XeNTaX attacked by virus
- Mr.Mouse
- Site Admin
- Posts: 4051
- Joined: Wed Jan 15, 2003 6:45 pm
- Location: Dungeons of Doom
- Has thanked: 421 times
- Been thanked: 575 times
- Contact:
XeNTaX attacked by virus
XeNTaX attacked by virus
August 28th, 2010 by Mr.Mouse and Craptain
If you wondered why we were down, we suffered an attack by a bot. The last few days our host and us worked hard to remove the infection. We will spend some more time to update the code to latest versions as we go. Sorry for the inconvenience.
Webmaster note: We were hit by a virus called Gumblar. It was a more sophisticated virus than usual. It used the password stored in the scp client of one of our webmasters to gain access to our server. Once it had access, it added obfuscated and encoded javascript to all index.html, index.php, etc files, in order to spread the infection.
If you have visited the xentax main site or any of the xentax subdomains from the 25th of august to the 28th, it’s probably a good idea to run a virus scanner. If you’re a webmaster who stores ftp or scp passwords in a local client, check your site’s source code for suspicious scripts.
We are still cleaning up this shit, and are taking this opportunity to upgrade our forum and blog software as well. We will be busy with this at least until sunday, because as usual real life gets in the way: a friend of ours is getting married today.
Sorry for the downtime and the inconvenience it may have caused.
Final edit: The javascript exploits a weakness in adobe acrobat reader and flash, probably only in Windows. So if you run Linux or other Unix clones, you get to be smug and self satisfied that this particular virus doesn’t target you. If you run OSX you can remain clueless about this whole conversation.
August 28th, 2010 by Mr.Mouse and Craptain
If you wondered why we were down, we suffered an attack by a bot. The last few days our host and us worked hard to remove the infection. We will spend some more time to update the code to latest versions as we go. Sorry for the inconvenience.
Webmaster note: We were hit by a virus called Gumblar. It was a more sophisticated virus than usual. It used the password stored in the scp client of one of our webmasters to gain access to our server. Once it had access, it added obfuscated and encoded javascript to all index.html, index.php, etc files, in order to spread the infection.
If you have visited the xentax main site or any of the xentax subdomains from the 25th of august to the 28th, it’s probably a good idea to run a virus scanner. If you’re a webmaster who stores ftp or scp passwords in a local client, check your site’s source code for suspicious scripts.
We are still cleaning up this shit, and are taking this opportunity to upgrade our forum and blog software as well. We will be busy with this at least until sunday, because as usual real life gets in the way: a friend of ours is getting married today.
Sorry for the downtime and the inconvenience it may have caused.
Final edit: The javascript exploits a weakness in adobe acrobat reader and flash, probably only in Windows. So if you run Linux or other Unix clones, you get to be smug and self satisfied that this particular virus doesn’t target you. If you run OSX you can remain clueless about this whole conversation.
-
invisghost
- advanced
- Posts: 55
- Joined: Tue Jul 13, 2010 7:16 pm
- Has thanked: 1 time
- Been thanked: 11 times
Re: XeNTaX attacked by virus
-
Energy
- ultra-n00b
- Posts: 8
- Joined: Fri Mar 19, 2010 2:05 am
- Has thanked: 9 times
- Been thanked: 1 time
Re: XeNTaX attacked by virus
Oh and my comp full with trojan horses. I delete some of them (shit) but the new is coming 
Avast blocking conection but virus come. So you need new antivurs. Microsoft Security Essentials safe my comp for now and delete 5 trojan in windows temp folder and interenet temp folder. I think my comp is clear now.
Avast blocking conection but virus come. So you need new antivurs. Microsoft Security Essentials safe my comp for now and delete 5 trojan in windows temp folder and interenet temp folder. I think my comp is clear now.
-
piecemontee
- advanced
- Posts: 50
- Joined: Mon Aug 03, 2009 9:34 pm
- Has thanked: 5 times
- Been thanked: 19 times
- Contact:
Re: XeNTaX attacked by virus
I am a looser
avast warned me, I thought "hey it's xentax, how dumb is this virus scanner?"
and I added an exception to the realtime protection...
how dumb am I
avast warned me, I thought "hey it's xentax, how dumb is this virus scanner?"
and I added an exception to the realtime protection...
how dumb am I
Last edited by piecemontee on Sat Aug 28, 2010 10:39 pm, edited 1 time in total.
-
invisghost
- advanced
- Posts: 55
- Joined: Tue Jul 13, 2010 7:16 pm
- Has thanked: 1 time
- Been thanked: 11 times
Re: XeNTaX attacked by virus
Lol I've had nod32 for about 3 years now and never once had a virus get through. I like it cause it doesn't bog down your computer like those other ones do. I need my computer's proformance for getting good FPS in pcsx2 
- XpoZed
- veteran
- Posts: 144
- Joined: Sat Oct 24, 2009 5:08 pm
- Location: Bulgaria
- Has thanked: 2 times
- Been thanked: 45 times
- Contact:
Re: XeNTaX attacked by virus
I don't think there was a virus that is downloaded on your PC. It's more likely a session/cookie stealer or something.
Anyway, if someone can provide me with a sample (exe,dll,ocx,sys, etc.) i'll be happy to reverse engineer it (that's my main hobby these days
).
Anyway, if someone can provide me with a sample (exe,dll,ocx,sys, etc.) i'll be happy to reverse engineer it (that's my main hobby these days
-
piecemontee
- advanced
- Posts: 50
- Joined: Mon Aug 03, 2009 9:34 pm
- Has thanked: 5 times
- Been thanked: 19 times
- Contact:
Re: XeNTaX attacked by virus
Yes U're right, I ran a full scan and nothing stood out.XpoZed wrote:I don't think there was a virus that is downloaded on your PC. It's more likely a session/cookie stealer or something.
Anyway, if someone can provide me with a sample (exe,dll,ocx,sys, etc.) i'll be happy to reverse engineer it (that's my main hobby these days).
It seems to hack FTP account throught filezilla to propagate throught javascript,
I checked my website and no javascript was added,
- chrrox
- Moderator
- Posts: 2601
- Joined: Sun May 18, 2008 3:01 pm
- Has thanked: 57 times
- Been thanked: 1358 times
Re: XeNTaX attacked by virus
I noticed a small bug the mark forum read no longer works after the site restore.
- Mr.Mouse
- Site Admin
- Posts: 4051
- Joined: Wed Jan 15, 2003 6:45 pm
- Location: Dungeons of Doom
- Has thanked: 421 times
- Been thanked: 575 times
- Contact:
Re: XeNTaX attacked by virus
Actually I does work for me. Cache problem? Does anyone else have this bug?
- chrrox
- Moderator
- Posts: 2601
- Joined: Sun May 18, 2008 3:01 pm
- Has thanked: 57 times
- Been thanked: 1358 times
Re: XeNTaX attacked by virus
im using firefox its only the mark forum read that does not work for me i can go into any thread and the mark read works.
- XpoZed
- veteran
- Posts: 144
- Joined: Sat Oct 24, 2009 5:08 pm
- Location: Bulgaria
- Has thanked: 2 times
- Been thanked: 45 times
- Contact:
Re: XeNTaX attacked by virus
Dont know about that, but you should integrate the "tanks" system back after the update.



