• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Collapse

You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:

  • You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
  • You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
  • If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.

Previously on "CUK May have yet another virus"

Collapse

  • Sysman
    replied
    Originally posted by Scoobos View Post
    I'd say the amateur hour is also on the code writer - since the malicious code seems to want to uninstall the environment it needs to run!!

    Java code wanting to uninstall Java Runtime??
    That had me wondering too.

    Perhaps they are hoping you will reinstall an ancient version you have lying around on disk?

    They could have been lying of course...

    ... or trying to point you at a dodgy version of Java to download

    Leave a comment:


  • Scoobos
    replied
    I'd say the amateur hour is also on the code writer - since the malicious code seems to want to uninstall the environment it needs to run!!

    Java code wanting to uninstall Java Runtime??

    Leave a comment:


  • alluvial
    replied
    Originally posted by NickFitz View Post
    Seems like it's primarily aimed at getting scareware on to systems: OpenX ads leading to malware c/o ‘BlackAdvertsPro’ | Naked Security
    Thanks Nick.
    Think I'd better run a full scan when I get back.
    I think I'd better review my antivirus provision as well. Any suggestions?

    Leave a comment:


  • BrilloPad
    replied
    Originally posted by Platypus View Post
    How so? Did I miss something?
    http://forums.contractoruk.com/gener...ml#post1542064

    Leave a comment:


  • NickFitz
    replied
    Originally posted by alluvial View Post
    Do you know what the virus is and what it does? Think I may have been hit by it last night and wondering if I'm fewked.
    Seems like it's primarily aimed at getting scareware on to systems: OpenX ads leading to malware c/o ‘BlackAdvertsPro’ | Naked Security

    Leave a comment:


  • alluvial
    replied
    Do you know what the virus is and what it does? Think I may have been hit by it last night and wondering if I'm fewked.

    Leave a comment:


  • Platypus
    replied
    Originally posted by BrilloPad View Post
    On the other hand only a few more days of putting up with MF.
    How so? Did I miss something?

    Leave a comment:


  • petergriffin
    replied
    Just disable the antivirus.

    Leave a comment:


  • BrilloPad
    replied
    Originally posted by MarillionFan View Post
    It's like ******* amateur hour on here. Come on Ad, sort your tulip out.
    I do hope Admin ups their rep power ang gives that -ve.

    On the other hand only a few more days of putting up with MF.

    Leave a comment:


  • administrator
    replied
    Originally posted by chef View Post
    I thought I'd go take a look at openx to see how expensive the non-opensource version is.

    I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.
    It's not the price but that it is hosted by them and as you said, they haven't been too hot in protecting themselves. Also this isn't a huge site and the hosted solution would be overkill for us. I am quite capable of hosting the thing, backing it up and working the interface without some grinning permie explaining to me how to use it. I just need the thing to be secure and to be told if / when there are patches or updates that need applying.

    Leave a comment:


  • Sysman
    replied
    Originally posted by chef View Post
    I thought I'd go take a look at openx to see how expensive the non-opensource version is.

    I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.
    It's a bit of an moment trying to look at their site with Javascript disabled

    And no, I don't feel inclined to switch JS on to see them, just in case there is still a nasty lurking.

    Leave a comment:


  • chef
    replied
    I thought I'd go take a look at openx to see how expensive the non-opensource version is.

    I don't think their site is intended to be viewed using adblock plus , however, given the malicious trojans that they seem to be bad at protecting themselves against then I'm not going to unblock their ad's to see. Ho hum.

    Leave a comment:


  • MarillionFan
    replied
    It's like ******* amateur hour on here. Come on Ad, sort your tulip out.

    Leave a comment:


  • administrator
    replied
    Cheers guys, yes looks to be the same beasty as last week. OpenX (ad manager) released a new patch yesterday:
    OpenX Blog » OpenX Source 2.8.9 Security Release

    Last time there was an upgrade released they emailed me on the three different addresses I have signed up to their mailing list, but this time nothing. Couple that with the source of the infection last week being a hack on their own site (OpenX CSRF Vulnerability Being Actively Exploited | InfosecStuff) then it does not leave me overly impressed with them but there is nothing else out there that I can find that gives me the functionality I would like (and no, dropping Trojans on you all is not the functionality I am looking for).

    Yes we did also have another hack a month or so ago but this was not the ad manager, it was vBulletin (the forum software) to blame...

    Can't remember the time before that but was about a year ago I think and I was able to catch that one pretty quickly but this year there does seem to be a raft of them.

    Do shoot me a PM if you spot anything like this as that goes to my email as well as the forum pop up so will spot things much quicker.

    I have cleaned up the source of the infection (JavaScript injection into the prepend field of all rows in the banner table, so not just the new banner that was infected) and then upgraded to the new version. That will have stopped the point of infection and should also stop us being open to the same attack again. Will be voicing my annoyance with OpenX for not emailing their users but as the system is Open Source and they want us to use their paid service then I doubt they will have much sympathy...

    Leave a comment:


  • Zippy
    replied
    Originally posted by AtW View Post
    Nice to see this place is full of CUK supporters.

    I have to use it or the Daily Wail site becomes unuseable. Honest guv.

    Leave a comment:

Working...
X