PDA

View Full Version : New Virus [Read]



AgnesIO
17-12-2009, 07:40 AM
Just a warning to you guys, found on Yahoo by a mate:

http://uk.news.yahoo.com/5/20091216/twl-net-users-warned-of-social-networkin-3fd0ae9.html

Basically a trick video messaage thing going round on Social Networking sites, when you click to play the video a Captcha comes up (Tells the difference between a computer of human), if you do not get the correct Captcha in 3 minutes your computer freezes etc.

:)

Techian
17-12-2009, 11:30 AM
That Why I never watch videos on facebook etc..

Kevin
17-12-2009, 12:30 PM
I'm sure most anti-viruses are able to detect it, no need to live in fear, lol.

Agnostic Bear
17-12-2009, 03:00 PM
I'm sure most anti-viruses are able to detect it.

not likely, not all antiviruses have proactive defenses and heuristics.

Kevin
17-12-2009, 03:10 PM
not likely, not all antiviruses have proactive defenses and heuristics.

I didn't say all anti-viruses, my one does though (eset)

AgnesIO
17-12-2009, 04:02 PM
I'm sure most anti-viruses are able to detect it, no need to live in fear, lol.

Actually I am not living in fear..

I am warning people against the attack, whether viruses are easy to get rid of or not (normally are), it's always nice to know what thw virus is, and the best way to fight. 'lol'

syko2006
17-12-2009, 04:08 PM
Thanks for the heads up. :)

Recursion
17-12-2009, 04:19 PM
LOLLLL It can't freeze your computer if you don't enter a Captcha.

AgnesIO
17-12-2009, 04:35 PM
LOLLLL It can't freeze your computer if you don't enter a Captcha.

LOLLLL just going by Yahoo :rolleyes:

N!ck
17-12-2009, 05:04 PM
The stupid organic material between keyboard and chair is the reason this sort of thing spreads. Don't click on "omglookatthispictureofyoulol.exe".

While not particularly related to this situation, the same principle still applies.

Chippiewill
17-12-2009, 05:08 PM
Also don't open any files with the extension:

.htm .pdf .mp3 and more, they can contain executable code which installs a virus ... LAME. (The times we now live in).

Although IE8's DEP will prevent such event occuring (Yay for safer IE8)

AgnesIO
17-12-2009, 05:31 PM
The stupid organic material between keyboard and chair is the reason this sort of thing spreads. Don't click on "omglookatthispictureofyoulol.exe".

While not particularly related to this situation, the same principle still applies.


Xmas e-card are sadly more believable


:D I love those look at picture things - do people actually fall for those??

Recursion
17-12-2009, 08:07 PM
Also don't open any files with the extension:

.htm .pdf .mp3 and more, they can contain executable code which installs a virus ... LAME. (The times we now live in).

Although IE8's DEP will prevent such event occuring (Yay for safer IE8)

OH NOEZZZZ! No more web designing, chart referring or music listening for me! :(

Chippiewill
17-12-2009, 09:36 PM
OH NOEZZZZ! No more web designing, chart referring or music listening for me! :(

Unless you trust the source, if you're not being spied on by the Chinese government that is...

http://en.wikipedia.org/wiki/GhostNet

They actually hijacked emails, sent from infected computers, to add viruses within pdfs sent to other people in order to infect them.

Agnostic Bear
17-12-2009, 10:40 PM
Unless you trust the source, if you're not being spied on by the Chinese government that is...

http://en.wikipedia.org/wiki/GhostNet

They actually hijacked emails, sent from infected computers, to add viruses within pdfs sent to other people in order to infect them.

That's pdf files, you cannot get a virus from an mp3 or .htm file (well I suppose you could from a .htm file redirecting you somewhere, but its' very unlikely)

HotelUser
17-12-2009, 11:31 PM
I am safe :)

xxMATTGxx
17-12-2009, 11:54 PM
I am safe :)

Is that your comment because you own a Mac? Even though, only people who don't know what they are doing are going to click links that end in LOOKATKATELALALA.EXE etc.

HotelUser
18-12-2009, 12:00 AM
Is that your comment because you own a Mac? Even though, only people who don't know what they are doing are going to click links that end in LOOKATKATELALALA.EXE etc.

No. It's because I'm not a moron and don't click files called SEXYMATT.PNG.EXE.

Actually I wasn't even thinking anything about OS X. There might not be as many but there's still horror stories about some nasty infections for us.

xxMATTGxx
18-12-2009, 12:02 AM
No. It's because I'm not a moron and don't click files called SEXYMATT.PNG.EXE.

Actually I wasn't even thinking anything about OS X. There might not be as many but there's still horror stories about some nasty infections for us.

You know you would click that!

HotelUser
18-12-2009, 12:04 AM
You know you would click that!

You just want me to click it for personal reasons which I cannot discuss!!!

Chippiewill
18-12-2009, 07:13 AM
That's pdf files, you cannot get a virus from an mp3 or .htm file (well I suppose you could from a .htm file redirecting you somewhere, but its' very unlikely)

You can, there may not be an exploit right now but there has been, that's why you should NEVER open email attachments. Ever..

If you want proof then listen to some 'Security Now!' podcasts episodes from March-May.

Agnostic Bear
18-12-2009, 09:44 AM
You can, there may not be an exploit right now but there has been, that's why you should NEVER open email attachments. Ever..

If you want proof then listen to some 'Security Now!' podcasts episodes from March-May.


You can't get a virus from an mp3 file. ever.

Kevin
18-12-2009, 04:54 PM
You can, there may not be an exploit right now but there has been, that's why you should NEVER open email attachments. Ever..

If you want proof then listen to some 'Security Now!' podcasts episodes from March-May.


The mp3 format does not allow you to execute code

Chippiewill
18-12-2009, 05:42 PM
The mp3 format does not allow you to execute code

The format might not, but you can you say the same for the player?

Agnostic Bear
18-12-2009, 05:44 PM
The format might not, but you can you say the same for the player?

Yes, yes I can.

Kevin
18-12-2009, 05:53 PM
The format might not, but you can you say the same for the player?

hey mr 1337 haxxk0r, do what you believe to be possible, and pm me the download link. I'll test it out on my VM

Chippiewill
18-12-2009, 06:31 PM
Security Now: Episode 197 23:00 - 28:07

'It's always scary when an exploit affects data files because everybody who listens to this show, anyway, knows to avoid executables.'

'And of course you back up data files. So you don't think, oh, a JPG, a PDF, an MP3. Those are harmless.'

'Well, and somewhere somebody was writing code to parse and process the samples in an MP3 sound file. They weren't thinking about security. They were thinking about getting the darn thing to work so that sounds come out. And it turns out that, as a consequence of that, if you give it a deliberately specially crafted sound file, an MP3 file, it will cause a hiccup in the processing that allows you then to, like, cause the rest of the sound buffer to be jumped into. So you have this special set of samples which causes this integer overflow, which causes the execution of the rest of the buffer. So you literally are putting a program into the sound file with a header that gets this vulnerable version of the library to execute the following code. And as soon as you do that, it can bring in some more code, take over your machine, go off to somewhere malicious, and install backdoors and trojans and worms. And, I mean, it's just the reality of computing today.'

I iz super 1337 haxxorr

http://aolradio.podcast.aol.com/sn/SN-187.mp3

Recursion
18-12-2009, 07:40 PM
Podcasts are like Wikipedia, usually right, but not always.

Chippiewill
18-12-2009, 07:45 PM
Podcasts are like Wikipedia, usually right, but not always.


:rolleyes: typical, cannot accept the truth... He is well known in the Security sector and is very well respected. He has one of the most accurate podcasts I know, he actually spends several hours preparing each one to check that his details are correct. If he was not in fact correct (On the rare occasion) he would have brought it up in the subsequent episode. He actually created his own e-commerce system.

You can look up the guy at grc.com

Want to hide these adverts? Register an account for free!