Bad Movie Logo
"A website to the detriment of good film"
Custom Search
HOMEB-MOVIE REVIEWSREADER REVIEWSFORUMINTERVIEWSUPDATESABOUT
Welcome, Guest. Please login or register.
Did you miss your activation email?
April 26, 2024, 06:30:33 PM
714415 Posts in 53097 Topics by 7742 Members
Latest Member: KathleneKa
Badmovies.org Forum  |  Movies  |  Bad Movies  |  Downloader Trojan « previous next »
Pages: [1] 2
Author Topic: Downloader Trojan  (Read 4458 times)
Andrew
Administrator
Frightening Fanatic of Horrible Cinema
****

Karma: 0
Posts: 8457


I know where my towel is.


WWW
« on: June 21, 2006, 04:03:57 PM »

I received two emails from readers who recently visited the site and received antivirus alerts about the downloader trojan trying to infect their system.  Having looked through the site with my own computer, I could not get the same alerts (I also Symantec and have the latest Java runtime - 5.0 version 7).  Nor could I locate anything in the html that was being served.

I uploaded new copies of most of the main pages to see if that helps.  However, if anyone else has seen this - can you tell me where you were at (or had recently looked at) when the alert popped up?  It would make the most sense for it to be here on the message board or in the comments system.
Logged

Andrew Borntreger
Badmovies.org
Andrew
Administrator
Frightening Fanatic of Horrible Cinema
****

Karma: 0
Posts: 8457


I know where my towel is.


WWW
« Reply #1 on: June 21, 2006, 07:08:14 PM »

Trek_geezer just let me know this popped up again. I located the code this time and it was specifically targeted at the homepage and the bottom navigator.  If I have to guess, someone has compromised the admin account on the shared server (I am on a VPS, just a handful of domains on the server) and the modification was targeted.  Since I cannot chase it down by checking all the logs myself, I alerted the Hostgator admins.

Please be careful until I get some resolution on this.  The latest version of Java seems safe, since it did not download the trojan when I checked.  The latest version is 5.0, update 7.  This is something that every computer should be using.  The install can be found here:

http://java.sun.com/j2se/1.5.0/download.jsp

What you want is, most often (unless you are a developer) JRE 5.0, Update 7.  You should always keep your Java up to date, as it is a common target for worms, trojans, and such.
Logged

Andrew Borntreger
Badmovies.org
odinn7
Frightening Fanatic of Horrible Cinema
****

Karma: 57
Posts: 2259



« Reply #2 on: June 21, 2006, 08:07:10 PM »

Thanks for letting us know about this Andrew.
Logged

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

You're not the Devil...You're practice.
ulthar
Frightening Fanatic of Horrible Cinema
****

Karma: 368
Posts: 4168


I AM serious, and stop calling me Shirley


WWW
« Reply #3 on: June 21, 2006, 08:23:42 PM »

Andrew,

Are they running tripwire (or similar) on the server?  If not, you might try something like this too-simple  home-grown solution.

If you are on good terms with the guys on your host (or have root access directly), could you not put a daily cron job to

(1) calc. the md5 hash of your key (static) files
(2) email you if it is different from a 'reference' value

This MAY help catch cases of tampering with your static html files.

Of course, if root is compromised, the cracker might see this and trojan it, too.  Perhaps better is to just email you the hashes and you do the comparison on the client side.

But, of course, if they get root, all bets are pretty much off if they do any real damage.
Logged

------------------------------------------------------------------------------------------------

Professor Hathaway:  I noticed you stopped stuttering.
Bodie:      I've been giving myself shock treatments.
Professor Hathaway: Up the voltage.

--Real Genius
Ed, Ego and Superego
Frightening Fanatic of Horrible Cinema
****

Karma: 300
Posts: 3016



« Reply #4 on: June 21, 2006, 09:59:33 PM »

Ulthar,
 WOW that looked like an episode of Start Trek with that techie talk.  I am absolutely in awe and jealous.  
But I use the word s"Acetoxymethyl Ester" on a daily basis so I can't complain too much.  
Great work guys!
-Ed
Logged

Quantum materiae materietur marmota monax si marmota monax materiam possit materiari?

Si Hoc Legere Scis Nimium Eruditionis Habes
Fearless Freep
Frightening Fanatic of Horrible Cinema
****

Karma: 15
Posts: 2328


« Reply #5 on: June 21, 2006, 10:01:01 PM »

Oh he was just explaining what happenes Andrew could do if he got pwned
Logged

=======================
Going places unmapped, to do things unplanned, to people unsuspecting
Ash
Frightening Fanatic of Horrible Cinema
****

Karma: 0
Posts: 6775


23 Year Badmovies.org Veteran


« Reply #6 on: June 22, 2006, 02:59:27 AM »

I downloaded the Java update.
So far, I haven't noticed anything out of the ordinary here on the board.
(knock on wood)

Can you poast a link for a cure if any of our p.c.'s happen to get infected?
Logged
akiratubo
Frightening Fanatic of Horrible Cinema
****

Karma: 480
Posts: 3801



« Reply #7 on: June 22, 2006, 06:06:36 AM »

I got an alert from Avira Antivir for those trojans as soon as the front page loaded, earlier today.
Logged

Kneel before Dr. Hell, the ruler of this world!
Andrew
Administrator
Frightening Fanatic of Horrible Cinema
****

Karma: 0
Posts: 8457


I know where my towel is.


WWW
« Reply #8 on: June 22, 2006, 07:40:45 AM »

This should now be resolved.  I stayed up until my hosting took care of one request I had (something I could not do myself, since the site is on a VPS).  Somehow the bad guy had my ftp password, which is strange - I am careful about where I log in from and how.  The password was also not a simple one.  The problem with FTP is that the password information is passed in the clear.  If the bad guy had somehow compromised a system between me and the server at some point, that would explain it.  My definite apologies to everyone for the problem.

I can do cron jobs and such, but tripwires often do funky things.  I will make a few changes and have some ideas how to keep an eye out for something like this in the future.

Ash, I am including a link to the Symantec page about the trojan (what popped up for Ed - he sent me a link).  However, your best bet is always to keep an updated virus scan.  Not doing so is a surefire recipe for danger.  At any one point there are several unpatched exploits for Internet Explorer.  I should also point out that the downloader trojan is just that, it attempts to download more nasty stuff onto a computer.  They are not uncommon at all on the Internet.  I have seen a few sites I use infected by them at times, usually bbs posts and such - most bbs software will catch this now.

I also should mention that I use Mozillla, vice IE.  Another reason I might not have seen this - but most of the Java-based trojans I have seen rely on exploiting Java.

http://securityresponse.symantec.com/avcenter/venc/data/downloader.html

The issue should have been fixed for the last eight hours.
Logged

Andrew Borntreger
Badmovies.org
AndyC
Global Moderator
B-Movie Kraken
****

Karma: 1402
Posts: 11156



« Reply #9 on: June 22, 2006, 09:49:47 AM »

I picked it up a couple of days ago, and yes my Java was far from up to date. Was a nasty little bugger that was difficult to dig out once it was in there. I got the virus alert as soon as I accessed the board, then noticed a few things had immediately gone wonky. Homepage had changed, and popular addresses (google, yahoo, download.com, etc.) were rerouted to a page alerting me to the spyware (throwing in a scare that my computer might also be full of hidden pornography) and offering to sell me software to clean it off. Can you imagine the nerve? Can you imagine someone too stupid to see what's going on and actually buying it?

I updated all my definitions, then ran PCcillin, AdAware, Spybot, CWShredder and Hijackthis. Each one caught something, but it was CWShredder that finally fixed the problem with Google et al. Hijackthis then found the hidden pornography (a whole mess of links to porn sites, probably put there for the anti-spyware software to find once some fool buys it).

Anyway, my computer is now probably cleaner than it's been since I first turned it on.

Hard to imagine getting infected on this board. When it happened, I couldn't understand it, because I hadn't visited any questionable sites. The warning popped up when I visited here, but it didn't make sense to me that the trojan came from here.
Logged

---------------------
"Join me in the abyss of savings."
Mr_Vindictive
Frightening Fanatic of Horrible Cinema
****

Karma: 129
Posts: 3702


By Sword. By Pick. By Axe. Bye Bye.


« Reply #10 on: June 22, 2006, 10:35:14 AM »

AndyC Wrote:
-------------------------------------------------------
> Homepage had changed, and
> popular addresses (google, yahoo, download.com,
> etc.) were rerouted to a page alerting me to the
> spyware (throwing in a scare that my computer
> might also be full of hidden pornography) and
> offering to sell me software to clean it off. Can
> you imagine the nerve? Can you imagine someone too
> stupid to see what's going on and actually buying
> it?


Actually, yeah.  A lot of people do download, and pay, for the software that is recommended by the trojan. The software never actually removes anything, just installs more spyware and crap on the PC.
Logged

__________________________________________________________
"The greatest medicine in the world is human laughter. And the worst medicine is zombie laughter." -- Jack Handey

A bald man named Savalas visited me last night in a dream.  I think it was a Telly vision.
Andrew
Administrator
Frightening Fanatic of Horrible Cinema
****

Karma: 0
Posts: 8457


I know where my towel is.


WWW
« Reply #11 on: June 22, 2006, 12:02:54 PM »

AndyC Wrote:
-------------------------------------------------------
> Hard to imagine getting infected on this board.
> When it happened, I couldn't understand it,
> because I hadn't visited any questionable sites.
> The warning popped up when I visited here, but it
> didn't make sense to me that the trojan came from
> here.

