amiga.org
     
iconAll times are GMT -6. The time now is 01:42 AM. | Welcome to Forum, please register to access all of our features.

» Amiga.org » Amiga computer related discussion » General chat about Amiga topics » Is Aminet OK/infected?

General chat about Amiga topics This forum is for conversations which are specifically "Amiga" related, but don't fit into other categories. Contents of this forum do appear on the main page, unlike Talk About. If a subject appears to be non-related, it will be moved to Talk About.

Reply
 
Thread Tools Display Modes
Old 05-11-2012, 08:37 AM   #16
carls
Defender of the Faith
Points: 10,480, Level: 68 Points: 10,480, Level: 68 Points: 10,480, Level: 68
Activity: 4% Activity: 4% Activity: 4%
 
Join Date: Mar 2002
Posts: 1,032
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by Piru View Post
Unfortunately you cannot trust anything coming from aminet at this stage. The FTP could be distributing malware as well, though luckily windows binaries are in the minority...
Correct. I should've considered Windows and Emulator users before posting. My bad.
__________________
Amiga: Too weird to live, too rare to die.
carls is offline   Reply With Quote
Old 05-11-2012, 08:37 AM   #17
desiv
Defender of the Faith
Points: 5,227, Level: 46 Points: 5,227, Level: 46 Points: 5,227, Level: 46
Activity: 11% Activity: 11% Activity: 11%
 
desiv's Avatar
 
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
Default Re: Is Aminet OK/infected?

As a side, I also ran a "full scan" on my machine to be safe. It found 1 instance of the file on my hard disk (not running, but waiting to be called I'm sure) and recommended a "boot scan" which I did.

The boot scan found a few more waiting to be called..

If you went there with a Windows machine, even tho your AV caught it, I'd recommend a full scan.
I'll use another product's scan after this to be sure...

desiv
(Didn't I say NOT to go there if you have Windows? It's bad enough I did.. And it's bad because I've seen encoded javascript "bad programs" before. Not enough to recognize them, but enough to know there probably shouldn't have been one on Aminet..)
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
desiv is offline   Reply With Quote
Old 05-11-2012, 11:19 AM   #18
Hitek
Merely Curious
Points: 139, Level: 2 Points: 139, Level: 2 Points: 139, Level: 2
Activity: 8% Activity: 8% Activity: 8%
 
Join Date: Mar 2012
Posts: 4
Default Re: Is Aminet OK/infected?

Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
Hitek is offline   Reply With Quote
Old 05-11-2012, 11:25 AM   #19
desiv
Defender of the Faith
Points: 5,227, Level: 46 Points: 5,227, Level: 46 Points: 5,227, Level: 46
Activity: 11% Activity: 11% Activity: 11%
 
desiv's Avatar
 
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by Hitek View Post
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
I can still get to Amibay, although there were people there saying they were getting virus alerts..
I'm using Linux at the moment..
(No, I'm not saying there are no Linux baddies out there...)

Yeah, several people on Amibay are having problems with the main page if they are using Windows (not sure which versions), but several others using Linux aren't having issues..

desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.

Last edited by desiv; 05-11-2012 at 12:02 PM..
desiv is offline   Reply With Quote
Old 05-11-2012, 11:33 AM   #20
Hitek
Merely Curious
Points: 139, Level: 2 Points: 139, Level: 2 Points: 139, Level: 2
Activity: 8% Activity: 8% Activity: 8%
 
Join Date: Mar 2012
Posts: 4
Default Re: Is Aminet OK/infected?

Interesting, I can get to it on my ubuntu box too, but not on my win7 box. I wonder if there is some OS detection going on there.
Hitek is offline   Reply With Quote
Old 05-11-2012, 11:33 AM   #21
zipper
Kindred of Babble-on
Points: 12,619, Level: 73 Points: 12,619, Level: 73 Points: 12,619, Level: 73
Activity: 14% Activity: 14% Activity: 14%
 
zipper's Avatar
 
Join Date: Feb 2002
Location: finland
Posts: 2,131
Default Re: Is Aminet OK/infected?

hxxp://ldsysgcaix.igg.biz/d/404.php?go=1 seems same type as the Aminet one.
zipper is offline   Reply With Quote
Old 05-11-2012, 11:50 AM   #22
Hitek
Merely Curious
Points: 139, Level: 2 Points: 139, Level: 2 Points: 139, Level: 2
Activity: 8% Activity: 8% Activity: 8%
 
Join Date: Mar 2012
Posts: 4
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by zipper View Post
hxxp://XXXXXXXX.igg.biz/d/404.php?go=1 seems same type as the Aminet one.
yeah, that's what I was saying. Same type of injection attack used on aminet. Probably not a coincidence. The code seems to change as well. I got one earlier for XXXXXXXX.usa.cc/site/main.php? earlier.
Hitek is offline   Reply With Quote
Old 05-11-2012, 12:47 PM   #23
paul1981
Cult Member
Points: 4,187, Level: 41 Points: 4,187, Level: 41 Points: 4,187, Level: 41
Activity: 27% Activity: 27% Activity: 27%
 
paul1981's Avatar
 
Join Date: Nov 2009
Location: England
Posts: 614
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by Hitek View Post
Now it appears that Amibay.com has been hit, but the code injection was done poorly, so the whole site is broke and just throws a php cookie/session error.
DON'T GO THERE!!!
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG!

STAY WELL AWAY!!
paul1981 is offline   Reply With Quote
Old 05-11-2012, 01:14 PM   #24
Snoozy
Technoid
Points: 2,598, Level: 30 Points: 2,598, Level: 30 Points: 2,598, Level: 30
Activity: 1% Activity: 1% Activity: 1%
 
Snoozy's Avatar
 
Join Date: Sep 2011
Location: UK
Posts: 249
Default Re: Is Aminet OK/infected?

Whats happened to amibay? my pc won't let me go there (firefox)

How did they catch the virus from aminet? surely they must have had some form of protection?
Snoozy is offline   Reply With Quote
Old 05-11-2012, 01:32 PM   #25
rockape
Technoid
Points: 7,384, Level: 57 Points: 7,384, Level: 57 Points: 7,384, Level: 57
Activity: 4% Activity: 4% Activity: 4%
 
rockape's Avatar
 
Join Date: Nov 2005
Location: Lincolnshire, England.
Posts: 288
Blog Entries: 1
Exclamation Re: Is Aminet OK/infected?

Hi,

I tried logging into Amibay using an A1200 and got:


"Unable to add cookies, header already sent.
File: /homepages/1/d277227762/htdocs/amibay/forum/index.php(1) : eval()'d code
Line: 7"


Regards, Michael

aka rockape
__________________
"A veteran is someone who, at one point in their life wrote a blank check made payable to 'Their Country' for an amount of 'up to and including their life'.

Last edited by rockape; 05-11-2012 at 01:37 PM..
rockape is offline   Reply With Quote
Old 05-11-2012, 01:46 PM   #26
desiv
Defender of the Faith
Points: 5,227, Level: 46 Points: 5,227, Level: 46 Points: 5,227, Level: 46
Activity: 11% Activity: 11% Activity: 11%
 
desiv's Avatar
 
Join Date: Oct 2009
Location: Oregon
Posts: 1,139
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by Snoozy View Post
..surely they must have had some form of protection?
Haven't you had that discussion yet,, where you learned that no protection is 100% effective??

desiv
__________________
Amiga 1200 w/ ACA1230/28 - 4G CF, MAS Player, ext floppy, and 1084S.
Amiga 500 w/ 2M CHIP and 8M FAST RAM, DCTV, AEHD floppy, and 1084S.
Amiga 1000 w/ 4M FAST RAM, DUAL CF hard drives, external floppy.
desiv is offline   Reply With Quote
Old 05-11-2012, 01:51 PM   #27
Snoozy
Technoid
Points: 2,598, Level: 30 Points: 2,598, Level: 30 Points: 2,598, Level: 30
Activity: 1% Activity: 1% Activity: 1%
 
Snoozy's Avatar
 
Join Date: Sep 2011
Location: UK
Posts: 249
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by desiv View Post
Haven't you had that discussion yet,, where you learned that no protection is 100% effective??

desiv
Errrr what do you mean i thought the stork brought children once they were born

I dare not go to amibay at the moment - when did they get infected?
Snoozy is offline   Reply With Quote
Old 05-11-2012, 02:44 PM   #28
TenWheeler
Merely Curious
Points: 204, Level: 4 Points: 204, Level: 4 Points: 204, Level: 4
Activity: 2% Activity: 2% Activity: 2%
 
Join Date: Apr 2012
Location: Oklahoma
Posts: 5
Default Re: Is Aminet OK/infected?

Aminet is now clean. But Amibay is now infected.
TenWheeler is offline   Reply With Quote
Old 05-11-2012, 03:11 PM   #29
Hitek
Merely Curious
Points: 139, Level: 2 Points: 139, Level: 2 Points: 139, Level: 2
Activity: 8% Activity: 8% Activity: 8%
 
Join Date: Mar 2012
Posts: 4
Default Re: Is Aminet OK/infected?

Quote:
Originally Posted by paul1981 View Post
DON'T GO THERE!!!
I just went there on my XP machine and that lovely java icon popped up on the toolbar and my hard drive started grinding away.... I PULLED THE PLUG!

STAY WELL AWAY!!
Do you not have virus protection? Any modern virus package should protect against that.

Quote:
Originally Posted by Snoozy View Post
Whats happened to amibay? my pc won't let me go there (firefox)

How did they catch the virus from aminet? surely they must have had some form of protection?
Amibay didn't "catch" the virus from aminet, both sites appear to have been hacked at some level. It could have been somebody sneaking something in via sql injection, or someone gaining root level access to the server, it's hard to tell at this point.

Either way, I'm surprised it hasn't been fixed yet. I'm sure *someone* over there has to know about it.

Keith
Hitek is offline   Reply With Quote
Old 05-11-2012, 03:35 PM   #30
WotTheFook
Technoid
Points: 4,548, Level: 42 Points: 4,548, Level: 42 Points: 4,548, Level: 42
Activity: 2% Activity: 2% Activity: 2%
 
WotTheFook's Avatar
 
Join Date: Mar 2007
Location: Mancland, UK
Posts: 155
Default Re: Is Aminet OK/infected?

We do know about it, I've been researching it all evening.

AmiBay and ClassicAmiga have both been hit with the same script exploit attack that hit Aminet.

It has only been partially effective and the root access, FTP and e-mail have not been compromised. A config file has been corrupted and there is a URL redirect to an ibiz.cc site in place, however, this is only affecting the home page. You should block this ibiz.cc redirect if it comes up on your machine.

If a Java icon appears in your Systray, you should kill it immediately, as this is part of the exploit that is attempting to download malware to your machine.

We hope to have this repaired by tomorrow morning. We backed up the site early this morning and once we have checked the backup config files, we can get the site fully functional again.

In the interim, you can access via any other AmiBay page except the home page. A Google link that isn't the home page will let you access the site, but please ensure that your anti-virus and malware protection is up to date.

WotTheFook aka Merlin

Last edited by WotTheFook; 05-11-2012 at 03:38 PM..
WotTheFook is offline   Reply With Quote
Reply

Bookmarks

Tags
aminet , ok or infected

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump