Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
ugh its Troika
May 2, 2009

by FactsAreUseless
gently caress Java and gently caress it's million versions that all install at once.

Adbot
ADBOT LOVES YOU

Qualor
Jan 7, 2004
Beware the ladle...

Megiddo posted:

Any word on whether this latest flaw also affects Java 6?

I'm just going to assume that Java 6 is also affected. I don't even want to think about trying to downgrade again given how much of a massive pain it was to get Java 6 to work after previously having Java 7 installed.

Java 6 was not affected. The security flaw was in a new class introduced in 7.0

See this for more:
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html

Megiddo
Apr 27, 2004

Unicorns bite, but their bites feel GOOD.
I was talking about a new flaw with 7u7:

http://www.theregister.co.uk/2012/08/31/critical_flaw_found_in_patched_java/

Craptacular!
Jul 9, 2001

Fuck the DH
If you've got a computer illiterate who is emailing spam links to everyone in their address books and isn't aware they have malware, where do you tell them to go?

I've got one of these, and I figured safety.live.com is a good start, but otherwise didn't know if there's anything better.

Ceros_X
Aug 6, 2006

U.S. Marine

Craptacular! posted:

If you've got a computer illiterate who is emailing spam links to everyone in their address books and isn't aware they have malware, where do you tell them to go?

I've got one of these, and I figured safety.live.com is a good start, but otherwise didn't know if there's anything better.

Meatspin

Smart Car
Mar 31, 2011

Goatse, mention it reminded you of their computer.

Garmann
Nov 4, 2009
Grimey Drawer

EvilMuppet posted:

But I need Java for my Minecraft :(

If my memory serves you'll be fine with this as it's only the plugin that serves as an attack vector for this, not standalone things that the JRE runs. You can keep building that skytower or whatever, just disable the java browser plugin.

randomidiot
May 12, 2006

by Fluffdaddy

(and can't post for 11 years!)

Scaramouche posted:

This makes me think of your stepdad as some Randall Flagg-esque character, roaming the world, sowing trouble where-ever he goes.

Guess who's infected again? :v:

randomidiot fucked around with this message at 13:11 on Sep 4, 2012

Seat Safety Switch
May 27, 2008

MY RELIGION IS THE SMALL BLOCK V8 AND COMMANDMENTS ONE THROUGH TEN ARE NEVER LIFT.

Pillbug

some texas redneck posted:

Guess who's infected again? :v:
Jesus. Buy your dad an iPad or something already. It's like repairing the car of someone who keeps crashing into daycares while reading Playboy.

Ceros_X
Aug 6, 2006

U.S. Marine

some texas redneck posted:

Guess who's infected again? :v:

You really should have left the first version of that post, it was spot on.

Factory Factory
Mar 19, 2010

This is what
Arcane Velocity was like.
Java chat? Java chat. Hackers bust open an FBI laptop using a Java exploit to steal over 12 million UDIDs, in many cases with associated personal information, for Apple iDevices.

http://www.macrumors.com/2012/09/04/hackers-release-1-million-ios-device-udids-obtained-from-fbi-laptop/

randomidiot
May 12, 2006

by Fluffdaddy

(and can't post for 11 years!)

Ceros_X posted:

You really should have left the first version of that post, it was spot on.

I was afraid of getting probated for PUI when I woke up :v:

Seat Safety Switch posted:

Jesus. Buy your dad an iPad or something already. It's like repairing the car of someone who keeps crashing into daycares while reading Playboy.

His pile of get rich quick schemes daytrading and speculation software only runs on Windows.

computer parts
Nov 18, 2010

PLEASE CLAP

Factory Factory posted:

Java chat? Java chat. Hackers bust open an FBI laptop using a Java exploit to steal over 12 million UDIDs, in many cases with associated personal information, for Apple iDevices.

http://www.macrumors.com/2012/09/04/hackers-release-1-million-ios-device-udids-obtained-from-fbi-laptop/

I guess the question now is "why did the FBI have this information".

Nintendo Kid
Aug 4, 2011

by Smythe

computer parts posted:

I guess the question now is "why did the FBI have this information".

