|   |   |   | ||||
| Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. | 
|    | 
| 
 | |||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
|  | Thread Tools | 
|  06-29-2004, 09:28 PM | #1 | 
| Entrepreneur Join Date: Oct 2002 Location: USA 
					Posts: 31,429
				 | 
				
				Watch Out For GIF Images Containing Hidden Malicious Code
			 On June 24th, a visitor to the SANS Internet Storm Center reported that his company was "...in the middle of a very disturbing ... issue regarding the adware/spyware/IE exploit genre..." He requested help analyzing an "encrypted or compressed" file that had been downloaded to a machine at their site. Tom Liston, one of our volunteer handlers, spent the weekend analyzing this issue. His findings are summarized here.  The victim of the attack found that a file called "img1big.gif" had been loaded onto their machine. Because of the account restrictions on the person running the machine, it had failed to install properly, which was why it had come to their attention. It is this file that they forwarded to the SANS Internet Storm Center for analysis. The file is not a graphic file at all. It is actually a 27648 byte Win32 executable that has been compressed using the Open Source executable compressor UPX. This file decompresses to an 81920 byte file which contains two Win32 executables bound together. The first portion of the file (and what actually runs if the file extension is changed and the program is launched) is a "file dropper" Trojan, designed to install any executable concatenated to its body. The second half of the file consists of a Win32 DLL that is installed by the file dropper under WindowsXP as a randomly named .dll file under C:\WINDOWS\System32\. This DLL is installed as a "Browser Helper Object" (BHO) under Internet Explorer. A "Browser Helper Object" is a DLL that allows developers to customize and control Internet Explorer. When IE 4.x and higher starts, it reads the registry to locate installed BHO's and then loads them into the memory space for IE. Created BHO's then have access to all the events and properties of that browsing session. This particular BHO watches for HTTPS (secure) access to URLs of several dozen banking and financial sites in multiple countries. When an outbound HTTPS connection is made to such a URL, the BHO then grabs any outbound POST/GET data from within IE before it is encrypted by SSL. When it captures data, it creates an outbound HTTP connection to http://www.refestltd.com/cgi-bin/yes.pl and feeds the captured data to the script found at that location. 
				__________________  If you would like to develop your domains, you can lease inexpensive foreign labor from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** ***  Domains  Adult News  KRL's Newsletter  Biz Tips  Just Listed Domains | 
|   |           | 
|  06-29-2004, 09:30 PM | #2 | 
| I need a beer   Industry Role:  Join Date: Jun 2002 Location: ♠ Toiletville ♠ 
					Posts: 133,947
				 | Actually that has been happening for awhile...fucking weasels are really up on this...hope they all rot in hell   
				__________________ | 
|   |           | 
|  06-29-2004, 09:31 PM | #3 | 
| GFY HALL OF FAME DAMMIT!!! Join Date: Jan 2002 Location: that 504 
					Posts: 60,840
				 | "You can point your gun at me And hope it will go away But if God was alive, He would hate you anyway." Cheers! just checking in on vacation    
				__________________  Want an Android App for your tube, membership, or free site? Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com -  recent work - About me | 
|   |           | 
|  06-29-2004, 09:31 PM | #4 | 
| Sofa King Band Join Date: Jul 2002 Location: Outside the box 
					Posts: 29,903
				 | I love using Mozilla   | 
|   |           | 
|  06-29-2004, 09:32 PM | #5 | 
| Guest 
					Posts: n/a
				 | Great, how long before we will have to make our sigs static jpegs on gfy? | 
|           | 
|  06-29-2004, 09:32 PM | #6 | 
| Too lazy to set a custom title Industry Role:  Join Date: Oct 2002 Location: The Boonies 
					Posts: 12,860
				 | man this shit is getting more and more sinister with each exploit/hack/trojan that comes to light, | 
|   |           | 
|  06-29-2004, 09:32 PM | #7 | 
| Chafed. Join Date: May 2002 Location: Face Down in Pussy 
					Posts: 18,041
				 | Anybody want me to write them a BHO? Its gonna cost ya.  | 
|   |           | 
|  06-29-2004, 09:34 PM | #8 | 
| Confirmed User Industry Role:  Join Date: Feb 2002 Location: NYC, NY 
					Posts: 8,531
				 | any protection out on this one yet? 
				__________________  ~ Webair Dedicated Cloud Servers™ ~ WEBAIR VSYS™ Virtual Hosting Platform ~ Superior CDN Network ~ ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~ ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected] | 
|   |           | 
|  06-29-2004, 09:36 PM | #9 | 
| holla Join Date: Jul 2003 Location: KFC 
					Posts: 11,769
				 | if any coders want to hook me up on how to execute spyware using GIFs, contact me, my aim info is in my profile | 
|   |           | 
|  06-29-2004, 09:38 PM | #10 | 
| Confirmed User Join Date: Jun 2001 Location: Closer than you think 
					Posts: 9,535
				 | Thanks for the info. 
				__________________ Need Mainstream Content and SEO? SEO * Website Copy * Blogs Blogging - PR Work - Forum Marketing - Social Marketing - Link building - Articles 100% Guaranteed Content! | 
|   |           | 
|  06-29-2004, 09:39 PM | #11 | |
| Confirmed User Join Date: Jan 2003 
					Posts: 3,852
				 | Quote: 
      | |
|   |           | 
|  06-29-2004, 09:40 PM | #12 | |
| holla Join Date: Jul 2003 Location: KFC 
					Posts: 11,769
				 | Quote: 
 get over it money is money people can download ad-aware if it bothers them | |
|   |           | 
|  06-29-2004, 09:46 PM | #13 | 
| Confirmed User Industry Role:  Join Date: Mar 2002 
					Posts: 7,245
				 | The surpreme court needs to stop wasting time with the porn sites and focus on shit like this | 
|   |           | 
|  06-29-2004, 09:48 PM | #14 | |
| Entrepreneur Join Date: Oct 2002 Location: USA 
					Posts: 31,429
				 | Quote: 
          
