![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Watch Out For GIF Images Containing Hidden Malicious Code
On June 24th, a visitor to the SANS Internet Storm Center reported that his company was "...in the middle of a very disturbing ... issue regarding the adware/spyware/IE exploit genre..." He requested help analyzing an "encrypted or compressed" file that had been downloaded to a machine at their site. Tom Liston, one of our volunteer handlers, spent the weekend analyzing this issue. His findings are summarized here.
The victim of the attack found that a file called "img1big.gif" had been loaded onto their machine. Because of the account restrictions on the person running the machine, it had failed to install properly, which was why it had come to their attention. It is this file that they forwarded to the SANS Internet Storm Center for analysis. The file is not a graphic file at all. It is actually a 27648 byte Win32 executable that has been compressed using the Open Source executable compressor UPX. This file decompresses to an 81920 byte file which contains two Win32 executables bound together. The first portion of the file (and what actually runs if the file extension is changed and the program is launched) is a "file dropper" Trojan, designed to install any executable concatenated to its body. The second half of the file consists of a Win32 DLL that is installed by the file dropper under WindowsXP as a randomly named .dll file under C:\WINDOWS\System32\. This DLL is installed as a "Browser Helper Object" (BHO) under Internet Explorer. A "Browser Helper Object" is a DLL that allows developers to customize and control Internet Explorer. When IE 4.x and higher starts, it reads the registry to locate installed BHO's and then loads them into the memory space for IE. Created BHO's then have access to all the events and properties of that browsing session. This particular BHO watches for HTTPS (secure) access to URLs of several dozen banking and financial sites in multiple countries. When an outbound HTTPS connection is made to such a URL, the BHO then grabs any outbound POST/GET data from within IE before it is encrypted by SSL. When it captures data, it creates an outbound HTTP connection to http://www.refestltd.com/cgi-bin/yes.pl and feeds the captured data to the script found at that location.
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
I need a beer
![]() Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,944
|
Actually that has been happening for awhile...fucking weasels are really up on this...hope they all rot in hell
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
GFY HALL OF FAME DAMMIT!!!
Join Date: Jan 2002
Location: that 504
Posts: 60,840
|
"You can point your gun at me
And hope it will go away But if God was alive, He would hate you anyway." Cheers! just checking in on vacation ![]() ![]()
__________________
![]() Want an Android App for your tube, membership, or free site? Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
I love using Mozilla
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Guest
Posts: n/a
|
Great, how long before we will have to make our sigs static jpegs on gfy?
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2002
Location: The Boonies
Posts: 12,860
|
man this shit is getting more and more sinister with each exploit/hack/trojan that comes to light,
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Chafed.
Join Date: May 2002
Location: Face Down in Pussy
Posts: 18,041
|
Anybody want me to write them a BHO?
Its gonna cost ya. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Feb 2002
Location: NYC, NY
Posts: 8,531
|
any protection out on this one yet?
__________________
![]() ~ Webair Dedicated Cloud Servers™ ~ WEBAIR VSYS™ Virtual Hosting Platform ~ Superior CDN Network ~ ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~ ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
holla
Join Date: Jul 2003
Location: KFC
Posts: 11,769
|
if any coders want to hook me up on how to execute spyware using GIFs, contact me, my aim info is in my profile
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Jun 2001
Location: Closer than you think
Posts: 9,535
|
Thanks for the info.
__________________
Need Mainstream Content and SEO? SEO * Website Copy * Blogs Blogging - PR Work - Forum Marketing - Social Marketing - Link building - Articles 100% Guaranteed Content! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Join Date: Jan 2003
Posts: 3,852
|
Quote:
![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
holla
Join Date: Jul 2003
Location: KFC
Posts: 11,769
|
Quote:
get over it money is money people can download ad-aware if it bothers them |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Mar 2002
Posts: 7,245
|
The surpreme court needs to stop wasting time with the porn sites and focus on shit like this
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
![]() ![]() ![]() ![]() ![]()
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
First African GFY Member
Join Date: Mar 2004
Location: New Jersey
Posts: 12,114
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
![]() ![]() ![]()
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Back in my trojanning days I met a chick who did a similar job in GIF's and when I tried to discuss it with a professor or two they'd always laugh me out of the room. You can't execute code from inside of a gif, there is no compiler (blah blah blah) and yada yada... So finally someone has probably paired it with IRC bots to infect hundreds a day and now all of a sudden it IS possible... funny how shit turns out.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
I'm Lenny2 Bitch
Join Date: Mar 2001
Location: On top of my soapbox
Posts: 13,449
|
Quote:
__________________
sig too big |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: May 2002
Location: Steeler Country
Posts: 1,307
|
Quote:
![]()
__________________
![]() $30 PER SIGNUP PLUS 25% RECURRING FREE HOSTED PIC AND MOVIE GALLERIES Submit Your Free Sites, Pic and Movie Galleries Here ICQ : 20034024 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Die With Your Boots On
Join Date: Oct 2003
Location: Hawaii
Posts: 22,872
|
Fuck, pretty soon they'll have to just abandon this internet as we know it and start all over again from scratch. Mark my words, it'll happen.
