amiga.org
     
iconAll times are GMT -6. The time now is 05:12 PM. | Welcome to Forum, please register to access all of our features.

» Amiga.org » Amiga computer related discussion » General chat about Amiga topics » Is Aminet OK/infected?

General chat about Amiga topics This forum is for conversations which are specifically "Amiga" related, but don't fit into other categories. Contents of this forum do appear on the main page, unlike Talk About. If a subject appears to be non-related, it will be moved to Talk About.

Reply
 
Thread Tools Display Modes
Old 05-10-2012, 09:51 PM   #1
desiv
Defender of the Faith
Points: 5,227, Level: 46 Points: 5,227, Level: 46 Points: 5,227, Level: 46
Activity: 11% Activity: 11% Activity: 11%
 
desiv's Avatar
 
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
Default Is Aminet OK/infected?

I couldn't download anything from there from my Amiga using either iBrowse or AWeb.

I poked my laptop at it, and Avast AV said it stopped a bad program....
I couldn't download from there either.
(Every thing I tried to DL actually downloads a script that's encoded, that sounds bad...)

(Note: don't go running there if you have Windows just to see if it's safe! :-)

desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
desiv is offline   Reply With Quote
Old 05-10-2012, 09:55 PM   #2
Gulliver
Defender of the Faith
Points: 13,347, Level: 75 Points: 13,347, Level: 75 Points: 13,347, Level: 75
Activity: 1% Activity: 1% Activity: 1%
 
Join Date: May 2007
Location: South of the south
Posts: 1,227
Blog Entries: 2
Default Re: Is Aminet OK/infected?

I also get a similar virus alert with NOD32
Gulliver is offline   Reply With Quote
Old 05-10-2012, 09:58 PM   #3
darkage
Technoid
Points: 5,286, Level: 46 Points: 5,286, Level: 46 Points: 5,286, Level: 46
Activity: 2% Activity: 2% Activity: 2%
 
Join Date: Aug 2007
Location: Melbourne, Australia
Posts: 334
Default Re: Is Aminet OK/infected?

I got similar too for Symantec.. Probably a real threat since other Virus Scanners are picking it up..
darkage is offline   Reply With Quote
Old 05-10-2012, 10:19 PM   #4
LoadWB
Kindred of Babble-on
Points: 13,227, Level: 74 Points: 13,227, Level: 74 Points: 13,227, Level: 74
Activity: 15% Activity: 15% Activity: 15%
 
LoadWB's Avatar
 
Join Date: Jul 2006
Location: Tallahassee, FL
Posts: 2,098
Default Re: Is Aminet OK/infected?

AVG: Script/Exploit.Kit

LoadWB is offline   Reply With Quote
Old 05-10-2012, 10:20 PM   #5
Paulie85
Too much caffeine
Points: 2,887, Level: 32 Points: 2,887, Level: 32 Points: 2,887, Level: 32
Activity: 4% Activity: 4% Activity: 4%
 
Paulie85's Avatar
 
Join Date: Dec 2009
Posts: 71
Default Re: Is Aminet OK/infected?

Slightly off topic but Norton 360 always shreds Hollywood on my PC before I can use it.
Paulie85 is offline   Reply With Quote
Old 05-10-2012, 10:58 PM   #6
Duce
Off to greener pastures
Points: 5,303, Level: 46 Points: 5,303, Level: 46 Points: 5,303, Level: 46
Activity: 24% Activity: 24% Activity: 24%
 
Join Date: Jul 2009
Posts: 1,057
Default Re: Is Aminet OK/infected?

Same thing here - main page flags Eset NOD32/Eset Smart Security the minute I visit the main Aminet page.
Duce is offline   Reply With Quote
Old 05-10-2012, 11:01 PM   #7
Piru
' union select name,pwd--
Points: 30,457, Level: 100 Points: 30,457, Level: 100 Points: 30,457, Level: 100
Activity: 69% Activity: 69% Activity: 69%
 
Piru's Avatar
 
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
Default Re: Is Aminet OK/infected?

Yes, aminet is infected. It attempts a drive-by attacks against windows systems via java vulnerability, at least. It likely attempts to use several attack vectors depending on the targets system: java, flash, pdf, and vulnerabilities in the browsers themselves.

Here's how you can see the initial javascript payload regardless of the platform:

Code:
curl --user-agent 'Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)' http://aminet.net/util/arc/lha.run | less
Modifying e(s) the end of the code to document.write(s) we can see the actual payload decoded. It opens an iframe with URL "http://<censored>.ibiz.cc/?go=2" that'll perform the actual drive-by attack:

Last edited by Piru; 05-10-2012 at 11:22 PM.. Reason: added as pic to avoid alerts
Piru is offline   Reply With Quote
Old 05-11-2012, 03:56 AM   #8
Lurch
Defender of the Faith
Points: 12,739, Level: 73 Points: 12,739, Level: 73 Points: 12,739, Level: 73
Activity: 30% Activity: 30% Activity: 30%
 
Lurch's Avatar
 
Join Date: Dec 2003
Location: Auckland, New Zealand
Posts: 1,058
Send a message via MSN to Lurch
Default Re: Is Aminet OK/infected?

aminet is toast, explains why grunch is dying
__________________
-=[LurcH]=-
A500 Plus·Black·030@14Mhz·2MB·8MB·A590·KS 3.1·WB 3.1·2GB CFCard·Mechware SCSI Card Reader·Indivision ECS
A1200 Tower·060@80MHz·2MB·32MB·KS 3.9·WB 3.9·Indivision AGA MkII·40GBHDD·FastATA·HxC2001·WPA2 Wireless·Subway USB·Pico ITX PSU·PS2/USB Mouse·Lyra2
Amiga Forever 2012 (Thanks MCB)
PowerMac G4·MorphOS Box·SBlive·5 port USB card
Indivision ECS (Chris at Amigakit is da'Man)
A1200 board·new caps·timing fixes (another awesome job Amigakit)
www.taf.org.nz
Lurch is offline   Reply With Quote
Old 05-11-2012, 04:05 AM   #9
Robert17
Cult Member
Points: 12,331, Level: 72 Points: 12,331, Level: 72 Points: 12,331, Level: 72
Activity: 2% Activity: 2% Activity: 2%
 
Join Date: Apr 2004
Location: Norfolk, UK
Posts: 964
Send a message via MSN to Robert17
Default Re: Is Aminet OK/infected?

I hope it can be sorted out, Where would we be without Aminet? :-(
__________________
A4000D CSMK3 060/50mhz, 144mb ram, CVPPC video - Currently broken scsi :-(
A4000D/T Warpengine 4040.
A2000 Blizzard 2060, Picasso 2 and Indivision ECS.
A2000 GVP G-Force 030-40mhz, 13mb Ram and Amber and Mechware SCSI Card reader.
A1200D 030/50 34mb ram with Indivision AGA.
Robert17 is offline   Reply With Quote
Old 05-11-2012, 05:07 AM   #10
carls
Defender of the Faith
Points: 10,480, Level: 68 Points: 10,480, Level: 68 Points: 10,480, Level: 68
Activity: 4% Activity: 4% Activity: 4%
 
Join Date: Mar 2002
Posts: 1,032
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by Robert17 View Post
I hope it can be sorted out, Where would we be without Aminet? :-(
Don't fear, you don't need the web for everything... yet.

Code:
ncftp> open ftp.aminet.net
Connecting to 69.163.220.116...
ProFTPD 1.3.3a Server (My FTP server) [::ffff:69.163.220.116]
Logging in...
Anonymous access granted, restrictions apply
Logged in to ftp.aminet.net.
ncftp / > ls
biz/                      gfx/                      pix/
comm/                     INDEX                     pub/
demo/                     INDEX.gz                  README.BEFORE.UPLOAD
dev/                      info/                     RECENT
disk/                     man                       RECENT.gz
docs/                     misc/                     robots.txt
driver/                   mods/                     text/
favicon.gif               MOTD                      touch
favicon.ico               mus/                      TREE
game/                     new/                      util/
ncftp / >
__________________
Amiga: Too weird to live, too rare to die.
carls is offline   Reply With Quote
Old 05-11-2012, 05:33 AM   #11
Piru
' union select name,pwd--
Points: 30,457, Level: 100 Points: 30,457, Level: 100 Points: 30,457, Level: 100
Activity: 69% Activity: 69% Activity: 69%
 
Piru's Avatar
 
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by carls View Post
Don't fear, you don't need the web for everything... yet.
Unfortunately you cannot trust anything coming from aminet at this stage. The FTP could be distributing malware as well, though luckily windows binaries are in the minority...
Piru is offline   Reply With Quote
Old 05-11-2012, 06:23 AM   #12
cgutjahr
Technoid
Points: 9,017, Level: 63 Points: 9,017, Level: 63 Points: 9,017, Level: 63
Activity: 2% Activity: 2% Activity: 2%
 
Join Date: Feb 2003
Location: Germany
Posts: 457
Default Re: Is Aminet OK/infected?

Thanks for pointing out the problem. Unfortunately, I'm on my way out, and I won't be back in civilisation until Sunday. I alarmed the server admin (nicomen), I hope he sees my mail asap and has the time to investigate and fix the problem.
cgutjahr is offline   Reply With Quote
Old 05-11-2012, 06:51 AM   #13
number6
Premium Member
Points: 7,481, Level: 57 Points: 7,481, Level: 57 Points: 7,481, Level: 57
Activity: 18% Activity: 18% Activity: 18%
 
Join Date: Mar 2005
Posts: 676
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by cgutjahr View Post
Thanks for pointing out the problem. Unfortunately, I'm on my way out, and I won't be back in civilisation until Sunday. I alarmed the server admin (nicomen), I hope he sees my mail asap and has the time to investigate and fix the problem.

From your post March 30, 2012 on AW, I notice:

Quote:
our hoster decided to make some changes for the sake of security
Perhaps a connection?

#6
number6 is offline   Reply With Quote
Old 05-11-2012, 07:49 AM   #14
Gulliver
Defender of the Faith
Points: 13,347, Level: 75 Points: 13,347, Level: 75 Points: 13,347, Level: 75
Activity: 1% Activity: 1% Activity: 1%
 
Join Date: May 2007
Location: South of the south
Posts: 1,227
Blog Entries: 2
Default Re: Is Aminet OK/infected?

It is fixed now.
Aminet seems clean and working
Gulliver is offline   Reply With Quote
Old 05-11-2012, 08:04 AM   #15
Piru
' union select name,pwd--
Points: 30,457, Level: 100 Points: 30,457, Level: 100 Points: 30,457, Level: 100
Activity: 69% Activity: 69% Activity: 69%
 
Piru's Avatar
 
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
Default Re: Is Aminet OK/infected?

I'd like to hear an explanation for this however. Unless if the method of original penetration can be figured out and blocked it could happen again and again (as has happened with certain other amiga related sites). Also, it seems that the domain name used to distribute the malware expired (or was changed deliberately).

Some official word from aminet would be in order I'd say.
Piru is offline   Reply With Quote
Reply

Bookmarks

Tags
aminet , ok or infected

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump