Approve the Cookies
This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and our Privacy Policy.
OK
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Guest
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Register to forums    Log in

 
FORUMS Community Talk, Chatter & Stuff The Lounge 
Thread started 03 Feb 2010 (Wednesday) 12:17
Search threadPrev/next
sponsored links (only for non-logged)

Awesome - just got virus thru Zach Arias' site

 
Mr. ­ Clean
Cream of the Crop
Avatar
6,002 posts
Likes: 3
Joined Jul 2005
Location: Olympia, Washington
     
Feb 03, 2010 12:17 |  #1

Clicked the link on his site to Radio Poppers and caught me an ITD. Internet Security 2010. Just FYI.
Wrong forum I know, but a high traffic area :D


Mike
some shots @ Zenfolio (external link)
Gear List

  
  LOG IN TO REPLY
Brett
Goldmember
Avatar
4,176 posts
Likes: 1
Joined Nov 2008
Location: Ohio
     
Feb 03, 2010 12:30 |  #2

Please point out the page with the link you clicked.



flickr (external link)

  
  LOG IN TO REPLY
Perfect_10
Goldmember
Avatar
1,998 posts
Likes: 7
Joined Aug 2004
Location: An Ex Brit living in Alberta, Canada
     
Feb 03, 2010 12:32 |  #3

Mr. Clean wrote in post #9533098 (external link)
.. caught me an ITD. Internet Security 2010. ..

You shouldn't go sippin' where someone's been dippin'

IMAGE: http://i1016.photobucket.com/albums/af290/Perfect_10_photos/Smilies/nono.gif

My Gear List  :p

  
  LOG IN TO REPLY
Mr. ­ Clean
THREAD ­ STARTER
Cream of the Crop
Avatar
6,002 posts
Likes: 3
Joined Jul 2005
Location: Olympia, Washington
     
Feb 03, 2010 12:39 |  #4

Brett wrote in post #9533172 (external link)
Please point out the page with the link you clicked.

Ah - I ain't goin' back. It was on the fron page IIRC, the link was RadioPoppers

Perfect_10 wrote in post #9533183 (external link)
You shouldn't go sippin' where someone's been dippin'
[GIFS ARE NOT RENDERED IN QUOTES]

amen brutha!


Mike
some shots @ Zenfolio (external link)
Gear List

  
  LOG IN TO REPLY
Brett
Goldmember
Avatar
4,176 posts
Likes: 1
Joined Nov 2008
Location: Ohio
     
Feb 03, 2010 13:04 |  #5

Mr. Clean wrote in post #9533238 (external link)
Ah - I ain't goin' back. It was on the fron page IIRC, the link was RadioPoppers

amen brutha!


The front page is all Flash with just a menu, so no RP links there.

Googling "site:zarias.com Radio Poppers" returns exactly one result:
http://www.zarias.com/​?p=281 (external link)

It's a page in his blog. There's a link to RP there:
**DON'T CLICK THIS** http://www.radiopopper​.com/blog (external link) **DON'T CLICK THIS**

That's a direct link; there's no javascript or link obfuscation from the zarias.com site.

Clicking that link takes you to the legit RP blog, but COMODO firewall stops AcroRd32.exe from loading. But, AcroRd32.exe is just an Adobe Acrobat Reader browser-integration file. Info here: http://kb2.adobe.com/c​ps/331/331506.html (external link)

COMODO reports that it attempted to "execute shellcode as a result of a possible buffer overflow attack. This is typical of a buffer overflow attack."

It sounds like something is amiss with the RP site. They are well-known and should be considered a "trusted" site, so it's possible an attack has been injected on their site. I'll shoot them an email to make them aware of it.

Edit: In fact, it's occurring on apparently all of their pages, including their front page. Email sent.



flickr (external link)

  
  LOG IN TO REPLY
Mr. ­ Clean
THREAD ­ STARTER
Cream of the Crop
Avatar
6,002 posts
Likes: 3
Joined Jul 2005
Location: Olympia, Washington
     
Feb 03, 2010 13:17 |  #6

Awesome job Brett, you're mostly right I think. I hit the front page using Chrome? I just googled Zach Arias...Maybe I just luckily hit that link.
Good job sending feedback too, my poor desktop is dyin'! Running malwarebytes right now...


