XeNTaX attacked by virus
- Mr.Mouse
- Site Admin
- Posts: 4051
- Joined: Wed Jan 15, 2003 6:45 pm
- Location: Dungeons of Doom
- Has thanked: 421 times
- Been thanked: 575 times
- Contact:
Re: XeNTaX attacked by virus
Yes. We will try to get everything back in. For now, new registrations have been disabled.
- Dinoguy1000
- Site Admin
- Posts: 759
- Joined: Mon Sep 13, 2004 1:55 am
- Has thanked: 129 times
- Been thanked: 142 times
Re: XeNTaX attacked by virus
It was almost certainly Gumblar, based on de-obfuscating the obfuscated javascript which was inserted on numerous pages. Maybe not a virus, true, but still some type of malware.XpoZed wrote:I don't think there was a virus that is downloaded on your PC. It's more likely a session/cookie stealer or something.
Anyway, if someone can provide me with a sample (exe,dll,ocx,sys, etc.) i'll be happy to reverse engineer it (that's my main hobby these days).
It's worth noting that people with properly-upgraded Windows systems and Acrobat/Flash installations may not have had anything to worry about, but you should still run a virus scan just in case (this is one of the basic maintenance tasks you should be regularly running anyways).
One last note, we don't load any scripts, images, or other resources from external URLs (to the best of my knowledge; there may be a couple of images on the wiki loaded from Wikimedia Commons), so you should be able to safely block any such resources from loading.
- Mr.Mouse
- Site Admin
- Posts: 4051
- Joined: Wed Jan 15, 2003 6:45 pm
- Location: Dungeons of Doom
- Has thanked: 421 times
- Been thanked: 575 times
- Contact:
Re: XeNTaX attacked by virus
Hmm. http://www.phpbb-seo.com/en/phpbb-forum ... e3678.html This seems to be a phpbb issuechrrox wrote:im using firefox its only the mark forum read that does not work for me i can go into any thread and the mark read works.
Re: XeNTaX attacked by virus
Looking at it again, it's an issue back in 2008, so I'm not sure how relevant it is now. Working in Chrome, the button functions as desired. We're still looking into it.Mr.Mouse wrote:Hmm. http://www.phpbb-seo.com/en/phpbb-forum ... e3678.html This seems to be a phpbb issuechrrox wrote:im using firefox its only the mark forum read that does not work for me i can go into any thread and the mark read works.
- Captain
- Site Admin
- Posts: 249
- Joined: Wed Jan 15, 2003 6:25 pm
- Location: Home
- Has thanked: 2 times
- Been thanked: 61 times
- Contact:
Re: XeNTaX attacked by virus
The button works in the subsections, like here, but doesn't work on the main forum index. I'm pretty sure it's not a browser issue. Tried it myself on Chrome, same result as in Firefox.DMorrone wrote:Working in Chrome, the button functions as desired. We're still looking into it.
Re: XeNTaX attacked by virus
Looks like there is a very recent debate as to how this button should ultimately function:Craptain wrote:The button works in the subsections, like here, but doesn't work on the main forum index. I'm pretty sure it's not a browser issue. Tried it myself on Chrome, same result as in Firefox.DMorrone wrote:Working in Chrome, the button functions as desired. We're still looking into it.
http://www.phpbb.com/community/viewtopi ... &t=2101636
- XpoZed
- veteran
- Posts: 144
- Joined: Sat Oct 24, 2009 5:08 pm
- Location: Bulgaria
- Has thanked: 2 times
- Been thanked: 45 times
- Contact:
Re: XeNTaX attacked by virus
Can anyone send me the virus ? The infected PDF or something will be fine too.
- Mr.Mouse
- Site Admin
- Posts: 4051
- Joined: Wed Jan 15, 2003 6:45 pm
- Location: Dungeons of Doom
- Has thanked: 421 times
- Been thanked: 575 times
- Contact:
Re: XeNTaX attacked by virus
Turns out our computers were clean, or at least a multitude of scanners found nothing.XpoZed wrote:Can anyone send me the virus ? The infected PDF or something will be fine too.
But whatever it was and where it came from, it injected the sites pages with this :
You do not have the required permissions to view the files attached to this post.
-
Rheini
- Moderator
- Posts: 653
- Joined: Wed Oct 18, 2006 9:48 pm
- Location: Germany
- Has thanked: 19 times
- Been thanked: 40 times
- Contact:
Re: XeNTaX attacked by virus
I didn't notice anything? What happens if you visit a site that's infected with it?
And what about the pdf etc. stuff? xentax doesn't use anything like flash, pdf...
And what about the pdf etc. stuff? xentax doesn't use anything like flash, pdf...
- XpoZed
- veteran
- Posts: 144
- Joined: Sat Oct 24, 2009 5:08 pm
- Location: Bulgaria
- Has thanked: 2 times
- Been thanked: 45 times
- Contact:
Re: XeNTaX attacked by virus
Thanks, but i've already got this... it just do a document.write('<script type="text/javascript" src="URL SNIP"> </script>')Mr.Mouse wrote: Turns out our computers were clean, or at least a multitude of scanners found nothing.
But whatever it was and where it came from, it injected the sites pages with this :
Then from URL SNIP we had similar script that do a document.write with script again, this time to something like URL SNIP, and there was only a redirect to google.com
That's why i've said that this is probably only a logger.
Anyway, if someone got the virus, i'll be happy to play with his bits'n bytes.
@Rheini i've seen similar javascript exploits like this one, that redirect the user to a PDF document with exploit in it. And if you already have installed acrobat reader, that is exploitable (old version etc), you get infected.
Last edited by Dinoguy1000 on Wed Sep 01, 2010 12:56 am, edited 2 times in total.
Reason: URL snip - no need to encourage visitors to visit a malicious site
Reason: URL snip - no need to encourage visitors to visit a malicious site
-
Rheini
- Moderator
- Posts: 653
- Joined: Wed Oct 18, 2006 9:48 pm
- Location: Germany
- Has thanked: 19 times
- Been thanked: 40 times
- Contact:
Re: XeNTaX attacked by virus
Thank god i don't have that damn Acrobat Reader installed at all (Foxit
)
I do have Flash though (with Opera)
I do have Flash though (with Opera)
- Dinoguy1000
- Site Admin
- Posts: 759
- Joined: Mon Sep 13, 2004 1:55 am
- Has thanked: 129 times
- Been thanked: 142 times
- Zerox
- mega-veteran

- Posts: 186
- Joined: Mon Aug 09, 2010 3:50 am
- Has thanked: 4 times
- Been thanked: 7 times
Re: XeNTaX attacked by virus
While attempting to go to the page to download Noesis I got this while using firefox:

This is the link I followed: http://oasis.xentax.com/index.php?content=downloads
Edit: I see it was already reported in his Noesis thread. My apologies.

This is the link I followed: http://oasis.xentax.com/index.php?content=downloads
Edit: I see it was already reported in his Noesis thread. My apologies.


