UltraBB Forums Home 
Home Search search Menu menu Not logged in - Login | Register
UltraBB Forums > UltraBB > Troubleshooting > FLASH CHAT WARNING

Welcome to the UltraBB public support forum! Did you know there is an inexpensive totally integrated gallery available for UltraBB? Read more here: Gallery Details

 Moderated by: Fake Mod Page:    1  2  Next Page Last Page  
New Topic Reply Printer Friendly
FLASH CHAT WARNING  Rate Topic 
AuthorPost
 Posted: Mon Dec 28th, 2009 11:08 am
  PM Quote Reply
1st Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
The virus we have all had to deal with could have originated from flash chat. Flash chat it's self (the folders on your site) are not infected, however a web reference in one of the preload flash routines point at an infected page spreading the virus.

IF YOU HAVE FLASH CHAT GET RID OF IT. DELETE THE FOLDER OR RENAME THE FOLDER AND CONTACT ME. IF YOU VISIT ANOTHER SITE WITH FLASH CHAT WARN THEM.

This way it can't be spread. As ming ming duck would say... "This is sewious"

Jim

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 12:06 pm
  PM Quote Reply
2nd Post
wingnutter
Forever Learning


Joined: Wed May 14th, 2008
Location: Ireland
Posts: 1843
Status: 
Offline
Mana: 
User Gallery
Can we just change the web reference Jim?

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 12:37 pm
  PM Quote Reply
3rd Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
They might have the link saved.That's why changing the folder name is safest.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 03:08 pm
  PM Quote Reply
4th Post
EricC
Worm Can Opener


Joined: Wed Jun 11th, 2008
Location: Altamont, New York USA
Posts: 325
Status: 
Offline
Mana: 
User Gallery
Jim wrote: This way it can't be spread. As ming ming duck would say... "This is sewious"

Jim


You can tell who has young children.....;)

 

....So seeing as I do not have Flash Chat is why I did not get infected?

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 03:12 pm
  PM Quote Reply
5th Post
Mag
License Holder
 

Joined: Thu Jan 31st, 2008
Location: England, United Kingdom
Posts: 1407
Status: 
Online
Mana: 
User Gallery
Seems like that to me Eric, our site was ok as well and we don't use any chat programs.

Aha Jim, so the boys watch Wonder Pets LOL

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 03:15 pm
  PM Quote Reply
6th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
LOL Flash chat might be what was unsuspectingly spreading it big time. A google search on the actual injected virus JS:Illredir-A shows TONS of sites on tons of hosts hit since right before Christmas. It was wide spread but since a lot of ex wow users have flash chat AND the infection isn't in the actual files it would be impossible to detect and quick to spread.

Avast only added that particular strain on the 21st of this month. Now variant B is sweeping....

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 03:43 pm
  PM Quote Reply
7th Post
Di
Administrator


Joined: Sat Apr 28th, 2007
Location: Columbus, Ohio USA
Posts: 2683
Status: 
Offline
Mana: 
User Gallery
Mag wrote:
Aha Jim, so the boys watch Wonder Pets LOL

LOL! what do you think?

Attached Image (viewed 100 times):

ming_ming.jpg

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 04:25 pm
  PM Quote Reply
8th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
Jim wrote: Avast only added that particular strain on the 21st of this month. Now variant B is sweeping....
It's variant B that's affecting my forum. One of my members is a major retail supplier of kit to the hobby and every time I go to a page where he has posted I get this warning :

yourmodelrailway.net/images/avatars/contains sample of JS:Illdirect B (Trj)

If I delete his post then there's no problem with the rest of the topic.
This member doesn't have an avatar and has never had one. I have contacted him and he says because of the importance to his business his machines are continuously scanned for viruses etc and they are clean.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 04:40 pm
  PM Quote Reply
9th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
EDIT: deleted

See next.

Last edited on Mon Dec 28th, 2009 04:52 pm by martin_wynne

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 04:50 pm
  PM Quote Reply
10th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Hi Bob,

Forget everything I just said. :whatever:

The index.php file in your /avatars/ folder (which should be empty) is infected, and my ESET NOD32 AV has now found it.

More to the point, the virus is actually called: JS/TrojanDownloader.Agent.NRL

which means that at long last I can search for some meaningful information about it. So thanks for that at least. See attached.

regards,

Martin.

Attached Image (viewed 92 times):

ymr_virus.png

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 05:07 pm
  PM Quote Reply
11th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
There's not supposed to be an index.php in avatar folders......

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 05:11 pm
  PM Quote Reply
12th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
It's gone now :)

It was index.html. It's supposed to be blank. The virus has not previously written to blank index files.

It looked like someone uploaded an alternate index file then it got hacked. Good catch Martin.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 05:14 pm
  PM Quote Reply
13th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
OK I just checked about 6 previously infected sites, all had a zero K file size for index.html in the avatar folder. Seems like a Bob exclusive.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 05:16 pm
  PM Quote Reply
14th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
martin_wynne wrote: Hi Bob,

Forget everything I just said. :whatever:

The index.php file in your /avatars/ folder (which should be empty) is infected, and my ESET NOD32 AV has now found it.

More to the point, the virus is actually called: JS/TrojanDownloader.Agent.NRL

which means that at long last I can search for some meaningful information about it. So thanks for that at least. See attached.

regards,

Martin.

Martin:

The different virus protection companies name the viruses themselves and they can be different names. I examined the virus string, except for the base 64 encoded URL it was identical.

Thanks for finding this Martin, Bob can rest a little better now.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 05:38 pm
  PM Quote Reply
15th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Jim wrote:The different virus protection companies name the viruses themselves and they can be different names.
Yes I know, and it makes it next to impossible to search for information about a specific virus, or to be sure that any information found is relevant.

ESET NOD32 last updated the virus signature for this one on 25th December, and first detected it on 16th December.



Bob can rest a little better now.
Maybe, but I think he would rest even better if he knew how it became infected in the first place, and how to prevent it happening again. Previous measures to protect the FTP password seem to have failed? :?

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 05:48 pm
  PM Quote Reply
16th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
That's why I figured he was infected, all but one other site I changed the password on didn't get re infected. The other (after the reinfection) I changed the password and didn't tell them what it was for a few days, no reinfections after that.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 06:01 pm
  PM Quote Reply
17th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Jim wrote: That's why I figured he was infected, all but one other site I changed the password on didn't get re infected. The other (after the reinfection) I changed the password and didn't tell them what it was for a few days, no reinfections after that.
Hi Jim,

On the Control Panel for my UK hosting provider (it's not cPanel), I can turn off all FTP access. I have now taken to doing that -- I turn it on only for a few minutes when I need to do an FTP transfer, and then turn it off again.

But I can't seem to do that in cPanel, unless I'm missing something?

Even more worrying is that the the main account FTP password seems to be the same as the cPanel password -- so if it's stolen, the cPanel could also be hacked?

On my UK hosting, the passwords are different, and the Control Panel has a captcha in the login.

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 06:18 pm
  PM Quote Reply
18th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
An exclusive for me. How flattering but I could have done without it. Must hurry back to the forum now and check for myself.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 06:52 pm
  PM Quote Reply
19th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
Update on the above. No trace of the virus found so it looks like we are clear once more. Thankfully there doesn't appear to be any damage caused but the nuisance value has been very high indeed. As a matter of interest I downloaded my database this morning and ran Avast, Ad-Aware and Superantispyware over it to no effect, as far as they were concerned it was clean.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 09:13 pm
  PM Quote Reply
20th Post
Devans
License Holder


Joined: Tue May 27th, 2008
Location: Iowa USA
Posts: 1398
Status: 
Offline
Mana: 
User Gallery
Hey Jim,

As you know, I used to use Flash Chat, on our forum. I have since upgraded to the new chat program, that you have here. I do, however, still have the Flashchat, although I have removed all links to it, in the forum. Should the Flash Chat folder(s) be deleted from cpanel?

I have no intentions on using it again, I just was unsure of which files and folders to remove.

Back To Top PM Quote Reply

Current time is 10:39 am Page:    1  2  Next Page Last Page    
UltraBB Forums > UltraBB > Troubleshooting > FLASH CHAT WARNING Top



Hosting

UltraBB 1.17 Copyright © 2007-2011 Data 1 Systems, INC.
Page processed in 0.5051 seconds (10% database + 90% PHP). 31 queries executed.