				__________________  If you would like to develop your domains, you can lease inexpensive foreign labor from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** ***  Domains  Adult News  KRL's Newsletter  Biz Tips  Just Listed Domains | |
|   |           | 
|  06-29-2004, 09:49 PM | #15 | |
| First African GFY Member Join Date: Mar 2004 Location: New Jersey 
					Posts: 12,114
				 | Quote: 
 | |
|   |           | 
|  06-29-2004, 09:49 PM | #16 | |
| Entrepreneur Join Date: Oct 2002 Location: USA 
					Posts: 31,429
				 | Quote: 
      
				__________________  If you would like to develop your domains, you can lease inexpensive foreign labor from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** ***  Domains  Adult News  KRL's Newsletter  Biz Tips  Just Listed Domains | |
|   |           | 
|  06-29-2004, 09:55 PM | #17 | 
| Damn Right I Kiss Ass! Industry Role:  Join Date: Dec 2003 Location: Cowtown, USA 
					Posts: 32,422
				 | Back in my trojanning days I met a chick who did a similar job in GIF's and when I tried to discuss it with a professor or two they'd always laugh me out of the room. You can't execute code from inside of a gif, there is no compiler (blah blah blah) and yada yada... So finally someone has probably paired it with IRC bots to infect hundreds a day and now all of a sudden it IS possible... funny how shit turns out. | 
|   |           | 
|  06-29-2004, 10:00 PM | #18 | |
| I'm Lenny2 Bitch Join Date: Mar 2001 Location: On top of my soapbox 
					Posts: 13,449
				 | Quote: 
 
				__________________ sig too big | |
|   |           | 
|  06-29-2004, 10:05 PM | #19 | |
| Confirmed User Join Date: May 2002 Location: Steeler Country 
					Posts: 1,307
				 | Quote: 
  you must be kidding 
				__________________  $30 PER SIGNUP PLUS 25% RECURRING FREE HOSTED PIC AND MOVIE GALLERIES Submit Your Free Sites, Pic and Movie Galleries Here ICQ : 20034024 | |
|   |           | 
|  06-29-2004, 10:07 PM | #20 | |
| Sofa King Band Join Date: Jul 2002 Location: Outside the box 
					Posts: 29,903
				 | Quote: 
  | |
|   |           | 
|  06-29-2004, 10:15 PM | #21 | 
| Die With Your Boots On Join Date: Oct 2003 Location: Hawaii 
					Posts: 22,872
				 | Fuck, pretty soon they'll have to just abandon this internet as we know it and start all over again from scratch.  Mark my words, it'll happen.    
				__________________   | 
|   |           | 
|  06-29-2004, 10:15 PM | #22 | |
| holla Join Date: Jul 2003 Location: KFC 
					Posts: 11,769
				 | Quote: 
 i'd set it up outside the u.s. lol | |
|   |           | 
|  06-29-2004, 10:57 PM | #23 | 
| Confirmed User Join Date: Feb 2004 Location: Anaheim - CA 
					Posts: 6,741
				 | I have been battling fucked up spyware all week and I know it came from some TGP sites. Fucking auto intalling mother fuckers. I can't see how screwing up my machine is making anyone money. I couldn't even buy something from them if I wanted to. It fucks the browser up so bad that even when you click on the search listings from the auto intalled hacked homepage, you just get ads to remove spyware. The pay per click search engine traffic will become worthless at this rate really. 
				__________________ AKA - Clubsexy | 
|   |           | 
|  06-29-2004, 11:37 PM | #24 | |
| Entrepreneur Join Date: Oct 2002 Location: USA 
					Posts: 31,429
				 | Quote: 
 
				__________________  If you would like to develop your domains, you can lease inexpensive foreign labor from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** ***  Domains  Adult News  KRL's Newsletter  Biz Tips  Just Listed Domains | |
|   |           | 
|  06-29-2004, 11:38 PM | #25 | 
| Registered User Join Date: May 2004 
					Posts: 20
				 | This is evil. 
				__________________ spyware instant help | 
|   |           | 
|  06-29-2004, 11:39 PM | #26 | |
| Confirmed User Join Date: Apr 2004 
					Posts: 3,875
				 | Quote: 
  
				__________________ No sig, just here to fuck around. | |
|   |           | 
|  06-29-2004, 11:41 PM | #27 | |
| So Fucking Banned Industry Role:  Join Date: Apr 2001 Location: the beach, SoCal 
					Posts: 107,089
				 | Quote: 
 | |
|   |           | 
|  06-29-2004, 11:41 PM | #28 | |
| I'm Lenny2 Bitch Join Date: Mar 2001 Location: On top of my soapbox 
					Posts: 13,449
				 | Quote: 
 Most surfers barely know how to open internet explorer, much less install and use opera or mozilla. If this stuff keeps up surfers will be afraid to go to adult sites period. 
				__________________ sig too big | |
|   |           | 
|  06-29-2004, 11:46 PM | #29 | 
| Confirmed User Join Date: Aug 2003 Location: DK 
					Posts: 779
				 | Mozilla Mozilla Mozilla Mozilla Mozilla 
				__________________ High Converting CCBILL Programs Amateur/CFNM -> http://www.boozedwomen.com/tour/ Best Selling Granny Site -> http://www.excitedwives.com/tour/  If I had a hammer.... | 
|   |           | 
|  06-30-2004, 12:18 AM | #30 | 
| ►SouthOfHeaven Join Date: Jun 2004 Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer 
					Posts: 28,609
				 | mozilla stopped using gif's ?? news to me   hahah mozilla has more holes than a golf course 
				__________________ hatisblack at yahoo.com | 
|   |           | 
|  06-30-2004, 01:13 AM | #31 | 
| So Fucking Banned Join Date: Apr 2003 Location: malta 
					Posts: 12,745
				 | Hey Smokey did you even read the post? "The file is not a graphic file at all. It is actually a 27648 byte Win32 executable that has been compressed using the Open Source executable compressor UPX. This file decompresses to an 81920 byte file which contains two Win32 executables bound together. The first portion of the file (and what actually runs if the file extension is changed and the program is launched) is a "file dropper" Trojan, designed to install any executable concatenated to its body. The second half of the file consists of a Win32 DLL that is installed by the file dropper under WindowsXP as a randomly named .dll file under C:\WINDOWS\System32\. This DLL is installed as a "Browser Helper Object" (BHO) under Internet Explorer. " Does nothing at all to people on Mozilla . Mozilla is secure because not many people use it.. so who is going to bother wasting time trying to exploit it? That being said.. I am sure any holes that people do find will be patched with alacrity. | 
|   |           | 
|  06-30-2004, 01:16 AM | #32 | |
| UNSTOPPABLE Join Date: Aug 2003 Location: UK :: ICQ# 156068 
					Posts: 11,569
				 | Quote: 
    | |
|   |           | 
|  06-30-2004, 03:05 AM | #33 | 
| Confirmed User Join Date: Feb 2002 
					Posts: 720
				 | Actually if you read the write-up at http://isc.sans.org/presentations/banking_malware.pdf you'll find that the image file needs to be renamed to install itself. They theorize that a .chm exploit is used to rename the GIF and run it. So the fact that it's a GIF file isn't really important, it could have any file extension the attacker would like. JPG would work just as well. | 
|   |           | 
|  06-30-2004, 03:09 AM | #34 | 
| Confirmed User Join Date: Nov 2002 Location: Belgium 
					Posts: 7,383
				 | woa! Imagine the data that "listener" server gets! Thousands and thousands of CC numbers/passwords... | 
|   |           | 
|  06-30-2004, 03:16 AM | #35 | 
| Confirmed User Join Date: Jun 2001 Location: Wherever I want 
					Posts: 7,517
				 | Thanks for the information! | 
|   |           | 
|  06-30-2004, 03:32 AM | #36 | |
| Too lazy to set a custom title Join Date: Jan 2002 Location: Holland 
					Posts: 9,870
				 | Quote: 
 
				__________________ Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 | |
|   |           | 
|  06-30-2004, 03:37 AM | #37 | |
| UNSTOPPABLE Join Date: Aug 2003 Location: UK :: ICQ# 156068 
					Posts: 11,569
				 | Quote: 
 2. Don't be so quick to open your mouth. | |
|   |           | 
|  06-30-2004, 03:42 AM | #38 | |
| Confirmed User Join Date: Mar 2003 
					Posts: 1,169
				 | Quote: 
 If you actually read the post you'd see that it uses the BHO... now my guess is telling me that Mozilla doesn't have this BHO. I'm glad I use Linux and Mozilla  
				__________________ SUBMIT YOUR BABE GALLERIES PROMOTE YOUR BLOG HERE always looking for hardlinks icq #207011694 Thunder-Ball.net, good for hardlink exchanges | |
|   |           | 
|  06-30-2004, 04:31 AM | #39 | |
| ►SouthOfHeaven Join Date: Jun 2004 Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer 
					Posts: 28,609
				 | Quote: 
 
				__________________ hatisblack at yahoo.com | |
|   |           |