Which is what really annoyed me.  I had gotten an email from Alex Baumans about the issue and was looking through the site, trying to trigger something as I also pulled up source code.  Then Ed emailed me while I was doing that saying the same thing.  At that point I just uploaded new versions of most of the pages.  When the bastard who was doing things came back I saw the change (took him about an hour).  By then I was already changing passwords and doing such.  Took me most of yesterday evening to make all the changes I wanted, just in case.

Quite honestly, if I was on a dedicated server I would probably just dump Russia and most countries over there into my firewall Deny pool.  You would not believe the number of attempted attacks I see daily.  And that is with the limited log access I have on the VPS.  Most are just scripted attacks, but there must be 50 to 100 per day, at least.
Logged

Andrew Borntreger
Badmovies.org
Ed, Ego and Superego
Frightening Fanatic of Horrible Cinema
****

Karma: 300
Posts: 3016



« Reply #12 on: June 22, 2006, 01:03:04 PM »

I rebuilt my computer recently and plugged it in to start re-installing all the updates to my original version of Windows and get my virus scanner, so I essentially had a "naked computer".  I googled some help sites to reference a process I didn't recognize and within 30 seconds  I had been hijcked, virused, spywared, etc.  I wiped the machine again, just to be safe.
It was big lesson in security and a dent in my faith in humanity.  But now I am all over security.  But I say the scum who do this should be lightly boiled and then dried with a cheese grater.
-Ed
Logged

Quantum materiae materietur marmota monax si marmota monax materiam possit materiari?

Si Hoc Legere Scis Nimium Eruditionis Habes
ulthar
Frightening Fanatic of Horrible Cinema
****

Karma: 368
Posts: 4168


I AM serious, and stop calling me Shirley


WWW
« Reply #13 on: June 22, 2006, 04:03:33 PM »

Ed Wrote:
-------------------------------------------------------
>
> It was big lesson in security and a dent in my
> faith in humanity.  But now I am all over
> security.

Well, er, at least a dent on one's faith of WINDOWS.  That's where the problem lies, but that is a discussion for another day.
Logged

------------------------------------------------------------------------------------------------

Professor Hathaway:  I noticed you stopped stuttering.
Bodie:      I've been giving myself shock treatments.
Professor Hathaway: Up the voltage.

--Real Genius
Dr. Whom
Frightening Fanatic of Horrible Cinema
****

Karma: 115
Posts: 1592


Cthulhu for president! Why choose the lesser evil?


« Reply #14 on: June 22, 2006, 04:38:56 PM »

ulthar Wrote:
-------------------------------------------------------
> >
> >
> But, of course, if they get root, all bets are
> pretty much off if they do any real damage.


I must remember this one. The best technical phrase since Jon Pertwee reversed the polarity of the neutron flow.
Logged

"Once you get past a certain threshold, everyone's problems are the same: fortifying your island and hiding the heat signature from your fusion reactor."

Wenn ist das Nunstück git und Slotermeyer? Ja! ... Beiherhund das Oder die Flipperwaldt gersput.
Pages: [1] 2
Badmovies.org Forum  |  Movies  |  Bad Movies  |  Downloader Trojan « previous next »
    Jump to:  


    RSS Feed Subscribe Subscribe by RSS
    Email Subscribe Subscribe by Email


    Popular Articles
    How To Find A Bad Movie

    The Champions of Justice

    Plan 9 from Outer Space

    Manos, The Hands of Fate

    Podcast: Todd the Convenience Store Clerk

    Faster, Pussycat! Kill! Kill!

    Dragonball: The Magic Begins

    Cool As Ice

    The Educational Archives: Driver's Ed

    Godzilla vs. Monster Zero

    Do you have a zombie plan?

    FROM THE BADMOVIES.ORG ARCHIVES
    ImageThe Giant Claw - Slime drop

    Earth is visited by a GIANT ANTIMATTER SPACE BUZZARD! Gawk at the amazingly bad bird puppet, or chuckle over the silly dialog. This is one of the greatest b-movies ever made.

    Lesson Learned:
    • Osmosis: os·mo·sis (oz-mo'sis, os-) n., 1. When a bird eats something.

    Subscribe to Badmovies.org and get updates by email:

    HOME B-Movie Reviews Reader Reviews Forum Interviews TV Shows Advertising Information Sideshows Links Contact

    Badmovies.org is owned and operated by Andrew Borntreger. All original content is © 1998 - 2014 by its respective author(s). Image, video, and audio files are used in accordance with the Fair Use Law, and are property of the film copyright holders. You may freely link to any page (.html or .php) on this website, but reproduction in any other form must be authorized by the copyright holder.