At first I thought it was a registry of devices being used by the FBI and its staff. Then I realized that 12 million devices is 4 times as many people as work for any branch of the federal government, and the FBI itself only has 35,890 workers.

There's about 47 million active iPhones in the US (about half of Americans own smartphones, about 30% of those smartphones that are active are iPhones), so the FBI apparently recorded information on a little over 1/4 of them.

angrytech
Jun 26, 2009
The moment I've waited for, time to send out a mass "I told you so" to everyone who's ever called me paranoid.

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


Install Gentoo posted:

At first I thought it was a registry of devices being used by the FBI and its staff. Then I realized that 12 million devices is 4 times as many people as work for any branch of the federal government, and the FBI itself only has 35,890 workers.

There's about 47 million active iPhones in the US (about half of Americans own smartphones, about 30% of those smartphones that are active are iPhones), so the FBI apparently recorded information on a little over 1/4 of them.

Maybe they have info on all of them and the laptop in question didn't have a complete database. Something that large, well why have 1 person hold on to all the data?

Nintendo Kid
Aug 4, 2011

by Smythe

pixaal posted:

Maybe they have info on all of them and the laptop in question didn't have a complete database. Something that large, well why have 1 person hold on to all the data?

Well that's the thing, why exactly would the FBI have that data at all? There's not really a reason the FBI should have it, no way that there's 12 million iPhone users suspected in crimes that would justify having this data. Or even the million or so who had more info in the data.

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


List of compromised accounts? Maybe its evidence and someone hacked a ton of iPhones with a new keylogger app, or something else. I'm sure if you are creative you can think of legitimate reasons. Or you can go with the government spying on you which could be true, I mean we have all the 9/11 laws that basically let them do it I think, I'm not an expert and that's a topic for another thread anyways.

I had a roomate that used to "hack" the local network at a collage and he had a 3TB database on the students back in 2006. He basically just through a custom trojan up on the local DC++ that everyone used to share :filez: listed it as porn and displayed said images.

It really could just be part of a hackers database, if the person was working on the case it could explain it.

Independence
Jul 12, 2006

The Wriggler

pixaal posted:

List of compromised accounts? Maybe its evidence and someone hacked a ton of iPhones with a new keylogger app, or something else. I'm sure if you are creative you can think of legitimate reasons. Or you can go with the government spying on you which could be true, I mean we have all the 9/11 laws that basically let them do it I think, I'm not an expert and that's a topic for another thread anyways.

I had a roomate that used to "hack" the local network at a collage and he had a 3TB database on the students back in 2006. He basically just through a custom trojan up on the local DC++ that everyone used to share :filez: listed it as porn and displayed said images.

It really could just be part of a hackers database, if the person was working on the case it could explain it.

It also could be part of The Program.

https://www.youtube.com/watch?v=r9-3K3rkPRE

Factory Factory
Mar 19, 2010

This is what
Arcane Velocity was like.
Well, now the FBI is saying there is no evidence of an attack or that the FBI sought or obtained any UDID data in the first place.

mindphlux
Jan 8, 2004

by R. Guyovich
alright, virus kit rollcall

what you guys got in your kits?

code:
09/05/2012  04:26 PM    <DIR>          .
09/05/2012  04:26 PM    <DIR>          ..
06/14/2012  05:29 PM    <DIR>          BlueScreenView
09/05/2012  04:08 PM         4,743,773 ComboFix.exe
06/14/2012  05:34 PM    <DIR>          Data+Password Recovery
12/01/2011  11:55 AM         1,932,256 FixTDSS.exe
09/05/2012  04:14 PM    <DIR>          GMER Rootkit Remover
12/01/2011  12:02 PM    <DIR>          Guides
09/05/2012  04:16 PM    <DIR>          HijackThis
09/05/2012  04:19 PM    <DIR>          HOSTSpermissionreset
09/05/2012  04:11 PM        10,651,816 mbam-setup.exe
09/05/2012  04:21 PM        10,288,512 mseinstall7x32.exe
09/05/2012  04:21 PM        12,621,696 mseinstall7x64.exe
09/05/2012  04:20 PM        10,288,512 mseinstallXP.exe
06/14/2012  05:36 PM    <DIR>          ProcessExplorer
06/14/2012  05:26 PM    <DIR>          ProduKey
09/05/2012  04:11 PM    <DIR>          rkill
09/05/2012  04:15 PM        19,572,648 SUPERAntiSpyware.exe
09/05/2012  04:22 PM         2,211,928 tdsskiller.exe
09/05/2012  04:12 PM    <DIR>          Unhide
06/14/2012  05:31 PM    <DIR>          Uninstaller
06/14/2012  05:48 PM    <DIR>          WhatisHang
12/01/2011  12:08 PM           108,368 zbotkiller.exe

