Exploit Incognito Exploit on myats page, page 1
Pages:
ATS Members have flagged this thread 2 times
Topic started on 20-9-2011 @ 04:34 PM by pthena
I just got a warning from virus scanner when I opened www.abovetopsecret.com... that
file name: zdcxz.myz.info/showthread.php?t=xxxxxxxx (numbers removed for privacy)
is Exploit Incognito Exploit kit (type 1473)

This kind of bums me out.
Can this be checked out?

Edit to add:
According to this website: www3.malekal.com...
its TrojanDownloader:Win32/Karagany.A
antivir: TR/Spy.ZBot.325690

edit on 20-9-2011 by pthena because: (no reason given)



reply posted on 20-9-2011 @ 05:14 PM by PlayeR87
reply to post by pthena



Yup my Anti-Virus picked up on it too, same exploit



reply posted on 21-9-2011 @ 01:22 AM by jamsession
reply to post by MuchTooSerious



ats might be a clean and safe place while those hosting the advertisers or their links to other servers may not. always good idea to keep an antivirus program with a functional antispyware feature in the background.


reply posted on 21-9-2011 @ 01:36 AM by pthena
reply to post by jamsession

ats might be a clean and safe place while those hosting the advertisers or their links to other servers may not. always good idea to keep an antivirus program with a functional antispyware feature in the background.

I viewed source generated by the .php file and saw tons of _javascript calls. The actual call for zdcxz.myz.info/showthread.php wasn't on the site .php so must have been one of the advertisers called by a _javascript.

Should there be rules about restricting advertisers from putting malware on webpages in order to appear on this site? That would seem reasonable to me.


reply posted on 21-9-2011 @ 02:46 AM by jamsession
reply to post by SkepticOverlord



i had experienced this issue also on the website of another community before. perhaps ad rotators (if any) run on the advertiser's server, which would be otherwise legit, could be the cause, ie. the connection to a website with the bad code may be there for an instance and gone afterwards.


reply posted on 21-9-2011 @ 04:15 PM by pthena
reply to post by SkepticOverlord

Our ads are scanned every day, and there are no alerts.

Thank you. I wouldn't expect anyone to do more than daily checkups on ads, else there wouldn't be time for anything else.

Thank you.


reply posted on 21-9-2011 @ 04:21 PM by pthena
reply to post by jamsession

perhaps ad rotators (if any) run on the advertiser's server, which would be otherwise legit, could be the cause, ie. the connection to a website with the bad code may be there for an instance and gone afterwards.

I think that's it also. When I viewed source no sign on this sites .php generated html. And my resident shield didn't give any later alert.

I think there are just too many spiderwebbing connections on the WWW for any one to deal with them all.



reply posted on 21-9-2011 @ 04:28 PM by pthena
reply to post by Kryties

You've probably picked up a virus somewhere else (hint: stop looking at porn) that takes a while to start manifesting itself.

That's why I use a separate computer for porn. I've discovered that game hacking websites are much worse than porn sites for malicious codes.

The worse codes attach themselves to automatic updaters such as adobe acrobat reader updater and Java updater. I quit using adobe acrobat reader and went with a 3rd party pdf reader. Haven't had to wipe my harddrive since.

edit on 21-9-2011 by pthena because: (no reason given)

Pages:     ^^TOP^^