Page 1 of 4 1234 LastLast
Results 1 to 20 of 62

Thread: AOTS Hacked/Infected?!

  1. #1

    Exclamation AOTS Hacked/Infected?!

    Went to AOTS to find out some armor info at 4am PST immediately got activex control panel which I said no to, at the same time adobe acrobat started running, I hit end program it would not each time I hit end it popped a new window, I shut down lappy n rebooted, when it came back up I was infected with Antivirus XP 2008 which also inserted 4 other EXTREMELY pervasive worms into HD. Trying to remove them burnt up my antivirus as the registry changed each time it detected it so "it wasnt there" each time I tried to heal, running malware designed specifically for this insidious bastard caused four different types of BSOD with tags like "youre******", etc, etc. Finally had to delete entire partion, create a new one and reformat OS from beginning. I would suggest EXTREME CAUTION in using AOTS until someone figures out wtf is going on with it.
    Quote Originally Posted by Venachar View Post
    Yes. I'm a total idiot. Please don't quote that last sentence out of context
    Well Duh lol.

    I have chronic dyslexia of the keyboard..

    Zen.

  2. #2
    As in Cybersheads' AO Tradeskills 2.0?

    Odd... used that either earlier in the week or late last week with no issue. Cybs hasn't been active in AO for some time (afaik) and then after putting up the 2nd version of his site I don't know how much he's looked after it so if there really is an issue then I don't know what to say
    Ruffixx, 220/30/66 Omni Opifex Fixer
    Pugilius, 206/30/49 Omni Opifex MA
    Blessedbrawl, 200/0 Omni Froob Opifex MA
    Medor, 199/23/42 Neutral Solitus Doctor
    Vindicius, 189/20/46 Omni Atrox Enforcer
    Evilrilius, 100/10 Omni Nano MP - Foremans Killing Machine

    Proud General of Obsidian Order

  3. #3
    Okie my friend just went there(cause he's hard headed and stupid) to test it Hes running xp 64,(im using xp pro 32) at the regular site nada but as soon as he hit the section I had saved to favorites (perfected alien tank armor) same thing happened adobe acrobat popped, he unlike me was able to end program. Apparentally his firewall stopped it. He's running t-time, me being the cheap bastard I am was using the windows firewall. So if your using windows as default firewall DO NOT GO THERE.
    Quote Originally Posted by Venachar View Post
    Yes. I'm a total idiot. Please don't quote that last sentence out of context
    Well Duh lol.

    I have chronic dyslexia of the keyboard..

    Zen.

  4. #4

  5. #5
    Anarchy Arcanum is back up, for tradeskill info, and there's http://lepetitengi-uk.phoenix-fr.org/index.php? as well for tradeskilling. Good to know about the malware at AOTS.
    Quote Originally Posted by Gorathon View Post
    Wouldn't it be better if all the attributes were combined into one skill called "goodness?"

  6. #6
    Quote Originally Posted by gergiskoo View Post
    TeaTimer/Spybot-S&D ftw!
    That **** is so annoying. Use Noscript for Firefox and you'll never need it again.
    Thor Mastablasta Hammersmith - Level 220, AI 30, LE 70 Clan Atrox Nano Technician - Setup
    The Red Brotherhood

    I'm a Nano-Technician, don't ever expect me to fight unbuffed, alone or fair.

    Means: about f'ing time :P
    Satenia: heresy <3
    Znore: Mastablasta <3
    Kinkstaah: I have agro from many mobs ;(
    Madarab: we are aoe class, we are supose to use pistols
    Marxgorm: the NT toolset does not fit into my raiding tactics

  7. #7
    Injections can be good...injections can be bad.

    Kids remember this information during your next doctor visit! /cheers


    /end silly
    No longer plays. It ruins my life.

  8. #8
    Ok another Orgmate went to AOTS 3 days before- Result ended up also having to delete that partition. (Tx fer lettin me know b4 I went matey LOL)

    DO NOT go there unless you have a HELLA good firewall/anti-virus, or just like to melt yer works lol.
    Quote Originally Posted by Venachar View Post
    Yes. I'm a total idiot. Please don't quote that last sentence out of context
    Well Duh lol.

    I have chronic dyslexia of the keyboard..

    Zen.

  9. #9
    Okay, I'm not familur with the site you speak of, please PM me the link to it so I can safely examine the page source and work my magic in determining if the site is safe or not.
    "When life knocks you on your butt, you have to get back up and punch it in the face." --DJ Ashval of GSP

    Nullified "Bitbucket" Deadcode - 220/25 Neut NanoMage Engi
    Bits10 - 150/14 Clan Opifex Trader

  10. #10
    ok, on my first anylisis, I have found some rather funky javascript code - it takes a hex-encoded string, translates it into a string of bytes and writes it to the page via document.write();

    I've not yet decoded the strings of machine code yet, but based on what I've found so far, I can tell you that this site is indeed infectious.

    STAY AWAY!
    "When life knocks you on your butt, you have to get back up and punch it in the face." --DJ Ashval of GSP

    Nullified "Bitbucket" Deadcode - 220/25 Neut NanoMage Engi
    Bits10 - 150/14 Clan Opifex Trader

  11. #11
    Second Analysis:

    I've fully decoded the javascript.

    it's a script that specifically targets and exploits security weakpoints in both Internet Exporer and Mozilla-Based browsers such as Firefox.

    anyway, the script translates the hexcoded string into more javascript that loads 2 viruses through IFRAMEs

    I've traced the source of the 2 viruses.
    1 is from St. Petersburg, Russia - IP Address 77.221.133.171
    The server is located
    59°89'44" N Latitude
    30°26'42" E Longitude



    the other virus is from a webdomain "reddii.org" - Registered to a server in Bejing, China. IP Address 220.196.42.213
    39°92'89" N Latitude
    116°38'83" E Longitude



    both servers seem to be sensitive to HTTP header information (Operating System & Browser Type) as I cannot fetch the viruses from my linux system normally

    I can however get them via WINE (windows emulation)

    no clue what the viruses do exactly, this part is beyond my expertise but given the locations of the servers, I'd say it's how these credit sales / farmers are stealing accounts.

    STAY AWAY FROM
    AOTRADESKILLS (dot) COM
    Last edited by Xyphos; Aug 9th, 2008 at 11:47:10.
    "When life knocks you on your butt, you have to get back up and punch it in the face." --DJ Ashval of GSP

    Nullified "Bitbucket" Deadcode - 220/25 Neut NanoMage Engi
    Bits10 - 150/14 Clan Opifex Trader

  12. #12
    Oi, interesting.

    Are those "generic" virus or homemade ones? I mean, do we have a string we could use to find info about them on the internet?

    I went there a couple weeks ago and site kinda crashed.
    There are no problem that an absence of solution could'nt solve

    Wielder of the "IWin" button.

  13. #13
    Quote Originally Posted by schloops View Post
    Oi, interesting.

    Are those "generic" virus or homemade ones? I mean, do we have a string we could use to find info about them on the internet?

    I went there a couple weeks ago and site kinda crashed.
    Sorry to tell ya mate, but youre probably infected then. One of the main problems I had with these is that as soon as antivirus picked it up, the values would change and it could not be fixed, it would pop up again in another location son after to change yet again once detected. Hence the wipe of partition and HD and reinstallation of my OS and everything else

    To xyphos, WTG in being more of a techie than me and pinpointing the nasty, damn j00 linux! (More like damn j00 BILL GATES for giving us such easily exploitable software ) heh

    Btw yes, the first one is easily looked up google/eldergeek/etc/etc..its not even a "virus" per se, its listed as very bad malware and GFL getting rid of it (Antivirus XP 2008), but as I said that is the LEAST of the problem at the site, its the worms it installs with that one that will absolutely slay your PC, I was so busy trying to repair/fix/restore/etc that I didnt write all their names down. Update your antivirus/anti-malware/Adaware/SpybotSD/etc and hope it'll pick em up.