Mike
some shots @ Zenfolio (external link)
Gear List

  
  LOG IN TO REPLY
Brett
Goldmember
Avatar
4,176 posts
Likes: 1
Joined Nov 2008
Location: Ohio
     
Feb 03, 2010 13:23 |  #7

Mr. Clean wrote in post #9533483 (external link)
Awesome job Brett, you're mostly right I think. I hit the front page using Chrome? I just googled Zach Arias...Maybe I just luckily hit that link.
Good job sending feedback too, my poor desktop is dyin'! Running malwarebytes right now...


Good luck. I'd be interested to know what the results are.

And get yourself a firewall! :)



flickr (external link)

  
  LOG IN TO REPLY
Brett
Goldmember
Avatar
4,176 posts
Likes: 1
Joined Nov 2008
Location: Ohio
     
Feb 03, 2010 13:51 |  #8

Todd Lambert wrote in post #9533536 (external link)
Man, so glad I'm on a Mac.... lol

Sorry ;-)a

Certainly doesn't make you entirely immune to malware, though. ;)

Radio Popper responded that they're looking into it now.



flickr (external link)

  
  LOG IN TO REPLY
Mr. ­ Clean
THREAD ­ STARTER
Cream of the Crop
Avatar
6,002 posts
Likes: 3
Joined Jul 2005
Location: Olympia, Washington
     
Feb 03, 2010 15:02 |  #9

Brett wrote in post #9533531 (external link)
Good luck. I'd be interested to know what the results are.

And get yourself a firewall!

Brett - worked like a charm! My desktop is good to go and I grabbed the free version of Comodo to try ;) Running another scan now just in case

Brett wrote in post #9533689 (external link)
Certainly doesn't make you entirely immune to malware, though. ;):)


Radio Popper responded that they're looking into it now.

Is it safe to go back yet :lol:


Mike
some shots @ Zenfolio (external link)
Gear List

  
  LOG IN TO REPLY
Brett
Goldmember
Avatar
4,176 posts
Likes: 1
Joined Nov 2008
Location: Ohio
     
Feb 03, 2010 21:53 |  #10

Mr. Clean wrote in post #9534164 (external link)
Brett - worked like a charm! My desktop is good to go and I grabbed the free version of Comodo to try ;) Running another scan now just in case

Is it safe to go back yet :lol:

Glad you're back in business. It doesn't seem to be huge threat to the PCs that visit that site, but I think there was an actual attack on radiopopper.com. Their site is currently completely down. :shock:

I'm glad you pointed it out here, so that I could alert them (something you should always try to do when you suspect an attack from a trusted site), and possibly save them some trouble.

So, you can try to go back, but it's currently a 404.



flickr (external link)

  
  LOG IN TO REPLY
sponsored links (only for non-logged)

3,945 views & 0 likes for this thread, 3 members have posted to it.
Awesome - just got virus thru Zach Arias' site
FORUMS Community Talk, Chatter & Stuff The Lounge 
AAA
x 1600
y 1600

Jump to forum...   •  Rules   •  Forums   •  New posts   •  RTAT   •  'Best of'   •  Gallery   •  Gear   •  Reviews   •  Member list   •  Polls   •  Image rules   •  Search   •  Password reset   •  Home

Not a member yet?
Register to forums
Registered members may log in to forums and access all the features: full search, image upload, follow forums, own gear list and ratings, likes, more forums, private messaging, thread follow, notifications, own gallery, all settings, view hosted photos, own reviews, see more and do more... and all is free. Don't be a stranger - register now and start posting!


COOKIES DISCLAIMER: This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and to our privacy policy.
Privacy policy and cookie usage info.


POWERED BY AMASS forum software 2.58forum software
version 2.58 /
code and design
by Pekka Saarinen ©
for photography-on-the.net

Latest registered member is Monkeytoes
1363 guests, 189 members online
Simultaneous users record so far is 15,144, that happened on Nov 22, 2018

Photography-on-the.net Digital Photography Forums is the website for photographers and all who love great photos, camera and post processing techniques, gear talk, discussion and sharing. Professionals, hobbyists, newbies and those who don't even own a camera -- all are welcome regardless of skill, favourite brand, gear, gender or age. Registering and usage is free.