|
Register or have you forgotten your password?
|
|
|
| General chat about Amiga topics This forum is for conversations which are specifically "Amiga" related, but don't fit into other categories. Contents of this forum do appear on the main page, unlike Talk About. If a subject appears to be non-related, it will be moved to Talk About. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#16 | ||||||||
|
Defender of the Faith
![]()
Join Date: Mar 2002
Posts: 1,032
|
Correct. I should've considered Windows and Emulator users before posting. My bad.
__________________
Amiga: Too weird to live, too rare to die. |
||||||||
|
|
|
|
|
#17 | ||||||||
|
Defender of the Faith
![]()
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
|
As a side, I also ran a "full scan" on my machine to be safe. It found 1 instance of the file on my hard disk (not running, but waiting to be called I'm sure) and recommended a "boot scan" which I did.
The boot scan found a few more waiting to be called.. If you went there with a Windows machine, even tho your AV caught it, I'd recommend a full scan. I'll use another product's scan after this to be sure... desiv (Didn't I say NOT to go there if you have Windows? It's bad enough I did.. And it's bad because I've seen encoded javascript "bad programs" before. Not enough to recognize them, but enough to know there probably shouldn't have been one on Aminet..)
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S. Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S. Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy. |
||||||||
|
|
|
|
|
#18 | ||||||||
|
Merely Curious
![]()
Join Date: Mar 2012
Posts: 4
|
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
|
||||||||
|
|
|
|
|
#19 | |||||||||
|
Defender of the Faith
![]()
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
|
Quote:
I'm using Linux at the moment.. ![]() (No, I'm not saying there are no Linux baddies out there...) Yeah, several people on Amibay are having problems with the main page if they are using Windows (not sure which versions), but several others using Linux aren't having issues.. desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S. Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S. Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy. Last edited by desiv; 05-11-2012 at 12:02 PM.. |
|||||||||
|
|
|
|
|
#20 | ||||||||
|
Merely Curious
![]()
Join Date: Mar 2012
Posts: 4
|
Interesting, I can get to it on my ubuntu box too, but not on my win7 box. I wonder if there is some OS detection going on there.
|
||||||||
|
|
|
|
|
#21 | ||||||||
|
Kindred of Babble-on
![]()
Join Date: Feb 2002
Location: finland
Posts: 2,131
|
hxxp://ldsysgcaix.igg.biz/d/404.php?go=1 seems same type as the Aminet one.
|
||||||||
|
|
|
|
|
#22 | ||||||||
|
Merely Curious
![]()
Join Date: Mar 2012
Posts: 4
|
yeah, that's what I was saying. Same type of injection attack used on aminet. Probably not a coincidence. The code seems to change as well. I got one earlier for XXXXXXXX.usa.cc/site/main.php? earlier.
|
||||||||
|
|
|
|
|
#23 | |||||||||
|
Cult Member
![]()
Join Date: Nov 2009
Location: England
Posts: 614
|
Quote:
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG! STAY WELL AWAY!! |
|||||||||
|
|
|
|
|
#24 | ||||||||
|
Technoid
![]()
Join Date: Sep 2011
Location: UK
Posts: 249
|
Whats happened to amibay? my pc won't let me go there (firefox)
How did they catch the virus from aminet? surely they must have had some form of protection? |
||||||||
|
|
|
|
|
#25 | ||||||||
|
Technoid
![]()
|
Hi,
I tried logging into Amibay using an A1200 and got: "Unable to add cookies, header already sent. File: /homepages/1/d277227762/htdocs/amibay/forum/index.php(1) : eval()'d code Line: 7" Regards, Michael aka rockape
__________________
"A veteran is someone who, at one point in their life wrote a blank check made payable to 'Their Country' for an amount of 'up to and including their life'. Last edited by rockape; 05-11-2012 at 01:37 PM.. |
||||||||
|
|
|
|
|
#26 | ||||||||
|
Defender of the Faith
![]()
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
|
Haven't you had that discussion yet,, where you learned that no protection is 100% effective??
![]() desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S. Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S. Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy. |
||||||||
|
|
|
|
|
#27 | ||||||||
|
Technoid
![]()
Join Date: Sep 2011
Location: UK
Posts: 249
|
|
||||||||
|
|
|
|
|
#28 | ||||||||
|
Merely Curious
![]()
Join Date: Apr 2012
Location: Oklahoma
Posts: 5
|
Aminet is now clean. But Amibay is now infected.
|
||||||||
|
|
|
|
|
#29 | ||||||||||
|
Merely Curious
![]()
Join Date: Mar 2012
Posts: 4
|
Quote:
Quote:
Either way, I'm surprised it hasn't been fixed yet. I'm sure *someone* over there has to know about it. Keith |
||||||||||
|
|
|
|
|
#30 | ||||||||
|
Technoid
![]()
Join Date: Mar 2007
Location: Mancland, UK
Posts: 155
|
We do know about it, I've been researching it all evening.
AmiBay and ClassicAmiga have both been hit with the same script exploit attack that hit Aminet. It has only been partially effective and the root access, FTP and e-mail have not been compromised. A config file has been corrupted and there is a URL redirect to an ibiz.cc site in place, however, this is only affecting the home page. You should block this ibiz.cc redirect if it comes up on your machine. If a Java icon appears in your Systray, you should kill it immediately, as this is part of the exploit that is attempting to download malware to your machine. We hope to have this repaired by tomorrow morning. We backed up the site early this morning and once we have checked the backup config files, we can get the site fully functional again. In the interim, you can access via any other AmiBay page except the home page. A Google link that isn't the home page will let you access the site, but please ensure that your anti-virus and malware protection is up to date. WotTheFook aka Merlin Last edited by WotTheFook; 05-11-2012 at 03:38 PM.. |
||||||||
|
|
|
![]() |
| Bookmarks |
| Tags |
| aminet , ok or infected |
| Thread Tools | |
| Display Modes | |
|
|