Khablam
Mar 29, 2012

code:
nothing
I sandbox my browser and I've not had a single virus that couldn't be removed by right clicking "end process" in my taskbar. To that end, I have removed resident A/V from my system as it's nothing more than a resource hog (and virustotal is the best on-demand for anything suspicious anyway).

I have literally no idea why people ever, ever trust a browser to interact with their base OS, or to that end, need it to.

e: if we're talking about offering tech support to others, then anything that hooks itself in and requires indepth cleaning is pretty much "reinstall OS, fix everything"

Khablam fucked around with this message at 17:47 on Sep 11, 2012

Gothmog1065
May 14, 2009

Khablam posted:

code:
nothing
I sandbox my browser and I've not had a single virus that couldn't be removed by right clicking "end process" in my taskbar. To that end, I have removed resident A/V from my system as it's nothing more than a resource hog (and virustotal is the best on-demand for anything suspicious anyway).

I have literally no idea why people ever, ever trust a browser to interact with their base OS, or to that end, need it to.

e: if we're talking about offering tech support to others, then anything that hooks itself in and requires indepth cleaning is pretty much "reinstall OS, fix everything"

I think I generally do MalwareBytes, Combofix and MSE. If those three can't get it, I generally just format and be done with it.

Laserface
Dec 24, 2004

Gothmog1065 posted:

I think I generally do MalwareBytes, Combofix and MSE. If those three can't get it, I generally just format and be done with it.

Ccleaner first (wipes browser cache) to make malware bytes scan not take 1000 years.

Matlock
Sep 12, 2004

Childs Play Charity 2011 Total: $1755
I'm a big fan of Kaspersky Rescue Disk lately. Haven't seen anything it can't rip out.

Ceros_X
Aug 6, 2006

U.S. Marine

Khablam posted:

code:
nothing
I sandbox my browser and I've not had a single virus that couldn't be removed by right clicking "end process" in my taskbar. To that end, I have removed resident A/V from my system as it's nothing more than a resource hog (and virustotal is the best on-demand for anything suspicious anyway).

I have literally no idea why people ever, ever trust a browser to interact with their base OS, or to that end, need it to.


Can you post some specifics on what program you use (Sandboxie?) and any config steps you take?

sfwarlock
Aug 11, 2007

Laserface posted:

Ccleaner first (wipes browser cache) to make malware bytes scan not take 1000 years.

Except check for the smtmp folders before that.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.

sfwarlock posted:

Except check for the smtmp folders before that.
Yea this sucks I always want to bash the first level tech upside the head that dumps the temp folder before escalating not only for the smtmp folder but also it wipes out potential samples of droppers or downloaders that I can submit for definitions updates.

Impotence
Nov 8, 2010
Lipstick Apathy
Blackhole exploit kit 2.0 out



Anyone speak russian?

Khablam
Mar 29, 2012

Ceros_X posted:

Can you post some specifics on what program you use (Sandboxie?) and any config steps you take?
I do indeed use sandboxie. Default options work just fine, though I drop rights just to be sure. I'm sure the actual attack vectors against sandboxed applications are theoretical at this point, however.

I don't know how it compares to other sandbox options on the market, so I can only recommend this one. The free version is functionally very similar to the paid version - you gain a nag and the inability to force programs to always run sandboxed; meaning you need to load the programs into it (right click).

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
http://malware.dontneedcoffee.com/2012/09/blackhole2.0.html

Has a google translate copy of the BHEK2.0 notes, it isn't pretty but I guess it gets the job done.