    At the VERY LEAST I'd suggest changing every single password you've used since going there!!!
    Last edited by ZenWon; Aug 9th, 2008 at 15:27:40.
    Quote Originally Posted by Venachar View Post
    Yes. I'm a total idiot. Please don't quote that last sentence out of context
    Well Duh lol.

    I have chronic dyslexia of the keyboard..

    Zen.

  14. #14
    Got information on the trojan

    http://www.paretologic.com/resources...ove=Win32.RBot

    Picked up with XoftSpy
    Plugsz
    President, Newcomers Alliance 220/30/70 Gun Advy RK1
    Advy Guns since day 1 and damn proud of it
    Manguyver's Foremans/Biomare Services services on pause for now

    Hardcorree 200/30/67 Bringing DD and off-tanking to a battle near you.

  15. #15

  16. #16
    So um...
    That site has always been weird for me, on my old comp (like 6months ago or more) it locked up firefox.

    But it seemed to work on this comp... Not sure though what files to look for to see if I did get infected... Gonna try Xoftspy I guess.

    I've got my firewall set up to be very strict about traffic, hopefully that helped since I used that site for AI armor a few weeks ago :s
    Stars "Wormx" Monkey 220/30/70 3rd opi fix on RK1, 7th on all dimensions to hit AI30 Thanks for all the raids : )
    DanceMeTo "Summerglow" TheEndOfLove 220/27/67 Opi Fixer. Yes, I like fixers.
    LifeIs "Winterglow" NoCabaret 150/14/42 Opi Fixer. Waiting for more hits with the nerfbat.
    Doctor "Wormx6" Panda 220/20/55 Atrox doctor, dinged 220 off Thrak key quest : )
    Mr "Ceilingcat" Monkey 220/23/52 Soli MP, hiding in the ceiling, watching...
    Too many other alts to list here...


  17. #17
    Use Linux or use a VM. All other surfing is subject to hell.
    No longer plays. It ruins my life.

  18. #18
    Ok, ran a Xoftspy scan and all it found was the usual low risk cookies.
    Looks like my firewall/antivirus/luck saved me this time

    Might aswell run some more scans, I.e. Ad-aware etc.
    Stars "Wormx" Monkey 220/30/70 3rd opi fix on RK1, 7th on all dimensions to hit AI30 Thanks for all the raids : )
    DanceMeTo "Summerglow" TheEndOfLove 220/27/67 Opi Fixer. Yes, I like fixers.
    LifeIs "Winterglow" NoCabaret 150/14/42 Opi Fixer. Waiting for more hits with the nerfbat.
    Doctor "Wormx6" Panda 220/20/55 Atrox doctor, dinged 220 off Thrak key quest : )
    Mr "Ceilingcat" Monkey 220/23/52 Soli MP, hiding in the ceiling, watching...
    Too many other alts to list here...


  19. #19
    These kind of javascript easy as pie scripts are so kid-like and we used to play with them in highschool. I cannot believe they are still up and around and going strong like this...scary actually.

    Create virii in asm and exploit like a champ or I am not impressed (if anybody associated with the virus is reading this.)
    Last edited by Sir_Malak; Aug 9th, 2008 at 16:52:57.
    No longer plays. It ruins my life.

  20. #20
    Quote Originally Posted by Sir_Malak View Post
    Create virii in asm and exploit like a champ or I am not impressed (if anybody associated with the virus is reading this.)
    Being a "script kiddie" is easy, writing a real virus takes skill.

    Even worse, most of the "script" ones are just made using someone elses toolkit to make them, just so sad they cant even do it themselves *sigh*.
    Omutb - President - Ring of Destruction

    If you only knew the power of the Frosted Strawberry Poptart....

    "Once more unto the breach, dear friends, once more; Or close the wall up with our English dead." - because Wales just isnt a country

    Chernobyl, providing the freshest bottled water since 1986, for that healthy green glow.

Page 1 of 4 1234 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •