1
Forum Settings
       
« Previous 1 2 3 4
Reply To Thread

Somepg javascript exploit on the looseFollow

#1 Dec 12 2007 at 1:42 AM Rating: Excellent
I know many of you hate BG forums but we want everyone to see this. It is real and many of you may have it and many of you may not. It takes all but 5 min max to read and execute. So swallow your pride and please read.

http://bluegartrls.com/forum/viewtopic.php?f=2&t=27256

Taken from the post incase skimmed over to fast.
Realplayer exploit article: Here

Quick steps to insure safety: Here

It seems it's an exploit on realplayer. Causing it to autodownload the script/trojan.

Edited, Dec 12th 2007 4:47am by Tearshang

Edited, Dec 12th 2007 5:13am by Tearshang

Edit: Added unfiltered abbreviation to subject

Edited, Dec 12th 2007 5:23pm by Pikko
#2 Dec 12 2007 at 1:56 AM Rating: Decent
**
327 posts
Post removed by myself after further information discovered.

Edited, Dec 12th 2007 5:21am by MidouSan


PS. Thank you for bringing this to our attention, even if my original response was a bit heavy handed.

Edited, Dec 12th 2007 5:35am by MidouSan
#3 Dec 12 2007 at 1:58 AM Rating: Excellent
Thanks for the info, we really appreciate it. As to the subject at hand, does anyone know how long this has been active? Any kind of guess work or research work as to how long the trojan has been there would be helpful. I know there was a big thread here on alla not long ago about how somepage had basically shut down and thrown in the towell, most likely it happened some time after that.
#4 Dec 12 2007 at 2:02 AM Rating: Excellent
As I stated you can blow this way out of the water if you want. This was discovered around 3 a.m. and more than GMs have been attempted to be contacted. Just follow the instructions to remove the files if they are there. That's all it's about no where is there an attack against Somepage. Most of the conversation and real action has been through IRC. Again this is just to be safe.
#5 Dec 12 2007 at 2:06 AM Rating: Default
**
327 posts
Quote:
As I stated you can blow this way out of the water if you want. This was discovered around 3 a.m. and more than GMs have been attempted to be contacted. Just follow the instructions to remove the files if they are there. That's all it's about no where is there an attack against Somepage. Most of the conversation and real action has been through IRC. Again this is just to be safe.


Once again, have you contacted the administration of somepage, because frankly theres not much FFXI gm's can do about this issue unless there happens to be the slight chance that a GM is also a moderator of Somepage.
#6 Dec 12 2007 at 2:07 AM Rating: Good
Also.

http://img502.imageshack.us/img502/6550/tajronmememe7.jpg
#7 Dec 12 2007 at 2:09 AM Rating: Excellent
MidouSan wrote:
Quote:
As I stated you can blow this way out of the water if you want. This was discovered around 3 a.m. and more than GMs have been attempted to be contacted. Just follow the instructions to remove the files if they are there. That's all it's about no where is there an attack against Somepage. Most of the conversation and real action has been through IRC. Again this is just to be safe.


Once again, have you contacted the administration of somepage, because frankly theres not much FFXI gm's can do about this issue unless there happens to be the slight chance that a GM is also a moderator of Somepage.


From what I hear they have been awall for awhile and unreachable. Don't hold me to this though, but it stands to reason since the site has also been down for no reason at all for awhile, just sort of abandoned.
#8 Dec 12 2007 at 2:09 AM Rating: Decent
That's not irony, it's mereley coincidental. Smiley: ducttape
#9 Dec 12 2007 at 2:10 AM Rating: Excellent
***
1,041 posts
Yeah, thats why it was said by me and my sister to try and avoid using that Firefox add-on that gives you a toolbar that links to FFXI-Atlas, WS/crafting calculator, somepage database info and so on.
#10 Dec 12 2007 at 2:16 AM Rating: Good
**
327 posts
SeriousBusiness wrote:
MidouSan wrote:
Quote:
As I stated you can blow this way out of the water if you want. This was discovered around 3 a.m. and more than GMs have been attempted to be contacted. Just follow the instructions to remove the files if they are there. That's all it's about no where is there an attack against Somepage. Most of the conversation and real action has been through IRC. Again this is just to be safe.


Once again, have you contacted the administration of somepage, because frankly theres not much FFXI gm's can do about this issue unless there happens to be the slight chance that a GM is also a moderator of Somepage.


From what I hear they have been awall for awhile and unreachable. Don't hold me to this though, but it stands to reason since the site has also been down for no reason at all for awhile, just sort of abandoned.


Alright then, now THAT makes this a major concern if it is true. A page frequented by many people of an online game, of which the Moderators have left lying there..Yeah that's like leaving a fort with the guns Offline. If what you say is true then Somepage has most likely been the target of an attack by hacker(s)


Im going to fireup my Junker laptop and take a look at somepage.




Edited, Dec 12th 2007 6:42am by MidouSan
#11 Dec 12 2007 at 2:17 AM Rating: Good
Smiley: dnp


















We told you not to push it!
Screenshot

Now internet kitten is mad at you!