![]()
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
holla
Join Date: Jul 2003
Location: KFC
Posts: 11,769
|
Quote:
i'd set it up outside the u.s. lol |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Join Date: Feb 2004
Location: Anaheim - CA
Posts: 6,741
|
I have been battling fucked up spyware all week and I know it came from some TGP sites.
Fucking auto intalling mother fuckers. I can't see how screwing up my machine is making anyone money. I couldn't even buy something from them if I wanted to. It fucks the browser up so bad that even when you click on the search listings from the auto intalled hacked homepage, you just get ads to remove spyware. The pay per click search engine traffic will become worthless at this rate really.
__________________
AKA - Clubsexy |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Quote:
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Registered User
Join Date: May 2004
Posts: 20
|
This is evil.
__________________
spyware instant help |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Join Date: Apr 2004
Posts: 3,875
|
Quote:
![]()
__________________
No sig, just here to fuck around. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
So Fucking Banned
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
I'm Lenny2 Bitch
Join Date: Mar 2001
Location: On top of my soapbox
Posts: 13,449
|
Quote:
Most surfers barely know how to open internet explorer, much less install and use opera or mozilla. If this stuff keeps up surfers will be afraid to go to adult sites period.
__________________
sig too big |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Join Date: Aug 2003
Location: DK
Posts: 779
|
Mozilla Mozilla Mozilla Mozilla Mozilla
__________________
High Converting CCBILL Programs Amateur/CFNM -> http://www.boozedwomen.com/tour/ Best Selling Granny Site -> http://www.excitedwives.com/tour/ ![]() If I had a hammer.... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
mozilla stopped using gif's ?? news to me
![]() mozilla has more holes than a golf course
__________________
hatisblack at yahoo.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
So Fucking Banned
Join Date: Apr 2003
Location: malta
Posts: 12,745
|
Hey Smokey did you even read the post?
"The file is not a graphic file at all. It is actually a 27648 byte Win32 executable that has been compressed using the Open Source executable compressor UPX. This file decompresses to an 81920 byte file which contains two Win32 executables bound together. The first portion of the file (and what actually runs if the file extension is changed and the program is launched) is a "file dropper" Trojan, designed to install any executable concatenated to its body. The second half of the file consists of a Win32 DLL that is installed by the file dropper under WindowsXP as a randomly named .dll file under C:\WINDOWS\System32\. This DLL is installed as a "Browser Helper Object" (BHO) under Internet Explorer. " Does nothing at all to people on Mozilla . Mozilla is secure because not many people use it.. so who is going to bother wasting time trying to exploit it? That being said.. I am sure any holes that people do find will be patched with alacrity. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 | |
UNSTOPPABLE
Join Date: Aug 2003
Location: UK :: ICQ# 156068
Posts: 11,569
|
Quote:
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Confirmed User
Join Date: Feb 2002
Posts: 720
|
Actually if you read the write-up at
http://isc.sans.org/presentations/banking_malware.pdf you'll find that the image file needs to be renamed to install itself. They theorize that a .chm exploit is used to rename the GIF and run it. So the fact that it's a GIF file isn't really important, it could have any file extension the attacker would like. JPG would work just as well. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Nov 2002
Location: Belgium
Posts: 7,383
|
woa! Imagine the data that "listener" server gets! Thousands and thousands of CC numbers/passwords...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Confirmed User
Join Date: Jun 2001
Location: Wherever I want
Posts: 7,517
|
Thanks for the information!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 | |
Too lazy to set a custom title
Join Date: Jan 2002
Location: Holland
Posts: 9,870
|
Quote:
__________________
Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 | |
UNSTOPPABLE
Join Date: Aug 2003
Location: UK :: ICQ# 156068
Posts: 11,569
|
Quote:
2. Don't be so quick to open your mouth. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 | |
Confirmed User
Join Date: Mar 2003
Posts: 1,169
|
Quote:
If you actually read the post you'd see that it uses the BHO... now my guess is telling me that Mozilla doesn't have this BHO. I'm glad I use Linux and Mozilla ![]()
__________________
SUBMIT YOUR BABE GALLERIES PROMOTE YOUR BLOG HERE always looking for hardlinks icq #207011694 Thunder-Ball.net, good for hardlink exchanges |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
►SouthOfHeaven
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
|
Quote:
__________________
hatisblack at yahoo.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |