|
Register or have you forgotten your password?
|
|
|
| General chat about Amiga topics This forum is for conversations which are specifically "Amiga" related, but don't fit into other categories. Contents of this forum do appear on the main page, unlike Talk About. If a subject appears to be non-related, it will be moved to Talk About. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 | ||||||||
|
Defender of the Faith
![]()
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
|
I couldn't download anything from there from my Amiga using either iBrowse or AWeb.
I poked my laptop at it, and Avast AV said it stopped a bad program.... I couldn't download from there either. (Every thing I tried to DL actually downloads a script that's encoded, that sounds bad...) (Note: don't go running there if you have Windows just to see if it's safe! :-) desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S. Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S. Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy. |
||||||||
|
|
|
|
|
#3 | ||||||||
|
Technoid
![]()
Join Date: Aug 2007
Location: Melbourne, Australia
Posts: 334
|
I got similar too for Symantec.. Probably a real threat since other Virus Scanners are picking it up..
|
||||||||
|
|
|
|
|
#4 | ||||||||
|
Kindred of Babble-on
![]()
Join Date: Jul 2006
Location: Tallahassee, FL
Posts: 2,098
|
AVG: Script/Exploit.Kit
|
||||||||
|
|
|
|
|
#5 | ||||||||
|
Too much caffeine
![]()
Join Date: Dec 2009
Posts: 71
|
Slightly off topic but Norton 360 always shreds Hollywood on my PC before I can use it.
|
||||||||
|
|
|
|
|
#6 | ||||||||
|
Off to greener pastures
Join Date: Jul 2009
Posts: 1,057
|
Same thing here - main page flags Eset NOD32/Eset Smart Security the minute I visit the main Aminet page.
|
||||||||
|
|
|
|
|
#7 | ||||||||
|
' union select name,pwd--
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
|
Yes, aminet is infected. It attempts a drive-by attacks against windows systems via java vulnerability, at least. It likely attempts to use several attack vectors depending on the targets system: java, flash, pdf, and vulnerabilities in the browsers themselves.
Here's how you can see the initial javascript payload regardless of the platform: Code:
curl --user-agent 'Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)' http://aminet.net/util/arc/lha.run | less
Last edited by Piru; 05-10-2012 at 11:22 PM.. Reason: added as pic to avoid alerts |
||||||||
|
|
|
|
|
#8 | ||||||||
|
Defender of the Faith
![]()
|
aminet is toast, explains why grunch is dying
__________________
-=[LurcH]=- A500 Plus·Black·030@14Mhz·2MB·8MB·A590·KS 3.1·WB 3.1·2GB CFCard·Mechware SCSI Card Reader·Indivision ECS A1200 Tower·060@80MHz·2MB·32MB·KS 3.9·WB 3.9·Indivision AGA MkII·40GBHDD·FastATA·HxC2001·WPA2 Wireless·Subway USB·Pico ITX PSU·PS2/USB Mouse·Lyra2 Amiga Forever 2012 (Thanks MCB) PowerMac G4·MorphOS Box·SBlive·5 port USB card Indivision ECS (Chris at Amigakit is da'Man) A1200 board·new caps·timing fixes (another awesome job Amigakit) www.taf.org.nz |
||||||||
|
|
|
|
|
#9 | ||||||||
|
Cult Member
![]()
|
I hope it can be sorted out, Where would we be without Aminet? :-(
__________________
A4000D CSMK3 060/50mhz, 144mb ram, CVPPC video - Currently broken scsi :-( A4000D/T Warpengine 4040. A2000 Blizzard 2060, Picasso 2 and Indivision ECS. A2000 GVP G-Force 030-40mhz, 13mb Ram and Amber and Mechware SCSI Card reader. A1200D 030/50 34mb ram with Indivision AGA. |
||||||||
|
|
|
|
|
#10 | |||||||||
|
Defender of the Faith
![]()
Join Date: Mar 2002
Posts: 1,032
|
Quote:
Code:
ncftp> open ftp.aminet.net Connecting to 69.163.220.116... ProFTPD 1.3.3a Server (My FTP server) [::ffff:69.163.220.116] Logging in... Anonymous access granted, restrictions apply Logged in to ftp.aminet.net. ncftp / > ls biz/ gfx/ pix/ comm/ INDEX pub/ demo/ INDEX.gz README.BEFORE.UPLOAD dev/ info/ RECENT disk/ man RECENT.gz docs/ misc/ robots.txt driver/ mods/ text/ favicon.gif MOTD touch favicon.ico mus/ TREE game/ new/ util/ ncftp / >
__________________
Amiga: Too weird to live, too rare to die. |
|||||||||
|
|
|
|
|
#11 | ||||||||
|
' union select name,pwd--
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
|
|
||||||||
|
|
|
|
|
#12 | ||||||||
|
Technoid
![]()
Join Date: Feb 2003
Location: Germany
Posts: 457
|
Thanks for pointing out the problem. Unfortunately, I'm on my way out, and I won't be back in civilisation until Sunday. I alarmed the server admin (nicomen), I hope he sees my mail asap and has the time to investigate and fix the problem.
|
||||||||
|
|
|
|
|
#13 | ||||||||||
|
Premium Member
Join Date: Mar 2005
Posts: 676
|
Quote:
From your post March 30, 2012 on AW, I notice: Quote:
#6 |
||||||||||
|
|
|
|
|
#15 | ||||||||
|
' union select name,pwd--
Join Date: Aug 2002
Location: Helsinki, Finland
Posts: 6,946
|
I'd like to hear an explanation for this however. Unless if the method of original penetration can be figured out and blocked it could happen again and again (as has happened with certain other amiga related sites). Also, it seems that the domain name used to distribute the malware expired (or was changed deliberately).
Some official word from aminet would be in order I'd say. |
||||||||
|
|
|
![]() |
| Bookmarks |
| Tags |
| aminet , ok or infected |
| Thread Tools | |
| Display Modes | |
|
|