Shemp, did you get me right?
That is host who redirects traffic.
You webmaster may be doesn't know about redirection, just recommend him to move site to another host.
fusionx, there are too many trojan.downloader versions, but as far as I could remember, second file (even if it is downloaded from the same URL) is another file, second file opens a few ports on your comp and it is ready to download and run ANY PROGRAM.
Downloaded programs do the rest.
Originally posted by Germes Shemp, did you get me right?
That is host who redirects traffic.
You webmaster may be doesn't know about redirection, just recommend him to move site to another host.
i got you...
we don't allow free hosts for preferred submitters...
the webmaster must have complete control of the domains.
thats part of the agreement of getting a submit account with us..
Originally posted by Germes fusionx, there are too many trojan.downloader versions, but as far as I could remember, second file (even if it is downloaded from the same URL) is another file, second file opens a few ports on your comp and it is ready to download and run ANY PROGRAM.
Downloaded programs do the rest.
I'm running zonealarm on that box, and I just tightened it up. I'll check it for a while and see if anything is trying to get in or out.
My server hasn't been hacked. I don't get the code, I think it's a jscript exploit that take advantage of certain browsers. But I'm still looking into it.
I got a virus on my laptop, and I can't get rid of it! And now I can't not surf, and my wireless connection is totally inexisting (not even showing up on Network Connections screen).
This fucking sucks!!! And they are chasing spammers? WTF?
If it was hacked don't you think I would be able to see the code? I haven't seen it yet on any of my pages.
I did see it on Pornno.com though so I'm stil trying to figure out why I can see it on his page and not mine.
Trying 64.158.30.220...
Connected to 64.158.30.220.
Escape character is '^]'.
Then type something like this:
GET /links.html HTTP/1.0
Host: www.snakesworld.com
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Accept-Language: en
Accept-Charset: iso-8859-1,*,utf-8
Accept: */*
Connection: close
And press "Enter" twice
And you will see page source code.
Snake, no I do not think so.
Have you turned off cookies?
Which IP-addresses did you use to see your page?
From how many computers did you try to do it?
Originally posted by fusionx I was able to download it, but it downloaded as a 0 (zero) byte file.
I have about 20 of them in my temp files directory. They are 9kb in size.
I copied it to an old machine and ran it just for fun.
All it did was open a URL in my browser to download the same file. (same URL at rockys).
Nothing new is running in system processes. I'm running a full scan with norton, and I'll also run one with AVG and AdAware just to check.
I'm not at all sure what it's supposed to be doing.
According to Symantec, the class "trojan horse" is just a generic label when they don't really know what it is. The classification is based on behavior, not contents.
It seems pretty harmless, so far. Just a pain in the butt.
Originally posted by cosis I was submitting galleries today and noticed a Trojan virus detected when loading both the main pages on pornno.com and snakesworld.com. I consider my computer pretty secure. Anyone else noticing this?
spyware
A program you can trust. Gallerybooster Run multiply TGPs of 1 script
JJJ, may be you can read own pages better.
Tell us please, what do you see on your main1.html page (via ftp or telnet) between
<FONT color=#000000 size=6>Asians</FONT></A>
and
<P>
<FONT color=#ff0000 face=arial size=4>
Snake, when you write "There is no code on my pages between the area you mentioned", do you read your page source via browser or directly from your server via ftp or telnet? I asked what do you see via ftp or telnet.
OK, problem solved. Now I can go about my business. No details but there was a problem on my server and I assume JJJ"s also. Everything should be clean and back to normal.
Comment