Zogo
Jul 29, 2003

Khablam posted:

I do indeed use sandboxie. Default options work just fine, though I drop rights just to be sure. I'm sure the actual attack vectors against sandboxed applications are theoretical at this point, however.

Do you use the experimental protection mode (for 64-bit Windows OSs)? I haven't tried it because they say it can cause system instability but I'm curious if anyone uses it.

http://www.sandboxie.com/index.php?ExperimentalProtection

BTW I also drop right (default option). The user account I use is a standard user anyway too.

edit: I highly recommend Sandboxie for anyone who doesn't mind opening an extra program and clicking an extra button after downloading items. I've been using it for over a year and it's worked almost perfectly (one flash update did have a conflict a few months back but was resolved by getting the latest version of Sandboxie). The only thing I do that won't work through Sandboxie is Netflix streaming. That's the only reason I run Firefox unprotected now.

Zogo fucked around with this message at 00:31 on Sep 13, 2012

Khablam
Mar 29, 2012

Zogo posted:

Do you use the experimental protection mode (for 64-bit Windows OSs)? I haven't tried it because they say it can cause system instability but I'm curious if anyone uses it.

http://www.sandboxie.com/index.php?ExperimentalProtection

BTW I also drop right (default option). The user account I use is a standard user anyway too.

I don't use it, since by that point you're looking at extreme edge cases in terms of a threat. From what I know about it, you would basically already need to be infected with a rootkit for any process running sandboxed to have something meaningful to do.

The likelihood of someone writing incredibly complex malware which would end up targeting a very very small percentage of machines is pretty small, so I don't lose any sleep over it; it's a numbers game to them, like casting a net.
I can tell you I can deliberately execute all of the worst rootkits out there, to no ill effect.

Revitalized
Sep 13, 2007

A free custom title is a free custom title

Lipstick Apathy
For some reason my Google search links *occasionally* redirect me somewhere else of some vaguely related site to my search.

Unfortunately Malware Bytes and MSE both say my computer is clean. My hosts file looks like it should (I think, with just the single local line on it) So what else is left?

sfwarlock
Aug 11, 2007
Combofix.

m2pt5
May 18, 2005

THAT GOD DAMN MOSQUITO JUST KEEPS COMING BACK

Revitalized posted:

For some reason my Google search links *occasionally* redirect me somewhere else of some vaguely related site to my search.

Unfortunately Malware Bytes and MSE both say my computer is clean. My hosts file looks like it should (I think, with just the single local line on it) So what else is left?

If you're using Firefox, it sounds like you have GooRed. (Google Redirect.) There's a specific fix for it - GooRedFix.

Revitalized
Sep 13, 2007

A free custom title is a free custom title

Lipstick Apathy

m2pt5 posted:

If you're using Firefox, it sounds like you have GooRed. (Google Redirect.) There's a specific fix for it - GooRedFix.

I am indeed using Firefox, and I tried the GooRedFix. It was done in a second but I still seem to get redirected on first click. I just decided to google "What exactly does Combofix do?" and the first link was to a forum post. Clicking on it redirected me to a Norton Security advertisement page, but I went back and clicked the link again and it took me through to the forum post.

I have combofix from when I was dealing with the Siefer previously, but it sounds a bit extreme, and also takes forever without moving, so I have no idea if my combofix died in the process or something. I guess I can just combofix before I go to sleep or something.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
If you run TDSSKiller does it execute? You mentioned Sirefef so i'm wondering if it managed to install the SST bootkit and that hasn't been cleaned properly.

xov
Nov 14, 2005

DNA Ts. Rednum or F. Raf
Perform a google search for one of the urls that you are being redirected to, and see where that leads you. Most browser redirects I've seen with no other symptoms are usually rootkits of some type.

Adbot
ADBOT LOVES YOU

SuperNuts
May 7, 2004

From the frozen north a... squirrel emerges?!?
:haw:

mindphlux posted:

alright, virus kit rollcall

what you guys got in your kits?

MBAM
Auto-Runs
Process Explorer
GMER/MBR

All you need really.

  • Locked thread