                          #21
                                          Originally posted by percy
                                          it looks like our server has been hacked. We are working on the problem.
                                          you'll have to do better than that...

                                          Comment

                                          • percy
                                            Registered User
                                            • Aug 2002
                                            • 11

                                            #22
                                            The executable was placed on our domain pornstarsxtra.com by a hacker. We do not know how they did it but there are just a few sites linking to that content (according to our server logs) and those sites are not ours. Check mommysuncensored dot com (not ours), the top left thumbs are linking to the content on our server (will probably be changed now we have removed the content from our server)

                                            Anyone know the owner of mommysuncensored dot com?


                                            Percy
                                            Netsaits/ClickZs

                                            Comment

                                            • RawAlex
                                              So Fucking Banned
                                              • Oct 2003
                                              • 9465

                                              #23
                                              percy, I got news for you... what you found on the domain isn't 10% of the hack. Good luck, the entire box is likely rooted beyond understanding.

                                              Comment

                                              • yahoo-xxx-girls.com
                                                Confirmed User
                                                • Jul 2006
                                                • 3143

                                                #24
                                                Not a good way to conduct business, thanks for the heads up !
                                                sig too big

                                                Comment

                                                • RawAlex
                                                  So Fucking Banned
                                                  • Oct 2003
                                                  • 9465

                                                  #25
                                                  Originally posted by Tempest
                                                  By the way 85.255.112.0 ? 85.255.127.255 is INHOSTER and it looks like they're associated with Intercage and the codec installing "group".
                                                  This is an IP block that shouldn't be carried by anyone. It is amazing how much shit they are getting away with.

                                                  Comment

                                                  • fris
                                                    I have to go potty
                                                    • Aug 2002
                                                    • 55800

                                                    #26
                                                    use chkrootkit to find which files have been modified
                                                    Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


                                                    My Newest Theme

                                                    Comment

                                                    • RawAlex
                                                      So Fucking Banned
                                                      • Oct 2003
                                                      • 9465

                                                      #27
                                                      Originally posted by Fris
                                                      use chkrootkit to find which files have been modified
                                                      Run it daily - because part of the trick is how they get access - the initial breakin occurs via FTP, usually obtained by a compromised webmaster PC. So the webmaster gets their server cleaned up, and the next day, they walk right back in (because even when you change the FTP or telnet passwords, they pick them right up again on your next access).

                                                      You need to check and clean not only the server, but any and all PCs that may have FTP or telnet access to the server, including all systems used by your hosting company that might have access.

                                                      Good fucking luck.

                                                      Comment

                                                      • JD
                                                        Too lazy to set a custom title
                                                        • Sep 2003
                                                        • 22651

                                                        #28
                                                        fuck me....

                                                        Comment

                                                        • rowan
                                                          Too lazy to set a custom title
                                                          • Mar 2002
                                                          • 17393

                                                          #29
                                                          bump....

                                                          Comment

                                                          • rowan
                                                            Too lazy to set a custom title
                                                            • Mar 2002
                                                            • 17393

                                                            #30
                                                            One more bump

                                                            Comment

                                                            • Quickdraw
                                                              Confirmed User
                                                              • Mar 2004
                                                              • 1717

                                                              #31
                                                              Originally posted by Tempest
                                                              I believe that the server has been hacked with a modified version of apache... I've seen that before and that's what the host said. Not to me, but someone else.
                                                              I would like to believe that, this trojan redirect has been happening for months, and is still happening at this moment.

                                                              They took care of those videos right away, but the redirection to the trojans was never addressed. They have had plenty of time to clean up their server, so why is the redirect still happening? Lazy admin, bad host, maybe not a hack? The longer it takes to get fixed the less I believe it is a hack.

                                                              Comment

                                                              • Aussie Rebel
                                                                Blow Me U Geeks
                                                                • Aug 2001
                                                                • 5108

                                                                #32
                                                                Bump.....

                                                                Comment

                                                                • boneless
                                                                  Confirmed User
                                                                  • Dec 2002
                                                                  • 3625

                                                                  #33
                                                                  as per my topic, thnk god for hacker, else there wasnt an excuse for this type of bad behaviour.
                                                                  icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com

                                                                  Comment

                                                                  • Godsmack
                                                                    Confirmed User
                                                                    • Apr 2004
                                                                    • 4525

                                                                    #34
                                                                    Originally posted by boneless
                                                                    as per my topic, thnk god for hacker, else there wasnt an excuse for this type of bad behaviour.
                                                                    LOL thats what i said earlier..
                                                                    Download the much improved Free Tube Script adult/mainstream tube solution for FREE!

                                                                    Comment

                                                                    • hdkiller
                                                                      Full time cybermage
                                                                      • Jun 2006
                                                                      • 461

                                                                      #35
                                                                      this is a gohackyourself thread?
                                                                      ClickPapa! - Buy and Sell traffic

                                                                      Comment

                                                                      • boneless
                                                                        Confirmed User
                                                                        • Dec 2002
                                                                        • 3625

                                                                        #36
                                                                        Originally posted by hdkiller
                                                                        this is a gohackyourself thread?
                                                                        i think so yes
                                                                        icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com

                                                                        Comment

                                                                        • Godsmack
                                                                          Confirmed User
                                                                          • Apr 2004
                                                                          • 4525

                                                                          #37
                                                                          Originally posted by hdkiller
                                                                          this is a gohackyourself thread?
                                                                          Lolol, sure looks like it
                                                                          Download the much improved Free Tube Script adult/mainstream tube solution for FREE!

                                                                          Comment

                                                                          • rowan
                                                                            Too lazy to set a custom title
                                                                            • Mar 2002
                                                                            • 17393

                                                                            #38
                                                                            Originally posted by hdkiller
                                                                            this is a gohackyourself thread?


                                                                            That's a better name for a knockoff board than many have come up with.

                                                                            Comment

                                                                            • NyLoS
                                                                              Confirmed User
                                                                              • Apr 2001
                                                                              • 724

                                                                              #39
                                                                              not again, gerco ! wake up !!! jeeez

                                                                              Comment

                                                                              • klinton
                                                                                So Fucking Banned
                                                                                • Apr 2003
                                                                                • 8766

                                                                                #40
                                                                                Originally posted by Tempest
                                                                                By the way 85.255.112.0 ? 85.255.127.255 is INHOSTER and it looks like they're associated with Intercage and the codec installing "group".


                                                                                I have also problems with this ip on my sites....redirects...and I also don't know how this could happen :P...damn

                                                                                Comment

                                                                                • biskoppen
                                                                                  Confirmed User
                                                                                  • Mar 2003
                                                                                  • 5809

                                                                                  #41
                                                                                  Nice... another 100k users infected with the codec trojan, another drop in our sales...

                                                                                  Let me repeat myself.. : I'm pretty sure, from stuff I've seen, that these guys are in the top 3 of affiliates overall with all programs.. You have NO IDEA how much they're stealing
                                                                                  Submit my videos to make bank, tons of 5 minute videos offered right here

                                                                                  Comment

                                                                                  • RawAlex
                                                                                    So Fucking Banned
                                                                                    • Oct 2003
                                                                                    • 9465

                                                                                    #42
                                                                                    The amount they are stealing is pretty stunning - and most programs know it and smile and take their traffic anyway.

                                                                                    Comment

                                                                                    • Tempest
                                                                                      Too lazy to set a custom title
                                                                                      • May 2004
                                                                                      • 10217

                                                                                      #43
                                                                                      Originally posted by klinton


                                                                                      I have also problems with this ip on my sites....redirects...and I also don't know how this could happen :P...damn
                                                                                      Have your host check the apache binary and ensure it hasn't been replaced.

                                                                                      Comment

                                                                                      • klinton
                                                                                        So Fucking Banned
                                                                                        • Apr 2003
                                                                                        • 8766

                                                                                        #44
                                                                                        Originally posted by Tempest
                                                                                        Have your host check the apache binary and ensure it hasn't been replaced.
                                                                                        at first I thought that it was dns cache poisoning...
                                                                                        but it looks like it is something different,maybe this what you are saying...hopefully..I'll contact them asap

                                                                                        Comment

                                                                                        • ServerGenius
                                                                                          Confirmed User
                                                                                          • Feb 2002
                                                                                          • 9377

                                                                                          #45
                                                                                          Originally posted by Fris
                                                                                          use chkrootkit to find which files have been modified
                                                                                          chkrootkit isn't nearly as good as rkunter free for download @ http://www.rootkit.nl/

                                                                                          | http://www.sinnerscash.com/ | ICQ: 370820 | Skype: SinnersCash | AdultWhosWho |

                                                                                          Comment

                                                                                          • Miguel T
                                                                                            ♦ Web Developer ♦
                                                                                            • May 2005
                                                                                            • 12470

                                                                                            #46
                                                                                            Happy I dont use that ;)

                                                                                            Full Stack Webdeveloper: HTML5/CSS3, jQuery, AJAX, ElevatedX, NATS, MechBunny, Wordpress

                                                                                            Comment

                                                                                            • Quickdraw
                                                                                              Confirmed User
                                                                                              • Mar 2004
                                                                                              • 1717

                                                                                              #47
                                                                                              Still hacked? This redirect happened today.

                                                                                              htxp://cz8.clickzs.com/tgp.php?bbgx&60&CJ1&hxtp://galleries.babes.tv/mg/08/?nats=MTAwMDQ5OjM6Ng,0,0,0,1107875810&content=suzi ecarina2b

                                                                                              htxp://85.255.115.222/ind.htm?e404=1&src=130&surl=cz8.clickzs.com
                                                                                              Last edited by Quickdraw; 07-13-2007, 08:39 AM.

                                                                                              Comment

                                                                                              Working...