free

News

collapse

User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

* Recent Posts

Re: Stopping by by Sinister
[June 08, 2025, 01:58:04 pm]


Re: Stopping by by Ehks
[June 04, 2025, 12:25:17 am]


Re: Rest in peace by Stefanrsb
[June 02, 2025, 03:38:02 am]


Re: [SA:MP]House of Sforza | The Elite Power | Estd. 2006 | LS - LV by Stefanrsb
[June 02, 2025, 03:09:22 am]


Re: The Soprano Family | Royal Loyalty by Stefanrsb
[June 02, 2025, 03:00:31 am]


Re: The Gvardia Family || San Fierro's Main Power || Best criminal group of 09/10/11 by Stefanrsb
[June 02, 2025, 02:47:01 am]


Re: BALLAS | In memory of INFERNO 9 and NBA by Stefanrsb
[June 02, 2025, 02:31:29 am]


Re: Count to 1,000,000. by Stefanrsb
[June 02, 2025, 02:15:04 am]


Re: Stopping by by Traser
[June 01, 2025, 10:23:13 pm]


Re: Stopping by by Old Catzu
[May 18, 2025, 07:27:06 pm]


Re: Stopping by by TheRock
[May 18, 2025, 06:44:49 am]


Re: Stopping by by KenAdams
[May 17, 2025, 06:33:45 am]

* Who's Online

  • Dot Guests: 464
  • Dot Hidden: 0
  • Dot Users: 0

There aren't any users online.

* Birthday Calender

June 2025
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 [16] 17 18 19 20 21
22 23 24 25 26 27 28
29 30

Malware

Reece · 10119

0 Members and 1 Guest are viewing this topic.

Offline LoHi

  • Regular
  • **
    • Posts: 501
    With us since: 14/09/2007
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #45 on: July 26, 2012, 11:13:08 pm
To those who say having another browser (other than Google) makes this a better situation, good luck when you visit an actual site with Malware ;)

IE, Firefox, Safari, Opera users may not experience this as primarily they do not have such detection, or their scanning tools are not quite as powerful (given the comparison of Googles ability). Not saying its a bad thing, or trying to start a browser debate. Just stating why they aren't seeing it.

Nothing seems fancy, I have malwarebytes premium version which has realtime mode, and its not blocking anything. So all should be well. You should maintain normal precautions (scanning computer 2-3 times per week, clearing browsing login data, etc).

Oh dear... While I have not looked in to this at all, an attack like this often relies on an exploit in either one of the plugins (Flash, Java) or the browser itself. In the 1st case it doesn't matter what browser you use, but in the 2nd case using a 'less-known' browser would actually be beneficial. Opera and Firefox (maybe IE and Safari too) both have a blocker like Chrome does (it does not scan every page, but rather it gets information from Google's database whether the site is infected or not).

No mercy for the weak, no pity for the dying, no tears for the slain.


Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #46 on: July 27, 2012, 01:09:04 am
This is a separate issue from the av.exe Malicious advertisement fro two years ago right?
Completely separate.



Offline Pandalink

  • Araatus Kumichō
  • Orc
  • *****
    • Posts: 10358
  • The Strategist
  • With us since: 08/05/2007
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
    • The Araatus Yakuza
  • SA:MP: Panda_Araatus
Reply #47 on: July 28, 2012, 02:51:32 am
IE, Firefox, Safari, Opera users may not experience this as primarily they do not have such detection, or their scanning tools are not quite as powerful (given the comparison of Googles ability).
I run firefox and I still got the malware warning, and the explanation linked to google's page. I don't even know why, I wasn't accessing the site from google.

Panda Araatus  -  Sovereign Overseer  -  The Araatus Yakuza


Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #48 on: July 28, 2012, 07:52:49 am
I run firefox and I still got the malware warning, and the explanation linked to google's page. I don't even know why, I wasn't accessing the site from google.
Firefox reads from another database that also gets it's information from Google's. They just need to query Google's list again sometime soon to update the argonathrpg.eu domain as no longer malicious.

Edit: I have submitted reviews to StopBadware.Org and Mozilla Phishing And Malware Protections' sites in order to have them remove the warning messages that are still lingering around. Give them a day or so to get to it and things should be back to normal again soon. :)



Offline ReeceTopic starter

  • Orc
  • *****
    • Posts: 4016
  • Living.
  • With us since: 07/01/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #49 on: July 29, 2012, 02:18:33 am
Uh is it back?




Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #50 on: July 29, 2012, 03:45:30 am
Uh is it back?


Ctrl+F5 and see if it continues. It may just be lingering around. DNS also may not have updated across all of the world yet, which I believe Google uses to "trick" browsers into going to that page instead.



Offline ReeceTopic starter

  • Orc
  • *****
    • Posts: 4016
  • Living.
  • With us since: 07/01/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #51 on: July 29, 2012, 10:48:14 am
Again:



I only get it using .com



Offline Pandalink

  • Araatus Kumichō
  • Orc
  • *****
    • Posts: 10358
  • The Strategist
  • With us since: 08/05/2007
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
    • The Araatus Yakuza
  • SA:MP: Panda_Araatus
Reply #52 on: July 29, 2012, 12:48:40 pm
Yea I'm still getting it.

Panda Araatus  -  Sovereign Overseer  -  The Araatus Yakuza


Offline stormeus

  • VC:MP Developer
  • VC:MP Scripter
  • *
    • Posts: 1775
    With us since: 06/03/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • VC:MP: [VU]Stormeus
Reply #53 on: July 29, 2012, 06:32:22 pm
Directly querying Google SafeBrowsing shows that Argonath is clean. However, querying VirusTotal still reports it as malicious. It would seem that either caches of the Google API results or some providers' records are just out of date.



Offline Gandalf

  • Owner
  • *******
    • Posts: 15956
    With us since: 12/07/2006
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #54 on: July 29, 2012, 06:46:29 pm
The malware seems to be lingering in the ad software. In the next week we will clean the database, though it is likely a rogue advertiser, in any way it has been reported to the network.
It is certain that our files are clean.

Do not roleplay a veteran on discord, be a veteran in game.


Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #55 on: July 30, 2012, 02:54:05 am
The malware seems to be lingering in the ad software. In the next week we will clean the database, though it is likely a rogue advertiser, in any way it has been reported to the network.
It is certain that our files are clean.
That was my finding as well when I checked the output source, as well as ran some online "web page" scanners on it. They were all pointing to the code previously reported.



Offline CrazyDude

  • Pwnz0r
  • User
  • *
    • Posts: 102
  • Baka
  • With us since: 14/08/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #56 on: August 02, 2012, 01:52:55 pm
Guys, you've got passive XSS on some page. So if a hacker posts some link, and then some admin/user clicks it, hacker gets his Cookies(no, not food) and login for his name, after he can upload web-shell and do such bad things :( For more info - PM me.



Offline Gandalf

  • Owner
  • *******
    • Posts: 15956
    With us since: 12/07/2006
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #57 on: August 02, 2012, 05:49:11 pm
Guys, you've got passive XSS on some page. So if a hacker posts some link, and then some admin/user clicks it, hacker gets his Cookies(no, not food) and login for his name, after he can upload web-shell and do such bad things :( For more info - PM me.
Which is why we never click links....  :cool:

Do not roleplay a veteran on discord, be a veteran in game.


Offline Teddy

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: EvilMiku
Reply #58 on: August 02, 2012, 10:51:41 pm
Guys, you've got passive XSS on some page. So if a hacker posts some link, and then some admin/user clicks it, hacker gets his Cookies(no, not food) and login for his name, after he can upload web-shell and do such bad things :( For more info - PM me.

:rofl: Give me a few moments to stop laughing



Offline Lionel Valdes

  • Hero
  • ****
    • Posts: 1846
  • Lionel Valdes
  • With us since: 13/09/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #59 on: August 02, 2012, 11:11:30 pm
Who wanted ad's in the first place  :neutral:

The Social Democratic Party of Los Santos - Progress and Prosperity

SA:MP Oscar Award Recipient; Holder of two Argonath Records (via Argonath World Records)


 


SimplePortal 2.3.7 © 2008-2025, SimplePortal