Edited, Dec 12th 2007 5:25am by ZelgadisXI
#12 Dec 12 2007 at 2:26 AM Rating: Excellent
**
318 posts
for your information, inside the hacked players thread on BG one of the admins of FFXIAH actually found the code that was imbedded inside the main pages source. I believe it was at the end of page 10

*edit* http://www.bluegartrls.com/forum/viewtopic.php?f=2&t=27042&start=270

Added link to the BG thread

Edited, Dec 12th 2007 5:28am by EzKill
____________________________
Retired March 2010

[ffxisig]116214[/ffxisig]
Linkshell: Social: ClanBEB
Dynamis: LegacyofOld
World O
Cop Complete
ZM Complete
Dynamis - Xarcabard Interloper O
Dynamis - Tavnazia Interloper O
Valor 5/5 Shadow Mantle Obtained
Melee 5/5 | Saotome 5/5 Belt Obtained | Monster 5/5 | Sorcerer 5/5 | War 5/5
#13 Dec 12 2007 at 2:26 AM Rating: Excellent
**
491 posts
Their host, theplanet.com should know about this. The page is still up with the iframe intact.
#14 Dec 12 2007 at 2:34 AM Rating: Excellent
**
327 posts
EzKill, Goblin in Disguise wrote:
for your information, inside the hacked players thread on BG one of the admins of FFXIAH actually found the code that was imbedded inside the main pages source. I believe it was at the end of page 10

*edit* http://www.bluegartrls.com/forum/viewtopic.php?f=2&t=27042&start=270

Added link to the BG thread

Edited, Dec 12th 2007 5:28am by EzKill



Yep, its about the 3rd last post, and THAT is definately an anomly. I see no reason for me to Go onto somepage with my Junker Laptop and do further research..Unless anyone else does.
#15 Dec 12 2007 at 3:22 AM Rating: Excellent
****
6,424 posts
The iframe loads a page from a domain called "www.miorsocft.com", which is owned by someone in China according to www.who.is.

Hope they take out the page asap.
#16 Dec 12 2007 at 3:22 AM Rating: Excellent
**
376 posts
lol thank god I never installed real player.....
#17 Dec 12 2007 at 3:55 AM Rating: Decent
***
1,991 posts
Great....just great. Some guy posted a link to sompeage recently when trying to help someone out, and me thinking it was closed down decided to give the link a click.

So if i come back from work and my account is gone i'm going to be really ****** off.
#18 Dec 12 2007 at 3:57 AM Rating: Decent
***
1,978 posts
RoverBST wrote:
lol thank god I never installed real player.....


Same here, I will still look for those files in my PC. Just in case.

Edited: I am clean, no Rsbo.exe, none of the other files found either.

Edited, Dec 12th 2007 8:14am by OmegaVegito
#19 Dec 12 2007 at 4:04 AM Rating: Decent
***
1,991 posts
Rate this guy up by the way. Everyone needs to see this...
#20 Dec 12 2007 at 4:05 AM Rating: Excellent
**
491 posts
The RP buffer overflow exploit dates back to October and a patch released to fix it. If you have RP 10 installed check this link for the patch : http://secunia.com/advisories/27248/ See "Solution" halfway down the page.
#21 Dec 12 2007 at 4:15 AM Rating: Decent
***
1,692 posts
It's getting to the point where you cannot safely visit any FFXI based websites, probably including Alla unless you take steps to block all ADs with firefox and adblock.
#22 Dec 12 2007 at 5:27 AM Rating: Excellent
Quote:
It's getting to the point where you cannot safely visit any FFXI based websites, probably including Alla unless you take steps to block all ADs with firefox and adblock


The exploit isn't associated with any advertisements. It appears that somepage was hacked and a replacement default web page got set to one that contained the iFrame. The iframe points to another website domain that houses the javascript code for exploiting Real Player.

I've already sent some emails to administrative contacts that I've located for Somepage in an attempt for them to correct it. We'll have to see what happens.

If it doesn't get fixed soon, people will have to either remove real player or patch it if they want to use that particular site.
#23 Dec 12 2007 at 5:31 AM Rating: Good
*****
15,512 posts
Perhaps this finally gives incentive to remove that piece of bloat that is Real Player!

Every cloud has a silver lining...
#24 Dec 12 2007 at 5:34 AM Rating: Good
***
1,692 posts
Quote:
The exploit isn't associated with any advertisements.


There was also information of similar things embedded in FFXIAH and a few other sites adverts.
#25 Dec 12 2007 at 5:36 AM Rating: Excellent
***
1,002 posts
Unholyllama wrote:
If it doesn't get fixed soon, people will have to either remove real player or patch it if they want to use that particular site.

Or just use Firefox/Opera, as the exploit is in the ActiveX plugin.
#26 Dec 12 2007 at 5:44 AM Rating: Excellent
Glad I don't use realplayer.

Or IE7 at home.

And I haven't looked at Somepage's front page in months.
« Previous 1 2 3 4
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 376 All times are in CST
Anonymous Guests (376)